NSPM-33 requires covered research institutions to operate a research security program with four mandated elements, one of which is foreign travel security. CASRAI’s overview of all four NSPM-33 elements summarizes what each one requires at a policy level. This guide goes further on the foreign travel element specifically: what a written foreign travel security policy needs to actually require of a traveler and a research-administration office, from before a trip is booked through what happens after the traveler is back.
What the Foreign Travel Security Element Actually Requires
OSTP’s July 2024 “Research Security Programs Standard Requirement” guidance — the document implementing NSPM-33’s four-element mandate for institutions of higher education, national laboratories, FFRDCs, and nonprofit research institutions that receive more than $50 million per year in federal science and engineering support — describes the foreign travel security element as having two components, consistently summarized this way across multiple independent legal-alert analyses of the guidance (Ropes & Gray, Hogan Lovells, and the Council on Governmental Relations, among others):
- Periodic training on foreign travel security, at least once every six years, for covered individuals engaged in international travel connected to organization business, teaching, conference attendance, or research.
- A travel reporting program for covered individuals participating in federally funded R&D awards, when the relevant funding agency has determined that security risks warrant collecting that information.
That second component is deliberately not a single fixed federal checklist — it is agency-triggered, which is exactly why the operational design work (who reports, what counts, how the report is reviewed, what gets screened, what happens after return) falls to the institution. The rest of this guide covers how institutions typically build that operational layer.
Pre-Travel Disclosure and Registration
A working foreign travel security policy has to answer four practical questions before it can function, and each one needs to be spelled out in the policy document itself, not left to case-by-case judgment:
- Who is covered. Typically senior/key personnel and other individuals named on, or materially working on, a federally funded award — consistent with how “covered individual” is used elsewhere in NSPM-33 implementation. A narrower population than “every employee,” but the policy needs to state the boundary explicitly rather than leave it implied.
- What counts as reportable travel. International travel “connected to” federally funded research — attending a conference to present funded work, a collaborative research visit, fieldwork abroad, a sponsor site visit. Personal travel with no research nexus is out of scope for this specific element, even though many institutions separately register all international travel for duty-of-care and insurance reasons (see below).
- How far in advance a trip must be disclosed. Institutions vary here, but the lead time has to be long enough for a real screening step to happen before departure — not a same-week formality. A policy that only asks for disclosure without giving the review step enough runway to matter isn’t operational in the sense OSTP’s guidance means.
- Where the disclosure goes and who reviews it. A named office (typically research security, export control, or international affairs) with actual responsibility for reviewing what’s reported — not a form that gets filed and never looked at.
This is a narrower, funding-tied obligation than a university’s general international-travel-registration policy. Most institutions already require all faculty, staff, and students to register international travel for duty-of-care, emergency-contact, and insurance purposes, regardless of any research-security nexus. The NSPM-33 foreign-travel element needs to interface with that broader system — flagging and routing federally funded travel for the additional review this element requires — rather than stand up a fully separate, duplicate reporting channel.
Screening the Destination Before Approving Travel
Once a trip is disclosed, the review step has to actually screen it against something concrete. In practice, institutions typically check a proposed destination and itinerary against several distinct lists and frameworks that serve different legal purposes — treating them as one undifferentiated “restricted countries list” is a common and consequential mistake:
- OFAC comprehensively embargoed countries. A short list of countries where virtually all transactions by US persons are restricted by Treasury sanctions law, independent of whether any controlled technology is involved. See CASRAI’s guide to the OFAC embargoed countries list for what this means specifically for research travel.
- Restricted- and denied-party screening. The Consolidated Screening List, published by the US Department of Commerce, merges the Commerce/BIS Entity List and Denied Persons List, the State Department’s debarred and nonproliferation-sanctions lists, and Treasury/OFAC’s Specially Designated Nationals list. A traveler meeting with, or visiting a facility affiliated with, a listed entity or individual raises a distinct compliance question even in a country with no comprehensive embargo. See CASRAI’s export-controlled research and deemed export entries for how this connects to technology-transfer risk specifically.
- Countries of concern under the CHIPS and Science Act’s malign foreign talent recruitment provisions. China (including Hong Kong and Macau), Russia, North Korea, and Iran are the statutorily designated foreign countries of concern relevant to research-security risk assessment — travel to, or funding/affiliation connected to, these countries carries a different review posture than a comprehensive OFAC embargo, and screening for one does not substitute for the other.
- State Department travel advisories. A Level 3 or 4 advisory is a duty-of-care and general safety signal, not itself an NSPM-33 requirement — but most institutions fold this check into the same pre-travel review step for practical reasons, since the office reviewing a trip for research-security purposes is usually the same one (or works alongside the one) already reviewing it for traveler-safety purposes.
These frameworks answer different questions — sanctions law, denied-party status, research-security risk designation, and personal safety — and a policy that only checks one of them will miss risks the others are designed to catch. CASRAI’s EAR/ITAR and international research collaboration guide covers the export-control side of this in more depth.
Device and Data Security Precautions
This is where the foreign travel element and NSPM-33’s export control training element (Element 4) genuinely intersect in practice, and where a policy that treats foreign travel purely as a reporting exercise leaves a real gap. Institutional guidance in this area typically covers:
- Loaner or “clean” devices for higher-risk destinations. A laptop or phone with no more institutional data, credentials, or software than the trip strictly requires, used specifically so that a border inspection, loss, or compromise doesn’t expose the traveler’s normal working environment.
- Not carrying export-controlled technical data on the trip at all. Physically carrying ITAR- or EAR-controlled technical data, software, or equipment into certain countries can itself constitute a regulated export or “deemed reexport” under export control law — a distinct legal exposure from the research-security reporting requirement, and one that a travel-approval process needs to screen for separately, not assume the export-control office has already caught.
- Minimizing data carried and maximizing what’s encrypted. Full-disk encryption, strong device passcodes, and avoiding storage of sensitive research data, unpublished manuscripts, or credentials on a device that will cross an international border.
- Network hygiene while traveling. Avoiding connection to institutional systems over unsecured foreign networks without a VPN, and treating public and hotel Wi-Fi as untrusted by default.
- A defined process if a device is inspected, copied, or seized. Travelers need to know in advance who to contact and what to report if a border authority examines or retains a device — after the fact is too late to design that process.
None of this is unique to research security — most of it mirrors standard institutional IT-security travel guidance — but a foreign travel security policy needs to state it explicitly rather than assume travelers already know it, and needs to require heightened versions of these precautions for higher-risk destinations identified in the screening step above.
Post-Travel Reporting and Debrief
The evidence-of-use standard that runs through all four NSPM-33 elements applies here too: a policy that collects pre-travel disclosures but never asks what happened on the trip is missing half of what “operational” means. A post-travel step typically asks the traveler to report:
- Any unsolicited offers of employment, funding, titles, or collaboration made during the trip, particularly from an entity or individual connected to a country of concern.
- Any request to share unpublished data, materials, or technical information outside the traveler’s approved collaboration.
- Any signs a device was accessed, copied, or tampered with.
- Confirmation the trip proceeded as disclosed, or a note of what changed (added destinations, added meetings) from the original disclosure.
As with the pre-travel disclosure, this only functions as evidence of an operating program if the report is actually reviewed and retained, and if there is a defined escalation path — typically to the research security office and, where the report suggests an actual foreign-influence or export-control concern, to institutional compliance and legal counsel — rather than a form that is filed and never read.
Building the Written Policy: A Practical Checklist
Pulling the sections above together, a foreign travel security policy document that would hold up under an institution’s own NSPM-33 certification review typically states, in writing:
- Who is covered and what travel is in scope.
- The disclosure lead time and where disclosures are submitted.
- Which lists and frameworks the destination-screening step checks, and who performs that review.
- Device, data, and network security requirements, with heightened requirements for higher-risk destinations.
- What the post-travel report must cover and the timeline for submitting it.
- The named office responsible for reviewing disclosures and reports, and the escalation path when a report raises a genuine concern.
- How this policy interfaces with the institution’s general international-travel-registration system, so the two don’t operate as disconnected, duplicative processes.
For the certification and deadline mechanics that sit above this policy-design question — which institutions are covered, and by when a program including this element has to be certified — see CASRAI’s NSPM-33 2026 deadline guide. For how this element fits alongside the other three, see the four-elements overview and research security training guide. For the term itself, see CASRAI’s NSPM-33 and research security policy dictionary entries.
Frequently Asked Questions
Does every international trip by a researcher need to be reported for research security purposes?
No. The NSPM-33 foreign travel security element is tied to federally funded research — travel connected to a federal award, not personal travel with no research nexus. Many institutions separately require all international travel to be registered for duty-of-care and insurance reasons, which is a different, broader requirement that happens to run alongside this one.
Is foreign travel security training required for all international travelers?
OSTP’s guidance calls for periodic training, at least once every six years, for covered individuals who travel internationally for organization business, teaching, conferences, or research — a broader population than the narrower group whose specific trips trigger the travel reporting program.
What counts as a “restricted destination” under NSPM-33?
NSPM-33 itself does not publish a single restricted-destination list. Institutions typically screen against several separate frameworks — OFAC’s comprehensively embargoed countries, the Commerce Department’s Consolidated Screening List of restricted and denied parties, and the CHIPS and Science Act’s statutorily designated countries of concern (China, Russia, North Korea, Iran) — each of which serves a different legal purpose.
Can a researcher bring their normal work laptop on a foreign research trip?
Institutional policies increasingly require a loaner or “clean” device for higher-risk destinations, particularly when the traveler’s normal device holds export-controlled technical data, unpublished research, or broad institutional system access. Carrying export-controlled technical data into certain countries can itself trigger export-control obligations distinct from the research-security reporting requirement.
What happens after a researcher returns from an international trip?
A complete policy requires a post-travel report covering any unsolicited offers or unusual requests received, any sign of device compromise, and confirmation the trip matched what was originally disclosed — reviewed by the office responsible for the program, with a defined escalation path if the report raises a genuine concern.







