Examples
Worked examples
- Is an instance
A DARPA co-PI's undisclosed adjunct appointment at a foreign institution on DARPA's higher-risk list is flagged during CFIP screening and resolved through disclosure and resignation during award negotiation.
- Is an instance
A named senior/key person's active, undisclosed foreign talent program membership is identified via CFIP review and, when not mitigated, results in DARPA declining the award as proposed.
Counter-examples
Looks similar, but isn't
- Not an instance
A DARPA proposal whose senior/key personnel have no foreign talent program participation, denied-entity affiliation, or undisclosed foreign funding is not subject to any CFIP mitigation step; the rubric only activates when a specific risk factor is present.
- Not an instance
A general NSPM-33 disclosure filing to NSF or NIH is not itself a CFIP review; CFIP is a DARPA-specific process applied only to DARPA-funded proposals and awards.
Editorial commentary
DARPA’s Countering Foreign Influence Program (CFIP) is an agency-specific risk-review process applied to proposals and awards funded by the Defense Advanced Research Projects Agency, part of the U.S. Department of Defense. It grew out of the FY2019 National Defense Authorization Act and the March 2019 DoD Research and Engineering memorandum Actions for the Protection of Intellectual Property, Controlled Information, Key Personnel and Critical Technologies, which directed DoD components to strengthen screening of federally funded research for undisclosed foreign ties. DARPA formalized CFIP as a standing policy (signed September 2021) and has briefed the research-administration community on its mechanics through the Council on Governmental Relations (COGR) and directly to performing institutions since.
CFIP is distinct from the government-wide disclosure framework established by NSPM-33: NSPM-33 sets baseline disclosure requirements (standardized forms, current-and-pending support, conflict of interest/commitment) that apply across federal funding agencies, while CFIP is DARPA’s own internal risk-assessment methodology for evaluating the disclosures it receives on its own awards. An institution can be fully NSPM-33 compliant and still be subject to a separate CFIP risk determination on a DARPA proposal.
How the risk rubric works
CFIP applies to all senior/key personnel named on a DARPA proposal, not just the principal investigator. DARPA’s Senior/Key Personnel Foreign Influence Risk Rubric evaluates, generally over the individual’s preceding four years of activity:
- Participation in foreign talent or foreign expert recruitment programs;
- Affiliation with entities on U.S. government restricted, denied, or entity lists;
- Funding, in-kind support, or affiliations from a foreign government source, including undisclosed positions or appointments at foreign institutions;
- Affiliation with foreign institutions DARPA has identified as higher risk.
Each factor is weighed qualitatively rather than scored on a fixed point system, and the assessment is deliberately kept separate from scientific and technical merit review, so a risk finding does not by itself disqualify a proposal from funding. Results are expressed as a risk level (from low through very high). Where DARPA identifies elevated risk, the awarding office generally raises it with the proposing institution during award negotiation, giving the institution an opportunity to clarify, correct, or mitigate the concern (for example, resignation from an undisclosed foreign talent program or termination of a conflicting affiliation) before a final funding decision. If mitigation is not achieved on a high or very-high-risk finding, DARPA can decline to make the award.
Who administers this at the institutional level
Because CFIP findings surface during proposal and award negotiation, not after an incident, institutions typically route the disclosure-review and mitigation-negotiation work through their research security officer or equivalent research-security/export-control office, working alongside the PI and sponsored-programs office. Post-award, recipients are expected to maintain internal processes to monitor and promptly report new or changed foreign talent program involvement for the personnel named on the award.
Worked example
A university submits a DARPA proposal naming a co-PI who, in the prior three years, held an unreported adjunct appointment at a foreign university on DARPA’s higher-risk list. CFIP screening flags this during proposal processing; DARPA’s program office raises it during negotiation, the co-PI discloses and resigns the appointment, and the institution documents the resolution — the award proceeds. In a second scenario, a named senior investigator has an active, undisclosed foreign talent program membership that is not resolved during negotiation; DARPA determines the risk is not adequately mitigated and declines to make the award to that team as proposed.
What CFIP is not
A proposal from an institution with strong NSPM-33-aligned disclosure practices and no foreign talent program, denied-entity, or undisclosed foreign-funding ties among its senior/key personnel is not subject to a CFIP mitigation process at all — the rubric only triggers a negotiation step where a genuine risk factor is present in the disclosures. CFIP is also not a blanket bar on international collaboration or foreign-born researchers; DARPA’s own framing is explicit that the review does not turn on nationality or protected characteristics, only on the specific, disclosed risk factors in the rubric.
References
- DARPA, Countering Foreign Influence Program policy (signed September 2021).
- Council on Governmental Relations (COGR), briefing materials on DARPA CFIP and the Senior/Key Personnel Foreign Influence Risk Rubric.
- DoD Research and Engineering memorandum, Actions for the Protection of Intellectual Property, Controlled Information, Key Personnel and Critical Technologies (March 2019).
Also known as
CFIP · Countering Foreign Influence Program
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="DARPA Countering Foreign Influence Program (CFIP)"
vocab-term-identifier="https://casrai.org/dictionary/term/darpa-countering-foreign-influence-program-cfip" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/darpa-countering-foreign-influence-program-cfip",
"name": "DARPA Countering Foreign Influence Program (CFIP)",
"identifier": "https://casrai.org/dictionary/term/darpa-countering-foreign-influence-program-cfip",
"description": "A DARPA-specific risk-review process, applied to proposed awards, in which senior/key personnel disclosures are screened against a qualitative risk rubric covering participation in foreign talent programs, affiliation with denied or restricted entities, funding or in-kind support from foreign government sources, and affiliation with designated high-risk foreign institutions, generally over the preceding four years, with results assigned a risk level from low to very high that informs (but does not automatically decide) award negotiation.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
"url": "https://casrai.org/dictionary/term/darpa-countering-foreign-influence-program-cfip",
"sameAs": [
"CFIP",
"Countering Foreign Influence Program"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T09:13:43",
"inLanguage": "en"
}






