New NIH CyberSecurity Questions during JIT Document Requests

Wow!  Teams which had submitted SBIR or STTR proposals to the NIH last September and who weren’t immediately funded at that time are getting JIT (just in time) notices as they’ve moved up the funding priority list.  NIIH (in recent webinars) has made it clear that they are expecting a HUGE influx of proposals in September, and that they’re going to put money to work in well-scored proposals from last September in the meantime.

With the new re-authorization, a number of requirements have either been added or strengthened.  You can see a collection of various JIT requirements sent to teams being considered on our post What to Expect with NIH JIT.

But one requirement grabbed my attention in a serious way.

NIH now has the foreign disclosures form (Required Disclosure of Foreign Affiliations or Relationships to Foreign Countries form) AND this form also includes a cybersecurity questionnaire.  This has not been spoken about publicly by NIH this past month and I felt when one of our coaching companies showed it to us, that it was a bit of a blind side.   These cybersecurity requirements seem pretty heavy, especially for a startup or very early company.

You can get the full form at – https://grants.nih.gov/grants/funding/SBIR-STTR-Foreign-Disclosure-Form.pdf

https://seed.nih.gov/foreignrisk  (details of foreign risk assessment)

Excerpt of Cyber questions from foreign disclosure form

HHS Specific Disclosure Questions – Cybersecurity & Information Safeguarding
1. Does the applicant maintain a cybersecurity plan that includes regular cybersecurity training for all covered individuals and self-assessments or internal reviews to verify ongoing cybersecurity compliance and hygiene practices?
Yes  No If no, explain.

2. Does the applicant implement cybersecurity controls consistent with applicable federal cybersecurity frameworks, including at a minimum FAR 52.204-21 and NIST guidance?

Yes   No If no, explain.

3. Does the applicant certify that it does not use prohibited information technology systems or services as listed in https://www.fcc.gov/supplychain/coveredlist or foreign country of concern-controlled IT)?
Yes   No If no, explain.

4. For projects that involve export-controlled technology, controlled unclassified information (CUI), or multiomic data, does the applicant apply additional technical and administrative security controls consistent with the data’s sensitivity?
Yes   No If no, explain.  Not applicable

Note that complying with the covered list of prohibited information technology systems ALSO includes certifying that you don’t use any equipment that is prohibited (https://www.fcc.gov/supplychain/coveredlist) or covered under the foreign made routers restrictions. ( https://www.fcc.gov/sites/default/files/NSD-Routers0326.pdf)


If you want advice and support as you build out your team, check out our StartupTherapy™ Resources and Help page!
Designer Investor Resources – Fundamentals of Raising Startup Capital is another summary page of great resources to help you if you are raising capital from investors.

Don’t forget, if you need more help, check out our online course, Develop a Winning SBIR Strategy, and don’t forget your free guide below!  It is truly unique in the industry, make sure to grab your copy!


Interested in creating an SBIR proposal?
Click to Get our free guide “40 Ways to Improve your SBIR/STTR proposal!

Nicole Toomey Davis Awards Interviews

Leave a Reply

Your email address will not be published. Required fields are marked *