Examples
Worked examples
- Is an instance
A principal investigator listed as senior/key personnel on an R01 renewal with a due date after May 25, 2026 completes an NIH-qualifying research security training module in March 2026 -- within the 12 months preceding the application's due date. At submission, the institution's AOR certifies the PI's completion on the SF424 R&R face page, and the PI's own certification is captured through their NIH Biographical Sketch in SciENcv.
- Is an instance
A co-investigator is added to a multi-PI NIH application as senior/key personnel, but last completed research security training 18 months before the application's due date. Because RST currency is measured against each specific application's due date rather than as a one-time lifetime credential, the co-investigator must retake qualifying training before the application can be truthfully certified compliant.
Counter-examples
Looks similar, but isn't
- Not an instance
A graduate research assistant named in an NIH application's personnel section, but not designated senior/key personnel, is not a "covered individual" under NOT-OD-26-017 and has no independent RST certification obligation tied to that application -- even though separate RCR training requirements tied to the specific award mechanism may still apply to that same person.
Editorial commentary
NIH Research Security Training (RST) is the requirement, established by NIH Guide notice NOT-OD-26-017, that every “covered individual” on an NIH grant application — meaning every person listed as senior/key personnel — has completed research security training within the 12 months before that application’s due date. It applies to applications with due dates on or after May 25, 2026. RST implements Section 10634 of the CHIPS and Science Act of 2022 and sits within the government-wide research-security framework established by NSPM-33.
What makes the requirement distinctive
Two features separate RST from most other NIH training obligations:
- It is currency-based, not one-and-done. RST is measured against each specific application’s due date rather than held as a lifetime credential. Training that was completed but has fallen outside the 12-month window does not satisfy the requirement for a new submission.
- It uses a dual certification. Compliance is evidenced twice: an institutional certification by the Authorized Organizational Representative (AOR) on the SF424 (R&R) face page, and an individual certification captured through the person’s NIH Biographical Sketch in SciENcv.
Who is covered
The obligation attaches to individuals designated senior/key personnel on a specific application — the Program Director/Principal Investigator and any co-investigator or other named scientist contributing substantively and measurably to the project’s scientific development or execution. It does not, by itself, reach personnel who are not senior/key personnel on that application.
What it is not
RST is frequently confused with three adjacent obligations, and the distinctions are administrative as well as legal:
- Not the Other Support / biosketch disclosure rules. NIH notice NOT-OD-25-133 (effective October 1, 2025) governs how covered individuals complete Other Support and biosketch disclosures. RST governs training. Two notices, two compliance obligations — they are conflated because both flow from the same research-security push and both touch the SciENcv workflow.
- Not NSF’s requirement. NSF runs its own research-security training certification under Important Notice No. 149. It is parallel to NIH’s but legally and administratively separate; completing one does not discharge the other.
- Not RCR training. Responsible Conduct of Research training is tied to particular award mechanisms (notably training and career-development grants) and covers research ethics rather than security. A graduate research assistant named in an application’s personnel section but not designated senior/key personnel has no independent RST obligation for that application, even where an RCR requirement does apply to the same person.
Worked example
A principal investigator listed as senior/key personnel on an R01 renewal with a due date after May 25, 2026 completes a qualifying research security training module in March 2026 — inside the 12 months preceding the due date. At submission the institution’s AOR certifies completion on the SF424 (R&R) face page, and the PI’s own certification is captured through their NIH Biographical Sketch in SciENcv.
Counter-example
A co-investigator is added to a multi-PI application as senior/key personnel but last completed research security training 18 months before the due date. Because currency is measured per application rather than as a standing credential, that co-investigator must retake qualifying training before the application can be truthfully certified compliant.
Training that satisfies the requirement
NIH’s notice does not require a single mandated vendor. Corroborated across the notice and multiple university sponsored-programs offices, three training pathways currently satisfy RST: the four government-wide research-security modules jointly developed by NSF, NIH, DOE and DOD; a condensed version of the same four modules offered through the SECURE Center (the NSF-funded Safeguarding the Entire Community of the U.S. Research Ecosystem center); and CITI Program’s Research Security series. Content across all three covers cybersecurity, foreign interference and foreign-talent-recruitment-program risk, disclosure requirements, and conflict of commitment/interest — the same subject-matter core NSF’s parallel Notice 149 requires.
Where each of these requirements is written down
| Requirement | Authority | Where to read it |
|---|---|---|
| Statutory basis for agency research-security training | CHIPS and Science Act of 2022, Section 10634 (42 U.S.C. 19234) | 42 U.S.C. 19234, Cornell LII |
| NIH’s specific RST requirement, covered individuals, and effective date | NIH Guide Notice NOT-OD-26-017 | NOT-OD-26-017, grants.nih.gov |
Because this is an agency notice rather than a codified regulation, NIH has revised notice numbers in this area before — confirm the current governing notice directly against grants.nih.gov before treating any single number as permanent.
Who tracks this in a research administration office
The notice names two certifiers — the individual covered person and the institution’s AOR — but it does not say who does the underlying legwork of confirming, before a proposal goes out, that every senior/key person’s training is inside the 12-month window. In practice that check lands wherever an institution already routes SciENcv biosketch review before submission: some offices have stood up a dedicated research security officer role since NSPM-33 first required an institutional research security program; others fold the check into the same pre-award staff who already verify Other Support disclosures under NOT-OD-25-133. Either way, the check has to happen before submission, because the AOR’s face-page certification cannot be corrected once NIH has the application.
What this page cannot tell you
Three things decide how this plays out on a specific application, and none of them are answered by the notice alone:
- Whether your institution’s chosen training vendor is on NIH’s current accepted list — the accepted-options list above is current as of this notice, and agencies have changed accepted vendors before.
- Whether a specific person on your application counts as senior/key personnel — that determination is made per application, by role and scientific contribution, not by job title or salary line.
- How your institution’s own SciENcv workflow validates a completion before submission — the notice sets the certification requirement; the internal routing that catches a missing or expired certification before the AOR signs is an institutional process, not a federal one.
Checking this against the current guidance
Whether a specific new co-investigator’s training window has to be current as of an application’s due date or a later prior-approval submission date is exactly the kind of institution-specific timing question the notice does not spell out.
It searches CASRAI’s indexed corpus of research-administration guidance and cites the passage behind each claim, so you can open the source and check it rather than take its word — and it says so when the corpus does not cover something instead of guessing. Two questions a day are free while you are signed out, no account and no card. Everything CASRAI publishes stays free to read.
Frequently asked questions
What training satisfies NIH’s Research Security Training requirement?
NSF’s four government-wide research-security modules, a condensed version offered through the SECURE Center, or CITI Program’s Research Security series. NIH does not mandate a single vendor.
Does RST apply to graduate students or postdocs?
Only if they are personally designated senior/key personnel on the specific application. Being named in an application’s personnel section without that designation does not create an independent RST obligation, even where a separate RCR training requirement applies to the same person.
Is RST the same as the Other Support disclosure training under NOT-OD-25-133?
No. NOT-OD-25-133 governs training on how to correctly complete Other Support and biosketch disclosures; RST governs completing research-security training itself. They are two separate NIH compliance obligations that happen to touch the same SciENcv workflow.
What happens if a covered individual’s certification turns out to be inaccurate?
Because the AOR’s certification on the SF424 (R&R) face page is a representation to NIH about compliance status, an inaccurate certification carries the same institutional exposure as any other false certification on that form.
When does the RST requirement start applying?
For applications with due dates on or after May 25, 2026. Earlier NIH notices — NOT-OD-25-133 among them — addressed related but narrower disclosure-training obligations before that date.
Related CASRAI content
For the full procedural treatment — the training options that satisfy the requirement, certification and institutional tracking mechanics, and a compliance timeline for research-administration offices — see the NIH research security training requirements guide. See also research security and Other Support (NIH format).
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="NIH Research Security Training (RST)"
vocab-term-identifier="https://casrai.org/dictionary/term/nih-research-security-training" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/nih-research-security-training",
"name": "NIH Research Security Training (RST)",
"identifier": "https://casrai.org/dictionary/term/nih-research-security-training",
"description": "NIH's Research Security Training (RST) requirement, established under NIH Guide Notice NOT-OD-26-017, requires every 'covered individual' -- meaning every senior/key person listed on an NIH grant application -- to complete research security training within the 12 months before the application's due date. Compliance is evidenced through a dual certification: an institutional certification by the Authorized Organizational Representative (AOR) on the SF424 R&R face page, and an individual certification captured through the person's NIH Biographical Sketch in SciENcv. It applies to applications with due dates on or after May 25, 2026.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/nih-research-security-training",
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-07-18T06:25:44",
"dateModified": "2026-09-05T23:09:38",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







