Editor's note: This article has been updated to reflect the April 2026 SBIR/STTR reauthorization, the expanded TABA rules, and the July 2026 suspension of CMMC Phase 2.
The Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs, often called "America's Seed Fund," are officially back. On April 13, 2026, the Small Business Innovation and Economic Security Act was signed into law, reauthorizing both programs through September 30, 2031 and ending a six-month lapse that had frozen new solicitations and awards across 11 federal agencies. Since 1982, these programs have invested more than $81 billion in over 34,000 small businesses.
For startups and small businesses that rely on SBIR/STTR funding, this is the stability the market has been waiting for. But as our partners at FedTech put it in their recent analysis, SBIR and STTR are back, but the bar is higher. Innovation still matters, but transition, commercialization, and research security matter more than ever. Agencies are working through a significant backlog of solicitations and awards, timelines are tighter, and companies that are operationally ready will capture opportunities that slower competitors miss.
Here is what changed, and what it means for your compliance strategy.
The reauthorization did more than turn the programs back on. Key updates include:
One of the most significant and least discussed changes is what the reauthorization did to Technical and Business Assistance (TABA).
TABA has always helped awardees access outside expertise for commercialization, delivered at no cost to founders. Support flows in one of two ways: agencies may directly fund approved vendors on behalf of small businesses, or provide additional funding so companies can contract consultants and service providers of their choosing. The new law expands TABA in three ways that matter directly to your compliance strategy:
For a Phase II awardee, that $50,000 can cover a complete NIST SP 800-171 Gap Assessment and meaningful remediation planning. Compliance readiness is now a funded activity, not a distraction from R&D.
On July 13, 2026, the Department of Defense suspended CMMC Phase 2, which would have required third-party (C3PAO) certifications in applicable contracts beginning November 10, 2026. Phases 3 and 4 are suspended as well, and a CMMC Reform Task Force is conducting a 60-day review of the program, with industry RFI responses due August 14, 2026.
We covered the suspension in detail in our post, CMMC Phase II Is Suspended: What It Actually Means for Your Contracts. The short version for SBIR awardees:
What is paused:
What remains fully in force:
The certification mechanism is paused. The security requirement is not. And with the proposed FAR CUI rule moving to extend safeguarding obligations across civilian agencies, awardees working with NIH, NASA, DOE, and NSF should expect similar expectations regardless of what happens with CMMC.
Put these developments together and a clear picture emerges:
Companies that treat this window as a reason to pause will be reacting late. Companies that use it to close gaps, document their environment, and strengthen their SPRS position will be first in line when contracts and follow-on opportunities move.
At Peerless, we hold our own CMMC Level 2 certification as a managed service provider, so the standards we help you meet are standards we have met ourselves. We support organizations navigating the transition from SBIR/STTR innovation to operational readiness.
Through our partnership with FedTech, an equity-free deep tech commercialization platform that has built 180+ companies since 2015 and serves as the preferred TABA provider for Army Phase I and II SBIR/STTR and NOAA Phase II awardees, we work closely with startups and small businesses participating in SBIR/STTR programs, including those leveraging TABA funding, to align cybersecurity and CMMC compliance with their growth strategy.
Our approach helps organizations:
Assess your alignment with NIST SP 800-171 and establish an accurate SPRS score. If you are self-attesting today, make sure the score you report is one you can defend.
If you are writing a proposal, request TABA, name your preferred provider, and include cybersecurity readiness in the scope. If you already hold an award and did not request TABA at proposal time, you may still be eligible, so ask your agency or a TABA provider like FedTech how to access funding for compliance work.
Develop the policies, procedures, and technical controls that support certification requirements. The reform review may change the mechanism, but it will not change the underlying standard.
Remediate now, while assessor demand is lower and TABA dollars are available, so you are ready the moment certification requirements resume.
The 2026 reauthorization delivered what SBIR companies needed most: stability, funding, and a clear runway through 2031. It also raised expectations. Faster timelines, research security screening, and continuing DFARS obligations mean operational readiness is now part of how you compete.
The good news is that the same law that raised the bar also funds the climb. TABA can pay for your compliance readiness, and the right partner can carry you from first assessment to certified.
Innovation gets you funded. Readiness helps you scale.
Ready to talk through your compliance posture? Speak with a Peerless compliance expert today.
These Stories on Compliance