Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

NIH Research Security Training Requirements

A deep-dive reference on NIH’s research security training (RST) requirement: the governing NOT-OD-26-017 notice, the May 25, 2026 effective date, accepted training options, and how completion is certified and tracked.

NIH’s research security training (RST) requirement is a distinct, narrower obligation from the broader senior/key-personnel training picture covered in NIH Senior/Key Personnel Training Requirements (which also covers RCR, FCOI, and mentoring plans) — this page is a deeper reference specifically on RST: the governing notice, the effective date, what the training must cover, which training options satisfy it, and how completion is certified and tracked. NIH’s RST requirement implements Section 10634 of the CHIPS and Science Act of 2022 and aligns with the government-wide research-security push under NSPM-33 — it runs parallel to, but is legally and administratively separate from, NSF’s own research-security training certification requirement under NSF Important Notice No. 149.

Governing notice and effective date

NIH’s RST requirement is set out in Guide notice NOT-OD-26-017, “Research Security Training Requirements for NIH,” issued in early April 2026. It applies to NIH applications with due dates on or after May 25, 2026 — for those applications, every individual listed as senior/key personnel must have completed RST within the 12 months prior to submission. Training completed before that window, or completed but not current at the time of submission, does not satisfy the requirement.

NOT-OD-26-017 is separate from, and should not be confused with, an earlier and narrower NIH notice — NOT-OD-25-133, effective October 1, 2025 — which governs how covered individuals correctly complete Other Support and biosketch disclosures. That earlier notice addresses disclosure formatting and accuracy; RST addresses training and awareness content. Institutions sometimes conflate the two because both flow from the same underlying research-security push and both touch the biosketch/SciENcv workflow — they are administered as two distinct compliance obligations with two distinct notice numbers.

Who is covered

The requirement applies to every individual named as senior/key personnel on an NIH grant application — the Program Director/Principal Investigator and any co-investigator or other named scientist who contributes substantively, measurably, to the project’s scientific development or execution. It does not, by itself, extend to personnel who are not senior/key personnel on the specific application (for example, postdoctoral associates or graduate students classified as trainees or other significant contributors), though those individuals may separately be subject to RCR training obligations tied to a training or career-development mechanism — see the senior/key personnel training guide for how the covered populations for RST, RCR, and FCOI differ.

What the training must cover

NIH has not published its own standalone RST curriculum; instead it points to the same government-wide research-security training content model that NSF, DOE, USDA, and NASA have each stood up for their funded populations under the same CHIPS Act authority. The required content addresses:

  • Cybersecurity awareness relevant to a research setting.
  • Foreign interference risk and Malign Foreign Talent Recruitment Program (MFTRP) awareness — see Malign Foreign Talent Recruitment Program (MFTRP).
  • Proper disclosure of foreign support, affiliations, and financial relationships — see Undue foreign influence.
  • Conflict-of-commitment and conflict-of-interest obligations connected to foreign or outside activities.
  • Proper use of federal funds and general research-security transparency expectations.

Training options that satisfy the requirement

NIH does not mandate a single training vendor or platform — it recognizes completion of any training that covers the required content areas, consistent with the approach DOE and other agencies have taken for their own parallel requirements. In practice, covered individuals typically complete one of a small number of established options:

  • NSF’s Research Security Training modules — a set of four online modules originally developed by NSF in partnership with NIH, DOE, and DOD, freely available and widely accepted as satisfying the content requirements of the parallel agency mandates.
  • The SECURE Center’s consolidated training module — a shorter, roughly one-hour version built from the same underlying NSF/NIH/DOE/DOD content, offered by the NSF-funded SECURE (Safeguarding the Entire Community of the U.S. Research Ecosystem) Center as a faster path to the same coverage.
  • CITI Program’s Research Security course series — CITI offers both the full NSF-derived modules and the SECURE Center’s condensed version through its existing institutional subscription, which is convenient for institutions that already run RCR, COI, and human-subjects training through CITI and want RST tracked in the same system.

Because NIH accepts any of these routes, the practical decision for a research-administration office is less “which training is compliant” and more “which one integrates cleanly with our existing training-tracking system” — an institution already using CITI for other mandates will usually find it simplest to also assign RST there, while an institution without an existing training platform may prefer the free, direct NSF or SECURE Center modules.

Certification and institutional tracking mechanics

RST completion is documented in two layers:

  • Individual certification — reported guidance describes the individual’s completion being certified through their biographical sketch in SciENcv, so the certification travels with the biosketch rather than being a separate uploaded document.
  • Institutional certification — the Authorized Organization Representative (AOR) additionally certifies, on the application’s signed face page, that every senior/key person named on that application has met the requirement as of submission.

Because the certification is tied to a rolling 12-month validity window rather than a one-time completion, a research-administration office cannot simply confirm training was completed once and stop tracking it. The practical tracking burden looks like the FCOI four-year-renewal problem, compressed to a one-year cycle: institutions need a system that flags, for each senior/key person on an active or pending application, when their most recent RST completion will lapse relative to the next likely submission date, not only whether they have ever completed it. Sponsored-programs offices that already track FCOI and RCR renewal dates in a research-administration system or spreadsheet typically add RST as an additional tracked credential with its own (shorter) renewal clock, rather than building a separate parallel system.

How RST fits with NIH’s other training and disclosure obligations

RST is one of several distinct compliance obligations that can apply to the same person on the same NIH application, and institutions should not assume that meeting one satisfies another:

  • Other Support disclosure training (NOT-OD-25-133, effective October 1, 2025) — addresses how to correctly complete Other Support and biosketch disclosures; does not by itself satisfy RST.
  • RCR training — required only for individuals supported by specific NIH training and career-development mechanisms (T, F, K, R25, D43/D71); unrelated in content and trigger to RST.
  • FCOI training under 42 CFR Part 50, Subpart F — a four-year-cycle institutional obligation for NIH “Investigators,” addressing financial conflicts specifically rather than research-security awareness broadly.

The full comparison of who is covered by each of these, including a role-by-role compliance checklist, is in NIH Senior/Key Personnel Training Requirements. For the broader foreign-influence and export/security compliance context RST sits within, see US-China Research Collaboration: Research Security and Compliance Concerns and Research Security.

Compliance timeline for research-administration offices

  • Now through May 24, 2026: RST is not yet a submission-blocking requirement for NIH applications, but institutions should begin enrolling senior/key personnel on pending and near-term applications so completions land inside the eventual 12-month validity window.
  • Applications due on or after May 25, 2026: every senior/key person named must have current (within 12 months) RST certified via SciENcv, and the AOR must certify compliance on the face page before submission.
  • Ongoing: track each senior/key person’s RST completion date against their likely next submission date the same way FCOI renewal is tracked, since a lapsed certification blocks submission the same way a missing one does.

Frequently asked questions

What is the exact NIH notice number for the research security training requirement?

NOT-OD-26-017, “Research Security Training Requirements for NIH.” Earlier notice numbers circulating in some secondary sources reflect the broader, fast-moving sequence of NIH research-security and Other Support policy notices issued through 2025 and early 2026; NOT-OD-26-017 is the notice that specifically governs the RST certification requirement described on this page. Confirm the live text at grants.nih.gov before a specific submission, since this policy area has been revised more than once already.

When does NIH’s research security training requirement take effect?

For NIH applications with due dates on or after May 25, 2026. Applications due before that date are not subject to the RST certification requirement.

Does NIH require a specific training vendor or course for RST?

No. NIH accepts training that covers the required content areas rather than mandating one platform. In practice, the NSF-developed Research Security Training modules, the SECURE Center’s condensed module built from the same content, and CITI Program’s Research Security series (which offers both) are the options institutions most commonly use.

Is NIH’s research security training the same as NSF’s?

They are separate agency requirements — NIH’s under NOT-OD-26-017, NSF’s under NSF Important Notice No. 149 — but both implement the same CHIPS and Science Act Section 10634 authority and both accept overlapping training content (the NSF-developed modules satisfy both agencies’ content expectations), so an individual who is senior/key personnel on both an NIH and an NSF award does not necessarily need to complete two different courses, only to certify separately to each agency.

How long is a completed RST certification valid?

12 months. Training must be current as of the application’s submission date, not merely completed at some point in the past.

How does an institution verify and track RST completion across its senior/key personnel?

There is no separate NIH-run tracking portal for institutions to query — verification runs through the individual’s SciENcv biosketch certification and the AOR’s face-page certification at submission. Research-administration offices generally need to track completion dates internally (in whatever system already tracks FCOI and RCR renewal dates) against each senior/key person’s likely next submission date, since the 12-month validity window means a completion can lapse between one application and the next.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →