Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

DMP Review Criteria: What Funders Actually Check

How funders actually evaluate a Data Management Plan: whether it is scored by peer reviewers or checked separately by program staff, plus the completeness, feasibility, budget-alignment, and repository criteria reviewers apply.

A Data Management Plan doesn’t get evaluated the way the rest of a grant application does. Depending on the funder, it may not be scored at all by the same panel that judges scientific merit — or it may be scored directly, on its own numeric scale, as part of that same judgement. Applicants who write a DMP as if there’s one universal review process consistently misjudge what actually gets checked, when, and by whom. This guide covers the review lens itself: who looks at a DMP, what they’re actually checking for, and where a technically complete plan still gets flagged.

This is not a guide to writing a DMP (see CASRAI’s Data Management Plan (DMP) entry and the NIH vs. NSF mechanics guide for that) and it isn’t a worked example. It’s the evaluation side: completeness against a specific funder’s stated elements, feasibility of what’s proposed, alignment between the DMP narrative and the budget, and the criteria an appropriate repository choice actually has to satisfy.

Review, assessment, and compliance checking are three different things

CASRAI’s Dictionary already distinguishes three related-but-distinct evaluation modes, and conflating them is a common source of confusion for first-time applicants:

  • DMP review — qualitative, judgement-based feedback from a peer, data steward, librarian, or funder reviewer: is the storage estimate realistic, is the chosen metadata standard adequate, are the sharing arrangements proportionate to the sensitivity of the data, is responsibility for each task clearly assigned to a named role.
  • DMP assessment — structured, rubric-based scoring against a published framework, producing a comparable score across plans rather than free-text comments. Real examples in active use include the DCC Checklist for a Data Management Plan (v4.0, 2013 — 13 questions covering the main themes a plan should address) and the Belmont Forum Data Management Plan Scorecard, which scores full DMP responses against the Belmont Forum’s own Data and Digital Outputs Management Plan template.
  • DMP compliance check — automated or rules-based verification against a specific structural requirement: does the DMP name a repository, does it include a retention period for sensitive data, does the underlying JSON validate against the RDA DMP Common Standard. A machine-actionable DMP makes this kind of check possible continuously, not only at submission.

A given funder’s process usually combines more than one of these. Understanding which mode applies at which stage is the actual key to knowing what to prioritize when writing the plan.

Whether a DMP is scored as part of scientific merit depends entirely on the funder

This is the single most consequential difference between major funders, and it’s rarely stated plainly in funder guidance itself.

NIH: assessed by program staff, not scored by peer reviewers

Under NIH’s Policy for Data Management and Sharing (effective for applications due on or after 25 January 2023), peer reviewers are explicitly not asked to factor the DMS Plan into the application’s Overall Impact score, unless data sharing is integral to the specific project design and the funding opportunity announcement says so. Peer reviewers can, and do, comment on the reasonableness of the proposed data management budget as part of the budget review — that’s a separate channel from Overall Impact scoring.

The substantive review of the DMS Plan itself happens after peer review, when NIH Institute or Center program staff check whether all required elements are adequately addressed and whether any justification for restricting data sharing is acceptable. An application otherwise selected for funding will not actually be funded until its DMS Plan is judged complete and acceptable by that program staff review — making it a real gate, just one that sits outside the peer-review score.

NSF: reviewed directly under Intellectual Merit and/or Broader Impacts

NSF takes the opposite approach. Per the Proposal & Award Policies & Procedures Guide (PAPPG), the Data Management and Sharing Plan (DMSP) is reviewed as an integral part of the proposal, considered under Intellectual Merit, Broader Impacts, or both, depending on what’s appropriate for the relevant scientific community. A proposal that omits a DMSP altogether cannot be submitted, or will be returned without review. This means NSF peer reviewers are, in effect, scoring the DMSP alongside the rest of the proposal’s scientific case — not treating it as a separate compliance artifact the way NIH does.

PAPPG 24-1 also tightened what counts as an adequate plan on one specific point: a DMSP must now name a specific, appropriate repository, rather than asserting that “an appropriate repository will be identified” at some later point.

Horizon Europe: scored on a 0–5 scale under Excellence

Horizon Europe proposals are judged against exactly three award criteria — Excellence, Impact, and Quality and Efficiency of Implementation — each scored 0 to 5 by evaluators. Data management sits inside Excellence, under the “soundness of the proposed methodology” sub-criterion, which explicitly includes the quality of open science practices: whether a DMP exists and whether FAIR principles are genuinely addressed, not just asserted. A full DMP is only formally due six months into the project, but the proposal-stage description of data management approach is itself part of what’s scored at application time.

Wellcome: reviewed proportionally, then checked again at reporting

Wellcome’s Outputs Management Plan is reviewed by Wellcome staff, advisory committees, and/or peer reviewers as part of the funding decision, with expected depth scaled to the complexity of the study, the type of data involved, the anticipated long-term value of the outputs, and the data security requirements — a plan for a small qualitative interview study isn’t held to the same bar as one for a large biobank. Wellcome then checks the same plan again at end-of-grant reporting, comparing what was proposed against what was actually done.

What “feasibility” actually means to a reviewer

Feasibility is the least formally documented of the four criteria in this guide’s scope, but it shows up consistently in how experienced DMP reviewers describe their own process (see the operational definition on CASRAI’s DMP review term): is the storage volume estimate plausible given the described methods and sample size, is the proposed timeline for deposit realistic given how long curation actually takes, and is the staffing named in the plan (a data steward, a lab manager, a named PI) actually available to do the work described. A DMP that promises daily backups to an institutional repository with no named person responsible for running them, or that estimates dataset size an order of magnitude below what the described instrumentation and sample size would actually produce, reads as infeasible even though every required section is technically present. Reviewers who evaluate DMPs regularly (institutional data librarians doing pre-submission review, in particular) flag this gap between narrative and plausibility more often than missing sections outright.

Budget alignment: does the money match the promise

Both NIH and NSF now permit data management and sharing costs — repository deposit fees, long-term storage, curation effort, staff time for metadata preparation — to appear as itemized direct costs in the grant budget, rather than being absorbed as unallocated overhead. NIH requires these costs, where they exist, to be itemized under a “Data Management and Sharing Justification” subheading in the budget justification, distinct from the DMS Plan document itself. NSF’s PAPPG similarly permits investigators to include DMSP-related costs as direct costs.

What a reviewer or program officer actually checks is consistency between the two documents: if the DMP commits to depositing a large sensitive dataset in a fee-charging domain repository with a named data steward’s time budgeted, the budget justification should show a corresponding line item. A DMP with strong commitments and a budget with nothing to support them is one of the more reliable tells that the plan was written to satisfy a checkbox rather than describe what will actually happen. CASRAI’s Dictionary models this explicitly — see cost element (in DMP), and note that the RDA DMP Common Standard represents cost as a typed entity (value, currency, description) specifically so it can be reconciled against a grant budget in a machine-actionable DMP, not just cross-checked by eye.

What makes a repository choice “appropriate,” not just named

Since PAPPG 24-1, NSF requires a DMSP to name a specific repository rather than defer the decision. NIH has never allowed deferral and publishes its own criteria for what makes a repository choice acceptable, in Selecting a Data Repository. The considerations a reviewer or program officer actually checks against:

  • Persistent identifiers — the repository assigns a citable, unique identifier (a DOI or accession number) that resolves to a stable landing page even if the dataset is later deaccessioned.
  • Metadata — datasets are accompanied by metadata sufficient for discovery, reuse, and citation, using a schema appropriate to (ideally standard within) the relevant research community. A domain repository typically enforces richer, more specific metadata than a generalist one.
  • Long-term sustainability — a credible plan for maintaining data integrity, authenticity, and availability, built on stable technical and funding infrastructure, with contingency plans for unforeseen events (an institution’s repository shutting down, a vendor going out of business).
  • Curation and quality assurance — some mechanism for checking submitted data before or during deposit, not a pure pass-through upload.
  • Access and terms — clear, published data-use terms, timely availability after submission, and (for sensitive data) documented security and confidentiality controls.

A repository that satisfies all of these is functionally what CoreTrustSeal certification exists to verify independently — naming a CoreTrustSeal-certified trusted digital repository is one of the fastest ways to answer most of the checklist above in one line, though it isn’t required by any of the funders discussed here. For the mechanics of narrowing down which type of repository actually fits a given dataset, see CASRAI’s How to Choose an Open Data Repository guide, and, for the metadata layer specifically, How to Choose a Metadata Schema for a Dataset.

Completeness against a funder’s stated elements

Completeness sounds like the simplest criterion, but “complete” is funder-specific, not generic. NIH’s policy names six required elements a DMS Plan must address (data type; related tools, software, and/or code; standards; preservation, access, and associated timelines; access, distribution, or reuse considerations; and oversight). NSF’s requirement is structured differently, and directorates including Engineering, Mathematical and Physical Sciences, and Social, Behavioral and Economic Sciences layer additional expectations on top of the PAPPG baseline. Horizon Europe frames completeness around FAIR — a reviewer checking the Excellence criterion is specifically asking whether Findability, Accessibility, Interoperability, and Reusability are each genuinely addressed, not just whether a document exists. A plan that would pass NIH’s completeness bar is not automatically complete by NSF’s or Horizon Europe’s standard, and vice versa — the specific mechanics differ by funder in ways covered in CASRAI’s NIH vs. NSF Data Management Plans guide.

For applicants preparing for a specific funder, checking completeness against a published, funder-agnostic framework before submission — such as the DCC Checklist or the Belmont Forum Scorecard referenced above, or DANS’s FAIR-Aware self-assessment tool — is a useful sanity check precisely because it surfaces gaps a funder-specific template’s fill-in-the-blank structure can hide. A plan can fully complete every field of a short template and still be substantively thin on, say, long-term preservation, if the template itself doesn’t press hard on that element.

Frequently asked questions

Do peer reviewers actually read and score my Data Management Plan?

It depends entirely on the funder. NSF and Horizon Europe both have peer reviewers or evaluators directly score the DMP as part of the scientific merit evaluation (Intellectual Merit/Broader Impacts for NSF; Excellence for Horizon Europe). NIH’s peer reviewers are explicitly told not to factor the DMS Plan into the Overall Impact score — it’s assessed separately by NIH program staff before an award is made.

What’s the difference between a DMP review and a DMP compliance check?

A review is qualitative and judgement-based — a person assessing whether the plan is realistic and well-reasoned. A compliance check is automated or rules-based, verifying specific structural requirements (does a repository get named, does a retention period exist) and returning a pass/fail result rather than commentary. See CASRAI’s DMP review and DMP compliance check entries for the full distinction.

Can I get my DMP reviewed before I submit it?

Many research institutions offer pre-submission DMP review as a service, typically through a research data librarian or data steward, distinct from and in addition to whatever the funder itself does after submission. This is worth using specifically for the feasibility check described above — an institutional reviewer is well placed to sanity-check storage estimates and staffing commitments against what your own institution can actually support.

Does naming a repository automatically satisfy a funder’s requirement?

No. Naming any repository technically satisfies a structural compliance check (a field is filled in), but reviewers and program staff assess whether the specific repository named is an appropriate fit — covering persistent identifiers, adequate metadata, long-term sustainability, curation, and clear access terms. A generalist repository named for a highly domain-specific or sensitive dataset can be flagged as inappropriate even though the DMP technically names a repository.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →