CMMC · ITAR · SOC staffing
Do your SOC analysts need to be US persons?
CMMC and NIST SP 800-171 don't require it. Export control rules can, and your SOC sees more of your data than you might think. Here's how to tell which side of the line you're on.
Published September 30, 2026 · Cyberuptive, Honolulu
The short answer
Not for CMMC by itself. Neither the CMMC rule nor NIST SP 800-171 says who can access CUI based on citizenship. Yes, if your SOC could see export-controlled technical data, because releasing ITAR- or EAR-controlled technology to a foreign person, even inside the US, can be an export that needs a license. Many defense contractors have that kind of data in the same logs their SOC reads, so in practice many need US-persons-only monitoring.
Why CMMC doesn't settle it
NIST SP 800-171 requirement 3.9.1 asks you to screen individuals before giving them access to systems with CUI. It doesn't specify nationality. The CMMC scoping rule treats your SOC as a Security Protection Asset if it holds your logs, or as part of your assessment if it can reach CUI (32 CFR 170.19). It doesn't say where analysts must sit or what passport they carry.
So a provider can meet its CMMC-relevant obligations while using non-US staff, and some large providers do. Arctic Wolf's current MDR terms, for example, say customer data "may be accessed by persons who are not United States citizens" and from locations outside the US (Arctic Wolf). That's a legitimate model for commercial data. Whether it works for you depends on what else is in your logs.
Where the requirement actually comes from
Export control. The Bureau of Industry and Security explains that releasing controlled technology to foreign persons in the US is "'deemed' to be an export to the person's country or countries of nationality" (BIS). ITAR works the same way for defense articles and technical data. If your SOC can see ITAR technical data and a foreign national on the SOC team looks at it, you may have made an unlicensed export.
Contracts and programs. Some contracts, security classification guides, or CUI categories carry dissemination controls such as NOFORN. Primes sometimes flow down US-persons requirements for anyone with system access.
Your cloud. Microsoft screens staff who get elevated access to GCC High customer content, including US citizenship verification (Microsoft). If you moved to GCC High to control who can see your data, handing the logs to a SOC with looser rules undoes part of that choice.
"US person" isn't "US citizen"
Under ITAR, a US person includes a lawful permanent resident and certain "protected individuals," not just citizens (22 CFR 120.62). BIS notes that people with permanent residence, US citizenship, or protected-individual status are exempt from the deemed export rule (BIS). A provider that says "US-based" may mean location. One that says "US citizens" may be stricter than you need. Ask for the exact definition in the contract.
What your SOC can actually see
People assume a SOC only sees alerts. In a typical Microsoft or EDR deployment, analysts can also see:
- File names and paths in endpoint and SharePoint events. A file named for a controlled part drawing is technical data in a file name.
- Email subjects and attachment names in phishing investigations.
- DLP alerts, which often include matched content.
- Quarantined and sandboxed files from EDR, which can be the controlled drawing itself.
- Search results across the SIEM when hunting.
If any of that includes controlled technical data, the SOC is receiving it. Your export compliance lead needs to know.
Get it in writing
See our US-persons contract language
We'll send the personnel, access, and location terms we sign with CMMC-scoped clients, so you can compare them with what your current provider has committed to.
What to put in the contract
- Definition. Everyone with logical access to our data is a US person under 22 CFR 120.62, verified before access.
- Location. Access only from within the United States, including support, escalation, and engineering.
- Subcontractors and affiliates. The same rules apply to them, or they get no access.
- Evidence. The provider can show employment-verification records under the engagement terms.
- Separation. If the provider also has non-US operations, the US environment is logically and physically separate, with its own access controls.
- Notification. You're told before any change in staffing model or location.
How Cyberuptive handles it
This is the core of how we're built. All US federal, defense, and CMMC-scoped client work is delivered from US soil by US-persons analysts on a physically and logically segregated SOC. We also serve commercial clients in Asia-Pacific, and those engagements are contracted and delivered separately from US federal and defense work. GCC High and GovCloud operations are performed only by US-persons analysts. See SOC as a Service, MDR for CUI environments, and single vs. segregated SOC.
Frequently asked questions
Does CMMC require SOC analysts to be US citizens?
No. Neither CMMC nor NIST SP 800-171 includes a citizenship requirement for people who access CUI or security data. NIST SP 800-171 requires personnel screening (3.9.1), not a particular nationality. Requirements for US persons come from export control rules, contract terms, or program-specific dissemination controls.
When do SOC analysts need to be US persons?
When they could receive ITAR- or EAR-controlled technical data, when your contract or customer requires it, or when the CUI category carries a dissemination control such as NOFORN. Releasing controlled technology to a foreign person inside the US can count as a deemed export.
Is a US person the same as a US citizen?
No. Under ITAR (22 CFR 120.62), a US person includes US citizens, lawful permanent residents (green card holders), and certain protected individuals such as refugees and asylees. BIS applies the same idea to deemed exports under the EAR.
Can a SOC really see export-controlled data?
Often, yes. File names, email subjects, DLP alerts, EDR file quarantine and sandboxing, and search results in a SIEM can all contain technical data. If your SOC can view them, your export compliance program needs to account for it.
Are Cyberuptive's analysts US persons?
For CMMC-scoped and federal clients, yes. All US federal, defense, and CMMC-scoped client work is delivered from US soil by US-persons analysts on a physically and logically segregated SOC. International commercial work is contracted and delivered separately.