Examples
Worked examples
- Is an instance
A public research university receiving more than $50 million/year in federal science and engineering funding designates a Research Security Officer inside its Office of Research (often paired with, or housed in, the export control office) who reviews foreign collaboration agreements and current-and-pending-support disclosures, coordinates with campus IT security on federally required cybersecurity controls, and prepares the institution's NSPM-33 certification submitted to its funding agencies.
- Is an instance
A federal funding agency designates its own internal research security point of contact to administer agency-level implementation of NSPM-33 requirements -- for example, NASA administers its research security training program (GIC 26-02) through an agency research security function, distinct from an individual grantee institution's own RSO.
Counter-examples
Looks similar, but isn't
- Not an instance
An export control officer who reviews only ITAR/EAR licensing questions, without also coordinating foreign-disclosure review, cybersecurity, and travel-security policy, is not functioning as a full RSO under the multi-element NSPM-33 program -- RSO responsibilities span all required program elements, not one compliance silo.
- Not an instance
A small institution below the $50 million/year federal science-and-engineering funding threshold has no CHIPS Act certification obligation and may have no formally named RSO at all, instead distributing the individual disclosure and training requirements attached to specific awards across existing sponsored-programs and compliance staff.
Editorial commentary
A Research Security Officer (RSO) is the institutional official (or office) responsible for coordinating a university’s or research institution’s research security program under NSPM-33 and its statutory implementation in the CHIPS and Science Act of 2022 (Section 10632). NSPM-33 and its implementing OSTP guidance direct federal research agencies to require institutions receiving significant federal science and engineering funding to certify that a research security program is in place; “Research Security Officer” is not itself a title mandated verbatim by the memorandum, but it is the role most institutions have created to own that certification and coordinate the program elements the guidance requires.
Where the Role Comes From
NSPM-33 (signed January 2021) tasked the Office of Science and Technology Policy (OSTP) with issuing government-wide guidance on research security, disclosure requirements, and consequences for noncompliance. The CHIPS and Science Act of 2022 later codified a key trigger for institutional compliance: institutions receiving more than $50 million per year in federal science and engineering support must certify to their funding agency that they have implemented a research security program. Federal funders have since operationalized this individually — for example, NSF’s Important Notice No. 149 sets out research security training, malign foreign talent recruitment program (MFTRP) certification, and foreign financial disclosure requirements for NSF-funded institutions and personnel. Because certification, training rollout, and disclosure review all have to be coordinated across offices that don’t normally talk to each other — export control, IT security, international affairs, sponsored programs — most covered institutions have designated a specific person or office as the point of accountability. That’s the Research Security Officer.
Core Responsibilities
Institutional guidance and program descriptions converge on a consistent set of duties, matching the program elements NSPM-33 guidance identifies:
- Export control coordination — working with (or holding) the institution’s export-controlled research review function, including ECCN determinations and technology control plans for export-controlled software and equipment.
- Foreign-influence and disclosure review — reviewing outside-activity and current-and-pending-support disclosures for undisclosed foreign affiliations, and administering institutional policy on foreign talent recruitment programs, which federal funders prohibit participation in without disclosure.
- Cybersecurity coordination — working with campus IT security to meet controls required for federally funded research systems (commonly referencing NIST SP 800-171-aligned safeguards where controlled unclassified information is involved).
- Travel-security policy — maintaining or advising on international travel security procedures for faculty and staff traveling on federally funded research business, particularly to higher-risk destinations.
- Training rollout — deploying required research security training (the specific modules and cadence vary by funding agency) and tracking completion for covered personnel.
- Certification — serving as the institution’s point of contact for certifying to funding agencies that the research security program is in place, and maintaining the documentation that certification rests on.
Who Has One
The CHIPS and Science Act’s $50 million/year federal science-and-engineering-funding threshold is the operative trigger for the certification requirement, so it’s effectively also the trigger for whether an institution has formalized a dedicated RSO role. Above that threshold, research-intensive universities and academic medical centers typically house the function inside the research compliance office, the export control office, or the Office of Research, sometimes as a standalone position and sometimes as an added responsibility layered onto an existing compliance role. Below the threshold, institutions generally still have to meet agency-specific requirements attached to individual awards (for example, disclosure and training requirements tied to a specific NSF or NIH grant) but may not have named a formal RSO, instead distributing the duties across existing sponsored-programs and compliance staff. Federal agencies themselves have designated comparable internal points of contact for administering their own research security requirements — for example, NASA’s research security training program (GIC 26-02) is administered through an agency research security function, distinct from an individual grantee institution’s RSO.
How It Differs From Related Roles
An RSO is a coordination role spanning multiple compliance domains, not a synonym for any single one of them. An institution’s export control officer, who focuses specifically on ITAR/EAR classification and licensing, is not automatically the RSO unless that office has also been assigned the broader NSPM-33 program elements (foreign disclosure, cybersecurity coordination, travel security, training). Likewise, a Chief Information Security Officer who owns cybersecurity controls generally isn’t functioning as the RSO unless foreign-influence disclosure and export control coordination also route through that office. In practice, institutions structure this differently — some centralize all elements under one RSO, others run a “research security committee” model with a named RSO chairing representatives from export control, IT security, and sponsored programs.
Related Terms
See also NSPM-33, research security policy, export-controlled research, foreign talent recruitment program, the JASON report on research security, and the export control (EAR/ITAR) guide for international research collaboration.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Research Security Officer (RSO)"
vocab-term-identifier="https://casrai.org/dictionary/term/research-security-officer" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/research-security-officer",
"name": "Research Security Officer (RSO)",
"identifier": "https://casrai.org/dictionary/term/research-security-officer",
"description": "The Research Security Officer (RSO) is the institutional official or office that coordinates a research institution's research security program under NSPM-33 and the CHIPS and Science Act of 2022 -- owning export control review, foreign-influence and foreign talent recruitment program disclosure, cybersecurity coordination for federally funded research, insider-threat and travel-security policy, training rollout, and certification to funding agencies that the required program is in place. \"Research Security Officer\" is not a title NSPM-33 itself mandates verbatim -- it is the role most covered institutions have created to hold that accountability.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
"url": "https://casrai.org/dictionary/term/research-security-officer",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T08:19:57",
"inLanguage": "en"
}






