A lot of the small businesses I talk to won DoD / DoW SBIR or STTR funding on the strength of a great idea, not a security program. That worked for years. It doesn’t anymore. CMMC is now written into SBIR and STTR solicitations and contracts, and if you hold — or want — a Department of Defense / Department of War (DoD / DoW) SBIR award and you don’t meet the cybersecurity requirement, the consequences are real. They range from losing the award to, in the worst case, a federal fraud claim. Here’s what actually happens.
First, CMMC almost certainly applies to your SBIR award
This catches a lot of founders off guard. Cybersecurity isn’t a side issue for SBIR work — it’s now a condition of doing business.
- Nearly every DoD / DoW SBIR awardee handles at least Federal Contract Information (FCI), which means CMMC Level 1 at a minimum.
- Phase II work almost always generates Controlled Unclassified Information (CUI) — often controlled technical information like export-controlled research and technical data. That means CMMC Level 2 and the full set of NIST SP 800-171 controls.
- The DoD / DoW now identifies a projected CMMC level inside each SBIR topic, and the level for a Phase II award can be higher than what was advertised at Phase I.
- The only real carve-outs are commercial off-the-shelf items and micro-purchases. Most SBIR firms don’t qualify for those exemptions.
You can review the Level 2 control set — the NIST SP 800-171 Revision 2 requirements — directly from NIST here: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
What happens if you don’t get it
- You don’t win the award. When the solicitation or contract carries the CMMC clause (DFARS 252.204-7021) at a level you don’t hold, you are not eligible for award. No certification at the required level, no contract.
- You can’t legally handle the data. Phase II work generates CUI, and without the controls in place you can’t process, store, or transmit it. The award can’t move forward even if you’ve already been selected on technical merit.
- A missing SPRS score disqualifies you today. Separate from full CMMC, the DoD / DoW already requires a current NIST SP 800-171 self-assessment score posted in the Supplier Performance Risk System (SPRS) as a condition of award. No active score, no award — and contracting officers are now checking.
- You lose the Phase II to Phase III pipeline. SBIR is a funnel: Phase I proves feasibility, Phase II builds it, Phase III is the commercialization and follow-on work where the real money is. Falling out at the cybersecurity gate ends that path, not just one contract.
- Flow-down kills your subcontracts. If you work as a subcontractor on someone else’s defense or SBIR effort, the requirements flow down to you. A prime can’t use you if you can’t meet the level.
- The big one: False Claims Act exposure. If you attest to a security score or a level of compliance you don’t actually have, you are exposed under the DOJ’s Civil Cyber-Fraud Initiative. This is not theoretical. In 2025, MORSECORP paid $4.6 million to settle allegations that it failed to implement required controls and reported inflated SPRS scores; Raytheon, RTX, and successor Nightwing paid $8.4 million over similar cybersecurity claims; and universities including Penn State and Georgia Tech have faced the same kind of action. Liability can attach even when there’s been no breach — misrepresenting your compliance is itself the violation. These cases are often brought by whistleblowers, which means your own employees can file, and damages under the False Claims Act are tripled and stacked with penalties.
- Wasted investment and lost ground. Time and money spent on the research don’t help if you can’t accept or keep the award, and the competitors who got ready take the work you can’t.
A quick caveat on that last point: I’m not a lawyer, and the False Claims Act risk is exactly the kind of thing to walk through with counsel. But the pattern is clear enough that no SBIR firm should be guessing about it.
The part people miss: you can fund the fix with the grant
Here’s something I push on every chance I get. CMMC compliance costs are allowable, and they can qualify for Technical and Business Assistance (TABA) funding in connection with an SBIR or STTR award. In other words, you can direct a portion of the grant toward getting CMMC-ready instead of treating it as pure overhead. If you’re writing proposals now, build that in.
What you need to do
- Determine your level — FCI means Level 1, CUI (most Phase II work) means Level 2.
- Run a NIST SP 800-171 self-assessment and post an accurate score in SPRS now. This is a condition of award today, not later.
- Do not inflate the score. Report what you’ve actually implemented. Accuracy here is a legal matter, not a formality.
- Document an SSP and POA&M, then remediate the gaps — and use TABA funding where you can.
- Start early. A Level 2 certification can take a year or more, so a future award is a today problem.
How CloudHesive helps
This is the kind of work we do for small businesses in the defense supply chain. We help SBIR and STTR firms get to a real, accurate SPRS score, stand up the NIST SP 800-171 controls on AWS, document the SSP and POA&M, and manage the environment so you stay ready between assessments. We don’t perform the certification audit itself — that’s the C3PAO’s role — but we get you to the point where you can pass it and keep your eligibility intact.
If you have an SBIR award, or you’re chasing one, and you’re not sure where you stand on CMMC, we can help you find out and build the plan. We should talk.
Frequently asked questions
Does CMMC apply to SBIR and STTR awards?
Yes. Nearly all DoD / DoW SBIR and STTR awardees handle federal contract information or controlled unclassified information, which means they must meet CMMC requirements. Only commercial off-the-shelf items and micro-purchases are generally exempt.
What CMMC level does an SBIR award need?
At minimum Level 1 for federal contract information. Phase II work usually involves controlled unclassified information, which requires Level 2 and full implementation of the 110 NIST SP 800-171 controls. The projected level is listed in each SBIR topic.
Can I lose my SBIR grant if I’m not CMMC compliant?
You can lose eligibility for the award. If the contract carries the CMMC clause at a level you don’t hold, or you have no current NIST SP 800-171 score in SPRS, you can be disqualified at award and cut off from Phase II and Phase III follow-on work.
What happens if I report a NIST SP 800-171 score I don’t actually meet?
Misrepresenting your compliance can trigger liability under the False Claims Act through the DOJ’s Civil Cyber-Fraud Initiative, even if you never have a breach. Recent settlements have run into the millions, and whistleblowers can bring the cases.
Can SBIR funds pay for CMMC compliance?
Yes. Compliance costs are allowable and may qualify for Technical and Business Assistance (TABA) funding tied to an SBIR or STTR award, so you can direct part of the grant toward getting certified.
Do CMMC requirements apply to Phase I?
Often yes, at Level 1, because Phase I work typically involves federal contract information. Phase II commonly rises to Level 2 as controlled unclassified information enters the picture.
