Department of Defense (DoD) SBIR/STTR Research

Overview

Department of Defense (DoD) Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) projects provide opportunities for universities and small businesses to collaborate on research and technology development supporting DoD missions.

Unlike many traditional university research awards, DoD SBIR/STTR projects may include research security, export control, cybersecurity, information protection, publication, foreign participation, and other contractual requirements that affect how Stony Brook University's portion of the research may be conducted.

The Office of Research Security (ORS) assists researchers in identifying these requirements early in proposal development and works with the Office of Sponsored Programs (OSP) and other University offices, as appropriate, before Stony Brook commits to participate.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS


Contact ORS Before You

Contact ORS as early as possible if you are considering participating in a DoD SBIR or STTR project, particularly when:

  • The solicitation or topic identifies the research as export controlled.
  • The project involves development of prototypes, software, source code, engineering designs, technical data, or other potentially controlled technology.
  • Stony Brook will receive or access proprietary company information, Federal Contract Information (FCI), Controlled Unclassified Information (CUI), Government-Furnished Information (GFI), or other restricted technical information.
  • Publication or dissemination of Stony Brook's research results may be restricted.
  • Participation by foreign persons or international collaborators may be restricted.
  • The project requires secure research computing or specific cybersecurity safeguards.
  • The solicitation, prime contract, or proposed subaward references DFARS cybersecurity clauses, NIST SP 800-171, Cybersecurity Maturity Model Certification (CMMC), CUI, or FCI.
  • Equipment, software, technical information, materials, or research data will be transferred internationally.
  • You are uncertain whether Stony Brook's portion of the work can be conducted as Fundamental Research.

Key Considerations

SBIR and STTR awards are made to eligible small businesses. Universities may participate in the research through subawards or other permitted research arrangements.

For STTR projects, the small business must perform at least 40% of the research and development work and the partnering research institution must perform at least 30%. STTR projects also require an agreement between the small business and research institution addressing intellectual property rights and rights to carry out follow-on research, development, or commercialization activities.

Although the small business is responsible for submitting the DoD SBIR/STTR proposal, requirements contained in the solicitation, prime contract, or award may affect Stony Brook's proposed scope of work or be incorporated into the University's subaward or research agreement.

Researchers should therefore evaluate the requirements applicable to Stony Brook's portion of the project before agreeing to participate.

An important consideration is whether Stony Brook's portion of the project can remain fundamental research.

Consider whether:

  • Stony Brook researchers will be free to publish the results of their research.
  • Publication is subject only to limited review for proprietary information or patent protection rather than sponsor approval.
  • Students and other appropriate University researchers may participate.
  • The work is intended to produce openly disseminated scientific knowledge rather than restricted technical deliverables.

Publication approval requirements, dissemination restrictions, access restrictions, or other contractual limitations may affect the fundamental research analysis and may introduce export control or other research security requirements.

Contact ORS before agreeing to restrictions affecting publication, dissemination, or participation.


Many DoD SBIR/STTR topics involve technologies with military, defense, aerospace, cybersecurity, microelectronics, autonomous systems, advanced computing, or other sensitive applications.

DoD topics may expressly identify technology as restricted under U.S. export control regulations and may require disclosure of proposed foreign-national participation. Depending on the technology and scope of work, foreign persons may be restricted from performing certain project activities or accessing controlled technical information.

Researchers should contact ORS when:

  • A topic or solicitation identifies export control restrictions.
  • Stony Brook will receive export-controlled technical information, software, equipment, or materials.
  • Foreign persons will participate in technical work that may involve controlled technology.
  • The project involves international transfers of equipment, software, technology, technical information, or research materials.

ORS can determine the export control requirements applicable to Stony Brook's proposed activities.

DoD SBIR/STTR projects frequently involve technical information provided by the small business, DoD, a prime contractor, or another project participant.

This information may include:

  • Proprietary company information.
  • Engineering drawings or design files.
  • Restricted software or source code.
  • Technical specifications.
  • Mission-specific or operational information.
  • Federal Contract Information (FCI).
  • Controlled Unclassified Information (CUI).
  • Government-Furnished Information (GFI).
  • Export-controlled technical information.

Receiving restricted information may affect where the work can be performed, who may access the information, how information may be shared, and what computing or information protection requirements apply.

Researchers should contact ORS before receiving restricted technical or government information for a proposed DoD SBIR/STTR project.


DoD increasingly incorporates cybersecurity requirements into contracts and solicitations involving Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

Depending on the project and applicable contract requirements, the small business or participating research institution may be required to demonstrate compliance with specified cybersecurity requirements, including applicable DFARS clauses, NIST SP 800-171 requirements, CMMC requirements, or other DoD safeguarding standards.

CMMC implementation is being phased into DoD contracting requirements and continues to evolve. Applicable CMMC requirements depend on the specific solicitation, contract, information involved, and required assessment level. Researchers should rely on the requirements stated in the applicable solicitation and award and consult ORS when CMMC requirements are identified.

Stony Brook researchers should not assume that ordinary University research computing resources satisfy project-specific DoD cybersecurity requirements.

ORS will review the requirements applicable to Stony Brook's scope of work and coordinate access to appropriate University resources when enhanced information protection or secure research computing is required.


DoD SBIR/STTR projects involving international activities may require additional research security or export control review.

Contact ORS when the project involves:

  • Foreign research collaborators.
  • Foreign persons participating in technical work.
  • Work conducted outside the United States.
  • International access to research systems or technical information.
  • International shipments or hand-carry of research equipment or materials.
  • Electronic transfers of software, technology, technical information, or research data outside the United States.
  • Foreign organizations or entities subject to U.S. Government restrictions.

The presence of international participants does not automatically prohibit a project, but the specific technology, information, recipient, destination, and contractual requirements must be evaluated.

DoD SBIR/STTR requirements may appear in the:

  • Topic description.
  • Broad Agency Announcement (BAA).
  • Request for Proposal or solicitation.
  • Statement of Work.
  • Prime contract.
  • Proposed subaward.
  • Research agreement.
  • Data or information protection requirements.
  • DFARS clauses or other incorporated contract provisions.

Researchers should pay particular attention to language involving:

  • Export controls.
  • Foreign nationals or foreign persons.
  • Publication or dissemination restrictions.
  • CUI or FCI.
  • NIST SP 800-171.
  • CMMC.
  • Secure computing.
  • Cybersecurity requirements.
  • Proprietary technical information.
  • Government-Furnished Information.
  • Restrictions on sharing technical information or software.

The absence of a particular requirement in the initial topic description does not necessarily mean it will not appear later in the contracting or award process.

Most proposed DoD SBIR/STTR collaborations can proceed after the applicable requirements are identified.

Depending on the project, ORS may:

  • Determine that no additional research security requirements apply to Stony Brook's scope of work.
  • Determine whether Stony Brook's proposed work may qualify as fundamental research.
  • Identify export control requirements.
  • Review foreign person participation or international research considerations.
  • Identify government or proprietary information protection requirements.
  • Determine whether applicable requirements call for a Data Protection Plan, Technology Control Plan, or secure research computing environment.
  • Coordinate with OSP during proposal development or agreement negotiation.
  • Coordinate with other University offices, as appropriate.

Early review is particularly important because research security and cybersecurity requirements may affect the proposed scope of work, project personnel, computing environment, budget, or agreement terms.


Related Guidance

Related Guidance Description
Sponsor & Project Requirements Guidance for reviewing and complying with research security, export control, information protection, publication, and other project-specific requirements contained in sponsor solicitations, award terms, and research agreements.
Working with Government Information Guidance for receiving, accessing, using, storing, sharing, and protecting government information, including CUI, FCI, Government-Furnished Information (GFI), and other government-controlled information.
Working with Proprietary & Confidential Research Information Guidance for receiving, accessing, using, storing, sharing, and protecting proprietary or confidential research information received from sponsors, collaborators, companies, universities, and other external organizations.
Secure Research Computing Guidance for research requiring secure research computing environments, specialized storage, controlled access, or sponsor-required cybersecurity safeguards.
Data Protection Plans Guidance for developing, implementing, and maintaining sponsor-, contractual-, or institutionally required Data Protection Plans.
Software, Source Code & Encryption Guidance for research involving software, source code, encryption, and specialized cybersecurity technologies that may raise export control considerations.
International Transfers (Shipments, Hand-Carry & Electronic Transmissions) Guidance for shipping, mailing, hand-carrying, or electronically transferring research equipment, materials, software, technology, technical information, or research information internationally.
Foreign Person Participating in Research Guidance for employing foreign national faculty, staff, postdoctoral researchers, and students participating in research activities.
Restricted Entity Screening Learn how organizations and individuals are screened against U.S. government restricted party and entity lists before certain research activities.

Frequently Asked Questions

Does every DoD SBIR/STTR project require additional research security review?

No. Requirements depend on the specific topic, Stony Brook's proposed scope of work, the information and technology involved, and the applicable solicitation and contract terms.

Because these requirements can affect the structure of the proposed research, faculty considering DoD SBIR/STTR participation should contact ORS early.


Is a DoD SBIR/STTR project automatically Fundamental Research?

No.

Whether Stony Brook's portion of a project qualifies as Fundamental Research depends on the actual scope of work and applicable restrictions, including publication and participation restrictions.

ORS can assist in making this determination.


Does a DoD SBIR/STTR project automatically involve CUI?

No.

CUI applies only when the project involves information designated or governed as CUI under applicable federal requirements. Researchers should not assume that all DoD research information is CUI.

Does every DoD SBIR/STTR project require CMMC compliance?

No.

CMMC requirements depend on the specific solicitation or contract, the federal information involved, and the applicable CMMC requirement. Researchers should review the project requirements and consult ORS rather than assume CMMC applies to every DoD SBIR/STTR project.


Can foreign persons participate in DoD SBIR/STTR research?

Possibly.

Participation depends on the technology, information, export classification, sponsor requirements, and specific role of the individual. Some DoD topics expressly restrict or require disclosure of foreign-national participation.

Contact ORS before including foreign persons to technical work when export control or sponsor restrictions may apply.


Need Assistance?

Contact ORS and OSP early when considering Stony Brook participation in a DoD SBIR/STTR project so research security, export control, cybersecurity, information protection, sponsor, and contractual requirements can be identified before the University's scope of work and commitments are finalized.

REQUEST A RESEARCH SECURITY REVIEW

SCHEDULE A CONSULTATION

CONTACT ORS