SBA Just Put $5 Million Into Small-Manufacturer Cybersecurity. Defense SBIR Firms Can't Apply — But They Shouldn't Ignore It.
August 19, 2026 · 7 min read
Granted Research Team · Editorial policy
SBIR and STTR founders selling into defense supply chains have until September 4, 2026 to shape where $5 million in new SBA cybersecurity money lands: opportunity SB-OEDCS-26-002, posted to Grants.gov on August 13, funds up to two $2.5 million awards aimed squarely at small-manufacturer cyber resilience.
The numbers SBA actually published, and the two attachments worth reading
The Small Business Administration's Office of Entrepreneurial Development posted the Manufacturing and Small Business Cybersecurity Resilience Program 2026 on August 13, 2026. The full listing on Grants.gov is short on prose and long on constraints:
- Opportunity number: SB-OEDCS-26-002
- Award ceiling: $2,500,000. Award floor: $0
- Expected awards: 2
- Period of performance: 24 months
- Cost sharing: none required
- Funding instrument: grant or cooperative agreement
- Assistance Listing: 59.079 — Cybersecurity for Small Business Pilot Program
- Closes: September 4, 2026, 11:59 p.m. ET. Archives October 4, 2026
That is a 22-day posting window, and SBA knew it. The attachment folder contains a file titled "Justification for Cyber Resiliency NOFO Posting Period" sitting alongside the NOFO itself — the paperwork an agency files when it opens a competition for less than the customary 30 days. Short windows favor incumbents who already have the narrative written. That fact alone tells you most of what you need to know about who this money is for.
The second thing worth noticing is a filing quirk. The primary NOFO PDF in the attachment folder is named "SBA Cyber Pilot Resilience SB-OEDSB-26-004," while the posting itself, its revision history, and the GrantSolutions pre-award page all carry SB-OEDCS-26-002. If you are citing this program in a partnership memo or a proposal letter, use SB-OEDCS-26-002. The other string will not resolve to anything on Grants.gov.
Program questions route to Traci Giddens and Teresa Clouser at SBA's Office of Small Business Development Centers — the OSBDC line, not the SBIR/STTR side of the house. That routing is a hint about the program's shape, and it is where most defense-adjacent founders stop reading. They should not.
You are not the applicant on this one — you are the deliverable
Read the eligibility language carefully, because it is unusually narrow:
To be eligible for this Funding Opportunity an applicant must be a state entity or university, or designee of the state, in the state of Indiana, Ohio, or Virginia.
A Phase II SBIR firm in Dayton cannot apply. Neither can a machine shop in Norfolk or a sensor startup in West Lafayette. Applicants must be states, state entities, universities, or state designees, and they must document a history of delivering Cybersecurity Maturity Model Certification tier 1 training.
But look at what SBA says the money buys: "to deliver technical assistance to small businesses," with a stated emphasis on small manufacturers, over a twenty-four-month period. Two awards, $2.5 million each, twenty-four months of training and technical assistance capacity — that is a pool of free cohort seats, free assessment support, and free engineering hours that will be allocated by whoever wins, according to a workplan being drafted right now.
This is the part small businesses routinely miss about SBA's entrepreneurial-development portfolio. The eligibility line says "state entity," so founders file it under "not for us" and move on. Meanwhile the proposals being assembled this month are naming industry partners, attaching letters of support from real manufacturers, budgeting subrecipient line items, and describing exactly which firms will be served first. Those names get written in before September 4. If your company is in the target sector and the target state, being named in a winning proposal is worth considerably more than any single Phase I award of comparable effort — and it costs you an email and a letter.
Why Indiana, Ohio, and Virginia, and nobody else
The three-state restriction is not arbitrary. In FY2023, SBA made six Cybersecurity for Small Business Pilot Program awards totaling roughly $6 million, to Ohio State University, Old Dominion University in Virginia, the Indiana Economic Development Corporation, the University of Wyoming, and the states of Colorado and Hawaii. The FY2024 round, worth about $3 million, went to Dakota State University, Eastern Washington University, and the University of Texas at San Antonio.
The 2026 NOFO narrows the field to three of those first-round states — the ones SBA says can document CMMC tier 1 training delivery. This is not a program seeding new capacity. It is a program re-upping proven capacity in three states with unusually dense defense manufacturing supply chains: Ohio's Wright-Patterson corridor, Virginia's Hampton Roads shipbuilding and naval base cluster, and Indiana's Crane Naval Surface Warfare Center orbit.
Which means the likely applicant pool is small and largely knowable. Ohio State's Center for Design and Manufacturing Excellence ran the Ohio pilot with an explicit manufacturing focus. Old Dominion took a roughly $1 million award to serve small Virginia businesses. The Indiana Economic Development Corporation held the Indiana award. If you operate in one of those three states, you can identify the probable winners today and start the conversation before the proposals close.
What a free CMMC Level 1 track is actually worth on your books
The timing here is the whole story. CMMC Phase 1 took effect on November 10, 2025: Level 1 self-assessment and annual affirmation became conditions on new DoD solicitations and on certain contract extensions. On July 13, 2026, the Pentagon paused the transition to Phase 2 pending a 60-day program review, which means program managers may currently designate only Level 1 (Self) or Level 2 (Self) — not third-party C3PAO or DIBCAC assessments.
Read that pause correctly. The requirement is not going away; the escalation is temporarily frozen. Level 1 self-assessment is live and binding right now, and DoD's own regulatory estimate puts the annual cost around $6,000 for a small entity, with commercial fixed-fee Level 1 packages running roughly $3,500 to $9,500. Those figures understate the real burden, because the expensive part was never the fee. It is the engineering time to scope your Federal Contract Information boundary, write the policies, get the System Security Plan into a defensible state, and file the SPRS affirmation without lying to the government by accident.
A state-run program that walks a 12-person hardware company through that process, at no cost, is worth several times its sticker price — and it arrives during exactly the window when the Phase 2 queue is short. When the review concludes and assessment demand resumes, the firms that already did Level 1 properly will be positioned; the ones that waited will be in line.
This compounds with the security regime Congress wrote into the latest SBIR/STTR reauthorization, which layered new due-diligence and foreign-ties screening obligations onto award recipients. We covered those changes in detail in our breakdown of the Small Business Innovation and Economic Security Act. The through-line is consistent: security posture is migrating from a nice-to-have into a gating condition on federal revenue, and the agencies are subsidizing the transition only in narrow, time-boxed windows.
Separate program, separate money from the NIST MEP competition
Do not confuse this with the other manufacturing competition running this summer. In July 2026, NIST announced a Manufacturing Extension Partnership funding opportunity covering 14 new MEP centers across states including Alabama, California, Georgia, Ohio, Pennsylvania, and Vermont, with maximum awards ranging from about $1 million to $15.6 million — Ohio and Pennsylvania at $6.1 million each, California at $15.6 million.
Same audience. Different agency, different appropriation, different eligibility, different application. A small manufacturer in Ohio sits inside the addressable population of both. Founders who track only Commerce and DoD opportunities systematically miss SBA's Office of Entrepreneurial Development portfolio, which is precisely why these NOFOs get thin applicant pools and short windows. We saw the same dynamic with SBA's $50 million Manufacturing in America E2G program, which funded just 10 intermediaries: enormous downstream reach, almost no visibility among the businesses it was designed to serve.
What to do in the next nineteen days
If you are in Indiana, Ohio, or Virginia and you sell into a defense supply chain:
- Identify the likely applicant in your state — the CDME at Ohio State, Old Dominion's cyber programs, or the Indiana Economic Development Corporation are the documented prior recipients.
- Send a letter of support this week. Offer a specific commitment: a named cohort seat, a pilot site, a case study, an advisory hour. Proposals due September 4 are being assembled now, and named industry partners strengthen them.
- Ask to be listed in the first service cohort. Twenty-four months of performance means the first cohort starts fast after award.
- Do not wait for the award announcement. By the time the winners are public, the workplan is fixed and the seats are spoken for.
If you are outside those three states, the read is different but still actionable: Assistance Listing 59.079 rotates. Colorado, Hawaii, and Wyoming took 2023 money; Dakota State, Eastern Washington, and UT San Antonio took the 2024 round. Watch for the next expansion and get in front of your state's economic development agency before the NOFO drops, not after.
Either way, the underlying obligation does not wait for a grant. Level 1 is binding on new DoD solicitations today.
Next step: Search active cybersecurity and small-manufacturer funding on Granted to see which of these programs your company can apply to directly — and which ones, like SB-OEDCS-26-002, you should be pursuing through a state partner instead.