Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Investing in a defense technology startup requires the usual analysis of its product, team, customers, economics and financing—plus a close look at who can influence the company, who can access its technology and data, what rights the government received, and whether government interest has become funded, repeatable business. These issues call for evidence-based risk assessment, not automatic rejection because a company has foreign ties or government funding. The implications depend on the company, its technology, its awards and contracts, and the rules that apply to them.

What makes defense startup diligence different?

Defense companies operate where commercial investment questions meet government procurement, national-security review, export controls and contract-specific rights. A technically strong company can still face material risks if its ownership or governance creates an unresolved influence concern, its personnel or partners can access sensitive technical data without appropriate controls, or a contract gives the government rights that constrain later commercialization.

The Army SBIR/STTR Due Diligence page describes its purpose as “a risk assessment to protect U.S. intellectual property and defense capabilities.” That framing is useful to investors: diligence identifies risks, tests whether they can be mitigated, and clarifies what remains uncertain. It is not a shortcut from a foreign affiliation, government award or security label to an automatic investment decision.

Who owns or can influence the company?

Look beyond the headline ownership percentage. Foreign ownership, control or influence (FOCI) concerns can arise through governance access, financing arrangements, affiliations and supply-chain relationships. Defense guidance treats influence as a question of whether a foreign entity can direct or affect management or operations—not merely a simple percentage test.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Map ownership and control rights

Reconcile the cap table and corporate records with beneficial-owner information, investor disclosures, government application representations and the company’s financing documents. Include direct and indirect investors, and review:

  • Voting rights, board seats, observer rights and information rights.
  • Vetoes, consent rights, side letters, debt covenants and other contractual levers.
  • Affiliations, joint ventures, subsidiaries, licensing arrangements and material suppliers.
  • Foreign financial obligations or intermediary relationships that could create influence or access.

For SBIR/STTR applicants, SBA rules require disclosures concerning investment and foreign ties. Compare those disclosures with the company’s present structure and identify changes since submission. Differences may have an explanation, but they should be resolved against source documents rather than accepted as a verbal assurance.

Assess the actual risk and its mitigations

FOCI guidance identifies governance, financial and supply-chain dimensions of risk. Ask what rights or dependencies create the concern, what mitigation is already in place, who monitors it and whether it has been accepted by the relevant government authority where required. Foreign nationality or investment alone does not establish that a company is disqualified; the outcome depends on the facts and applicable program or contract rules.

What government programs and awards has the company actually received?

For a company with Small Business Innovation Research or Small Business Technology Transfer (SBIR/STTR) awards, obtain the original proposals and disclosure forms, award documents, compliance correspondence, subcontracting records and any available security-risk review outcome. Match the company’s account of its status to the agency record and the terms of each award.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Department of Defense’s May 23, 2024 release described security-risk forms required with proposals. The current Department of War (DoW) Office for Small Business Innovation materials, accessed October 7, 2026, describe the review as Foreign Risk Evaluation (FRE) following reauthorization in April 2026. Because these program requirements can change, check the live program materials and the specific solicitation and award terms that govern the company; do not treat an older policy memo or management summary as conclusive.

DoW program materials describe program eligibility and registration requirements. Army SBIR/STTR guidance says its review considers FOCI, cybersecurity hygiene and patent risk, and can recommend denial if an unacceptable national-security risk cannot be mitigated. A program award therefore does not, by itself, establish that every investor-relevant risk has been cleared or that later awards will follow.

Who owns the technology, and what rights did the government receive?

Build a chain-of-title and rights record for each material technology, software component and technical-data set. Trace contributions by founders, employees, universities, laboratories, subcontractors and prior employers; identify licenses, open-source components and other encumbrances. For government-funded work, tie each asset to the relevant award, contract clauses, markings, dates and any Phase III or follow-on work.

Separate company assets from award-derived material

Do not assume SBIR/STTR data-rights provisions cover every company asset. DFARS 227.7104 addresses covered data delivered, developed or generated under covered work, including certain Phase III work. Confirm that the specific material and work fall within the clause, and inspect the contract and markings with qualified counsel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Under DFARS 227.7104-2, the standard SBIR/STTR data-protection period runs for 20 years from the award unless a different period is negotiated after award. After that period, government-purpose rights apply under the provision. The practical effect for an investor depends on the covered data, the award and contract history, and the rights that apply to the specific material; a single company-wide label is not enough to establish those boundaries.

Who can access the technology and technical data?

Request the company’s written export-control classification process and determinations, any Commodity Jurisdiction or classification correspondence, licensing history, technical-data access controls, foreign-person access controls and training records. Test whether the documented process matches the technology and transactions the company actually handles.

The SBA’s SBIR ITAR FAQ explains that classification may require analysis of the relevant control lists and that disclosure to foreign persons may be restricted unless authorized or an applicable exception applies. Do not infer that a product is ITAR-controlled—or not controlled—from marketing language, a customer list or the fact that the company works with the government. The result is specific to the technology, data, people and transaction.

Are cybersecurity controls matched to the company’s obligations?

First identify which systems contain controlled unclassified information (CUI), technical data or other protected material. Then compare the company’s control implementation with the requirements in its actual contracts and solicitations. Review assessment evidence, incident history, remediation plans and the security obligations passed to subcontractors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Army’s diligence guidance identifies cybersecurity hygiene as a review area. The DoD CIO CMMC resources page signals that policy materials are subject to review, so investors should verify the current requirement for each contract and the evidence supporting the company’s position. A general resource page or management statement is not proof that a particular company or contract is compliant.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is the government customer paying for work—or signaling possible demand?

Government interest, a pilot, an award announcement or a route to a future procurement is not the same thing as repeatable revenue. Inspect the underlying documents and establish what the customer has funded, what the company must deliver, and what could cause the work to stop or change.

  • Verify the solicitation, award or contract, funded amount, period of performance, deliverables and acceptance criteria.
  • Check options, termination rights, modification history, subcontracting roles and the company’s share of the work.
  • Confirm payment and milestone status with records and, where available, customer references.
  • Separate funded work from unfunded pathways, anticipated follow-ons and nonbinding expressions of interest.
  • Assess whether a plausible follow-on path exists and whether unit economics, deployment costs and customer concentration support the investment case.

Ask management to distinguish prototype performance from deployment readiness. Review demonstrations alongside independent technical review, user or field feedback where available, integration requirements, reliability evidence and manufacturing readiness. Compare genuine alternatives on mission performance, interoperability, reliability, manufacturability, deployment time and cost, security and export-control burden, data and IP rights, funding and follow-on potential, and customer concentration. Some defense technologies have no meaningful commercial-market analogue, so avoid forcing a comparison that does not fit.

How should investors organize the review?

A disciplined process ties each material claim to documents, responsible people and unresolved questions. A practical sequence is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Define the investment thesis and exposure. Identify the technology, intended users, government programs, known contracts, critical partners and the claims that must be true for the thesis to work.
  2. Build a document-backed ownership and influence map. Reconcile cap-table, governance, financing and affiliation records with disclosures made in government applications.
  3. Trace awards, obligations and review outcomes. Match management’s description to proposals, award terms, compliance correspondence, subcontract records and applicable current program requirements.
  4. Trace technology, data and access rights. Map ownership and licenses to the work that produced each asset; identify who can access controlled technology or data and under what procedures.
  5. Verify security and export-control evidence. Review classification work, access controls, assessments, incidents and remediation against the company’s actual technology and contract obligations.
  6. Re-underwrite customer traction. Confirm funded scope, performance evidence, customer feedback, economics and the distinction between current work and possible future procurement.
  7. Record mitigations and residual risk. For each concern, note the evidence, the accountable owner, any required specialist review, the mitigation, its cost and what remains unresolved.

Specialist counsel or advisors may be appropriate for FOCI and security, export controls, and government data-rights questions. Their work should answer specific questions about the company’s facts and governing documents, rather than substitute a generic compliance label for investment analysis.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.