Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

NIH Genomic Data Sharing Policy and Institutional Certification

Who signs the NIH Institutional Certification, what it attests, and how it gates dbGaP genomic data submission — with the full step-by-step workflow from IRB review through award and repository acceptance.

Ask about NIH Genomic Data Sharing Policy and Institutional Certification

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

The NIH Genomic Data Sharing (GDS) Policy requires investigators generating large-scale human or non-human genomic data with NIH funds to submit that data to an NIH-designated repository — most commonly dbGaP for human data. What actually gates that submission, in practice, is a single document: the Institutional Certification. This guide covers who signs it, what it attests, when it is due, and how it interacts with the NIH Data Management and Sharing (DMS) Plan submitted at application time.

Last verified 2026-08-16 against grants.nih.gov, “About Institutional Certifications” (NIH Office of Extramural Research), page last updated by NIH on August 5, 2025.

Institutional Certification at a glance

Question Answer
Who signs it The submitting Principal Investigator and the institution’s Signing Official (SO), after IRB review
Who else is involved The IRB (or privacy board/equivalent), which reviews consent adequacy before the SO signs
What it attests That the data-sharing plan is consistent with participants’ informed consent, applicable law, and the GDS Policy; states any data-use limitations; confirms participant identities won’t be disclosed to the repository
When it’s submitted (extramural) As part of the Just-in-Time (JIT) process — required before the award can be issued
When it’s submitted (NIH intramural) At the time of scientific review
When it’s submitted (non-NIH-funded studies) By the submitting institution’s SO, after the project is sponsored by an NIH Institute or Center for dbGaP submission
What it gates Award issuance (extramural) and acceptance of the dataset into dbGaP or another NIH-designated repository
Multi-site studies Either each site submits its own certification, or one site certifies on behalf of all contributing sites

Who has to submit an Institutional Certification

The requirement applies to any NIH-funded (or NIH-sponsored, for non-NIH-funded studies) project that will generate large-scale human genomic data covered by the GDS Policy — genome-wide association studies, whole-genome or whole-exome sequencing, transcriptomic, epigenomic, and other large-scale omics data with linked phenotype information. It is a study-level requirement tied to the specific dataset being submitted, not a one-time institutional registration: a new certification is needed for each dataset submission unless it is explicitly covered by an existing one.

What an Institutional Certification actually attests

By signing, the institution (via its SO) and its IRB or equivalent body assure NIH of two separate sets of things:

The institution certifies that:

  • The study submission is consistent with relevant local, state, federal, Tribal, and/or institutional laws and policies.
  • Any data-use limitations that apply to secondary research use of the data are stated in the certification.
  • Participants’ identities will not be disclosed to the NIH-designated data repository.

The IRB (or equivalent) certifies that:

  • The data collection protocol appropriately protects research participants.
  • Submission and sharing of the data are consistent with the informed consent participants actually gave.
  • The risks associated with sharing genomic data broadly have been considered.

The full, current list of assurances is on the Institutional Certification form itself, linked from the grants.nih.gov certification page — treat the form as the authoritative text if there is ever a discrepancy with a summary (including this one).

Who signs it, and who is allowed to

The submitting PI and the institution’s Signing Official (SO) must both sign, after IRB review. The SO is a senior official credentialed through NIH eRA Commons and authorized to enter the institution into a legally binding contract — the same role that signs off on grant applications in eRA Commons/ASSIST generally, not a role created specifically for genomic data. For an NIH intramural project, the SO is the funding Institute or Center’s scientific director or their designee. Questions about who qualifies as SO for GDS Policy purposes go to NIH’s GDS Policy staff, not the general eRA help desk.

The submission workflow, step by step

  1. Anticipate genomic data sharing in the DMS Plan. At the time of application, applicants describe anticipated genomic data generation and sharing in their Data Management and Sharing Plan. This is a forecast, not the certification itself.
  2. IRB review. Before the SO signs, the IRB (or privacy board/equivalent) reviews whether the Institutional Certification accurately reflects the terms of participants’ informed consent, and whether the consent process was adequate for generating and broadly sharing the data for secondary research use, consistent with the GDS Policy. NIH publishes “Points to Consider for Institutions and IRBs” specifically to guide this review.
  3. PI and SO sign the certification. Once the IRB is satisfied, the PI and SO both sign the completed Institutional Certification form.
  4. Submission to the funding IC. For extramural awards, the SO provides the certification to the program officer at the funding NIH Institute or Center as part of the Just-in-Time (JIT) process; it (or a provisional version) must be accepted before the award is issued. For NIH intramural projects, it’s submitted at the time of scientific review. Non-NIH-funded studies route through the sponsoring IC’s Genomic Program Administrator (GPA) instead.
  5. Reconcile with the DMS Plan. If the signed certification reflects more current or different information than the DMS Plan submitted at application, the applicant should update the DMS Plan and contact the Program Officer — the two documents are expected to stay consistent.
  6. Data submission to dbGaP. Once the certification is accepted, the study team proceeds with the technical dbGaP submission (via the eRA-Commons-linked dbGaP Submission Portal). The certification is what NIH checks before a dataset is accepted into the repository, separate from the technical file-upload process itself.

How this gates dbGaP submission

The Institutional Certification is a precondition, not a formality that runs in parallel. dbGaP will not accept a large-scale human genomic dataset without an accepted certification behind it, because the certification is how NIH confirms the consent basis for controlled-access sharing exists and is documented before data ever reaches a Data Access Committee’s review queue. This is distinct from the researcher-level Data Access Request process that downstream users go through to request access to already-deposited controlled-access data.

Multi-site studies

For a multi-site project with samples collected at more than one institution, there are two accepted approaches: each contributing site submits its own Institutional Certification, or one site submits a single certification on behalf of all contributing sites. Either way, the submitting institution is assuring NIH — based on its own review or on assurance obtained from the other sites — that the certification’s expectations and conditions are met project-wide, not just at the submitting site.

Consent language: the January 25, 2015 line

For specimens or data collected, or cell lines created, on or after January 25, 2015 (the GDS Policy’s effective date), the informed consent form must state that genomic and phenotypic data may be used in future research and shared broadly through a controlled-access repository — this is required even when the resulting data will be de-identified. NIH’s separate guidance document, “Guidance on Consent for Future Research Use and Broad Sharing of Human Genomic and Phenotypic Data Subject to the NIH GDS Policy,” covers what NIH considers adequate consent language in more detail; it is the reference an IRB should be working from during its review, not a general human-subjects consent template.

GDS Plan vs. DMS Plan: how they relate

The Institutional Certification is not the same document as the Data Management and Sharing Plan, and it is not the same as the older Genomic Data Sharing Plan language some funding opportunity announcements still reference. In practice: the DMS Plan is submitted with the application and describes intended data management and sharing broadly (required for all NIH awards since 2023); the Institutional Certification is a narrower, later, IRB-gated document specific to large-scale human genomic data, required before award (extramural) or before dbGaP submission. See the site’s dedicated comparison of NIH Resource Sharing Plans vs. the DMS Plan for how these older and newer sharing-plan requirements sit alongside each other.

Common pitfalls

  • Treating the DMS Plan as sufficient. A DMS Plan that mentions genomic data sharing does not substitute for the Institutional Certification — extramural awards can be held at JIT stage until an accepted certification is on file.
  • Consent language gaps. Consent forms drafted without the broad-sharing/future-use language (required for specimens/data from January 25, 2015 onward) can force an IRB to determine the data isn’t eligible for unrestricted secondary use, which then has to be reflected as a data-use limitation on the certification — or blocks certification altogether.
  • Assuming one SO signature covers every future dataset. Certification is tied to the specific dataset/study submission, not a blanket institutional sign-off.
  • Multi-site ambiguity. Not deciding up front whether each site certifies separately or one site certifies for all can stall submission when sites have different consent language or IRB determinations.

Frequently asked questions

Does every NIH-funded genomics grant need an Institutional Certification?

Only awards that will generate large-scale human genomic data covered by the GDS Policy. A grant that uses existing, already-deposited genomic data (via a Data Access Request instead of generating new data) does not need one for that purpose.

Can a provisional Institutional Certification be used to get an award issued?

Yes — NIH’s own guidance notes that a provisional Institutional Certification, in some cases, can be accepted before the award is issued, with the complete certification following. Confirm the specific expectation with the funding IC’s Genomic Program Administrator, since this is handled case by case.

Who at NIH should certification questions go to?

NIH’s GDS Policy staff for general certification-process questions, or the Genomic Program Administrator (GPA) assigned to the funding Institute or Center for study-specific questions.

Does the Institutional Certification expire?

It is tied to the specific dataset submission rather than carrying an independent expiration date; changes to consent, data-use limitations, or study scope are the trigger for updating or re-certifying, not a fixed calendar interval.

Related CASRAI pages

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →