Examples
Worked examples
- Is an instance
A principal investigator preparing a DOE Office of Science R&D financial-assistance application, and named on it as a covered individual, completes the SECURE Center Consolidated Training Module a few months before submission; the applicant institution certifies the PI's completed training via its Current and Pending Support disclosure certification.
- Is an instance
A university sponsored-programs office builds its own in-house training module covering cybersecurity, international travel, foreign interference, and conflict-of-interest/commitment disclosure, and uses it instead of the SECURE Center module for its DOE-funded senior/key personnel -- compliant because DOE does not mandate a specific pre-approved course.
Counter-examples
Looks similar, but isn't
- Not an instance
A graduate student who performs technical work on a DOE-funded project but is not named as a covered individual (senior/key person) on the financial-assistance application is not independently subject to this certification requirement for that application, even though the PI and other named covered individuals are.
Editorial commentary
The DOE Research Security Training Requirement is the Department of Energy’s implementation of the government-wide research-security training mandate created by Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. Section 19234) and directed by NSPM-33. DOE announced the requirement through Policy Flash PF 2025-04 (Financial Assistance Letter FAL 2025-02), ‘Research Security Training Requirements for all R&D Financial Assistance Awards,’ dated October 7, 2024: ‘covered individuals’ listed on a DOE research-and-development financial-assistance application must complete research security training within the 12 months prior to submitting that application, and the applicant organization must certify that every covered individual named on the application has done so. This page covers what DOE’s requirement asks for specifically; for the broader federal policy this and comparable NIH/NSF requirements implement, see NSPM-33 and research security policy.
What PF 2025-04 / FAL 2025-02 actually requires
DOE’s own summary page for the requirement (energy.gov/ia/research-security-training-requirement) states the scope narrowly: the training obligation applies to ‘Research & Development (R&D) Applications/Projects’ under DOE financial assistance, not to every DOE award or contract. Covered individuals named on such an application must complete qualifying training within the 12 months immediately preceding the application’s submission date, and the prime applicant certifies completion for all its listed covered individuals as part of the application. DOE’s guidance does not require use of any single pre-approved course — an organization may use its own training program provided that program addresses the required topic areas below; DOE does not separately review or pre-approve institutional training content, only the organization’s certification that it meets the requirement.
Who counts as a "covered individual"
DOE’s published summary confirms the requirement applies to covered individuals listed on a financial-assistance application, without reproducing the full definition on that page; the operative definition sits in the linked FAL 2025-02 guidance document itself. In practice, and consistent with how the same term is used across the parallel NSF and NIH requirements built on the same CHIPS Act Section 10634 authority, this means senior/key personnel named on the application — principal investigators, co-PIs, and others substantively contributing to the proposed research — rather than every individual anywhere in the application’s personnel section. Research administrators should confirm the precise, current definition against the full FAL 2025-02 text (available via DOE’s Office of Acquisition and Project Management, [email protected]) rather than assuming it is identical to NSF’s or NIH’s covered-individual definitions, since each agency’s implementing notice is its own controlling document.
Required training topics
DOE’s summary page specifies that qualifying training must address: cybersecurity, international collaboration and international travel, foreign interference, and rules for proper use of funds, disclosure, conflict of commitment, and conflict of interest. DOE recognizes the SECURE Center Consolidated Training Module — a roughly one-hour, free module developed by the SECURE Center in partnership with NSF, NIH, DOE, and DoD — as one compliant option, but does not require its use over an institution’s own program covering the same topics.
How certification works
Individual completion is certified ‘via Current and Pending Support disclosure certification,’ per DOE’s summary page, meaning RST completion is folded into a disclosure artifact research administrators already prepare for federal applications rather than tracked through a wholly separate DOE system. The prime applicant organization is responsible for certifying, at submission, that every covered individual named on the application has completed compliant training within the preceding 12 months.
Effective date — verify directly, this is a fast-moving area
DOE’s policy flash is dated October 7, 2024, but that page does not itself state a single application-submission effective date, and multiple institutional research-office summaries (not DOE primary sources) describe DOE and the National Nuclear Security Administration as having begun enforcing the requirement for new R&D financial-assistance proposals from May 1, 2025 onward. Because DOE research-security policy has already been revised more than once in this area, and because this page is not a substitute for DOE’s own guidance, sponsored-programs offices should confirm the current effective date, any transition or grace-period provisions, and the full covered-individual definition directly against the live FAL 2025-02 text and energy.gov/ia/research-security-training-requirement before relying on a secondary summary, including this one.
How this compares to NSF’s and NIH’s parallel requirements
DOE, NSF, and NIH each built a research-security training and certification requirement on the same Section 10634 CHIPS Act authority and the same NSPM-33 policy direction, but each agency implemented it through its own notice, on its own timeline, with its own certification mechanism — satisfying one agency’s requirement does not automatically satisfy another’s for the same individual. NSF’s version is documented in NSF Important Notice No. 149; NIH’s is documented in NOT-OD-26-017 (see CASRAI’s NIH Research Security Training entry). An institution managing federally funded researchers across DOE, NSF, and NIH awards should expect to track and evidence training currency separately per funder rather than assuming a single completed course clears every agency’s requirement.
Examples
- A principal investigator preparing a DOE Office of Science R&D financial-assistance application, and named on that application as a covered individual, completes the SECURE Center Consolidated Training Module a few months before submission. The applicant institution certifies the PI’s completed training as part of its Current and Pending Support disclosure certification when the application is submitted.
- A university sponsored-programs office builds its own in-house training module covering cybersecurity, international travel, foreign interference, and conflict-of-interest/commitment disclosure, and uses it in place of the SECURE Center module for all its DOE-funded senior/key personnel. Because DOE does not mandate a specific pre-approved course, this is compliant provided the institution can certify the training addresses the required topics.
Counter-example
A graduate student who performs technical work on a DOE-funded project but is not named as a covered individual (senior/key person) on the financial-assistance application is not independently subject to this specific certification requirement for that application, even though the PI and other named covered individuals on the same application are.
Related terms
- NSPM-33 — the national-security policy memorandum this and comparable agency training requirements implement
- CHIPS and Science Act — the 2022 statute whose Section 10634 is DOE’s, NSF’s, and NIH’s shared statutory basis for research-security training requirements
- NIH Research Security Training (RST) — NIH’s parallel requirement under NOT-OD-26-017
- Research security policy — the broader compliance landscape this specific DOE requirement sits inside
For the broader compliance context, see the Integrity & Compliance cluster page.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="DOE Research Security Training Requirement"
vocab-term-identifier="https://casrai.org/dictionary/term/doe-research-security-training-requirement" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/doe-research-security-training-requirement",
"name": "DOE Research Security Training Requirement",
"identifier": "https://casrai.org/dictionary/term/doe-research-security-training-requirement",
"description": "DOE's research security training requirement, announced via Policy Flash PF 2025-04 (Financial Assistance Letter FAL 2025-02) under Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. Section 19234) and NSPM-33, requires that 'covered individuals' named on a DOE R&D financial-assistance application complete research security training -- addressing cybersecurity, international collaboration/travel, foreign interference, and rules on proper use of funds, disclosure, conflict of commitment, and conflict of interest -- within the 12 months prior to submitting that application. The applicant organization certifies completion for all listed covered individuals via Current and Pending Support disclosure certification; DOE does not require use of any specific pre-approved training course.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/doe-research-security-training-requirement",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T06:05:06",
"inLanguage": "en"
}






