Wow! Teams which had submitted SBIR or STTR proposals to the NIH last September and who weren’t immediately funded at that time are getting JIT (just in time) notices as they’ve moved up the funding priority list. NIIH (in recent webinars) has made it clear that they are expecting a HUGE influx of proposals in September, and that they’re going to put money to work in well-scored proposals from last September in the meantime.
With the new re-authorization, a number of requirements have either been added or strengthened. You can see a collection of various JIT requirements sent to teams being considered on our post What to Expect with NIH JIT.
But one requirement grabbed my attention in a serious way.
NIH now has the foreign disclosures form (Required Disclosure of Foreign Affiliations or Relationships to Foreign Countries form) AND this form also includes a cybersecurity questionnaire. This has not been spoken about publicly by NIH this past month and I felt when one of our coaching companies showed it to us, that it was a bit of a blind side. These cybersecurity requirements seem pretty heavy, especially for a startup or very early company.
You can get the full form at – https://grants.nih.gov/grants/funding/SBIR-STTR-Foreign-Disclosure-Form.pdf
https://seed.nih.gov/foreignrisk (details of foreign risk assessment)
Excerpt of Cyber questions from foreign disclosure form
HHS Specific Disclosure Questions – Cybersecurity & Information Safeguarding
1. Does the applicant maintain a cybersecurity plan that includes regular cybersecurity training for all covered individuals and self-assessments or internal reviews to verify ongoing cybersecurity compliance and hygiene practices?
Yes No If no, explain.
2. Does the applicant implement cybersecurity controls consistent with applicable federal cybersecurity frameworks, including at a minimum FAR 52.204-21 and NIST guidance?
Yes No If no, explain.
3. Does the applicant certify that it does not use prohibited information technology systems or services as listed in https://www.fcc.gov/supplychain/coveredlist or foreign country of concern-controlled IT)?
Yes No If no, explain.
4. For projects that involve export-controlled technology, controlled unclassified information (CUI), or multiomic data, does the applicant apply additional technical and administrative security controls consistent with the data’s sensitivity?
Yes No If no, explain. Not applicable
Note that complying with the covered list of prohibited information technology systems ALSO includes certifying that you don’t use any equipment that is prohibited (https://www.fcc.gov/supplychain/coveredlist) or covered under the foreign made routers restrictions. ( https://www.fcc.gov/sites/default/files/NSD-Routers0326.pdf)
If you want advice and support as you build out your team, check out our StartupTherapy™ Resources and Help page!
Designer Investor Resources – Fundamentals of Raising Startup Capital is another summary page of great resources to help you if you are raising capital from investors.
Don’t forget, if you need more help, check out our online course, Develop a Winning SBIR Strategy, and don’t forget your free guide below! It is truly unique in the industry, make sure to grab your copy!

