Due Diligence Programs
DOE conducts a review of risk separately from the merit review and can elect not to fund applications that present unacceptably high foreign risks. DOE has implemented the following changes as part of its implementation of its due diligence program.
- In FY 2023, DOE amended its review of risk in its SBIR/STTR Funding Opportunity Announcements to address the new requirements associated with evaluation of foreign risks. In addition, it required all applicants to include a disclosure of foreign relationships in their applications.
- In FY 2024, DOE extended the scope of its review of risk to include cybersecurity practices of Phase II applicants. Phase II applicants will be required to submit a cybersecurity self-assessment. More details on this cybersecurity self-assessment will be included in the Phase II Funding Opportunity Announcement. Phase I awardees are encouraged to prepare for this self-assessment by leveraging available resources to improve their cybersecurity practices in advance of submitting a Phase II application. Many of the practices needed for a small business to meet a passing threshold of a cyber checklist are free or provided in the costs of commercial-grade IT services. Examples of services and training are included below and can also be found on the Cybersecurity Resources for Small Business Web page.
- NIST Cybersecurity Framework Small Business Quick Start Guide: https://www.nist.gov/itl/smallbusinesscyber
- NIST SP 800-171 Rev.3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: https://csrc.nist.gov/pubs/sp/800/171/r3/final
- Cybersecurity Maturity Model Certification (CMMC): https://dodcio.defense.gov/CMMC/Model/
- CISA Cross-Sector Cybersecurity Performance Goals: https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
- CISA Cyber Essential Starter Kit: https://www.cisa.gov/resources-tools/resources/cisa-cyber-essentials-starter-kit
- NIST Fundamentals of Small Business Information Security: https://csrc.nist.gov/pubs/ir/7621/r1/final
- The FBI Internet Crime Complaint Center (IC3) provides information about the latest and most harmful cyber threats and scams: https://www.ic3.gov
- The Federal Trade Commission has a reference page dedicated to small businesses and cybersecurity https://www.ftc.gov/business-guidance/small-businesses/cybersecurity
- USAF SBIR cybersecurity page: https://www.safcn.af.mil/CISO/Small-Business-Cybersecurity-Information/
The SBIR Extension Act of 2022 required agencies to assess cybersecurity practices, patent analysis, employee analysis, and foreign ownership, including financial ties to foreign countries, individuals, or entities. The Small Business Innovation and Economic Security Act of 2026 (S.3971) expanded the list to also include foreign affiliations of covered individuals, owners, or other key personnel with entities in a foreign country of concern (FCOC); investment relationships with individuals or entities in an FCOC; technology licensing agreements or joint ventures with individuals or entities in an FCOC; and business relationships between key personnel and individuals or entities in an FCOC.
A new provision further requires agencies to examine any relationship between the applicant and any entity or individual on the eight sanctions and restricted party lists:
The UFLPA Entity List (Department of Homeland Security)
The Non-SDN Chinese Military-Industrial Complex Companies List (Department of Treasury, OFAC)
The Section 889 Prohibition List (Department of War)
The 1260H Chinese Military Companies list (Department of War)
The Military End User List (Department of Commerce, BIS)
The Entity List (Department of Commerce, BIS)
Small businesses are encouraged to carry out their own due diligence to address risks associated with loss of their intellection property. These activities can include proper vetting of employees, investors, and business partners in addition to adherence to good cybersecurity practices. The National Counterintelligence and Security Council has provided the following bulletins that provides useful guidance for protecting emerging technologies from foreign risks.
The SBIR and STTR Extension Act of 2022 mandates that federal agencies operating SBIR/STTR programs implement a due diligence program to address cybersecurity (CS) and foreign risks. The goals of this mandate are to ensure that SBIR/STTR awardees implement appropriate CS practices to protect their research and development from cyber criminals and reduce risk to critical infrastructures.
The CS Due Diligence Program assesses for risks of cybersecurity business practices of SBIR/STTR applicant and awardees the cybersecurity risk associated with SBIR/STTR applicant/awardee business practices of SBIR/STTR applicants and practices to ensure awardees have appropriate protections in place uses on the CS risks associated with the business practices of SBIR/STTR applicants and awardees. The program requirements derived from the Cybersecurity Infrastructure Security Agency (CISA) Cybersecurity Performance Goals (CPGs) and are aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). The DOE SBIR/STTR CS Due Diligence Program is focused on protecting the SBIR/STTR research and development efforts from the unauthorized disclosure to foreign countries of concern (China, Russia, North Korea, & Iran). The SBIR/STTR CS Due Diligence Program assesses the CS business practices of all Phase II small business applicants to ensure they are within the acceptable level of risk to conduct research and development.The following content was developed to help DOE SBIR/STTR applicants understand and implement the CS requirements:
- SBIR/STTR CS Requirement: Self-Assessment
- Risk Rating Information
- Learning and Education Resources
- Auditing Information
- Cyber Risk Management FAQs
- Cybersecurity Contact Information
- Feedback
Examples of Intellectual Property Theft
A former SBIR awardee, ASMC, suffered severe economic damages as the result of an employee stealing source code related to wind energy technology. A Chinese firm, Sinovel, paid an employee of an ASMC subsidiary to steal the source code and subsequently provided him with employment. The economic impact to ASMC was a loss of $1B in shareholder value and 700 jobs. Sinovel was found guilty and was ordered to pay restitution in addition to a fine.
A scientist at Phillips 66 stole $1B in trade secrets related to flow battery technology used for large scale energy storage. He was a participant in China’s Thousand Talents Plan, through which lucrative incentives are offered to recruit individuals with expertise in high-priority fields. The scientist had planned to leave the company and return to China to work for a company that developed battery materials. He was arrested, sentenced, and fined for the trade secret theft.