DAF SBIR DAF26BX06-DV512: Cyberspace Warfare for Space

Quick Answer

DAF26BX06-DV512 is a Department of the Air Force SBIR Direct to Phase II topic under the DAF 2026 SBIR Commercial Solutions Opening, Release 6. SpaceWERX, working with Cyberspace Warfare professionals in the U.S. Space Force, is looking for solutions that defend space systems from adversarial attack through the cyber domain. The topic is organized into eight distinct focus areas, and proposals need to address one or more of them, not all eight. Awards are up to $2,000,000 for up to 24 months, with a 20 page technical volume limit. The topic opens September 23, 2026 and closes October 21, 2026 through the Defense SBIR/STTR Innovation Portal.

The eight focus areas are genuinely different businesses: data ingestion, software supply chain vetting, on-orbit cyber defense running on a satellite, a cyber range for training space operators, data parsing and normalization, AI threat detection, supply chain risk analytics, and a portable field kit. A company with a mature product in any one of them has a credible path here, which makes this the broadest topic in the release and probably the most accessible to commercial cybersecurity firms that have never worked with the Space Force.

Topic At a Glance

Topic number: DAF26BX06-DV512

Title: Cyberspace Warfare for Space

Solicitation: Department of the Air Force 2026 SBIR Commercial Solutions Opening (CSO), Release 6, Direct to Phase II

Sponsoring organization: SpaceWERX, in partnership with Cyberspace Warfare professionals within the U.S. Space Force

Program type: Direct to Phase II (D2P2), no Phase I awards will be made for this topic

Award maximum value: $2,000,000

Award maximum duration: 24 months

Technical volume page limit: 20 pages or slides

Component Technology Priority Area: Space Technology

Projected CMMC level requirement: Level 2 (Self)

Export control status: Restricted under ITAR 22 CFR Parts 120-130 and EAR 15 CFR Parts 730-774

Focus areas: eight, and proposals should address one or more

Target maturity for Phase III transition: TRL 6 or 7

Topic open date: September 23, 2026

Proposal deadline: October 21, 2026, at the time stated in the DoW FY26 SBIR CSO

Selection timeline: within approximately 90 calendar days of solicitation close, meaning on or about January 19, 2027

Submission portal: DSIP at dodsbirsttr.mil

Keywords: SpaceWERX, on-orbit cyber defense, space vehicles, autonomous cyber response, real-time monitoring, defensive cyber warfare, artificial intelligence, machine learning, threat simulation

Note on the deadline time. The DAF instructions direct applicants to the DoW FY26 SBIR CSO for the proposal submission deadline date and time. DoW SBIR CSO deadlines are ordinarily 12:00 p.m. Eastern on the close date. Confirm on the live DSIP posting rather than assuming end of day.

What the Space Force Is Actually Trying to Build

The strategic framing

The Space Force's defensive cyber operations mission is focused on rapid integration of capabilities into the Defensive Cyber Warfare pipeline, referred to throughout as DCW, to address the unique and complex cybersecurity requirements of space systems. The stated aims are to enable scaling of current DCW systems for widespread protection and to improve Space Force operational readiness.

The Space Force describes the change it wants in terms worth quoting closely, because they tell you what language to use. Modernizing Defensive Cyber Warfare for Space requires shifting from fragmented, reactive security to a cohesive, intelligence-driven posture that spans from the commercial supply chain to the orbital edge.

That phrase, from the commercial supply chain to the orbital edge, is the organizing idea behind the eight focus areas. Two of them are supply chain problems, three are data and analytics problems on the ground, one is a training environment, one runs on the satellite itself, and one goes in a case to a forward location.

The initiative is described as seeking to build a unified defense ecosystem where AI-enhanced vetting ensures the integrity of hardware and software long before deployment. Once operational, agile data architectures will seamlessly normalize complex telemetry across hybrid networks, fueling advanced machine learning engines to autonomously detect and intercept threats in real time. The focus areas should optimize the existing IT environment to minimize cost and maximize efficiency. By extending lightweight, resilient safeguards directly onto spacecraft and disconnected ground infrastructure, and validating them through hyper-realistic, immersive training environments, the initiative aims to equip cyber operators with a decisive, end-to-end advantage against advanced adversaries.

The desired outcome, stated at the top, is to produce capabilities that advance the domain of defensive cyber warfare operations in eight different focus areas, each presenting a unique opportunity for industry. This initiative supports the Space Force's broader strategy to generate, present, sustain, and improve Cyberspace Warfare forces for the Joint Force.

The eight focus areas

Proposals should address one or more of the following. Pick the one where you have real product maturity and feasibility evidence, and say so clearly and early in your proposal.

Focus Area 1: Lightweight and Cloud-Agnostic Data Ingest. To support future-ready data operations for DCW systems, the team wants best value, lightweight, efficient data ingestion at the edge or at the hub. The named problem is the significant infrastructure overhead associated with traditional data capture methods. Solutions should deploy with minimal impact to existing systems, providing high-throughput data capture without demanding extensive hardware or complex configurations. The goal is to pull critical data into analytics platforms so that on-premises monitoring capabilities are both effective and sustainable. In parallel, the effort is interested in cloud data ingestion, with Cloud Service Provider agnostic approaches offering flexible and scalable ingestion independent of cloud provider solutions, including exploring technologies such as virtual TAPs. The ultimate objective is a cohesive data ingest solution independent of the underlying infrastructure, whether on-premises, in a single cloud, or across a multi-cloud landscape.

Focus Area 2: Defensive Cyber Warfare Systems, Proactive Software Assurance and Malware Detection. To safeguard DCW systems against an increasingly compromised global software supply chain, the team wants advanced capabilities for deep inspection and security vetting of third-party software packages. The initiative is twofold, addressing both Free and Open-Source Software and non-approved Commercial Off-the-Shelf products, with the goal of proactively identifying and mitigating threats before they enter critical operational environments. Solutions should thoroughly evaluate FOSS packages to produce a comprehensive Software Bill of Materials and detailed risk analysis, automatically alerting operators to embedded malware, hidden back-doors, and vulnerabilities corresponding to the OWASP Top 10. A key feature will be the ability to trace software origin and development lineage, providing critical intelligence on contributions from foreign nationals or known adversaries. A similar vetting mechanism is desired for COTS software not currently on an Approved Product List, leveraging techniques such as binary analysis, SBOM generation, or other advanced methods to produce a thorough risk assessment covering both specific security vulnerabilities and broader digital supply chain risks. These detection mechanisms would provide the greatest value if implemented for validation onboard or integrated prior to space system deployment.

Focus Area 3: On-Orbit Space Vehicle Cyber Defense and Monitoring. The team wants an advanced on-orbit detection and response capability for Space Vehicles that directly reduces or negates the impact of cyber-attacks on critical space systems. The primary objective is to deploy a persistent monitoring solution directly onto the Space Vehicle that can identify and, in approved instances, autonomously respond to malicious activity in real time. This onboard capability should integrate seamlessly with existing ground-based DCW systems so all telemetry and alert data are relayed to terrestrial monitoring centers. Solutions should monitor a wide spectrum of the Space Vehicle's internal functions, including detecting unauthorized software, firmware, or critical configuration changes; monitoring traffic on essential, non-redundant components such as the 1553 Bus and SpaceWire; and identifying anomalous behavior such as irregular commands or malware uploads. The system should be sensitive to threat indicators targeting the vehicle's core subsystems, including triggers related to power manipulation, system timing interference, or unauthorized payload function commands. Upon detecting an approved event, the system should execute a direct response on the Space Vehicle and transmit comprehensive logs to the ground segment for analysis. Given the highly restrictive nature of space platforms, solutions should be engineered with minimal size, weight, and power impact, and software-based solutions that impose a negligible resource footprint on the host vehicle are strongly preferred. Offerors should be aware that development and testing will likely be conducted using high-fidelity environments such as a FlatSat or realistic simulations.

Focus Area 4: Immersive Space Cyber Test Environment. The team wants a comprehensive and immersive test and purple teaming platform designed to prepare cyber operators for the unique challenges of defending space systems against advanced cyber threats. The objective is a realistic, hands-on environment where operators develop and hone skills in detecting and responding to attacks targeting space assets and their supporting infrastructure, described as instrumental in building a proficient and mission-ready cyber defense workforce. The proposed solution should include two core high-fidelity components: a simulated space asset, which could be a physical FlatSat or a sophisticated digital twin, and a corresponding simulated ground system. The ground simulation should realistically model all essential elements, including the ground control segment, remote tracking stations, and antenna systems. A critical requirement is full integration of the government-furnished DCW tool suite, allowing operators to train with the actual systems they will use in live missions. The training platform should also come equipped with a robust curriculum of realistic, scenario-based cyber-attacks serving as the foundation for training exercises, simulating credible threats including direct cyber-attacks against the space vehicle's onboard systems, attacks targeting the ground control systems, and threats aimed at compromising the communication and access links between the space and ground segments.

Focus Area 5: Adaptive Data Parsers and Transformation Engine. The team wants a universal parser or data transformation mechanism capable of ingesting and normalizing a wide array of data types into a single standardized format for seamless integration into DCW analytics systems. The stated problem is that developing dedicated parsers for each data source is time consuming, labor intensive, and creates significant code maintenance challenges. The needed solution handles a wide range of data types used in analytics, including space specific protocols, proprietary logs from various network devices, proprietary data types produced by cyber tools, and non-standard formats from numerous intelligence threat feeds. It should minimize code maintenance when new Security Information and Event Management systems or data structures are introduced, and support incorporation of new data formats without requiring major code revisions. By transforming disparate data into a common, queryable format, the solution will significantly enhance analytical capabilities and provide a comprehensive, correlated view of the battlespace, described as essential for creating a unified and consistent data pipeline fundamental to effective security monitoring, threat hunting, and incident response.

Focus Area 6: AI-Driven Cyber Threat Detection. In response to emerging adversarial tactics, the team recognizes that traditional signature-based detection methods are no longer sufficient to provide a decisive advantage, and wants to augment DCW systems with an advanced, behavior-based threat detection capability. The solution should leverage artificial intelligence, machine learning, or advanced heuristics to establish a baseline of normal activity and proactively identify anomalies indicative of a compromise. Required elements include anomaly detection across multi-domain data sources such as network, host, user, and space specific telemetry; automated threat hunting correlating disparate indicators to reveal hidden patterns; predictive analytics identifying potential attack vectors before they are exploited; and natural language processing that automatically analyzes and correlates intelligence from multiple threat feeds. AI and ML capabilities should be trained in an operational-like environment to reduce noise and optimize detection, and should operate effectively in bandwidth constrained or contested environments common to space operations. Automated triage and prioritization of alerts is needed to reduce analyst fatigue and speed response times, along with AI assisted incident response recommendations informed by historical attack patterns and mission context.

Focus Area 7: AI-Driven Digital Supply Chain Illumination and Risk Management. The team wants a comprehensive digital supply chain risk management capability to safeguard the flow of software and hardware from vendors and suppliers. Proposed solutions should leverage artificial intelligence and advanced analytical tools to provide deep, multi-tier visibility and proactive risk identification across the entire supplier ecosystem. The capability should continuously monitor and analyze a wide range of data sources to deliver real-time intelligence on potential disruptions, including detecting cybersecurity risks such as data breaches or attacks within a supplier's network, as well as broader supplier and operational risks including material shortages, production delays, financial instability, or legal and labor issues. The system should use AI to identify and alert on emerging threats that could impact the ecosystem, protecting against both immediate cyber threats and long-term operational disruptions. By creating a unified view of the supply chain and automating vulnerability detection, this capability enables a move from a reactive to a predictive and resilient posture, ensuring the integrity and continuity of DCW systems.

Focus Area 8: Portable Edge Cyber Defense Kit. The team wants a lightweight, portable, plug-and-play fly-away kit for cyber threat detection, investigation, and response at remote and forward-deployed locations. As operations increasingly extend into austere environments, the Space Force wants a self-contained capability that functions effectively with limited or nonexistent network connectivity, addressing the challenge of robust cyber defense in disconnected, intermittent, and low-bandwidth settings where reliance on centralized security infrastructure is not feasible. The kit should empower operators to conduct local threat hunting and initial remediation, ensuring security of critical assets at the tactical edge. It should be engineered with a minimal physical footprint for portability and ease of deployment, and should possess onboard processing and analytical power to autonomously detect and investigate threats without real-time reach-back. A critical requirement is sufficient internal storage to collect and securely hold logs, forensic data, and other mission-critical artifacts for extended periods, and that stored data must be easily transferable so operators can push it to central analysis platforms for deeper post-mission analysis upon returning to a connected environment. The kit should provide an intuitive interface enabling an operator to effectively manage incidents and secure networks in the field, bridging the gap between disconnected operations and enterprise-level situational awareness.

Which focus area fits you

A short guide to self-selection. If you build data pipeline or observability infrastructure, look at Focus Areas 1 and 5. If you do SBOM generation, binary analysis, or software composition analysis, Focus Area 2, and if you do supplier risk intelligence, Focus Area 7. If you build embedded security or runtime monitoring for constrained systems, Focus Area 3, which is the most space-specific and most technically distinctive of the eight. If you build cyber ranges, digital twins, or training platforms, Focus Area 4. If you build behavioral detection, UEBA, or AI security analytics, Focus Area 6. If you build deployable forensic or incident response appliances, Focus Area 8.

The two focus areas with the highest barrier to entry, and therefore the least competition, are 3 and 4, because both require genuine space system knowledge. Focus Area 3 asks for monitoring on a 1553 Bus and SpaceWire in a minimal SWaP footprint, tested against a FlatSat. Focus Area 4 requires integration of a government-furnished DCW tool suite into your range. The other six are closer to adaptations of commercial cybersecurity products, which makes them more accessible and probably more crowded.

The Feasibility Requirement

Direct to Phase II means you must document that you already completed the Phase I equivalent work outside the SBIR program. The DAF disqualifies proposals where the Phase I equivalency documentation does not establish the proposed technical approach's feasibility and technical merit, and applies that screen before evaluating technical merit.

What this topic requires, in three specific parts

The topic states it is intended for technology proven ready to move directly into Phase II, that Phase I awards will not be made, and that the applicant must provide detail and documentation in the D2P2 proposal demonstrating accomplishment of a Phase I type effort including a feasibility study. That includes determining, insofar as possible, the scientific and technical merit and feasibility of ideas appearing to have commercial potential. The applicant must have validated the product-mission fit between the proposed solution and a potential U.S. Air Force or Space Force stakeholder, and should have defined a clear, immediately actionable plan with the proposed solution and the DAF customer and end-user.

Then the topic lists three things the feasibility study should have. These are unusually explicit and you should mirror them as headings.

First, clearly identified the potential stakeholders of the adapted solution for solving the USAF or USSF needs.

Second, described the pathway to integrating with DAF operations, to include how the applicant plans to accomplish core technology development, navigate applicable regulatory processes, and integrate with other relevant systems or processes.

Third, described if and how the solution can be used by other Department of Defense or Governmental customers.

Notice that all three are about customers, integration pathways, and regulatory navigation rather than about technical performance. For a commercial cybersecurity company, that is the real bar on this topic. Your product probably works. What the Space Force is checking is whether you have identified who inside the USSF would use it, whether you understand the accreditation and integration path, and whether you can articulate broader government demand. If you have not had those conversations, that is the gap, and four weeks is not much time to close it.

The general D2P2 rules

The feasibility work must have been substantially performed by the applicant or the principal investigator.

Feasibility documentation cannot be based upon or logically extend from any prior or ongoing federally funded SBIR or STTR work. This authority exists for companies that matured technology outside the SBIR pipeline.

If technology in the feasibility documentation is subject to intellectual property rights, provide IP rights assertions, plus a short summary for each item asserted with less than unlimited rights describing the nature of the restriction and the intellectual property intended for use in the proposed research.

Feasibility documentation can be included as part of Volume 5 and is required of all proposal submissions.

Phase II and Phase III Expectations

Phase II: proposed solutions should develop and demonstrate innovative technologies to support operations as part of the Space Force's cyberspace warfare for space operations. Solutions should address one or more of the eight focus areas.

Phase III: potential Phase III efforts will pursue transition of the capability to operational use through non-SBIR/STTR funding streams, aiming for a Technology Readiness Level of 6 or 7 and demonstrating functionality in relevant environments. Phase II efforts that demonstrate technical maturity, integration feasibility, and mission alignment may be selected for continued development and deployment into operational environments.

During Phase III, performers may be expected to advance system readiness, demonstrate operational capability, enable cross-service application, and pursue dual-use commercialization. Phase III work may be performed with non-SBIR/STTR funding and can include further government-sponsored prototyping, operational transition activities, or commercialization via strategic partners in the defense and aerospace sectors.

The reference the Air Force cites for this topic is the GAO Technology Readiness Assessment Guide, at gao.gov/assets/gao-20-48g.pdf. That is a meaningful hint. If you are going to make TRL claims, and the Phase III target is stated as TRL 6 or 7, use the GAO guide's definitions rather than your own informal scale, and cite it.

Funding Allowance and Cost Structure

Award ceiling

Up to $2,000,000 across up to 24 months. The topic index states that proposals in excess of this amount will not be considered for evaluation or award, and proposals in excess of this duration will not be considered for evaluation or award.

The DAF also notes that per-award and per-topic funding caps are budgetary estimates only, more or less funding may become available, multiple procurements are planned and anticipated, each proposal is a separate procurement evaluated on its own merit, and the Government may award all, some, or none. Funding decisions are made with complete disregard to the other awards under the same topic.

Because this topic has eight focus areas and the Government may award multiple times, do not assume you are competing against every other proposal. You are most directly competing against other proposals in your focus area, though the topic does not commit to distributing awards across focus areas.

Contract type and fee

Generally firm-fixed-price contracts are appropriate for Phase II awards, and per the SBA SBIR/STTR Policy Directive, Phase II contracts must include profit or fee.

Technical and Business Assistance

Up to $50,000 per Phase II award, in addition to the per-topic total, identified in the Volume 3 Cost Proposal. Applicants may elect to use $25,000 on a first SBIR Phase II award and $25,000 on a sequential SBIR Phase II award.

TABA can only fund the activities in 15 U.S.C. 638(q)(1)(A) through (E): access to a network of scientists and engineers, assistance with product sales, intellectual property protections, cybersecurity assistance, market research, market validation, development of regulations and manufacturing plans, and access to technical and business literature through online databases. Those activities must serve one of these purposes: making better technical decisions, solving technical problems arising during the project, minimizing technical risks, developing and commercializing new commercial products and processes including intellectual property protections, and screening for potential foreign involvement in technology development or commercialization activities.

The detailed request must appear in Volume 5, including provider name, point of contact with email and phone, an explanation of the provider's unique qualifications, the tasks the provider will perform including purpose and objective, and total provider cost with hours and labor rates. Average or blended rates are acceptable. The task milestone list must track to the milestone payment schedule otherwise provided by the applicant. Requests that only specify a request value in the Volume 3 Cost Proposal will not be considered.

If using TABA to hire new staff, augment staff, or direct staff into training, provide names and positions, the business need to be filled or training to be provided, the number of employees to be hired, augmented, or directed into training, their qualifications or the detailed need for training, the tasks to be performed with a description of the activity and the purpose it serves, and total staff or training cost with hours and labor rates.

Cost volume expectations

A detailed cost proposal by individual cost element and by contractor fiscal year, in sufficient detail to determine the basis for estimates and the purpose, necessity, and reasonableness of each. Cost proposal attachments do not count toward page limits, and cost proposal information will be treated as proprietary.

Direct labor: key personnel by name where possible, labor category otherwise, with direct labor hours, labor overhead or fringe benefits, and actual hourly rates for each individual, which the Contracting Officer needs to determine whether hours, fringe rates, and hourly rates are fair and reasonable. For a software-heavy proposal this will be the dominant cost element and deserves the most care.

Direct cost materials: an itemized list of types, quantities, prices, and where appropriate purpose. For planned computer or software purchases, detailed information such as manufacturer, price quotes, proposed use, and support for the need will be required. Cloud infrastructure, commercial software licenses, and development hardware belong here.

Other direct costs: specialized services such as machining or milling, special test and analysis, and costs for temporary use or lease of specialized facilities or equipment, with usage hours, rates, sources, and justification. Leased hardware requires a lease versus purchase rationale. FlatSat access or cyber range infrastructure, depending on your focus area, may live here.

Special tooling, special test equipment, and material: carefully reviewed relative to need and appropriateness, must in the Contracting Officer's opinion be advantageous to the Government and relate directly to the effort, and should not be of a type an applicant would otherwise possess in the normal course of business.

Subcontracts: supported with copies of subcontract agreements adequately describing the work and cost bases, including a statement of work, assigned personnel, hours and rates, materials, and proposed travel. A letter from a subcontractor agreeing to perform a task at a fixed price is expressly not sufficient. The prime must accomplish price analysis including reasonableness, identifying the basis where prior efforts are used for comparison, and provide cost analysis where price analysis techniques are inadequate or the FAR requires cost or pricing data.

Consultants: a separate agreement letter for each, stating the service, hours required, and hourly rate, plus a short concise resume.

Travel: each effort should include at a minimum a kickoff or interim meeting, with destinations, trips, travelers, airfare, per diem, lodging, and ground transportation justified against the Joint Travel Regulation.

Indirect costs: indicate proposed rate bases, identify specific rates and allocation bases, and provide rates and applications per fiscal year across the anticipated performance period. Do not propose composite rates.

Non-SBIR governmental or private investment is allowed but not required and will not be a proposal evaluation factor.

If no exceptions are taken to your proposal, the Government may award a contract without exchanges, so your initial proposal should contain your best terms from a cost, price, and technical standpoint.

Work performance requirements

The instructions state two thresholds that do not obviously align. The Consultants and Subcontractors section requires, per the SBA SBIR Policy Directive, a minimum of 50 percent of the R/R&D be performed by the proposing firm unless otherwise approved in writing by the Contracting Officer. The Performance of Work Requirements section states that for Phase II a minimum of one-third of the research or analytical effort must be performed by the awardee, measured by both direct and indirect costs, not including profit. Separately, the proposed total of all consultant fees, facility leases or usage fees, and other subcontract or purchase agreements may not exceed one-half of the total contract price unless approved in writing by the Contracting Officer.

Planning to perform at least half the R/R&D in house and keeping all outside costs below half the contract price satisfies every reading. This is usually easier on a software topic than a hardware one, but watch cloud and licensing costs if you are treating them as purchases. If you cannot meet the thresholds, requests for Performance of Work deviations must be made twice: prior to submission during the topic open period, and again as part of the initial proposal submission. The DAF will not consider these requests before proposal submission. Given the ambiguity between the two stated thresholds, raise it with the DAF SBIR/STTR One Help Desk early.

Where work must be performed

All R/R&D must be performed in the United States by the small business and its team members. Based on rare and unique circumstances the DAF may approve a particular portion of the work to be performed or obtained outside the United States, and the awarding Funding Agreement officer must approve each specific condition in writing. Requests must accompany the initial proposal submission.

This deserves particular attention on a cybersecurity topic. Distributed engineering teams and offshore development are common in commercial software, and this requirement rules that out for the funded work absent specific written approval.

Export Control and Foreign Nationals

The technology in this topic is restricted under ITAR 22 CFR Parts 120-130, which controls the export and import of defense-related material and services including sensitive technical data, and EAR 15 CFR Parts 730-774, which controls dual use items.

Offerors must disclose any proposed use of foreign nationals, their countries of origin, the type of visa or work permit possessed, and the statement of work tasks intended for accomplishment by those individuals. The topic advises that foreign nationals proposed to perform on this topic may be restricted due to the technical data under U.S. export control laws.

A foreign national means any person who is not a citizen or national of the United States, not a lawful permanent resident, and not a protected individual as defined by 8 U.S.C. 1324b. All applicants proposing to use foreign nationals must follow the FY26 SBIR CSO and disclose regardless of whether the topic is subject to ITAR.

Where the topic area is subject to export control, permitted foreign national participants are limited to work in the public domain, and assigned tasks must not be capable of assimilation into an understanding of the project's overall objectives, which prevents foreign persons from acting in key positions such as Principal Investigator or Senior Engineer. Additional information may be requested during negotiations to verify eligibility.

For projects with military or dual-use applications developing beyond fundamental research, the contractor must comply with all U.S. export control laws, is responsible for obtaining appropriate licenses or approvals including for deemed exports of hardware, technical data, and software, must obtain export licenses before using foreign persons including where work is performed on-site at any Government installation whether inside or outside the United States, is responsible for regulatory record keeping associated with the use of licenses and exemptions, and must ensure these provisions apply to its subcontractors.

If asserting export-controlled status, a certified DD Form 2345, or evidence of application submission, belongs in Volume 5, and DD Form 2345 approval will be required if the proposal is selected for award.

There is a notable interaction with Focus Area 2. That focus area asks for the ability to trace software origin and development lineage, providing critical intelligence on contributions from foreign nationals or known adversaries. If you are proposing that capability, your own team composition and development practices are fair territory for scrutiny. Be prepared for that consistency check.

Proposal Structure: The Seven Volumes

Formatting

Type no smaller than 11-point on standard 8.5 by 11 paper, one-inch margins, pages consecutively numbered. This differs from Army SBIR instructions, which allow 10-point.

The technical volume limit is 20 pages or slides, and pages in excess will not be considered by the Government in evaluations. Because the limit is expressed as pages or slides, a slide-format volume is acceptable.

Twenty pages is tight for a topic with this much surface area. The strategic implication is to be decisive about scope: name your focus area or areas in the first paragraph, and do not spend pages surveying the other seven. A proposal that gestures at breadth across all eight focus areas will read as unfocused and will run out of room to substantiate anything.

Proposals should be direct, concise, and informative. Applicants are discouraged from including promotional and non-programmatic items, and if included that material counts toward the page limit. Marketing material will not be evaluated. Preferred format is PDF, graphics must be distinguishable in black and white, and all submissions must be virus-checked.

Volume 6 Fraud, Waste, and Abuse training must be completed before submission, and DSIP will not allow submission until it is complete and certified. The DAF recommends completing submission early because site traffic is heavy prior to close and causes system lag, will not be responsible for proposals not completely submitted before the deadline due to system inaccessibility unless advised by DoW, and will not accept submission outside DSIP.

Volume 1, Cover Sheet

Per DSIP instructions. The technical abstract should include a brief description of program objectives, a description of the effort, anticipated benefits, commercial applications, and a list of keywords and terms. The abstract of each successful proposal goes to the Office of the Secretary of War for publication and must not contain proprietary or classified information. If selected for funding, the technical abstract and discussion of anticipated benefits will be publicly released. For a cybersecurity topic, take care that your abstract does not disclose detection methods or architecture detail you consider protected.

Volume 2, Technical Volume

Required items in the order provided: table of contents immediately after the cover sheet; glossary of acronyms and abbreviations; milestone identification with a program schedule showing all key milestones; identification and significance of the problem or opportunity; Phase II technical objectives with technical approach and methods and an assessment of potential commercial application for each objective; work plan; deliverables; related work; commercialization potential; relationship with future R/R&D efforts; key personnel; facilities and equipment; consultants and subcontractors; and prior, current, or pending support of similar proposals or awards.

The work plan is a separate and distinct part of the proposal package, divided from the technical proposal by a page break and begun on a new page. It must contain a summary description of the technical methodology and task description in broad enough detail to provide contractual flexibility, and must not contain proprietary information, because if the proposal is selected the work plan will be incorporated into the resulting contract by reference. Recommended format is 1.0 Objective, a brief overview of the specialty area explaining purpose and expected outcome; 2.0 Scope, concisely describing the work including technology area, goals, and major milestones, with task development and deliverables as key elements, consistent with section 4.0; 3.0 Background, identifying appropriate specifications, standards, and other documents applicable to the effort, constraints to understanding requirements, relationships to previous, current, or future operations, and techniques previously determined ineffective; and 4.0 Task and Technical Requirements, with detailed individual task descriptions developed in orderly progression with sufficient detail to establish overall program requirements and goals, work segregated into major tasks in separately numbered paragraphs, each major task delineated by subtask. The work plan must contain every task to be accomplished in definite, realistic, and clearly stated terms. Use "shall" for binding provisions, "should" or "may" to express a declaration or purpose, and "will" when no contractor requirement is involved.

Deliverables must clearly describe the specific sample or prototype hardware and software to be delivered, plus data deliverables, schedules, and quantities. Be aware of the possible unique item identification requirement under DFARS 252.211-7003 for hardware, which matters if you are proposing Focus Area 8's fly-away kit or Focus Area 4's physical FlatSat. If hardware or software will be developed but not delivered, provide an explanation. At minimum all Phase II contracts require Scientific and Technical Reports. Rights in technical data including software developed under a SBIR contract generally remain with the contractor, and the Government obtains SBIR/STTR data rights in all data developed or generated under the contract for a period of 20 years commencing at contract award, after which the Government has Government purpose rights to the SBIR data. The Final Report's first page is a single-page project summary identifying the work's purpose, briefly describing the effort accomplished, and listing potential result applications, which may be published by DoW and therefore must not contain proprietary or classified information. Status reports are due quarterly at a minimum. The Air Force may require additional reporting including software documentation and users' manuals, engineering drawings, operation and maintenance documentation, safety hazard analysis when the project results in partial or total development and delivery of hardware, and updates to commercialization results.

For a software company, the 20 year SBIR data rights provision is the single most commercially significant clause in this document. Read it with counsel before you decide what code you are willing to develop under this award.

Related work must describe significant activities directly related to the proposed effort, including previous programs conducted by the principal investigator, proposing firm, consultants, or others, and their application to the proposed project, describe how these activities interface with the proposed project, and discuss planned coordination with outside sources. List any applicant-identified subject matter experts regardless of affiliation, providing comments regarding the applicant's knowledge of the state of the art in the specific approach proposed. Describe previous work not directly related but similar, with a short description, the client for which the work was performed including an individual to be contacted and phone number, and the date of completion.

Commercialization potential requires a commercialization plan addressing what the first planned product to incorporate the proposed technology is, who the probable customers are and the estimated market size, how much money is needed to bring the technology to market and how it will be raised, whether the firm has the necessary marketing expertise and if not how it will compensate, and who the probable competitors are and what price or quality advantage is anticipated. Commercial potential is evidenced by the existence of private sector or non-SBIR governmental funding sources demonstrating commitment to Phase II efforts and results, the existence of Phase III follow-on commitments for the research subject, and other indicators of commercial technology potential including the firm's commercialization strategy. If awarded, the awardee must periodically update commercialization results via SBA. The Commercialization Plan and the Company Commercialization Report are distinct documents.

Relationship with future R/R&D efforts must state the anticipated results of the proposed approach, specifically addressing plans for Phase III if any, and discuss the significance of the D2P2 effort in providing a basis for the Phase III effort if planned. Given that the topic states a Phase III target of TRL 6 or 7 and cites the GAO Technology Readiness Assessment Guide, use GAO TRL definitions here.

Key personnel must identify all key personnel with information directly related to education, experience, and citizenship, and include a technical resume for the principal investigator with publications. Concise technical resumes for subcontractors and consultants are also useful. Identify all non-U.S. citizens expected to be involved in the project as direct employees, subcontractors, or consultants, and for those individuals provide countries of origin, type of visa or work permit held, and identify the tasks they are anticipated to perform. The principal investigator's primary employment must be with the small business concern at the time of award and during the entire period of performance, where primary employment means more than one-half of the PI's time is spent in the small business's employ, which precludes full-time employment with another entity. Only one principal investigator or project manager may be designated per proposal.

Facilities and equipment must describe instrumentation and physical facilities necessary and available to carry out the effort, justify equipment to be purchased with detail in the cost proposal, and state whether proposed performance locations meet federal, state, and local environmental laws and regulations for airborne emissions, waterborne effluents, external radiation levels, outdoor noise, solid and bulk waste disposal practices, and handling and storage of toxic and hazardous materials.

Consultants and subcontractors: private companies, consultants, or universities may be involved and all should be described in detail and included in the cost proposal. Signed copies of all consultant or subcontractor letters of intent must be attached, briefly stating the contribution or expertise being provided, with statements of work, detailed cost proposals, and information regarding unique qualifications. Subcontract copies and supporting documents do not count against the Phase II page limit, which is a useful relief valve on a 20 page topic. Identify any subcontractor or consultant foreign citizens.

Prior, current, or pending support: while it is permissible with proper notification to submit identical proposals or proposals containing a significant amount of essentially equivalent work for consideration under numerous federal program solicitations, it is unlawful to enter into contracts or grants requiring essentially equivalent effort, and any potential for that situation must be disclosed to the solicitation agencies before award. If your proposal is substantially the same as another submitted previously, currently, or in the process of being funded by another federal agency, DoW component, or the DAF, indicate so on the cover sheet and provide the agency names and addresses, submission or award dates, proposal titles, PI names and titles, solicitation titles, numbers and dates, contract numbers if awarded, and the applicable topics for each. If the section does not apply, state so in the proposal and certify on the cover sheet, "No prior, current, or pending support for proposed work."

This section matters more than usual on this topic, because a commercial cybersecurity company with a mature product may well have submitted similar material to other agencies. Disclose fully.

Volume 3, Cost Volume

Covered above.

Volume 4, Company Commercialization Report

Required in DSIP. The DAF states that information contained in the CCR will not be considered during proposal evaluations, unlike Army SBIR practice. Complete it for compliance.

Volume 5, Supporting Documents

May be required if applicable: DD Form 2345, which applies to this export-controlled topic; Verification of Eligibility of Small Business Joint Ventures, Attachment 3 to the DoW SBIR FY26 CSO; and Technical Data Rights Assertions if asserting data rights restrictions. That last one deserves attention here. A commercial cybersecurity product built on years of private investment almost certainly carries background IP you want to protect, and asserting those restrictions properly is how you do it.

Required of all submissions: feasibility documentation as described above, including IP rights assertions with a short summary for each item asserted with less than unlimited rights describing the restriction's nature and the intellectual property intended for use in the proposed research.

If appropriate, include a reference or works cited list as the last page. Do not include marketing material, which will not be evaluated.

Volume 6, Fraud, Waste, and Abuse Training

Complete once per year, before submission.

Volume 7, Disclosures of Foreign Affiliations or Relationships to Foreign Countries

Complete the webform in Volume 7 of the DSIP submission. It will not be accepted as a PDF supporting document in Volume 5, and do not upload previous versions of the form to Volume 5.

How Your Proposal Will Be Evaluated

The criteria for this topic

DV512 is evaluated under the criteria set covering DV026, DV511, DV512, and DV513, in descending order of importance.

Criteria A, most important: the soundness, technical merit, and innovation of the proposed approach and its incremental progress toward topic or subtopic solution, and the qualifications of the proposed principal and key investigators, supporting staff, and consultants. This includes whether the proposed cost elements are realistic for the work to be performed, reflect a clear understanding of the requirements, and are consistent with the unique methods of performance and materials described in the technical proposal.

Note the phrase "toward topic or subtopic solution." With eight focus areas, the subtopic language is doing work: you are being assessed on progress toward the focus area you selected, so name it explicitly and frame your progress against it.

Criteria B, second: the degree of mission impact and the urgency of the identified need, the specificity of the defense requirement addressed, and the adequacy of the proposed effort in fulfilling the research topic or subtopic solution.

Criteria C, third: the potential for commercial application in the Government or private sector and the benefits expected to accrue from that commercialization.

For a commercial cybersecurity firm, the counterintuitive lesson is that Criteria C, where you are probably strongest, is the least important of the three. Your commercial traction is useful evidence but it does not carry the proposal. The weight sits on technical merit against a specific Space Force focus area and on mission urgency, which means your proposal needs to be written in the Space Force's language rather than repurposed from commercial marketing.

General evaluation process

D2P2 proposals are evaluated on a competitive basis by subject matter expert scientists, engineers, or other technical personnel, with confidential proposal and evaluation information protected to the greatest extent possible. Proposals will be disqualified and not evaluated if the Phase I equivalency documentation does not establish the proposed technical approach's feasibility and technical merit.

Selections are based on a determination of the overall technical value of each proposal and an evaluation of the cost volume for selection of the proposals most advantageous to the Government. Where technical evaluations are essentially equal in merit, cost or price will be considered in determining successful applicants. All evaluation criteria other than cost or price, when combined, are significantly more important than cost or price. The DAF is seeking varying technical and scientific approaches and varying and new technologies responsive to the problem statements and areas of interest in the topic, multiple procurements are planned and anticipated, each proposal is considered a separate procurement evaluated on its own merit, and the Government may award all, some, or none of the proposals.

Foreign risk evaluation

The DAF will evaluate all small business concerns submitting under this release on whether they present a security risk, using the due diligence process required under 15 U.S.C. 638(vv), disclosures required under 15 U.S.C. 638(g) and (o), and coordination with the intelligence community as defined in section 3 of the National Security Act of 1947, federal law enforcement, and other counterintelligence capabilities of the United States Government.

The risk-based assessment covers cybersecurity practices, patent analysis, employee analysis, foreign ownership including financial ties and obligations covering surety, equity, and debt obligations of the concern and its employees to a foreign country, person, or entity, foreign affiliations of a covered individual, owner, or other key personnel with an entity in a foreign country of concern, investment relationships with an individual or entity in a foreign country of concern, technology licensing agreements or joint ventures including joint venture like agreements with an individual or entity in a foreign country of concern, and business relationships between a covered individual, owner, or other key personnel and an individual or entity in a foreign country of concern.

Cybersecurity practices lead that list, and on this topic in particular the assessment of your own security posture carries obvious weight. A company proposing to defend Space Force systems should expect its own practices to be examined closely.

The DAF also assesses proposals using open-source analysis and analytical tools for nondisclosures of the information set forth in 15 U.S.C. 638(g)(13) or 638(o)(17), and examines any relationship of the concern to any entity or individual on the lists described in 15 U.S.C. 638(g)(16)(D) and 638(o)(20)(D).

If the DAF assesses security risks, it may either create a plan to mitigate them or decide not to select the proposal based upon a totality of the review.

Awards must be denied under 15 U.S.C. 638(g)(16) or 638(o)(20) where the concern has an owner or covered individual party to a malign foreign talent recruitment program; a business entity, parent company, or subsidiary located in the People's Republic of China or another foreign country of concern; an owner or covered individual with a foreign affiliation with a research institution located in the PRC or another foreign country of concern; or a security risk connecting the concern, including any affiliates, to an entity or individual on the UFLPA Entity List maintained by the Department of Homeland Security, the Non-SDN Chinese Military-Industrial Complex Companies List maintained by Treasury's Office of Foreign Assets Control, the Section 889 Prohibition List, the Section 1260H list of Chinese Military Companies, the Military End User List maintained by Commerce's Bureau of Industry and Security, the Entity List maintained by BIS, the FCC List of Equipment and Services, or the Withhold Release Orders and Findings List maintained by U.S. Customs and Border Protection. Awards are also denied where the concern has a security risk with a primary source that is classified, or a security risk the DAF determines warrants denial.

Applicants must disclose under penalty of perjury the representations, attestations, and certifications required under 15 U.S.C. 638(g)(13) and 638(o)(17), fulfilled by completing Volume 7, and must provide a written statement of any substantial changes to the foreign disclosure form to the awarding agency within 30 days of any changes while on a project for the DAF.

If an award is denied on these grounds, the DAF will as appropriate and in a manner that does not compromise security provide notification advising the small business of the determination, the basis for it, and a statement that denial does not prohibit eligibility for an award in a subsequent award cycle.

Ownership, support contractors, status, and protests

Small business concerns owned in majority part by multiple venture capital operating companies, hedge funds, or private equity funds are eligible to submit applications or receive awards for DAF topics. This is relevant on a cybersecurity topic, where venture funding is the norm.

Proposals may be handled for administrative purposes only by support contractors, which may include APEX, Peerless Technologies, Engineering Services Network, HPC-COM, Mile Two, REI Systems, MacB (an Alion company), Montech, Oasis, Astrion/Oasis, and Infinite Management Solutions. Only Government employees and technical personnel from the FFRDCs MITRE and Aerospace Corporation working under contract to provide technical support to Air Force Life Cycle Management Center and Space Force may evaluate proposals. All support contractors are bound by appropriate non-disclosure agreements. Contact the DAF SBIR/STTR Contracting Officer with concerns about any of these contractors.

The principal investigator and Corporate Official indicated on the cover sheet will be notified by email regarding selection or non-selection, with a separate notification for each proposal submitted. Read each notification carefully and note the proposal number and topic number referenced. Automated feedback is provided for proposals designated Not Selected, and additional feedback may be provided at the sole discretion of the DAF. Proposals are received and evaluated by different organizations, handled by topic, each operating on its own schedule, so notification timeframes vary.

The DAF anticipates that all proposals will be evaluated and selections finalized within approximately 90 calendar days of solicitation close. Refrain from contacting the DAF for proposal status before that time. Protests after award should be submitted, as prescribed in FAR 33.106(b) and FAR 52.233-3, to the Air Force SBIR/STTR Contracting Officer and to the individual procuring contracting officer listed on the firm's selection notification. Final reports go to the awarding DAF organization per contract instructions, not directly to the Defense Technical Information Center.

Timeline and What to Do When

The dates

Topic opens: September 23, 2026

Proposal deadline: October 21, 2026, at the time specified in the DoW FY26 SBIR CSO, ordinarily 12:00 p.m. Eastern. Confirm on DSIP.

Selections finalized: within approximately 90 calendar days of close, on or about January 19, 2027

Period of performance: up to 24 months from award

A working backward plan

Before September 23. Choose your focus area. That decision governs everything else, and it should be driven by where you have deployed product and documented results. Assemble the feasibility package around the three named elements: identified USAF or USSF stakeholders for your adapted solution, the pathway to integrating with DAF operations including core technology development, regulatory navigation, and integration with other systems, and whether and how other DoD or governmental customers could use it. Determine your export control posture and confirm which team members are U.S. persons under the stated definition. Review your own cybersecurity practices, since they are the first item on the foreign risk assessment list. Inventory your background IP so you can assert data rights properly. Complete Volume 6 training, verify SAM and DSIP alignment, and send clarifying questions to the DAF SBIR/STTR One Help Desk, which explicitly encourages early inquiries.

September 23 through October 3. Draft Volume 2 against the 20 page limit. Name your focus area in the opening paragraph. Build the milestone schedule early, since the TABA task milestone list must track to your milestone payment schedule. If you are proposing Focus Area 3 or 4, address FlatSat or simulation environment access explicitly, and for Focus Area 4 address integration of the government-furnished DCW tool suite.

October 4 through October 12. Build the cost volume by element and by fiscal year, with individual named labor rates, cloud and license costs itemized, and indirect rates per fiscal year with no composite rates. Collect signed letters of intent, statements of work, and detailed cost proposals from every consultant and subcontractor, remembering that a letter agreeing to a fixed price is not sufficient. Check your work-performance percentages against the thresholds and the one-half outside cost cap. Write the detailed TABA request into Volume 5 if requesting TABA.

October 13 through October 16. Assemble Volume 5 including Technical Data Rights Assertions and DD Form 2345, complete the Volume 7 webform, finish the Volume 4 CCR, and run compliance: 20 page limit, 11-point minimum type, one-inch margins, consecutive page numbers, graphics legible in black and white, virus-checked PDF, no marketing material, and no proprietary content in the technical abstract or the work plan.

October 17 through October 19. Submit and certify in DSIP.

October 20 through October 21. Buffer only.

Frequently Asked Questions

‍ ‍

What is DAF SBIR topic DAF26BX06-DV512?

‍ ‍

DAF26BX06-DV512 is a Department of the Air Force SBIR Direct to Phase II topic titled "Cyberspace Warfare for Space," released under the DAF 2026 SBIR Commercial Solutions Opening, Release 6. SpaceWERX, partnering with Cyberspace Warfare professionals in the U.S. Space Force, seeks next generation capabilities to defend space systems from adversarial attack through the cyber domain, organized into eight focus areas.

‍ ‍

How much funding is available under DAF26BX06-DV512?

‍ ‍

Up to $2,000,000 for a period of performance up to 24 months. Proposals exceeding either limit will not be considered for evaluation or award. Up to $50,000 in Technical and Business Assistance may be requested in addition to that ceiling.

‍ ‍

When is the proposal deadline?

‍ ‍

The topic closes October 21, 2026. The DAF instructions direct applicants to the DoW FY26 SBIR CSO for the exact submission time, ordinarily 12:00 p.m. Eastern on the close date. Confirm on the live DSIP posting.

‍ ‍

When does this topic open?

‍ ‍

September 23, 2026, giving a 29 day submission window.

‍ ‍

Do I have to address all eight focus areas?

‍ ‍

No. Proposals should address one or more of the eight focus areas. Choose the area where you have genuine product maturity and documented feasibility evidence, name it explicitly in your proposal, and resist the temptation to claim breadth across all eight. With a 20 page limit, a diffuse proposal cannot substantiate anything.

‍ ‍

What are the eight focus areas?

‍ ‍

Lightweight and cloud-agnostic data ingest; defensive cyber warfare systems with proactive software assurance and malware detection; on-orbit space vehicle cyber defense and monitoring; an immersive space cyber test environment; adaptive data parsers and a transformation engine; AI-driven cyber threat detection; AI-driven digital supply chain illumination and risk management; and a portable edge cyber defense kit.

‍ ‍

Which focus area is the best fit for my company?

‍ ‍

Data pipeline and observability companies should look at Focus Areas 1 and 5. SBOM, binary analysis, and software composition analysis companies at Focus Area 2, and supplier risk intelligence at Focus Area 7. Embedded security and runtime monitoring for constrained systems at Focus Area 3. Cyber ranges, digital twins, and training platforms at Focus Area 4. Behavioral detection and AI security analytics at Focus Area 6. Deployable forensic and incident response appliances at Focus Area 8.

‍ ‍

Which focus areas have the least competition?

‍ ‍

Focus Areas 3 and 4 carry the highest barrier to entry because both require real space system knowledge. Focus Area 3 requires monitoring a 1553 Bus and SpaceWire in a minimal SWaP footprint with FlatSat or simulation-based testing. Focus Area 4 requires integrating a government-furnished DCW tool suite into your training platform. The other six are closer to adaptations of commercial cybersecurity products and are likely more crowded.

‍ ‍

What does Focus Area 3 require technically?

‍ ‍

A persistent monitoring solution deployed directly onto the Space Vehicle that identifies and, in approved instances, autonomously responds to malicious activity in real time, integrating with existing ground-based DCW systems so all telemetry and alerts reach terrestrial monitoring centers. Monitoring must cover unauthorized software, firmware, or critical configuration changes, traffic on essential non-redundant components such as the 1553 Bus and SpaceWire, and anomalous behavior including irregular commands or malware uploads, with sensitivity to indicators targeting core subsystems such as power manipulation, system timing interference, or unauthorized payload function commands. Minimal size, weight, and power impact is required, and software-based solutions with a negligible resource footprint are strongly preferred. Development and testing will likely use high-fidelity environments such as a FlatSat or realistic simulations.

‍ ‍

Can I submit a Phase I proposal for this topic?

‍ ‍

No. This topic is intended for technology proven ready to move directly into Phase II, and Phase I awards will not be made.

‍ ‍

What feasibility documentation does this topic require?

‍ ‍

Detail and documentation demonstrating accomplishment of a Phase I type effort including a feasibility study, plus validated product-mission fit between your solution and a potential USAF or USSF stakeholder and a clear, immediately actionable plan with the DAF customer and end-user. The feasibility study should have clearly identified the potential stakeholders of the adapted solution for solving USAF or USSF needs, described the pathway to integrating with DAF operations including core technology development, applicable regulatory processes, and integration with other relevant systems or processes, and described if and how the solution can be used by other DoD or governmental customers.

‍ ‍

Can I use a prior SBIR award as my feasibility basis?

‍ ‍

No. Feasibility documentation cannot be based upon or logically extend from any prior or ongoing federally funded SBIR or STTR work, and the feasibility effort must have been substantially performed by the applicant or the principal investigator.

‍ ‍

How long can my technical volume be?

‍ ‍

20 pages or slides. Pages in excess will not be considered during evaluations. Type must be no smaller than 11-point on 8.5 by 11 paper with one-inch margins and consecutively numbered pages. Subcontract copies, supporting documents, and cost proposal attachments do not count toward the limit.

‍ ‍

Is this topic export controlled?

‍ ‍

Yes. The technology is restricted under ITAR 22 CFR Parts 120-130 and EAR 15 CFR Parts 730-774. You must disclose any proposed foreign nationals with countries of origin, visa or work permit type, and the statement of work tasks intended for them, and the topic advises those individuals may be restricted from performing. A certified DD Form 2345, or evidence of application, belongs in Volume 5, and approval will be required if selected for award.

‍ ‍

Can my offshore development team work on this?

‍ ‍

No, absent specific written approval. All R/R&D must be performed in the United States by the small business and its team members. The DAF may approve a particular portion of work performed or obtained outside the United States only based on rare and unique circumstances, with written approval from the awarding Funding Agreement officer for each specific condition, and the request must accompany the initial proposal submission.

‍ ‍

How is my proposal evaluated?

‍ ‍

Under three criteria in descending order of importance. Criteria A, most important, covers soundness, technical merit, and innovation of the approach, incremental progress toward the topic or subtopic solution, the qualifications of key personnel, and whether proposed cost elements are realistic and consistent with the technical proposal. Criteria B covers degree of mission impact, urgency of the identified need, specificity of the defense requirement, and adequacy of the effort. Criteria C covers commercial application potential. All criteria other than cost or price, combined, are significantly more important than cost or price.

‍ ‍

My company has strong commercial traction. Does that carry the proposal?

‍ ‍

Not by itself. Commercialization is Criteria C, the least important of the three. Technical merit against the specific focus area you selected and mission urgency carry the weight, which means the proposal has to be written in the Space Force's terms rather than repurposed from commercial materials.

‍ ‍

Who owns the software I develop?

‍ ‍

Rights in technical data including software developed under a SBIR contract generally remain with the contractor. The Government obtains SBIR/STTR data rights in all data developed or generated under the contract for 20 years commencing at contract award, after which the Government has Government purpose rights to the SBIR data. For a software company, this is the most commercially significant clause in the instructions and warrants review with counsel before you decide what to develop under the award.

‍ ‍

How do I protect my existing intellectual property?

‍ ‍

Technical Data Rights Assertions are listed as a Volume 5 document if you are asserting data rights restrictions. Separately, if technology in your feasibility documentation is subject to IP rights, you must provide IP rights assertions plus a short summary for each item asserted with less than unlimited rights, describing the nature of the restriction and the intellectual property intended for use in the proposed research.

‍ ‍

How much of the work must my company perform?

‍ ‍

The instructions state two thresholds. The Consultants and Subcontractors section requires at least 50 percent of the R/R&D be performed by the proposing firm unless the Contracting Officer approves otherwise in writing. The Performance of Work Requirements section states at least one-third of the Phase II research or analytical effort must be performed by the awardee, measured by direct and indirect costs excluding profit. Separately, all consultant fees, facility leases, and other subcontract or purchase agreements together may not exceed one-half of the total contract price without written Contracting Officer approval. Performing at least half in house satisfies every reading. Deviation requests must be made twice, prior to submission during the open period and again with the initial proposal.

‍ ‍

Does the Company Commercialization Report affect my score?

‍ ‍

No. Completing the CCR as Volume 4 is required, but the DAF states information contained in the CCR will not be considered during proposal evaluations.

‍ ‍

What is TABA and how do I request it?

‍ ‍

Up to $50,000 per Phase II award in addition to the per-topic ceiling, identified in the Volume 3 Cost Proposal, splittable as $25,000 on a first SBIR Phase II and $25,000 on a sequential one. Cybersecurity assistance and intellectual property protections are both eligible activities. The detailed request must be in Volume 5 with provider name, point of contact, unique qualifications, tasks with purpose and objective, and total cost with hours and labor rates, and the task milestone list must track to your milestone payment schedule. Requests specifying only a value in Volume 3 will not be considered.

‍ ‍

What happens in Phase III?

‍ ‍

Phase III pursues transition to operational use through non-SBIR/STTR funding streams, aiming for TRL 6 or 7 and demonstrating functionality in relevant environments. Phase II efforts demonstrating technical maturity, integration feasibility, and mission alignment may be selected for continued development and deployment. Performers may be expected to advance system readiness, demonstrate operational capability, enable cross-service application, and pursue dual-use commercialization. Phase III work may include further government-sponsored prototyping, operational transition activities, or commercialization via strategic partners in the defense and aerospace sectors.

‍ ‍

Are venture-backed companies eligible?

‍ ‍

Yes. Small business concerns owned in majority part by multiple venture capital operating companies, hedge funds, or private equity funds are eligible to submit applications or receive awards for DAF topics.

‍ ‍

When will I hear about selection?

‍ ‍

The DAF anticipates all proposals evaluated and selections finalized within approximately 90 calendar days of solicitation close, meaning on or about January 19, 2027. The principal investigator and Corporate Official on the cover sheet are notified by email, with a separate notification per proposal.

‍ ‍

Who do I contact with questions?

‍ ‍

The DAF SBIR/STTR One Help Desk at usaf.team@afsbirsttr.us for general program and proposal preparation questions, and the DAF encourages requesting clarifying information as early as possible because delays constrain its ability to respond. For DSIP submission system issues, dodsbirsupport@reisystems.com. The Air Force SBIR/STTR Contracting Officer is Mr. Daniel J. Brewer at Daniel.Brewer.13@us.af.mil. Address or point of contact changes after submission go to the One Help Desk with the subject line "FY26 SBIR CSO Address Change."

‍ ‍

Positioning Advice for Startups Considering This Topic

‍ ‍

Pick one focus area and commit. This is the single most consequential decision on this topic. Twenty pages does not permit a survey. Name the focus area in your first paragraph, structure the proposal around it, and let your feasibility evidence be about that area specifically.

‍ ‍

Translate your product into Space Force language. A commercial SIEM connector becomes lightweight, cloud-agnostic data ingest for DCW systems at the edge or hub. A software composition analysis tool becomes proactive software assurance for FOSS and non-APL COTS with SBOM generation and development lineage tracing. Use the topic's own vocabulary, including DCW, FlatSat, purple teaming, orbital edge, and Approved Product List. Evaluators read for alignment, and the topic hands you the words.

‍ ‍

Close the stakeholder gap before you write. The feasibility requirement is fundamentally about customers and integration pathways, not technical performance. Identified USSF stakeholders, an integration pathway that accounts for regulatory processes, and articulated demand from other government customers are the three things the topic asks you to have already established. This is where a strong commercial product with no Space Force relationship will fail.

‍ ‍

Address the space-specific constraint in your focus area. Every focus area has one. Bandwidth constrained and contested environments in Focus Area 6. Space specific protocols in Focus Area 5. Minimal SWaP and 1553 and SpaceWire in Focus Area 3. Disconnected, intermittent, and low-bandwidth settings in Focus Area 8. A proposal that ignores the space-specific twist reads as a generic commercial pitch.

‍ ‍

Get your own security posture in order. Cybersecurity practices is the first item on the foreign risk assessment list, and CMMC Level 2 self-assessment is the projected requirement. A firm proposing to defend space systems will be judged on its own house.

‍ ‍

Read the data rights clause before you decide what to build. Twenty years of Government SBIR data rights in everything developed or generated under the contract, followed by Government purpose rights, is a significant commitment for a software company whose core asset is code. Structure the work so what you contribute as background IP is properly asserted and what you develop under the award is what you intend to give those rights in.

‍ ‍

Use the GAO TRL guide. The topic cites it and states a Phase III target of TRL 6 or 7. Using GAO definitions rather than an informal scale makes your maturity claims checkable, which supports Criteria A.

‍ ‍

Make cost realism match the work plan. Cost realism sits inside the top-weighted criterion. For a software effort, that mostly means credible labor: named people, real rates, hours that match the tasks. Understaffing a 24 month program to look cheap will read as a misunderstanding of the requirements.

‍ ‍

Disclose equivalent submissions honestly. A mature commercial product often means similar proposals elsewhere. The instructions permit that with proper notification but make it unlawful to enter into contracts requiring essentially equivalent effort. Full disclosure protects the award.

Previous
Previous

DAF SBIR DAF26BX06-DV513: Autonomous On Orbit Logistics and Sustainment Architecture

Next
Next

DAF SBIR DAF26BX06-DV511: Low SWaP-C Tactical Awareness Payload for Proliferated, Agile Satellites (TAPPAS) for Space Domain Awareness