Relevant Policy

May 13, 2024: Defense Small Business Innovation Research and Small Business Technology Transfer Due Diligence Program

July 9, 2026: 2026 Department of War (DoW) Small Business Innovation Research and Small Business Technology Transfer Foreign Risk Evaluation Program Common Decision Matrix

In May 2024, the Deputy Secretary of Defense established the Defense SBIR/STTR Due Diligence Program to screen small businesses for foreign ownership, control, and influence before award. As of July 2026, that program has been reissued as the DoW SBIR/STTR Foreign Risk Evaluation (FRE) Program, on a new statute, a simplified decision structure, and a much larger set of named prohibited-entity triggers. Here are the changes that matter most, with source language, and what each means for companies applying to SBIR/STTR topics, the analysts conducting reviews, and the program managers running FRE/DD programs.

Most Significant Impacts (BLUF)

SBIR/STTR Applicants (Small Businesses)

  • More clarity and insight into FRE program risk review. The prohibition and mitigation requirements state what you are LEGALLY REQUIRED to do prior to receiving an award. Documented and proactive mitigation included in the proposal package will give you a significant advantage and reveal a culture of integrity and transparency
  • Stand up an internal security function, checking owners, employees, etc. against foreign entities of concern (FEOCs). As a startup, this doesn’t need to be extensive. At a minimum, check the prohibited factors against your company and people. 

SBIR/STTR Risk Analysts 

  • Expanded prohibited list screening of companies, employees, and affiliates. This requires more sophisticated tooling and entity-sanctions mapping.
  • While non-security risks are allowed (see below quotes), security is clearly the priority. In practice, this isn’t a big change but the intent is made more explicit.
  • More clarity through policy decision support rather than HML scoring. Components, however, maintain discretion. The policy establishes a stronger minimum standard.

FRE Program Managers

  • Build scalable processes and support capability development for requirements in this matrix which are not yet in use

Quotes Supporting Component Discretion

“Table 1 [decision matrix] is not an exhaustive list of all potential risk factors”

“…security risks manifest through, but are not limited to, the risks described in 15 U.S.C. § 638(vv)(2)”

“Mitigation Measures Required for Award: Rejection required if Component determines sufficient mitigation is not possible.

→ the policy gives language which allows analysts to account for matrix-excluded but material risks and enables component-level judgement. 

1. New name, new legal distinction

2026: “The ‘Defense SBIR and STTR Due Diligence Program’ has been formally redesignated as the ‘Foreign Risk Evaluation (FRE) Program.’ This change clearly distinguishes these security-focused reviews from routine financial and legal due diligence.”

The 2024 memo never separated security screening from general DD. 2026 makes this explicit.

  • Companies: Don’t treat FRE as covered by your standard financial/legal DD process. It’s a distinct security track with its own form and criteria.
  • Analysts: Report FRE findings using security-risk logic, not commingled with other risk findings. Recognize there may be material risks found outside the matrix. These may also be considered in the decision, especially if they relate to security.
  • Program managers: Update SOPs, training, and repository naming to reflect “FRE”

2. New statutory foundation, more prescriptive

2024: “Pursuant to 15 U.S.C. § 638(g)(15)(B), the DoD is prohibited from making an award…” (a compound factor-plus-harm test). 2026: “The FRE program is established in accordance with 15 U.S.C. § 638(vv). The statute requires executive agencies to assess specific security risks for each SBIR/STTR proposal.”

  • 638(vv) is newer and enumerates eight specific assessment requirements (cybersecurity, patents, employees, ownership, affiliations, investments, licensing, business relationships), reproduced in full as Appendix A.
  • Companies: Compliance review should now map to § 638(vv)’s eight categories directly, not the older statute. Those are areas which are required for assessment.
  • Analysts: Cite § 638(vv) in written assessments/memos to strengthen defensibility.
  • Program managers: Confirm Component policy documents cite the current statute.

3. Five-tier risk ladder replaced by a binary test (no more HML!)

2024: “Prohibited Factors… Very High Risk… High Risk… Medium Risk… Low Risk…” with criteria varying by time period (before/after Oct 2019, Aug 2022, Aug 2024). 2026: “Prohibited Factors… Mitigation Measures Required for Award – Rejection required if Component determines sufficient mitigation is not possible… No Mitigation Required.”

  • Companies: Simpler to track. Companies should conduct their own internal matrix assessment to see where they sit with FRE. This requires building an internal picture of your company, people, and associated relationships.  
  • Analysts: Shift from a five-point score to a binary mitigability judgment, with more narrative justification required.
  • Program managers: Risk Mitigation Review Board charters and training built around the old four escalation tiers need rebuilding.

4. Prohibited-entity lists spelled out — plus a new policy-based layer

2024: Fewer lists named (1286, BIS Entity List, BIS Denied Persons, 1260H, SDN) . 2026: Names eight statutory lists (UFLPA, Non-SDN CMIC, Section 889, NDAA 1260H, BIS Military End User, BIS Entity List, FCC List of Equipment and Services, CBP WRO/Findings List) and adds a new “Entities Prohibited by Policy” section: “the DoW 1286 List… the SDN list… the Denied Persons List… the Debarred Parties List… the Annex to Executive Order (EO) 14032…”

  • Companies: Screen company and employee relationships against all thirteen named lists. Incorporate these employee checks into hiring practices.
  • Analysts: Build screening workflows around these prohibited lists.
  • Program managers: Add explicit guidance for policy-list screening as distinct from statutory-list screening.

5. FCOC is no longer a fixed list

2024: “FCOC: The People’s Republic of China, the Democratic People’s Republic of Korea, the Russian Federation, and the Islamic Republic of Iran.” 2026: Same four countries, “or any other country determined to be a country of concern by the Secretary of State.” [Countries of Particular Concern List by DoS]

  • Companies: FCOC exposure can change without a matrix revision — don’t treat the list as static. Check first for the standard FCOCs then for all companies on the DoS CPC list. Document and mitigate where required.
  • Analysts: Check current State Department determinations regularly and cross-check all company or people locations with the DoS Countries of Particular Concern list. Recommend additionally checking for obfuscation countries.
  • Program managers: Build a mechanism to catch and propagate FCOC designation changes quickly.

6. “Covered Individuals”, “owners”, and “key employees” are delineated and treated differently

2024: Covered individual defined functionally — substantial contributor, PI/co-PI. 2026: “…contributes in a substantive, meaningful way… and (B) is designated as a covered individual by the Federal research agency concerned.” Key employee newly designated: “has a critical influence in or substantive control over the operations or management of the concern.” Owner undefined but is implied to mean “person with influence or control over the company”.

  • Companies: When assessing internally, look at covered individuals, key employees (including leadership), and owners.
  • Analysts: You’re not just assessing engineers/covered individuals anymore – you’re assessing owners and key employees too. The decision matrix shows nuanced requirements factor by factor which need to be carefully scrutinized.
  • Program managers: Stand up a defined designation process — the statute now presupposes one exists. 

7. Patent USG-funding check dropped

2024: “All patent application(s) or patent(s) resulting from research funded by the USG have been filed in the U.S. prior to filing in any other country.” 2026: “All patent application(s) or patent(s) have been filed in the U.S. prior to filing in any other country.” — the USG-funding qualifier is dropped.

  • Companies: Foreign-first filings unrelated to SBIR/STTR-funded work may now read as a risk indicator; revisit foreign-filing sequencing across the full portfolio.
  • Analysts: Identify any patents filed on behalf of an FEOC, especially those which were previously filed in the US. 
  • Program managers: Ensure patent analysis is a component of the FRE process and considered in the final assessment.

Overall implications

These changes point toward DoW making foreign-risk screening more precise, more codified, and operationally simpler to execute, while expanding the surface area for a company to be found at risk. The binary mitigation test reduces scoring ambiguity for analysts; meanwhile, thirteen explicitly named prohibited lists, discretionary FCOC expansion, and broadened patent/financial-relationship language all raise the bar for what companies must track and disclose.

Companies now face a longer, more explicit list of authorities to screen against, a foreign-country list that can shift without notice, and clearer expectations to disclose individual-level financial and fiduciary ties. Analysts need to upgrade tooling around binary mitigability judgments, expanded list screening, and sophisticated matrix assessments which record evidence associated with a rating. DD/FRE Program managers must update statutory citations and build processes for expanded requirements.

More broadly, this update is a useful bellwether for the rest of the DoW and federal due-diligence community: consolidating scattered prohibitions into explicit enumerations, replacing graduated risk tiers with binary decision support, and building discretionary expansion authority into core definitions are patterns likely to recur as other FOCI and foreign-influence frameworks are next revised.

Note from the author, Bruce Jansa: I am personally a huge fan of replacing the HML matrix with explicit decision-support for prohibition and mitigation. Policy should set the minimum standard for assessment and decision-making while enabling components to make their own decisions based on their own perspectives and tolerances. The only improvement I would recommend is clarifying explicit component authority to make risk-based decisions outside of the matrix. Language in the key quotes I mentioned shows the non-exhaustive scope of the matrix. But if a company is found, for example, to be committing likely fraud during the review, I believe the component has the right and obligation to support a risk-based reject decision. Legal teams rely on policy when defending against protests and this policy does not give as much breathing room for decision-making discretion outside the matrix as I had hoped. Overall, I believe that this policy and its intent is a significant step in the right direction.