DIRECT TO PHASE II: Cross-domain Interface for Trusted Access & Data Exchange Logic

Navy DIRECT TO PHASE II SBIR Release 5 Topic: DON26BZ05-DV082
Naval Air Systems Command (NAVAIR)
Pre-release 8/5/26   Opens to accept proposals 8/26/26   Closes 9/23/26 12:00pm ET    [ View Q&A ]

DON26BZ05-DV082 TITLE: DIRECT TO PHASE II: Cross-domain Interface for Trusted Access & Data Exchange Logic

OUSW (R&E) CRITICAL TECHNOLOGY AREA(S): Quantum and Battlefield Information Dominance (Q-BID)

COMPONENT TECHNOLOGY PRIORITY AREA(S): Advanced Computing and Software

PROJECTED CMMC LEVEL REQUIREMENT: Level 2 (Self)

OBJECTIVE: Develop a bi-directional software Cross Domain System (CDS) guard capable of executing on expeditionary, small form factor, fielded modular computer systems with a Peripheral Component Interconnect Express (PCIe) open systems interface.

DESCRIPTION: The Navy (aircraft and ships) requires a bi-directional software CDS guard capable of executing on small form factor, modular, removable, commercially available, and affordable computer systems with PCIe open standard interfaces to increase interoperability. The host hardware must contain, at a minimum, a 10-core processor, 64 GB of DDR5 RAM, 2 TB of SSD storage, and multiple I/O ports, including at least four (4) 1 GigE outputs, four (4) USB outputs, and one HDMI or DisplayPort interface.

The CDS guard software and architecture will support rapid rule set updates enabling more efficient certification and approval processes by the National Security Agency (NSA). A key development objective is to provide an affordable software licensing and updated approach that reduces acquisition and sustainment cost of ownership for the Navy.

The CDS guard software architecture will allow for rapid implementation of business rules provided by the Government as Government Furnished Equipment (GFE) following award (classified content). The CDS guard software architecture must support updating and maintaining the software rule set within a data library maintained by the contractor to facilitate rapid business rule updates required for emergent systems. The CDS guard must support up to 100 Mbps of data parsing, including video streams, tracks, messaging, and voice, and must also support data logging.

Work produced in Phase II may become classified. Note: The prospective contractor(s) must be U.S. owned and operated with no foreign influence as defined by 32 U.S.C. § 2004.20 et seq., National Industrial Security Program Executive Agent and Operating Manual, unless acceptable mitigating procedures can and have been implemented and approved by the Defense Counterintelligence and Security Agency (DCSA) formerly Defense Security Service (DSS). The selected contractor and/or subcontractor must be able to acquire and maintain a secret level facility and Personnel Security Clearances. This will allow contractor personnel to perform on advanced phases of this project as set forth by DCSA and NAVAIR in order to gain access to classified information pertaining to the national defense of the United States and its allies; this will be an inherent requirement. The selected company will be required to safeguard classified material during the advanced phases of this contract IAW the National Industrial Security Program Operating Manual (NISPOM), which can be found at Title 32, Part 2004.20 of the Code of Federal Regulations.

PHASE I: For a Direct to Phase II topic, the Government expects that the small business will have accomplished the following in a Phase I-type effort and developed a concept for a workable prototype or design to address, at a minimum, the basic requirements of the stated objective above. The following actions would be required to satisfy the requirements of Phase I:

DIRECT TO PHASE II: Cross-domain Interface for Trusted Access & Data Exchange Logic (CITADEL) has demonstrated the use of cross domain guard on commercial single board computer solutions while emphasizing affordability, modularity, and rapid prototyping, while maintaining high assurance through hardware and software controls.

FEASIBILITY DOCUMENTATION: Offerors interested in participating in Direct to Phase II must include in their response to this topic Phase I feasibility documentation that substantiates the scientific and technical merit and Phase I feasibility described in Phase I above has been met (i.e., the small business must have performed Phase I-type research and development related to the topic NOT solely based on work performed under prior or ongoing federally funded SBIR/STTR work) and describe the potential commercialization applications. The documentation provided must validate that the proposer has completed development of technology as stated in Phase I above.

PHASE II: Develop and demonstrate a bi-directional CDS guard running on four (4) commercial off-the-shelf (COTS), removable, plug and play computer modules to support cross domain data parsing of Internet Protocol (IP)-based High Frequency (HF) track data, voice and messaging. One of the computer modules will host the guard and include four (4) 1 GIGe ports to support guard functions, while the remaining computer modules will operate as independent enclaves with bi-directional data exchange through the guard.

Develop a software architecture capable of approval by the NSA that provides a means of updating rule sets through a partitioned software layout scheme that minimizes the need for repeated NSA re-approval. Deliver a prototype containing the CDS guard software and COTS hardware.

Work in Phase II may become classified. Please see note in the Description section.

PHASE III DUAL USE APPLICATIONS: Focus on operational testing, certification, and transition of the bi-directional CDS guard to fleet platforms supporting Distributed Maritime Operations and Combined Joint All-Domain Command and Control. Perform final testing that includes integration with afloat and ashore command-and-control systems, validation on COTS and Small Form Factor Modular hardware, and security accreditation in coordination with the NSA. Support transition through Navy program offices responsible for tactical networks, maritime operations centers, and joint fires integration. Package the solution for rapid installation using open standards to support scalable deployment across surface, subsurface, aviation, and expeditionary forces.

Phase III outcomes will directly enable fleet-wide adoption and sustainment through government-owned data rights and modular upgrade paths.

The proposed CDS guard has strong dual-use potential for commercial sectors that require secure data transfer between networks of differing trust levels. Critical infrastructure operators, including energy, transportation, and port authorities, can leverage this technology to protect operational technology while sharing real-time data with enterprise systems. Financial services, healthcare networks, and cloud service providers can apply the same rules-based data transfer to comply with regulatory and cybersecurity requirements. The software-defined architecture enables adaptation for commercial environments without dependence on classified hardware. These markets provide a sustainable commercial pathway while preserving Department of Defense mission relevance.

REFERENCES:

  1. Smith, Scott. "Shedding Light on Cross Domain Solutions." SANS Institute, 09 December 2015. https://www.sans.org/white-papers/36492
  2. Sundaravarathan, Vignesh. "Cross-Domain Solutions (CDS): A Comprehensive Survey." IEEE Access, Vol. 12, 26 September 2024. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=10721459
  3. National Industrial Security Program Executive Agent and Operating Manual (NISP), 32 U.S.C. § 2004.20 et seq. 1993". https://www.ecfr.gov/current/title-32/subtitle-B/chapter-XX/part-2004

KEYWORDS: Cross Domain Solution; Bi-Directional Data Transfer; Distributed Maritime Operations; Combined Joint All-Domain Command and Control; Software-Defined Guard; Tactical Edge Computing


Topic Q & A

9/2/26  Q. What is the period of performance? Base and option years?
   A. You can find all cost and period of performance information in the DON instructions posted to this topic (page 5).
9/2/26  Q. Is the original CDS deployment expected to be an on-prem or CSP solution?
   A. The initial deployment is an afloat solution. The work is performed at secure contractor facilities and deployed on naval platforms. GUNSS architecture clearly shows its placement within the "Navy Afloat" environment, distinct from ashore and public networks.
9/2/26  Q. What is the period of performance? Base and option years?
   A. You can find all cost and period of performance information in the DON instructions posted to this topic (page 5).
9/2/26  Q. Will the data be stored in 1 location (on-prem or CSP) or multiple (on-prem and/or CSP)
   A. The data will be in multiple locations. The architecture involves afloat processing on naval vessels (CANES, ADNS). Furthermore, the GUNSS system integrates with cloud-based SATCOM transport and DoD Information Network (DoDIN) sources, indicating a hybrid architecture that spans on-prem, afloat, and potentially cloud environments.
9/2/26  Q. Does it include SAP data?
   A. Not at this time.
7/1/26  Q. Which networks are needed for bi-directional transfer? Secret is mentioned in the write-up, so confirm we are only looking at U <-> S workflows?
   A. Data exchange occurs across Unclassified, Secret, and Top Secret domains. The GUNSS roadmap specifically includes secure, real-time streaming capabilities over GBS networks, supporting both SIPR and JWICS classifications, confirming the need for bi-directional transfers across multiple classified networks.
9/2/26  Q. Q11. Teaming and Data Security Role: For a small business that provides proven data-centric security and encryption technology deployed across DoD — including ABAC, TDF/ACP 240 compliance, and cross-domain policy enforcement — what role does NAVAIR envision for such a capability within the CITADEL effort?
   A. Data exchange occurs across Unclassified, Secret, and Top Secret domains. The GUNSS roadmap specifically includes secure, real-time streaming capabilities over GBS networks, supporting both SIPR and JWICS classifications, confirming the need for bi-directional transfers across multiple classified networks.
9/2/26  Q. Q10. Tactical Data Types: The solicitation references HF track data, voice, and messaging. Are these Link-16/Link-22/JREAP-C tactical data link formats, or IP-native protocols? Does the guard need TDL protocol awareness, or does it operate purely at the IP layer?
   A. GUNSS integrates with systems like Network Tactical Common Data Link (NTCDL) and handles Link-16/Link-22. This demonstrates a clear need for Tactical Data Link (TDL) protocol awareness to ingest, process, and disseminate this critical data, rather than operating purely at the IP layer.
9/2/26  Q. Q8. Relationship to Existing CDS Market: Is CITADEL intended as a complement to existing NSA-accredited CDS solutions, or as a next-generation alternative? How does NAVAIR envision the relationship between CITADEL and the current accredited guard portfolio?
   A. The information suggests CITADEL, powered by a system like GUNSS, is a next-generation alternative. GUNSS is an interoperability 'jump-off' point to move beyond "stove-piped" and antiquated systems. It provides a software-based, agile hosting environment, indicating a significant leap forward from traditional hardware-based CDS solutions.
9/2/26  Q. Q7. Coalition Interoperability: Phase III references CJADC2 transition. Does the CITADEL vision include coalition data sharing across security domains? If so, is ACP 240 / ZTDF compliance part of the interoperability roadmap?
   A. Yes, absolutely. GUNSS advances interoperability capabilities with both Allied and International Partner platforms. GUNSS can move Tomahawk strike packages to coalition partners and has developed solutions for platforms that are not equipped with GBS that can be implemented. Coalition data sharing is a central component GUNSS.
9/2/26  Q. The solicitation emphasizes rapid rule set updates and a partitioned software layout that minimizes NSA re-approval. Does NAVAIR envision the CITADEL guard supporting attribute-based or data-centric security standards — specifically, the ability to make transit and release decisions based on structured metadata bound to individual data objects (such as TDF or ACP 240 security labels) — as part of the rule set architecture?
   A. The capabilities of GUNSS SFF strongly align with this vision. GUNSS has a "Universal parser" for diverse data formats and can be used for moving highly sensitive Tomahawk Strike Packages to coalition partners. This mission requires a robust, data-centric security model to ensure proper handling and release, which is the core principle of attribute-based security. The CITADEL guard would need to support such standards to fulfill this role.
9/2/26  Q. Has the government chosen an SBC today, as we have already deployed to a number of different ones and must make sure they are RTB compliant along with the software?
   A. No.
9/2/26  Q. Can you provide more detail on the data types and how many? Specifically, numbers and types of video and audio streams?
   A. Yes, the GUNSS Small Form Factor (SFF) system is proven to handle 50 Full-Motion Video (FMV) feeds and over 1.3 million tracks per hour. It processes multi-iNT data, including FMV, imagery, and track data. While the original solicitation mentioned HF track data, voice, and messaging, GUNSS SFF confirms a high-volume, multi-format capability.

** TOPIC NOTICE **

The Navy Topic above is an "unofficial" copy from the Navy Topics in the DoW FY-26 Release 5 SBIR BAA. Please see the official DoW Topic website at www.dodsbirsttr.mil/submissions/solicitation-documents/active-solicitations for any updates.

The DoW issued its Navy FY-26 Release 5 SBIR Topics pre-release on August 5, 2026 which opens to receive proposals on August 26, 2026, and closes September 23, 2026 (12:00pm ET).

Direct Contact with Topic Authors: During the pre-release period (August 5, through August 25, 2026) proposing firms have an opportunity to directly contact the Technical Point of Contact (TPOC) to ask technical questions about the specific BAA topic. The TPOC contact information is listed in each topic description. Once DoW begins accepting proposals on August 26, 2026 no further direct contact between proposers and topic authors is allowed unless the Topic Author is responding to a question submitted during the Pre-release period.

DoD On-line Q&A System: After the pre-release period, until September 9, 2026, at 12:00 PM ET, proposers may submit written questions through the DoW On-line Topic Q&A at https://www.dodsbirsttr.mil/submissions/login/ by logging in and following instructions. In the Topic Q&A system, the questioner and respondent remain anonymous but all questions and answers are posted for general viewing.
NOTE: You must have registered in the DSIP system in order to ask an on-line topic question.

DoW Topics Search Tool: Visit the DoW Topic Search Tool at www.dodsbirsttr.mil/topics-app/ to find topics by keyword across all DoW Components participating in this BAA.

Help: If you have general questions about the DoD SBIR program, please contact the DoD SBIR Help Desk via email at DoDSBIRSupport@reisystems.com


[ Top  -  Return ]