From TRL to ERL: readiness in the age of geopolitics
For fifty years, one scale has governed how technology gets funded, procured, and deployed across aerospace and defence: Technology Readiness Level (TRL), developed at NASA in the 1970s and later adopted by the European Commission, NATO, and defence acquisition programmes worldwide, gives everyone involved in a technology decision a shared vocabulary for defining how mature is a given technology. TRL 9 means it has flown, or fought, or flown and fought, and works as intended.
It is a genuinely good scale, observable, communicable, and telling both sides of a deal exactly what has to happen next. That is precisely why it became a standard rather than staying a NASA internal tool.
But TRL was built to measure a technology, not the organisation that built it. And in defence and aerospace, more than almost anywhere else, that distinction has started to matter as much as the technology itself.
A technically mature solution is not automatically an adoptable one
Ask anyone who has run technology scouting inside a large industrial group, and they will tell you the same story with different names attached. A startup arrives with a system that is technically sound, sometimes genuinely impressive, evaluated at TRL 7 or 8 by any reasonable standard. Eighteen months later, it still has not become a programme of record. Not because the technology stopped working, but because it turned out the company could not pass a security audit, had no clear answer on data residency, could not commit to a support structure that survives its own founder leaving the room, or simply was not built to survive the procurement cycle of an organisation the size of the one trying to buy from it.
This is the gap the Enterprise Readiness Level (ERL) framework is designed to close. ERL does not replace TRL, it sits next to it, and asks a different question: is this company, as an organisation, ready to operate as a reliable partner to an enterprise. It looks at identity, product maturity, technical architecture, security and compliance posture, commercial traction, and operational capacity, and maps the result onto five levels, from Concept to Enterprise Scalable.
Enterprise Readiness Levels from 0 to 5
That framework was built first for a general audience, and is based on an universal signal catalogue, applicable to any type of startup, scale-up or SME. Defence and aerospace, though, add a layer that the general model was not built to carry.
What changed is not the technology, but the map.
In May, we ran the first Novable Connect Golden Session, an online panel for our customers, on the topic of how geopolitics is rewriting the rules of corporate-startup collaboration. The panel brought together Jessy DROUILLARD from Airbus, Liviu Lazar from NATO's industry relations team, Jason Wiseman from the European Parliament's foreign affairs and defence side, and Robbie Boyd OBE, an advisor who has spent years inside corporate venturing programmes. Thibaut Claes from FNX Ventures moderated.
The questions we asked them were deliberately blunt : can you still scout and partner across borders the way you used to ? Can you still work with startups depending on where their capital, their founders, or their customers sit ? What decisions now require approvals that did not exist two years ago, and how do you justify risk internally when a geopolitical judgment call can override a perfectly good technical case ?
None of the panellists pretended these were easy questions. What came through clearly, across every answer, was that the old assumption, that a globalised, frictionless market for innovation was the default state of affairs, no longer holds. Export control regimes have tightened. Ownership structures that used to be a footnote are now a first question. Dual-use classification has expanded well beyond what most people would intuitively call a weapon. And the corporates in that room were not describing a hypothetical future. They were describing decisions they were already making, and increasingly having to defend, that quarter.
By the end of the session, the conversation had shifted from geopolitics as a backdrop to geopolitics as a category of due diligence. Let's dive into it.
"Know Your Startup" (KYS)
Financial institutions have run Know Your Customer processes for decades, not because they assume every customer is a bad actor, but because the cost of not checking, once, systematically, is too high to leave to individual judgment calls. Corporates engaging with startups in defence, aerospace, and other strategically sensitive sectors are arriving at the same conclusion, without yet having the same vocabulary or the same discipline.
We call the underlying practice Know Your Startup, or KYS. The idea is simple to state and harder to operationalise: before a corporate commits meaningful resources to a startup relationship, and periodically afterward, it should have a structured, repeatable way to answer who actually owns and controls this company, where does its funding come from, is it or its key people subject to sanctions or export restrictions, and does its customer base or investor base create exposure the corporate has not yet considered.
The instrument that makes KYS concrete is what we call a Startup Background Check, or SBC. Think of it as the equivalent of the background check a large organisation runs before extending trust to a new senior hire, applied to the corporate entity a company is about to build a dependency on. It is not a one-time gate: ownership changes, funding rounds bring in new investors, and a company that looked clean at first contact can look different eighteen months and two funding rounds later. The practice has to be continuous, or it is mostly theatre.
This is far more than a bureaucratic addition bolted onto innovation for its own sake. It is, above all, the direct answer to the question the Golden Session panel kept returning to. When geopolitics can function as a veto on a partnership that made complete technical and commercial sense, the organisations that get ahead are the ones that ran that check early, systematically, and on their own terms, rather than the ones that found out the hard way, in a headline, or in a procurement review that stops a deployment cold.
Where this fits inside ERL
KYS and SBC are what the Security and Compliance dimension of ERL has to include once you apply the model to defence and aerospace specifically. The general ERL model already looks for signals like data protection posture, certifications, and compliance documentation. A defence-grade version of that same dimension has to go further, into ownership transparency, export control status, and sanctions exposure, because in this sector those factors decide whether a partnership is even legally possible, independent of how good the technology is.
This is also where we face limits of automation. Much of what ERL measures at its automated Estimate level comes from what a company publishes about itself online: security pages, named customers, certifications, documented processes, and from specific datasets. Companies operating in defence and aerospace often do the opposite of that by design. A supplier under NDA, working on classified or export-controlled programmes, has every reason to say as little as possible publicly. A crawler will read that silence as immaturity, even if it's usually not.
That is why we tiered ERL from the start. An automated Estimate is a reasonable first filter for a wide market of vendors trying to sell into the enterprise. It is the wrong tool, on its own, for a sector where the most readiness-relevant facts are the ones a company is legally required to keep quiet about. Defence and aerospace readiness assessment has to live at the Assessment and Certification levels, where a human, working with structured evidence the company chooses to disclose under appropriate confidentiality, does the part a crawler cannot.
The point of all this
TRL told the industry whether a technology works. It never claimed to tell you whether the company behind it should be trusted with your supply chain, your data, or your reputation. For most of the history of corporate-startup collaboration, that second question could be handled informally, through relationships, references, and common sense.
That is no longer sufficient, and the Golden Session made that clear from people who deal with the consequences directly, at NATO, in the European Parliament, and inside Airbus's own scouting function. Knowing that a startup is technically ready is necessary. Knowing who the startup actually is, and staying current on that answer, is now just as necessary. Building that discipline systematically, rather than reactively, is what Know Your Startup and Startup Background Checks are for, and it is where we see the Enterprise Readiness Level framework heading next for defence and aerospace specifically.
We will be sharing more on this as the framework develops. If you work in technology scouting, corporate venturing, or procurement in this sector, I would genuinely like to hear how your organisation currently handles this question, formally or otherwise.