Stay Informed

Are you a small business seeking to engage in federal government–sponsored R&D? Lincoln Laboratory has a robust program designed to maximize opportunities for small businesses to participate in Laboratory acquisitions and obtain funding awards.

Let us know which research areas are of interest to you, and we will notify you of new postings for funding opportunities that mutually align with your interests and our strategic priorities.

Propellors background image

Ways to Engage

SBIR & STTR Programs

Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs provide equity-free funding through federal agencies to American small businesses.

CRADAs

Cooperative Research and Development Agreements (CRADAs) are made between Lincoln Laboratory and private companies to pursue joint R&D.

Test Agreements

Test agreements enable businesses unable to access test facilities in the private sector to have their technology tested in select state-of-the-art facilities at Lincoln Laboratory.

Commercial Solutions Openings

Commercial Solutions Openings provide opportunities for small businesses and nontraditional defense contractors to work with Lincoln Laboratory.

Current Opportunities

No opportunities are currently available. Please check back regularly for new postings.


CMMC Concerns

Explore our CMMC Quick Reference Guide to learn how your small business can partner with us while meeting Cybersecurity Maturity Model Certification (CMMC) requirements. This resource includes key guidelines, practical steps, and FAQs to help you navigate compliance and collaboration opportunities.

Small Business Program Office CMMC Resource Letter

CMMC Supplier Compliance FAQ

Q: What changes to the Cybersecurity Maturity Model Certification (CMMC) program did the Department of War announce on July 13, 2026?
A: On July 13, 2026, the Department of War (DoW) announced the following changes to the CMMC program:
The DoW suspended the CMMC Phase II implementation planned for November 10, 2026, including the requirement for contractors handling controlled unclassified information (CUI) to obtain assessments from a Certified Third-party Assessor Organization (C3PAO). All Phase I self-assessment requirements remain firmly in place. The DoW CIO also announced the formation of a “CMMC Reform Task Force,” which has 60 days to review the CMMC program.
 
Q: Are CMMC requirements going away?
A: No. While the assessment timeline has changed, the underlying cybersecurity requirements continue. Suppliers that receive, or expect to receive, Controlled Unclassified Information (CUI) should continue implementing NIST SP 800-171 and be prepared to complete a CMMC Level 2 (Self) assessment when contractually required.
 
Q: What is the goal of the CMMC Reform Task Force referenced in the DoW announcement?
A: The goal of the Task Force is to make CMMC faster to implement, less burdensome on industry, more supportive of small, medium, and non-traditional defense contractors, and more closely aligned to the Secretary of War’s Acquisition Transformation Strategy (ATS) initiative. ATS prioritizes speed to capability, lowered barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient, cybersecurity measures.
 
Q: When will the CMMC Reform Task Force release its findings?
A: The review period began on July 13, 2026. The Task Force has 60 days to gather feedback and review the program, and then it has an additional 15 days to provide a report with its recommendations. We expect to learn the output from the Task Force by the end of September.
 
Q: Should suppliers hold off on fulfilling compliance requirements while awaiting the findings from the CMMC Reform Task Force?
A: Suppliers should continue to implement their CMMC compliance plans, as the only element currently paused is the need for third-party assessments. Specifically, suppliers should:
  1. Continue to implement and document required security controls in accordance with applicable CMMC and NIST SP-800-171 requirements.
  2. Maintain records and evidence of compliance activities so they are readily available if third-party assessments resume.
  3. Conduct internal reviews or self-assessments to monitor progress and identify any new compliance gaps.
  4. Ensure personnel complete required cybersecurity and role-based awareness training, where applicable.
  5. Monitor official Department of War guidance for updates from the CMMC Reform Task Force and any changes to implementation timelines or requirements.
  6. Continue to remediate vulnerabilities and manage cybersecurity risks as part of normal security operations.
  7. Proactively report readiness concerns to MIT Lincoln Laboratory.
 
Q: If a supplier already has a third-party/C3PAO assessment scheduled, should they cancel it?
A: Suppliers should not assume that scheduled third-party (C3PAO) assessments should be canceled because of the current pause. The decision to cancel or postpone an assessment belongs to the supplier. Any associated risks, including potential impacts to contract opportunities, customer expectations, or future assessment scheduling, are borne by the supplier. Organizations should coordinate directly with their C3PAO and carefully consider their contractual obligations, business objectives, and readiness before making changes to any scheduled or planned assessments.
 
Q: Do suppliers still need to file a SPRS score? If so, are they required to have a score of 110?
A: Suppliers should continue to maintain a current SPRS score and submit any required affirmations, as these requirements have not been paused. However, suppliers are not required to have a perfect 110 SPRS score unless a specific solicitation or contract explicitly requires it. Suppliers should ensure their SPRS score accurately reflects the implementation status of their applicable NIST SP 800-171 security requirements and should continue working to close any identified gaps.
 
Q: In summary, what is the Lab’s current guidance for suppliers regarding CMMC compliance?
A: In brief, stay the course! This pause is an opportunity for suppliers to strengthen their cybersecurity program – not a reason to delay it. Organizations that remain focused on maturing their cybersecurity programs will be better positioned when the revised assessment timeline is announced. MIT Lincoln Laboratory will continue to enforce the cybersecurity requirements contained in its purchase orders and will update supplier guidance as additional directions are provided by the Department of War.
 

Other Than Small Business

Government

Lincoln Laboratory conducts R&D to provide technological solutions for problems faced by Department of Defense organizations. We also undertake projects to address needs of nondefense U.S. agencies such as NASA or the Federal Aviation Administration. Our role is to develop technologies that are beyond the scope of the government’s in-house and contractor resources.

Academia & Not-for-Profits

We support collaborative research at universities across the United States and offer opportunities for partnering with academic and not-for-profit institutions.

NDA Information

If a Non-Disclosure Agreement (NDA) is required to begin discussions between MIT Lincoln Laboratory and an outside organization, Contracting & Logistics (C&L) at MIT Lincoln Laboratory can facilitate this process. NDAs must be requested by an MIT Lincoln Laboratory employee who will be the primary recipient and/or discloser of the confidential information. For inquiries regarding NDAs, please contact [email protected].