Over the past year, we have been asked with increasing frequency by foreign companies looking to enter the U.S. market: “If we want to work with the U.S. defense industry, what do we actually need to do?”
The question is usually driven by real opportunity. Many foreign companies manufacture advanced products used in automotive, industrial, or technology markets — products that are also attractive to U.S. defense customers. But the U.S. defense ecosystem is often misunderstood, particularly by non-U.S. companies unfamiliar with how national security, export controls and corporate structure intersect.
The reality is that not all defense work is classified, not all defense customers impose the same requirements and not all compliance obligations arise at the same stage of a company’s growth. Understanding these distinctions early can prevent over-structuring, under-compliance and costly delays.
Throughout this article, we will occasionally return to a hypothetical German automotive supplier as an illustrative example — not because these issues are unique to Germany or automotive companies, but because it helps ground abstract rules in a practical, familiar scenario.
Not All Defense Work Is Classified
One of the most common misconceptions is that any work connected to the defense sector automatically involves classified information. That is not the case. Defense-related work generally falls into three broad categories.
- Commercial and dual-use work involves products that are designed for civilian markets but are also useful to defense customers. For example, a German automotive supplier may manufacture advanced radar or sensor systems used in commercial vehicles for collision avoidance or autonomous driving. Those same sensors may be attractive for military logistics vehicles or surveillance platforms. At this stage, the work is often unclassified, does not require a facility security clearance and can typically be performed through a standard U.S. subsidiary. However, this does not mean the work is unregulated. Export controls often apply even when the end product is sold commercially.
- The second category is work involving Controlled Unclassified Information, or CUI. Many U.S. Department of Defense contracts involve sensitive but unclassified information such as technical specifications, procurement details, or system vulnerabilities. CUI does not require a facility security clearance, but it does require specific safeguarding measures, cybersecurity compliance and contractual controls.
- The third category is classified work. Classified information — designated as Confidential, Secret, or Top Secret — triggers a separate and significantly more complex regulatory framework. Classified work requires facility security clearances, restrictions related to foreign ownership or control and limitations on who may access certain programs. This is the point at which corporate structure and governance become critical.
Export Controls Often Arise Before Classified Work
Export controls frequently come into play long before a company ever handles classified information, particularly for companies with advanced or dual-use technologies. For many foreign companies, export controls — not classified contracts — are the first real regulatory constraint they encounter when entering the U.S. defense ecosystem.
Export controls regulate far more than the physical shipment of products across borders. They also govern the transfer of technical data, design information, software, source code and certain services. Critically, export controls apply even when no product leaves the United States.
This is because U.S. export laws regulate so-called “deemed exports.” A deemed export occurs when controlled technology or technical data is released to a foreign national, even if that person is physically present in the United States and even if the information never leaves U.S. territory.
Returning to the German automotive supplier example, assume the company establishes a U.S. subsidiary and transfers German engineers to help stand up operations. Even if the radar sensor itself is sold commercially, the underlying design data, algorithms, manufacturing processes, or software may be controlled under U.S. export laws due to their potential military, surveillance, or critical-infrastructure applications.
If those German engineers access controlled technical data in the U.S., that access may legally be treated as an export to Germany. Depending on how the technology is classified, that “export” may require a license from the U.S. government — or may be prohibited altogether without prior authorization. These restrictions can often limit collaboration between individuals in the U.S. offices and collaboration between the U.S. entities and their foreign counterparts.
Two regulatory regimes are most relevant:
The Export Administration Regulations (EAR) govern most commercial and dual-use items and technology. Many advanced automotive, robotics, sensor, AI-enabled and manufacturing technologies fall under the EAR. Whether a license is required depends on the technology’s classification, the nationality of the employee accessing it, the end use and the end user.
The International Traffic in Arms Regulations (ITAR) apply to defense-specific articles and technical data listed on the U.S. Munitions List. While fewer automotive suppliers fall under ITAR, it can apply depending on how specifically a product is adapted or integrated into military systems. ITAR is particularly restrictive when it comes to foreign national access to controlled technical data.
What often surprises foreign companies is that export control obligations can exist even when:
- The product is primarily commercial
- The work is unclassified
- The employee is lawfully present in the U.S.
- The company is operating through a U.S. subsidiary
As a result, export control analysis frequently becomes a gating issue for how U.S. teams are staffed, how information is shared internally, and how quickly foreign transferees can be integrated into technical roles.
This is one of the earliest points at which export controls, immigration strategy, and business planning intersect.
Immigration Strategy and Workforce Planning
Foreign companies expanding into the U.S. commonly want to transfer key personnel — executives, engineers or product specialists — to launch operations. For the German automotive supplier, this might involve transferring engineers to establish manufacturing processes, quality control systems or research and development functions.
These transfers raise immigration questions, such as which U.S. visa type is most appropriate. But immigration approval alone does not resolve export control concerns. A foreign national may be fully authorized to work in the United States from an immigration perspective yet still be restricted from accessing certain controlled technical data under U.S. export laws. This distinction is often misunderstood by companies that are new to the U.S. regulatory environment.
In practice, this means companies must assess, before transferring personnel:
- What technical data those employees will need to access
- Whether that data is controlled under EAR or ITAR
- Whether a deemed export license is required
- Whether certain roles must be reserved for U.S. persons
Separately, if a company later decides to pursue classified defense work, U.S. national security rules impose additional constraints. Classified programs and certain security-sensitive roles generally must be performed by U.S. citizens. Even companies with highly skilled foreign technical teams must plan to hire and empower U.S. workers for these roles.
This layered framework means that workforce planning for foreign companies entering the defense-adjacent market is not simply a question of “who is best qualified,” but also “who is legally permitted to access which information and at what stage.”
Why This Matters for Foreign Companies Early On
From a business perspective, export control issues involving foreign transferees can affect:
- How quickly a U.S. subsidiary can become operational
- Whether foreign engineers can perform hands-on technical work
- How R&D and manufacturing functions are structured
- Whether parallel teams or information barriers are required
- The long-term cost and complexity of compliance
For the German automotive supplier, careful planning might mean:
- Allowing transferred engineers to focus initially on non-controlled commercial work
- Segmenting controlled technical data within the U.S. entity
- Hiring U.S. persons for roles that involve sensitive technology or defense-facing programs
- Building export compliance into job descriptions and onboarding processes
Handled early and thoughtfully, these constraints are manageable. Handled late, they can delay contracts, disrupt staffing plans and create compliance risk that undermines otherwise strong market opportunities.
When Corporate Structure and Security Requirements Apply
If a foreign-owned company decides to pursue classified defense contracts, it must address issues of Foreign Ownership, Control, or Influence, commonly referred to as FOCI. Foreign ownership does not automatically bar a company from classified work. However, the U.S. government will require mitigation measures to ensure that classified programs are insulated from foreign influence. These measures may include a U.S. subsidiary with independent governance, limits on the foreign parent’s access to classified information, formal security agreements such as Special Security Agreements and a clear separation between commercial and classified operations.
For the German automotive supplier, this could mean maintaining one U.S. subsidiary focused on commercial and dual-use business, while any classified defense work — if pursued at all — is conducted through a second U.S. subsidiary that is separately governed and operated exclusively by U.S. persons. Under common FOCI mitigation structures, foreign persons would be prohibited from involvement in the management, direction or control of the classified entity, as well as from access to classified information. At the same time, these arrangements do not necessarily prevent the economic benefits of the classified work from flowing back to the broader corporate structure; subject to the applicable security agreement and government approval, profits may generally be distributed to a U.S. parent or foreign ultimate parent so long as governance, control and security requirements are strictly maintained. Importantly, these requirements apply only if and when classified work is sought, not merely because a company sells commercial or dual-use products to defense customers.
Why a Layered Understanding Matters
Foreign companies often fall into one of two traps. Some assume they must adopt heavy security structures immediately, even when they are only pursuing commercial or unclassified defense work. Others underestimate the regulatory complexity until they are already deep into negotiations with defense customers.
Understanding the distinctions between commercial, CUI and classified work, recognizing when export controls apply, aligning immigration and staffing decisions with compliance obligations, and knowing when FOCI mitigation becomes necessary allows companies to sequence their U.S. expansion intelligently.
The German automotive supplier example illustrates how a company can enter the U.S. market commercially, build relationships with defense customers, comply with export controls early and transition — only if needed — into classified defense work with the appropriate structure.
Conclusion
The U.S. defense market is not closed to foreign companies, but it is highly regulated. Success depends less on any single rule and more on understanding how multiple legal and regulatory regimes interact over time.
For foreign companies with advanced, dual-use technologies, the key question is not simply whether they can work with the defense industry, but at what level, under what rules and with what structure — both now and as their U.S. presence grows. In practice, answering that question requires a coordinated, cross-functional approach. By starting with a clear understanding of a company’s end goals and working backward, corporate, immigration, export control, security and intellectual property considerations can be aligned from the outset to ensure the U.S. structure supports — not constrains — those objectives.
This article is part of The U.S. Expansion Playbook, a series designed to help foreign companies enter and grow in the United States with clarity and confidence. Each installment addresses a critical stage of U.S. market entry — from structure and incentives to workforce strategy, regulatory exposure, and long-term risk management.
Warner’s International Business & Trade team works across corporate, tax, regulatory, intellectual property, litigation and immigration disciplines to help foreign companies navigate U.S. expansion, including in the defense sector, strategically and sustainably.


