Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Horizon Europe Research Security: “As Open As Possible, As Closed As Necessary” and Sensitive-Technology Screening

How Horizon Europe balances its default open-science principle against mandatory security appraisal and sensitive-technology screening, and how that EU framework differs from US research-security regimes like NSPM-33.

Horizon Europe, the EU’s EUR 95.5 billion 2021-2027 research and innovation framework programme, is built on a default of openness: the “as open as possible, as closed as necessary” principle governs how project results and data are shared. But that same programme also runs a mandatory security screening process for every proposal, and can restrict which countries and organisations may even join a consortium when “Union strategic assets, interests, autonomy or security” are at stake. For research administrators managing Horizon Europe grants — especially those with non-EU partners — understanding how these two mechanisms fit together, and how they differ from the US research-security regime many international collaborators may already be navigating, is now a core part of grant management.

What “As Open As Possible, As Closed As Necessary” Actually Means

The phrase originates in the Open Research Data (ORD) Pilot, introduced under Horizon 2020 in 2016 to expand access to and reuse of data generated in EC-funded projects. It was framed from the outset as a balance, not an absolute: openness was the default, but the pilot explicitly built in the need to protect scientific information, intellectual property, commercialisation interests, privacy, and security. Horizon Europe carried that balancing principle forward as the baseline for its open science policy, applying it to both publications and research data.

In practice, the principle operates as a presumption with defined exceptions rather than a blanket mandate. Peer-reviewed publications arising from Horizon Europe funding are generally required to be made immediately open access with no embargo, under Article 39 of the Grant Agreement (see CASRAI’s guide to Horizon Europe Article 39). Research data, by contrast, follows the “as open as possible, as closed as necessary” standard directly: beneficiaries are expected to make data findable, accessible, interoperable, and reusable (FAIR) by default, but may keep specific datasets closed, or open them only under restricted access, where doing so is justified by legitimate interests. Recognised legitimate reasons include:

  • Protecting intellectual property or the beneficiary’s ability to commercially exploit results
  • Compliance with personal-data-protection obligations under the GDPR
  • Confidentiality obligations set out elsewhere in the Grant Agreement
  • Security concerns, including the sensitive-technology screening covered below
  • The core legitimate interests of the beneficiary more broadly

The practical implication for a Data Management Plan is that “closed” is not a default fallback — it has to be justified, dataset by dataset, against one of these grounds. CASRAI’s Horizon Europe FAIR Data Management Plan guide covers how that justification is documented in practice.

Sensitive-Technology Screening: The Security Appraisal Procedure

Separately from the open-science default, every Horizon Europe proposal is subject to a security appraisal procedure — the successor to the optional “security scrutiny” process used under Horizon 2020, now mandatory across the programme. The mechanics, as described in European Commission and National Contact Point guidance, work in layers:

  • Self-assessment for every proposal. All applicants complete a security issues self-assessment table as part of the standard application, flagging whether the project could involve security-sensitive materials, technologies, or findings.
  • A dedicated security section for known sensitive domains. Calls in security-sensitive areas — notably Cluster 3 (Civil Security for Society, coordinated with DG HOME) and Cluster 4’s Space topics — require applicants to complete an additional, more detailed security section in the application form itself.
  • Multi-stage review. The granting authority performs initial pre-screening; DG HOME conducts the screening phase; a security screening group carries out deeper analysis where flags are raised; and, in the scrutiny phase, nationally appointed security experts from Member States review proposals that warrant it.
  • A range of possible outcomes. For most proposals, appraisal ends at the self-assessment stage with no further action. Where concerns are identified, outcomes can include reclassifying specific deliverables as EU classified information (RESTREINT UE/EU RESTRICTED or, for threat assessments tied to specific actors, CONFIDENTIEL UE/EU CONFIDENTIAL), requiring appointment of a project security officer, establishing a security advisory board, imposing additional security training, or — rarely — declining to fund the proposal.

The European Commission’s guidance document on classification of information in Horizon Europe projects sets out the classification levels and handling rules in detail; institutions with a security officer or classified-information handling capability should route any project flagged during appraisal through that function early, not after the Grant Agreement is signed.

This is distinct from CASRAI’s general sensitive technology dictionary entry, which surveys how the US, UK, Canada, and Australia each maintain their own national sensitive-technology lists — Horizon Europe’s screening is the EU funding programme’s own internal appraisal mechanism, layered on top of (not a replacement for) any Member State’s separate national export-control or investment-screening law.

Eligibility Restrictions for Strategic Assets, Interests, and Security (Article 22)

Beyond appraisal of individual proposals, Regulation (EU) 2021/695 — the Horizon Europe framework regulation — gives the Commission two further tools to control participation in sensitive actions:

  • Article 22(5): for actions concerning the Union’s strategic assets, interests, autonomy, or security, work programmes may restrict participation to legal entities established in Member States, or in specific Associated Countries, and may exclude or restrict entities that are themselves controlled by a non-eligible country or entity — even if the applicant entity is legally established within the EU.
  • Article 22(6): work programmes covering these actions may add further eligibility conditions, such as restricting the type of legal entity that may participate, requiring participants to have a specific establishment location, or setting minimum or maximum numbers of participants from particular categories of country.

A related control applies after the project is running: under Article 40, the Commission can object to a beneficiary transferring ownership of, or granting an exclusive licence over, project results where doing so would be contrary to EU interests or inconsistent with the exploitation and dissemination obligations set out in the Grant Agreement.

For a consortium with international partners, the practical consequence is that eligibility is not settled purely by an entity’s country of establishment — ownership and control matter too, and a work programme’s Article 22 conditions have to be checked call-by-call rather than assumed to be uniform across Horizon Europe.

How This Compares to US Research-Security Requirements — Without Conflating the Two

Institutions running international consortia often have staff who are simultaneously handling US federal research-security obligations, and it’s worth being precise about how the two regimes differ rather than treating them as equivalents:

  • Different point of control. Horizon Europe’s security appraisal is a funding-programme-level screening mechanism applied by the European Commission (chiefly DG HOME) at the proposal and results-transfer stage. NSPM-33, the US National Security Presidential Memorandum underlying US federal research-security policy, instead mandates that federal agencies require standardised researcher disclosures and that institutions themselves stand up an institutional research security program with four defined elements — see CASRAI’s guide to the NSPM-33 program’s four mandated elements. It is an institution-level and individual-disclosure-level regime, not a per-proposal appraisal run by the funder.
  • Different unit of analysis. Horizon Europe’s Article 22 restrictions turn on the legal entity’s establishment and control; NSPM-33’s disclosure obligations turn substantially on the individual researcher — who qualifies as a “covered individual” and what affiliations, support, and travel they must disclose.
  • Export control is a separate regime again, in both jurisdictions. EAR/ITAR in the US, and the EU’s own Dual-Use Regulation (EU) 2021/821, are item- and technology-based controls that apply regardless of funding source or nationality of the researcher handling the technology — passing Horizon Europe’s security appraisal does not clear a separate export-control determination, any more than receiving a US federal grant clears an EAR/ITAR determination. CASRAI’s Four Pillars of Export Control Compliance guide covers the US side of that distinction.
  • Investment screening is narrower still. CFIUS in the US reviews foreign investment and acquisition transactions, not research grants or academic collaboration as such — it is not a meaningful analogue to either the Horizon Europe appraisal or NSPM-33, though EU Member States increasingly run their own foreign-direct-investment screening regimes in parallel to Horizon Europe’s own eligibility rules.

The takeaway for administrators: don’t assume that satisfying one country’s research-security paperwork discharges obligations under another’s. A US-based partner institution on a Horizon Europe grant still owes NSPM-33 disclosures to its own federal funders on its own federal awards; the Horizon Europe consortium’s security appraisal and Article 22 eligibility screening run on an entirely separate track administered by the Commission.

Practical Implications for Research Administrators

  • Complete the security self-assessment early, not at submission deadline. A “yes” answer that triggers Cluster 3/4’s dedicated security section, or a flag that routes into deeper DG HOME review, can affect proposal timelines — build this into the internal proposal-development schedule rather than treating it as a late-stage checkbox.
  • Screen consortium composition against Article 22 before finalising partners, particularly for calls explicitly tied to strategic autonomy or security. Country of establishment is necessary but not sufficient — check whether a prospective partner is controlled by an entity from a non-eligible country, since that can affect eligibility even for an EU-established legal entity.
  • Treat “as open as possible, as closed as necessary” as a documentation obligation, not a free pass to close data by default. Each dataset kept closed in the Data Management Plan needs a stated legitimate-interest justification (IP, GDPR, confidentiality, security, or core legitimate interest) — reviewers can and do query DMPs that close data without one.
  • Route any security-appraisal flag through your institution’s export-control or research-security office in parallel, not instead of, the Horizon Europe process. A project can clear the EU’s security appraisal and still trigger a separate national export-control determination for a non-EU partner receiving controlled technology or technical data — the two checks are not substitutes for each other.
  • Plan for classified-deliverable handling early if a flag is raised. RESTREINT UE/EU RESTRICTED or CONFIDENTIEL UE/EU CONFIDENTIAL classification carries real handling, storage, and personnel-clearance implications; institutions without existing classified-information infrastructure should identify this risk during proposal development, not after the Grant Agreement is signed.
  • Use your National Contact Point. NCPs can advise on how a specific call’s eligibility and security conditions apply to a proposed consortium — see CASRAI’s guide to Horizon Europe National Contact Points.

Frequently Asked Questions

Does “as open as possible, as closed as necessary” mean Horizon Europe data has to be open by default?

The presumption favours openness and FAIR data practices, but it is not unconditional — a beneficiary may keep specific data closed where justified by intellectual property, commercial exploitation, GDPR compliance, confidentiality obligations in the Grant Agreement, security, or other legitimate interests. The justification has to be documented in the project’s Data Management Plan.

Is Horizon Europe’s security appraisal the same as export control?

No. The security appraisal procedure is an internal Horizon Europe screening mechanism run by the European Commission at the proposal stage. Export control — the EU’s Dual-Use Regulation (EU) 2021/821, or EAR/ITAR for US-linked technology — is a separate, item-based legal regime that applies independently of whether a project received Horizon Europe funding.

Does passing Horizon Europe security screening satisfy US NSPM-33 obligations for a US partner institution?

No. NSPM-33 obligations attach to US institutions and individuals in connection with US federal funding and are administered by US federal agencies; they are unaffected by a separate EU funding programme’s own screening outcome. A US institution participating in a Horizon Europe consortium still meets its NSPM-33 disclosure and program obligations independently, on its own US-funded awards.

What happens if a Horizon Europe proposal is flagged during security appraisal?

Outcomes range widely: most proposals clear the self-assessment stage with no further action. Where concerns are identified, the Commission may require specific deliverables to be classified, require appointment of a project security officer, establish a security advisory board, or impose additional security training; declining to fund a proposal on security grounds is described in EC-adjacent guidance as a rare outcome.

Sources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →