Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

NIH Research Security Training (RST)

NIH's Research Security Training (RST) requirement, established under NIH Guide Notice NOT-OD-26-017, requires every 'covered individual' -- meaning every senior/key person listed on an NIH grant application -- to complete research security training within the 12 months before the application's due date. Compliance is evidenced through a dual certification: an institutional certification by the Authorized Organizational Representative (AOR) on the SF424 R&R face page, and an individual certification captured through the person's NIH Biographical Sketch in SciENcv. It applies to applications with due dates on or after May 25, 2026.

ByCASRAI Editorial Board
· Last updated 18 Jul 2026

Examples

Worked examples

  • Is an instance

    A principal investigator listed as senior/key personnel on an R01 renewal with a due date after May 25, 2026 completes an NIH-qualifying research security training module in March 2026 -- within the 12 months preceding the application's due date. At submission, the institution's AOR certifies the PI's completion on the SF424 R&R face page, and the PI's own certification is captured through their NIH Biographical Sketch in SciENcv.

  • Is an instance

    A co-investigator is added to a multi-PI NIH application as senior/key personnel, but last completed research security training 18 months before the application's due date. Because RST currency is measured against each specific application's due date rather than as a one-time lifetime credential, the co-investigator must retake qualifying training before the application can be truthfully certified compliant.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A graduate research assistant named in an NIH application's personnel section, but not designated senior/key personnel, is not a "covered individual" under NOT-OD-26-017 and has no independent RST certification obligation tied to that application -- even though separate RCR training requirements tied to the specific award mechanism may still apply to that same person.

Editorial commentary

NIH Research Security Training (RST) is a specific, named certification requirement — not a synonym for NIH’s general Responsible Conduct of Research (RCR) training, and not the same thing as the broader NSPM-33 policy framework it implements. Under NIH Guide Notice NOT-OD-26-017, every ‘covered individual’ — NIH’s term for a senior/key person named on a grant application — must complete research security training within the 12 months before that application’s due date, evidenced through a two-part certification process. The requirement takes effect for applications with due dates on or after May 25, 2026. This page covers what RST actually requires and how it differs from the training obligations CASRAI already covers elsewhere; for the underlying national-security policy this implements, see NSPM-33, and for NIH’s separate general research-ethics training requirement, see RCR training.

What NOT-OD-26-017 actually requires

NOT-OD-26-017 requires that each covered individual on an NIH application certify completion of research security training that meets NIH’s requirements, completed within the 12 months immediately preceding the application’s due date. This is a rolling window tied to each specific application, not a one-time, career-long certification — a person named as senior/key personnel on more than one application over time needs their training to stay current relative to each submission’s due date, not just their first one.

NIH frames this requirement as implementing the research-security disclosure and training standardization directed by NSPM-33 (January 2021), Section 10634 of the CHIPS and Science Act of 2022, and the Office of Science and Technology Policy’s July 29, 2024 memorandum, ‘Guidelines for Research Security Programs at Covered Institutions.’ An earlier NIH notice on this subject, NOT-OD-25-154, was issued and subsequently rescinded; NOT-OD-26-017 is the notice that currently governs the requirement, and institutions should treat it, not any earlier or informally circulated guidance, as controlling.

Who counts as a "covered individual"

NIH’s RST requirement applies to senior/key personnel — the same population NIH’s biographical sketch and current-and-pending-support disclosure rules apply to, not every person named anywhere in an application’s personnel section. A graduate student or staff scientist listed as project personnel but not designated senior/key personnel is not independently subject to RST certification for that application, even though other training obligations (RCR training tied to a specific award mechanism, for instance) may separately apply to them. Confirming who is correctly designated senior/key personnel on a given application — a determination that already matters for biosketch and current-and-pending-support purposes — is therefore also the threshold question for who owes RST certification.

The two-part certification: institutional and individual

RST compliance is documented through two separate certifications, not one:

  • Institutional certification. The Authorized Organizational Representative (AOR) certifies, via signature on the SF424 R&R application face page, that every individual identified as senior/key personnel on the application has completed research security training meeting NIH’s requirements within the preceding 12 months. This puts the burden of tracking and confirming completion on the submitting institution’s sponsored-programs office at the point of submission, not on NIH after the fact.
  • Individual certification. NIH separately collects each covered individual’s own certification through their NIH Biographical Sketch in SciENcv, at the time the application is submitted. Because NIH’s Biographical Sketch is itself now a mandatory SciENcv-generated Common Form document (see CASRAI’s guide to the NSPM-33 Common Forms), RST certification is layered onto an artifact research administrators already have to manage for every senior/key person on an application, rather than a wholly separate submission step.

Both certifications point to the same underlying fact — that each covered individual actually completed qualifying training within the window — but they are tracked through different systems (the face page vs. SciENcv) and are each the submitting institution’s or individual’s own representation; NIH does not independently verify completion against a central training registry as part of this process.

How this differs from RCR training and from NSF’s Research Security Training

Research administrators managing compliance across funders need to keep three related but distinct obligations separate, because conflating them is a common and consequential tracking error:

  • NIH RCR/RECR training is NIH’s long-standing responsible-conduct-of-research requirement, tied to specific award mechanisms (training grants, career development awards, and similar), historically including an in-person component and covering research-ethics topics such as data management, authorship, mentoring, and conflict of interest. See CASRAI’s RCR training entry and Responsible Conduct of Research Training guide for the full mechanics.
  • NIH Research Security Training (this page) is a newer, separate certification under NOT-OD-26-017, tied to senior/key-personnel status on any NIH application (not just specific training mechanisms), with a rolling 12-month currency window measured against each application’s due date rather than RCR’s multi-year cadence.
  • NSF’s Research Security Training is a parallel but administratively distinct obligation at a different federal funder, created under the same Section 10634 of the CHIPS and Science Act but implemented through NSF’s own PAPPG and NSF Important Notice No. 149, with its own effective dates (training effective October 10, 2025; certification effective December 2, 2025) and its own 12-month currency window. NIH’s and NSF’s requirements share statutory ancestry and a similar shape — senior/key personnel, a certification, a 12-month window — but they are certified through different systems, under different notices, and satisfying one does not automatically satisfy the other. See CASRAI’s RCR training guide for how NSF’s version is documented in detail.

An institution working across NIH, NSF, and other federal sponsors should expect to track RST-equivalent certifications separately per funder rather than assuming a single training completion satisfies every agency’s requirement.

Why this is a genuinely evolving compliance area

NIH’s RST requirement is recent, was preceded by a rescinded notice, and — like NSF’s research-security certification before it — is likely to be clarified through further NIH Guide notices as the May 25, 2026 effective date approaches and institutions begin actually certifying against it. Research administrators should treat NOT-OD-26-017 on grants.nih.gov as the controlling source and confirm current requirements directly there, rather than relying on any single secondary summary (including this page) as the last word once new guidance is issued.

Examples

  • A principal investigator listed as senior/key personnel on an R01 renewal with a due date after May 25, 2026 completes an NIH-qualifying research security training module in March 2026 — within the 12 months preceding the application’s due date. At submission, the institution’s AOR certifies the PI’s completion on the SF424 R&R face page, and the PI’s own certification is captured through their NIH Biographical Sketch in SciENcv.
  • A co-investigator is added to a multi-PI NIH application as senior/key personnel, but last completed research security training 18 months before the application’s due date. Because RST currency is measured against each specific application’s due date rather than as a one-time lifetime credential, the co-investigator must retake qualifying training before the application can be truthfully certified compliant.

Counter-example

A graduate research assistant named in an NIH application’s personnel section, but not designated senior/key personnel, is not a "covered individual" under NOT-OD-26-017 and has no independent RST certification obligation tied to that application — even though separate RCR training requirements tied to the specific award mechanism may still apply to that same person. Being listed somewhere in an application’s personnel is not sufficient to trigger RST; senior/key-personnel designation specifically is.

Related terms

  • NSPM-33 — the national-security presidential memorandum this training requirement implements
  • RCR training — NIH’s separate, longer-standing research-ethics training requirement
  • Responsible Conduct of Research Training guide — covers NSF’s parallel Research Security Training requirement in detail
  • CHIPS and Science Act — the 2022 statute whose Section 10634 anchors research-security training requirements across federal funders
  • Biosketch (NIH-style) and NSF Biosketch (SciENcv) — the SciENcv-generated documents through which individual RST certification is captured for NIH
  • Current and pending support — another senior/key-personnel disclosure obligation administered through the same NSPM-33 Common Forms infrastructure
  • Research security policy — the broader compliance landscape this specific training requirement sits inside

For the broader compliance context, see the Integrity & Compliance cluster page.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="NIH Research Security Training (RST)"
      vocab-term-identifier="https://casrai.org/dictionary/term/nih-research-security-training" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/nih-research-security-training",
  "name": "NIH Research Security Training (RST)",
  "identifier": "https://casrai.org/dictionary/term/nih-research-security-training",
  "description": "NIH's Research Security Training (RST) requirement, established under NIH Guide Notice NOT-OD-26-017, requires every 'covered individual' -- meaning every senior/key person listed on an NIH grant application -- to complete research security training within the 12 months before the application's due date. Compliance is evidenced through a dual certification: an institutional certification by the Authorized Organizational Representative (AOR) on the SF424 R&R face page, and an individual certification captured through the person's NIH Biographical Sketch in SciENcv. It applies to applications with due dates on or after May 25, 2026.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/nih-research-security-training",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-18T06:30:44",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →