1,000+ Opportunities
Find the right grant
Search federal, foundation, and corporate grants with AI — or browse by agency, topic, and state.
This listing may be outdated. Verify details at the official source before applying.
Find similar grantsZero Trust Identity is sponsored by U.S. Army SBIR. This SBIR topic aims to research and develop innovative ways to determine the trustworthiness of a personal device without requiring software installation, enabling users to access Army resources with dynamic risk analysis in accordance with Zero Trust principles (NIST 800-207).
Get a weekly digest of new grants like this
A free weekly digest of new foundation and federal funding opportunities as they're added to Granted. Unsubscribe anytime.
Or search similar grants →Extracted from the official opportunity page/RFP to help you evaluate fit faster.
Zero Trust Identity – Army SBIR|STTR Program Application Due Date: 06/14/2023 Amount Up To: Up to $111,500 Determine the level of risk when a person uses a personal device to access Army resources (i.e., Bring Your Own Device (BYOD)) in accordance with Zero Trust principles As per NIST 800-207, one of the basic tenets of Zero Trust is “Access to resources is determined by dynamic policy—including the observable state of client identity, application/service, and the requesting asset—and may include other behavioral and environmental attributes”.
When the requesting asset is an approved managed device, the security and trustworthiness of the device can be determined using the one of the many agents that are already installed on the asset and are used to control the asset configuration. In a Bring Your Own Device (BYOD) scenario the device is not managed by the Army and the state and trustworthiness of the asset is unknown.
Additionally, people are highly reluctant to install monitoring software (e.g., agents) on their personal device to allow the Army to determine the state of the device. Without an understanding of the state of the device, the device is considered untrustworthy and it is prevented from accessing Army resources.
This results in the Army having to purchase, provide, manage and maintain equipment (e.g., laptops, mobile phones etc.) for people to access Army resources. This cost grows very large when considering the large quantity and variety of users, such as active-duty military, guard, reserves, civilians and contractors that utilize Army resources.
The purpose of this SBIR is to research and develop innovative ways to determine the trustworthiness of a personal device, without requiring software to be installed on the device.
A solution to this problem would enable any user to utilize personal devices, such as mobile devices and personal computers, to access Army resources, while still providing the Army with a dynamic risk analysis that help protect Army resources from being accessed from untrustworthy devices. Determine the feasibility of the proposed solution.
The solution should describe in detail the approach to be used for determining the trustworthiness of the device without installing software on the device. The solution should also describe the technical challenges, the risks and how they will be mitigated and any dependencies that are required for the solution to work. The approach should be designed with open architecture and industry standards and protocols in mind.
Develop the solution outlined in Phase I. A demonstration of the solution determining the trustworthiness of a BYOD (specific device information will be provided after award).
The demonstration should include the ability for the observers to determine how the level of trustworthiness for a given device was measured (e.g., what specific device factors were used to determine the level of trustworthiness of the device, any configuration data used in the decision and how that data was mapped to a level of trustworthiness etc.).
Expand the solution to enable determining trust on additional devices (examples information will be provided after award). The demonstration in Phase II is expected to utilize a small number of trust factors, so in Phase III the solution should be enhanced to include additional trust factors for the types of devices supported in Phase II. Submit in accordance with DoD SBIR BAA 23.
2 “NIST Special Publication 800-207 Zero Trust Architecture” https://csrc. nist. gov/publications/detail/sp/800-207/final “DOD Zero Trust Reference Architecture v2.
0” https://dodcio. defense. gov/Portals/0/Documents/Library/(U)ZT_RA_v2.
0(U)_Sep22.
pdf Determine the level of risk when a person uses a personal device to access Army resources (i.e., Bring Your Own Device (BYOD)) in accordance with Zero Trust principles As per NIST 800-207, one of the basic tenets of Zero Trust is “Access to resources is determined by dynamic policy—including the observable state of client identity, application/service, and the requesting asset—and may include other behavioral and environmental attributes”.
When the requesting asset is an approved managed device, the security and trustworthiness of the device can be determined using the one of the many agents that are already installed on the asset and are used to control the asset configuration. In a Bring Your Own Device (BYOD) scenario the device is not managed by the Army and the state and trustworthiness of the asset is unknown.
Additionally, people are highly reluctant to install monitoring software (e.g., agents) on their personal device to allow the Army to determine the state of the device. Without an understanding of the state of the device, the device is considered untrustworthy and it is prevented from accessing Army resources.
This results in the Army having to purchase, provide, manage and maintain equipment (e.g., laptops, mobile phones etc.) for people to access Army resources. This cost grows very large when considering the large quantity and variety of users, such as active-duty military, guard, reserves, civilians and contractors that utilize Army resources.
The purpose of this SBIR is to research and develop innovative ways to determine the trustworthiness of a personal device, without requiring software to be installed on the device.
A solution to this problem would enable any user to utilize personal devices, such as mobile devices and personal computers, to access Army resources, while still providing the Army with a dynamic risk analysis that help protect Army resources from being accessed from untrustworthy devices. Determine the feasibility of the proposed solution.
The solution should describe in detail the approach to be used for determining the trustworthiness of the device without installing software on the device. The solution should also describe the technical challenges, the risks and how they will be mitigated and any dependencies that are required for the solution to work. The approach should be designed with open architecture and industry standards and protocols in mind.
Develop the solution outlined in Phase I. A demonstration of the solution determining the trustworthiness of a BYOD (specific device information will be provided after award).
The demonstration should include the ability for the observers to determine how the level of trustworthiness for a given device was measured (e.g., what specific device factors were used to determine the level of trustworthiness of the device, any configuration data used in the decision and how that data was mapped to a level of trustworthiness etc.).
Expand the solution to enable determining trust on additional devices (examples information will be provided after award). The demonstration in Phase II is expected to utilize a small number of trust factors, so in Phase III the solution should be enhanced to include additional trust factors for the types of devices supported in Phase II. Submit in accordance with DoD SBIR BAA 23.
2 “NIST Special Publication 800-207 Zero Trust Architecture” https://csrc. nist. gov/publications/detail/sp/800-207/final “DOD Zero Trust Reference Architecture v2.
0” https://dodcio. defense. gov/Portals/0/Documents/Library/(U)ZT_RA_v2.
0(U)_Sep22. pdf Assistant Secretary of the Army for Acquisition, Logistics, and Technology ASA(ALT) releases contract opportunities on an ad-hoc basis to meet Army research and development needs. Army Futures Command (AFC) releases topics during three specific solicitation periods throughout the fiscal year to address the Army’s current and anticipated war-fighting technology needs.
Army STTR follows AFC’s topic release schedule but partners with a university, federally funded research and development center, or a qualified non-profit research institution as part of their contract. Is the opportunity to establish the scientific, technical, commercial merit and feasibility of your proposed innovation. Is focused on the development, demonstration and delivery of your innovation from Phase I.
Represents the commercialization phase of the program in which the company can market their products or services developed in Phase II, either to the government or in the commercial sector. Allows small businesses to submit to Direct to Phase II applications if they performed the Phase I research through other funding sources. Provides funding to projects that require additional funding during their open Phase II contract.
A Phase II Awardee may receive one additional, sequential Phase II award to continue the work of an initial Phase II award. The sequential Phase II award has the same guideline amounts and limits as an initial Phase II award.
Artificial Intelligence/Machine Learning (supply chain management, logistics coordination, target identifications and simulation) Advanced Materials and Manufacturing (additive manufacturing) Autonomy (unmanned systems, drones, ground vehicle capabilities) Chemical and Biological (detection, defense) Cyber (biometric authentication, secure communications) Electronics (microelectronics, Very-Large-Scale Integration (VLSI)) Electronic Warfare (jamming, spoofing) Human Performance (wearables) Immersive (augmented reality, virtual reality, mixed reality) Network Technologies (antennas, radio frequency, communications systems) Position, Navigation, and Timing (GPS) Power (batteries, generators) Software Modernization (high performance computing, data management and visualization) Sensors (infrared sensing) Weapons Systems (hypersonics, munitions and projectiles, directed energy)
According to the current listing, eligibility includes: Small businesses. Specific eligibility criteria are outlined in the DoD SBIR BAA 23. 2. Confirm the full requirements in the official notice before applying.
The current listing shows up to $111,500. Verify award ceilings, matching requirements, and allowable costs in the official notice.
Zero Trust Identity is funded by U.S. Army SBIR. Verify program details on the funder's official page before applying.
Start from the official opportunity page linked in this listing — it carries the sponsor's submission instructions.
After SBIR reauthorization, the U.S. Army released five new small-business topics under Army FUZE — Ka-Band metamaterial radar, a Li-ion 6T battery open topic, in-transit-visibility blockchain, modular UAS payloads, and the xTech|Phantum prize competition. Awards run from $150K to $300K per Phase I. But the bigger story is the Army's shift from funding parts to funding whole systems. Here is what each topic funds and how to compete.
Read articleDARPA transferred its first autonomous-ready H-60Mx Black Hawk to the Army on March 20, capping a decade of ALIAS research. Now the same technology underpins an SBIR XL opportunity for small businesses building wildfire autonomy.
Read articleOn September 2, 2026, SBA published an updated commercialization benchmark: firms with more than 25 Phase II awards in five years must derive at least 33 percent of total revenue from non-SBIR sources in FY2027, and 50 percent from FY2028 onward. It takes effect November 15, 2026. Because the measurement window looks backward three completed fiscal years, the first test is already decided — and the second is two-thirds decided. Here is the arithmetic, the history, and what firms near the line should do.
Read article