Examples
Worked examples
- Is an instance
A research institution that receives more than $50 million per year in federal research funding certifies, under NSPM-33's implementing guidance, that it operates a research security program addressing cybersecurity, foreign travel security, research security training, and export control training for covered personnel.
- Is an instance
A senior/key person on an NSF award completes the research-security training certification required by NSF Important Notice No. 149 (tied to Section 10634 of the CHIPS and Science Act of 2022, 42 U.S.C. 19234) before submitting a proposal, and the institution's Authorized Organizational Representative certifies completion.
- Is an instance
A university reports a gift or contract of $50,000 or more from a country of concern under NSF's Foreign Financial Disclosure Reporting (FFDR) requirement, or discloses a researcher's participation in a foreign talent recruitment programme as required under the CHIPS and Science Act.
Counter-examples
Looks similar, but isn't
- Not an instance
A university's general campus IT-security policy -- patching schedules, firewall configuration, password rules -- is information security, not research security, unless it is specifically scoped to protect federally funded research data, systems, or outputs from foreign-interference risk.
- Not an instance
An investigation into data fabrication or plagiarism in a published paper is a research integrity matter handled under an institution's research misconduct policy; it becomes a research security matter only where the underlying conduct also involves undisclosed foreign support, foreign talent recruitment, or interference with the federal funding relationship -- the two domains overlap but are not the same, which is why NSPM-33's own definition names research integrity violations as one input to, not a synonym for, research security.
Editorial commentary
What “research security” means
“Research security” is a term of art in U.S. federal research policy, not a generic synonym for cybersecurity or lab safety. It refers specifically to the government-wide effort — formalized under NSPM-33 and expanded through the CHIPS and Science Act of 2022 — to protect federally funded research and development from foreign government interference, undisclosed foreign financial support, and the misappropriation of research outputs. Every major federal research funder (NSF, NIH, DOE, NASA, USDA and others) now operates research-security requirements built on this same federal framework, though each agency implements the specifics through its own notices and grant terms.
Where the definition comes from
NSPM-33, issued in January 2021, directed the National Science and Technology Council (NSTC), through the Office of Science and Technology Policy (OSTP), to issue implementation guidance for federal research agencies. That guidance — released January 2022 and finalized in July 2024 — is the source of the operational definition above and of the requirement that research organizations receiving more than $50 million per year in federal research funding certify a research security program covering four elements: cybersecurity, foreign travel security, research security training, and export control training. The CHIPS and Science Act of 2022 then wrote several of these obligations directly into statute, including the research-security training certification (Section 10634, 42 U.S.C. 19234) and the prohibition on participation in a Malign Foreign Talent Recruitment Program (Section 10632, 42 U.S.C. 19232).
How it shows up in day-to-day grants administration
For a research administrator, research security is rarely a single standalone requirement — it surfaces across several distinct compliance touchpoints on a federally funded project:
- Disclosure: reporting foreign financial support, foreign appointments, and in-kind foreign contributions on current-and-pending-support forms, and complying with Section 117 foreign gift and contract reporting where applicable.
- Certification: senior/key personnel and Authorized Organizational Representatives certifying non-participation in a foreign talent recruitment programme and completion of required training.
- Training: agency-specific research-security training requirements, such as NIH Research Security Training (RST), the DOE Research Security Training Requirement, USDA’s version, and NASA’s (GIC 26-02).
- Institutional oversight: many research organizations designate a Research Security Officer (RSO) to coordinate the institution’s compliance program across all of the above.
Research security vs. adjacent terms
Research security is frequently, and incorrectly, used interchangeably with three related but distinct concepts:
- Research integrity concerns the honesty and rigor of the research process itself (fabrication, falsification, plagiarism). It overlaps with research security where a research-integrity violation also involves undisclosed foreign support or interference, but most research-integrity matters have no research-security dimension at all.
- Export control (ITAR/EAR) governs the transfer of controlled technology, software, and technical data to foreign persons or countries. Export control training is one of the four required elements of a research security program, but export control itself is a separate, older regulatory regime that also applies outside the federally funded research context.
- General cybersecurity is a required element of a research security program, but a research security program is broader than IT controls alone — it also covers disclosure, personnel certification, and foreign travel.
Related reading
See the Research Security Officer (RSO) entry for the role that typically owns this compliance area institutionally, and NSPM-33 for the foundational policy memorandum. The CHIPS and Science Act entry covers the statutory layer that turned much of NSPM-33’s guidance into binding requirements, and the JASON Report on research security covers the earlier advisory report that shaped the federal approach.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Research Security"
vocab-term-identifier="https://casrai.org/dictionary/term/research-security" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/research-security",
"name": "Research Security",
"identifier": "https://casrai.org/dictionary/term/research-security",
"description": "<p>Research security is the set of institutional and federal policies, disclosures, and safeguards designed to protect the U.S. federally funded research enterprise against foreign government interference, undisclosed foreign support, and the misappropriation of research and development. The controlling federal definition comes from <a href='/dictionary/term/nspm-33'>National Security Presidential Memorandum 33 (NSPM-33)</a> (issued January 2021) and its implementing guidance from the National Science and Technology Council (NSTC): research security means <em>\"safeguarding the research enterprise against the misappropriation of research and development to the detriment of national or economic security, related violations of research integrity, and foreign government interference.\"</em></p><p>An activity, disclosure, or policy is an instance of research security -- as distinct from general information security, export control, or <a href='/dictionary/term/research-integrity'>research integrity</a> -- when it satisfies three conditions together: (1) it concerns federally funded or federally regulated research; (2) it addresses a risk tied to foreign government interference, undisclosed foreign talent recruitment, or misuse of research outputs for national/economic security ends; and (3) it maps to one of the concrete compliance mechanisms federal research agencies now require -- disclosure of foreign financial support and affiliations, foreign travel security, research security training, export control training, and cybersecurity controls for federally funded R&D. Under NSPM-33's implementation, research organizations that receive more than $50 million per year in federal research funding must certify they operate a research security program covering four elements: cybersecurity, foreign travel security, research security training, and export control training.</p>",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/research-security",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T09:14:35",
"inLanguage": "en"
}






