Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Research Security Officer (RSO)

The Research Security Officer (RSO) is the institutional official or office that coordinates a research institution's research security program under NSPM-33 and the CHIPS and Science Act of 2022 -- owning export control review, foreign-influence and foreign talent recruitment program disclosure, cybersecurity coordination for federally funded research, insider-threat and travel-security policy, training rollout, and certification to funding agencies that the required program is in place. "Research Security Officer" is not a title NSPM-33 itself mandates verbatim -- it is the role most covered institutions have created to hold that accountability.

ByCASRAI Editorial Board
· Last updated 23 Jul 2026

Examples

Worked examples

  • Is an instance

    A public research university receiving more than $50 million/year in federal science and engineering funding designates a Research Security Officer inside its Office of Research (often paired with, or housed in, the export control office) who reviews foreign collaboration agreements and current-and-pending-support disclosures, coordinates with campus IT security on federally required cybersecurity controls, and prepares the institution's NSPM-33 certification submitted to its funding agencies.

  • Is an instance

    A federal funding agency designates its own internal research security point of contact to administer agency-level implementation of NSPM-33 requirements -- for example, NASA administers its research security training program (GIC 26-02) through an agency research security function, distinct from an individual grantee institution's own RSO.

Counter-examples

Looks similar, but isn't

  • Not an instance

    An export control officer who reviews only ITAR/EAR licensing questions, without also coordinating foreign-disclosure review, cybersecurity, and travel-security policy, is not functioning as a full RSO under the multi-element NSPM-33 program -- RSO responsibilities span all required program elements, not one compliance silo.

  • Not an instance

    A small institution below the $50 million/year federal science-and-engineering funding threshold has no CHIPS Act certification obligation and may have no formally named RSO at all, instead distributing the individual disclosure and training requirements attached to specific awards across existing sponsored-programs and compliance staff.

Editorial commentary

A Research Security Officer (RSO) is the institutional official (or office) responsible for coordinating a university’s or research institution’s research security program under NSPM-33 and its statutory implementation in the CHIPS and Science Act of 2022 (Section 10632). NSPM-33 and its implementing OSTP guidance direct federal research agencies to require institutions receiving significant federal science and engineering funding to certify that a research security program is in place; “Research Security Officer” is not itself a title mandated verbatim by the memorandum, but it is the role most institutions have created to own that certification and coordinate the program elements the guidance requires.

Where the Role Comes From

NSPM-33 (signed January 2021) tasked the Office of Science and Technology Policy (OSTP) with issuing government-wide guidance on research security, disclosure requirements, and consequences for noncompliance. The CHIPS and Science Act of 2022 later codified a key trigger for institutional compliance: institutions receiving more than $50 million per year in federal science and engineering support must certify to their funding agency that they have implemented a research security program. Federal funders have since operationalized this individually — for example, NSF’s Important Notice No. 149 sets out research security training, malign foreign talent recruitment program (MFTRP) certification, and foreign financial disclosure requirements for NSF-funded institutions and personnel. Because certification, training rollout, and disclosure review all have to be coordinated across offices that don’t normally talk to each other — export control, IT security, international affairs, sponsored programs — most covered institutions have designated a specific person or office as the point of accountability. That’s the Research Security Officer.

Core Responsibilities

Institutional guidance and program descriptions converge on a consistent set of duties, matching the program elements NSPM-33 guidance identifies:

  • Export control coordination — working with (or holding) the institution’s export-controlled research review function, including ECCN determinations and technology control plans for export-controlled software and equipment.
  • Foreign-influence and disclosure review — reviewing outside-activity and current-and-pending-support disclosures for undisclosed foreign affiliations, and administering institutional policy on foreign talent recruitment programs, which federal funders prohibit participation in without disclosure.
  • Cybersecurity coordination — working with campus IT security to meet controls required for federally funded research systems (commonly referencing NIST SP 800-171-aligned safeguards where controlled unclassified information is involved).
  • Travel-security policy — maintaining or advising on international travel security procedures for faculty and staff traveling on federally funded research business, particularly to higher-risk destinations.
  • Training rollout — deploying required research security training (the specific modules and cadence vary by funding agency) and tracking completion for covered personnel.
  • Certification — serving as the institution’s point of contact for certifying to funding agencies that the research security program is in place, and maintaining the documentation that certification rests on.

Who Has One

The CHIPS and Science Act’s $50 million/year federal science-and-engineering-funding threshold is the operative trigger for the certification requirement, so it’s effectively also the trigger for whether an institution has formalized a dedicated RSO role. Above that threshold, research-intensive universities and academic medical centers typically house the function inside the research compliance office, the export control office, or the Office of Research, sometimes as a standalone position and sometimes as an added responsibility layered onto an existing compliance role. Below the threshold, institutions generally still have to meet agency-specific requirements attached to individual awards (for example, disclosure and training requirements tied to a specific NSF or NIH grant) but may not have named a formal RSO, instead distributing the duties across existing sponsored-programs and compliance staff. Federal agencies themselves have designated comparable internal points of contact for administering their own research security requirements — for example, NASA’s research security training program (GIC 26-02) is administered through an agency research security function, distinct from an individual grantee institution’s RSO.

How It Differs From Related Roles

An RSO is a coordination role spanning multiple compliance domains, not a synonym for any single one of them. An institution’s export control officer, who focuses specifically on ITAR/EAR classification and licensing, is not automatically the RSO unless that office has also been assigned the broader NSPM-33 program elements (foreign disclosure, cybersecurity coordination, travel security, training). Likewise, a Chief Information Security Officer who owns cybersecurity controls generally isn’t functioning as the RSO unless foreign-influence disclosure and export control coordination also route through that office. In practice, institutions structure this differently — some centralize all elements under one RSO, others run a “research security committee” model with a named RSO chairing representatives from export control, IT security, and sponsored programs.

Related Terms

See also NSPM-33, research security policy, export-controlled research, foreign talent recruitment program, the JASON report on research security, and the export control (EAR/ITAR) guide for international research collaboration.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Research Security Officer (RSO)"
      vocab-term-identifier="https://casrai.org/dictionary/term/research-security-officer" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/research-security-officer",
  "name": "Research Security Officer (RSO)",
  "identifier": "https://casrai.org/dictionary/term/research-security-officer",
  "description": "The Research Security Officer (RSO) is the institutional official or office that coordinates a research institution's research security program under NSPM-33 and the CHIPS and Science Act of 2022 -- owning export control review, foreign-influence and foreign talent recruitment program disclosure, cybersecurity coordination for federally funded research, insider-threat and travel-security policy, training rollout, and certification to funding agencies that the required program is in place. \"Research Security Officer\" is not a title NSPM-33 itself mandates verbatim -- it is the role most covered institutions have created to hold that accountability.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
  "url": "https://casrai.org/dictionary/term/research-security-officer",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-23T08:19:57",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →