Technology Control Plans

Overview 

A Technology Control Plan (TCP) is a written compliance plan used to prevent unauthorized access to export-controlled equipment, materials, software, technology, technical information, technical data, or other controlled items.

A TCP establishes safeguards and procedures for controlling access to export-controlled items or information and helps the University comply with applicable U.S. export control requirements.

The Office of Research Security (ORS) determines when a Technology Control Plan is required and works with researchers and other University offices to develop and implement appropriate safeguards.

REQUEST AN EXPORT CONTROL REVIEW]

Schedule a consultation 

Contact ORS 


When May a Technology Control Plan Be Required?

A Technology Control Plan may be required when research or another University activity involves:

  • Export-controlled equipment or materials.
  • Export-controlled software or technology.
  • Controlled technical information or technical data.
  • Foreign-person access to controlled technology or technical data.
  • Sponsor- or third-party-provided export-controlled information.
  • Activities conducted under an export license or other U.S. Government authorization.
  • Other activities requiring access controls under U.S. export control regulations.

The need for a TCP depends on the specific activity, export control classification, individuals requiring access, applicable regulations, and any license or other authorization requirements.

ORS determines whether a TCP or other safeguards are required.


What May a Technology Control Plan Include?

Technology Control Plans are tailored to the specific research project or activity.

Depending on the circumstances, a TCP may establish requirements for:

  • Personnel & Access — Identification of authorized personnel and procedures for controlling access to export-controlled items or information.
  • Physical Security — Security of laboratories, offices, equipment, materials, and other physical locations.
  • Information Security — Appropriate storage, transmission, and protection of controlled electronic information, software, and technical data.
  • Visitors — Procedures for controlling visitor access to restricted areas, equipment, or information.
  • Handling & Storage — Requirements for storing, using, reproducing, or disposing of controlled items and information.
  • International Transfers — Procedures for international shipments, electronic transfers, and other exports when applicable.
  • International Travel — Requirements affecting travel with controlled equipment, software, technology, or information.
  • Training — Export control training and TCP-specific responsibilities for authorized personnel.
  • Recordkeeping — Documentation required by applicable export control regulations, licenses, authorizations, or University procedures.

Additional safeguards may be required depending on the applicable regulations and the activity.


Responsibilities of Project Personnel

Individuals authorized to participate in an activity subject to a Technology Control Plan are responsible for following the safeguards and procedures established in the TCP.

Responsibilities may include:

  • Completing required training.
  • Limiting access to authorized personnel.
  • Following physical and information security requirements.
  • Protecting controlled items and information from unauthorized access or release.
  • Following approved procedures for visitors, travel, shipments, and transfers.
  • Promptly reporting proposed changes that may affect the TCP.
  • Contacting ORS before providing access to individuals who are not authorized under the TCP.

ORS should be consulted before making changes to personnel, access, facilities, technology, or other circumstances covered by an existing Technology Control Plan.


How ORS Can Help

The Office of Research Security assists by:

  • Determining whether a Technology Control Plan is required.
  • Developing TCPs in collaboration with researchers.
  • Identifying appropriate physical, personnel, and information security safeguards.
  • Reviewing foreign-person access to controlled technology or technical data.
  • Coordinating with Information Security, Sponsored Programs, Environmental Health & Safety, Procurement, and other University offices, as appropriate.
  • Providing required training and compliance guidance.
  • Reviewing changes that may affect an existing TCP.

Related Guidance

Related Guidance Description
Export Control Classification Learn how equipment, materials, software, technology, and technical information are classified under U.S. export control regulations.
Deemed Exports Learn when releasing controlled technology or source code to a foreign person within the United States may constitute a deemed export.
Export Administration Regulations (EAR) Learn about the regulations governing commercial, dual-use, and less-sensitive military items, software, and technology.
International Traffic in Arms Regulations (ITAR) Learn about the regulations governing defense articles, defense services, and technical data.
Government Information Learn about the types of government information and associated requirements

Need Assistance?

If your research or other University activity involves export-controlled equipment, materials, software, technology, technical information, technical data, or foreign-person access, contact the Office of Research Security.

ORS will determine whether a Technology Control Plan or other safeguards are required.

REQUEST AN EXPORT CONTROL REVIEW]

Schedule a consultation 

Contact ORS