Department of Defense (DoD) SBIR/STTR Research
Overview
Department of Defense (DoD) Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) projects provide opportunities for universities and small businesses to collaborate on research and technology development supporting DoD missions.
Unlike many traditional university research awards, DoD SBIR/STTR projects may include research security, export control, cybersecurity, information protection, publication, foreign participation, and other contractual requirements that affect how Stony Brook University's portion of the research may be conducted.
The Office of Research Security (ORS) assists researchers in identifying these requirements early in proposal development and works with the Office of Sponsored Programs (OSP) and other University offices, as appropriate, before Stony Brook commits to participate.
REQUEST A RESEARCH SECURITY REVIEW
Contact ORS Before You
Contact ORS as early as possible if you are considering participating in a DoD SBIR or STTR project, particularly when:
- The solicitation or topic identifies the research as export controlled.
- The project involves development of prototypes, software, source code, engineering designs, technical data, or other potentially controlled technology.
- Stony Brook will receive or access proprietary company information, Federal Contract Information (FCI), Controlled Unclassified Information (CUI), Government-Furnished Information (GFI), or other restricted technical information.
- Publication or dissemination of Stony Brook's research results may be restricted.
- Participation by foreign persons or international collaborators may be restricted.
- The project requires secure research computing or specific cybersecurity safeguards.
- The solicitation, prime contract, or proposed subaward references DFARS cybersecurity clauses, NIST SP 800-171, Cybersecurity Maturity Model Certification (CMMC), CUI, or FCI.
- Equipment, software, technical information, materials, or research data will be transferred internationally.
- You are uncertain whether Stony Brook's portion of the work can be conducted as Fundamental Research.
Key Considerations
SBIR and STTR awards are made to eligible small businesses. Universities may participate
in the research through subawards or other permitted research arrangements. For STTR projects, the small business must perform at least 40% of the research and
development work and the partnering research institution must perform at least 30%.
STTR projects also require an agreement between the small business and research institution
addressing intellectual property rights and rights to carry out follow-on research,
development, or commercialization activities. Although the small business is responsible for submitting the DoD SBIR/STTR proposal,
requirements contained in the solicitation, prime contract, or award may affect Stony
Brook's proposed scope of work or be incorporated into the University's subaward or
research agreement. Researchers should therefore evaluate the requirements applicable to Stony Brook's
portion of the project before agreeing to participate. An important consideration is whether Stony Brook's portion of the project can remain
fundamental research. Consider whether: Publication approval requirements, dissemination restrictions, access restrictions,
or other contractual limitations may affect the fundamental research analysis and
may introduce export control or other research security requirements. Contact ORS before agreeing to restrictions affecting publication, dissemination,
or participation. Many DoD SBIR/STTR topics involve technologies with military, defense, aerospace,
cybersecurity, microelectronics, autonomous systems, advanced computing, or other
sensitive applications. DoD topics may expressly identify technology as restricted under U.S. export control
regulations and may require disclosure of proposed foreign-national participation.
Depending on the technology and scope of work, foreign persons may be restricted from
performing certain project activities or accessing controlled technical information. Researchers should contact ORS when: ORS can determine the export control requirements applicable to Stony Brook's proposed
activities. DoD SBIR/STTR projects frequently involve technical information provided by the small
business, DoD, a prime contractor, or another project participant. This information may include: Receiving restricted information may affect where the work can be performed, who may
access the information, how information may be shared, and what computing or information
protection requirements apply. Researchers should contact ORS before receiving restricted technical or government
information for a proposed DoD SBIR/STTR project. DoD increasingly incorporates cybersecurity requirements into contracts and solicitations
involving Federal Contract Information (FCI) and Controlled Unclassified Information
(CUI). Depending on the project and applicable contract requirements, the small business
or participating research institution may be required to demonstrate compliance with
specified cybersecurity requirements, including applicable DFARS clauses, NIST SP
800-171 requirements, CMMC requirements, or other DoD safeguarding standards. CMMC implementation is being phased into DoD contracting requirements and continues
to evolve. Applicable CMMC requirements depend on the specific solicitation, contract,
information involved, and required assessment level. Researchers should rely on the
requirements stated in the applicable solicitation and award and consult ORS when
CMMC requirements are identified. Stony Brook researchers should not assume that ordinary University research computing
resources satisfy project-specific DoD cybersecurity requirements. ORS will review the requirements applicable to Stony Brook's scope of work and coordinate
access to appropriate University resources when enhanced information protection or
secure research computing is required. DoD SBIR/STTR projects involving international activities may require additional research
security or export control review. Contact ORS when the project involves: The presence of international participants does not automatically prohibit a project,
but the specific technology, information, recipient, destination, and contractual
requirements must be evaluated. DoD SBIR/STTR requirements may appear in the: Researchers should pay particular attention to language involving: The absence of a particular requirement in the initial topic description does not
necessarily mean it will not appear later in the contracting or award process. Most proposed DoD SBIR/STTR collaborations can proceed after the applicable requirements
are identified. Depending on the project, ORS may: Early review is particularly important because research security and cybersecurity
requirements may affect the proposed scope of work, project personnel, computing environment,
budget, or agreement terms.
Related Guidance
| Related Guidance | Description |
|---|---|
| Sponsor & Project Requirements | Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements. |
| Working with Government Information | Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information. |
| Working with Proprietary & Confidential Research Information | Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations. |
| Secure Research Computing | Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards. |
| Data Protection Plans | Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans. |
| Software, Source Code & Encryption | Guidance for research involving software, source code, encryption, and specialized cybersecurity technologies that may raise export control considerations. |
| International Transfers (Shipments, Hand-Carry & Electronic Transmissions) | Guidance for shipping, mailing, hand-carrying, or electronically transferring research equipment, materials, software, technology, technical information, or research information internationally. |
| Foreign Person Participating in Research | Guidance for employing foreign national faculty, staff, postdoctoral researchers, and students participating in research activities. |
| Restricted Entity Screening | Learn how organizations and individuals are screened against U.S. government restricted party and entity lists before certain research activities. |
Frequently Asked Questions
Does every DoD SBIR/STTR project require additional research security review?
No. Requirements depend on the specific topic, Stony Brook's proposed scope of work, the information and technology involved, and the applicable solicitation and contract terms.
Because these requirements can affect the structure of the proposed research, faculty considering DoD SBIR/STTR participation should contact ORS early.
Is a DoD SBIR/STTR project automatically Fundamental Research?
No.
Whether Stony Brook's portion of a project qualifies as Fundamental Research depends on the actual scope of work and applicable restrictions, including publication and participation restrictions.
ORS can assist in making this determination.
Does a DoD SBIR/STTR project automatically involve CUI?
No.
CUI applies only when the project involves information designated or governed as CUI under applicable federal requirements. Researchers should not assume that all DoD research information is CUI.Does every DoD SBIR/STTR project require CMMC compliance?
No.
CMMC requirements depend on the specific solicitation or contract, the federal information involved, and the applicable CMMC requirement. Researchers should review the project requirements and consult ORS rather than assume CMMC applies to every DoD SBIR/STTR project.
Can foreign persons participate in DoD SBIR/STTR research?
Possibly.
Participation depends on the technology, information, export classification, sponsor requirements, and specific role of the individual. Some DoD topics expressly restrict or require disclosure of foreign-national participation.
Contact ORS before including foreign persons to technical work when export control or sponsor restrictions may apply.
Need Assistance?
Contact ORS and OSP early when considering Stony Brook participation in a DoD SBIR/STTR project so research security, export control, cybersecurity, information protection, sponsor, and contractual requirements can be identified before the University's scope of work and commitments are finalized.