Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

NSF Research Security Training Requirements

NSF’s research security training mandate under Notice 149: who must complete it, what modules satisfy it, and the Dec. 2, 2025 certification deadline.

NSF’s research security training requirement is one of four certification obligations that Important Notice No. 149 (“Updates to NSF Research Security Policies,” published June 30, 2025 and updated November 24, 2025) folded into every NSF proposal’s certification package, effective December 2, 2025. This page focuses specifically on the training requirement itself — who has to complete it, what it must cover, which courses satisfy it, and how completion is certified — distinct from the certification-and-award compliance picture (MFTRP, Confucius Institute contracts, Foreign Financial Disclosure Reporting) covered in the full Notice 149 breakdown linked above, and distinct from NIH’s and DOE’s parallel-but-separate requirements covered in the cross-agency research security training guide.

Who has to complete NSF’s research security training

The requirement applies to proposers and individuals identified as senior/key personnel on an NSF proposal. Each covered individual must have completed qualifying training within the 12 months prior to submission, and the institution’s Authorized Organizational Representative (AOR) must certify that compliance on the proposal’s Cover Sheet before it can be submitted. As with the comparable NIH and DOE requirements, the covered population is the people actually named on the proposal — not every member of a research team, and not personnel added to a project only after award.

What the training has to cover

NSF does not require a specific branded course; it requires that whatever training an individual completes address a defined set of content areas: cybersecurity, international collaboration, foreign interference, and the rules governing proper use of funds, disclosure, conflict of commitment, and conflict of interest. NSF ties this authority to Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. § 19234), the same statutory basis NIH and DOE cite for their own training notices — which is why the substantive content areas overlap heavily across agencies even though each agency’s notice, effective date, and certification mechanics are separate.

Training options that satisfy the requirement

Because NSF specifies required content rather than a single mandated vendor, institutions have real choice among qualifying courses:

  • The four government-wide research security training modules — developed jointly by NSF, NIH, DOE, and DOD as a shared baseline resource for awardee organizations across all four agencies.
  • The SECURE Center’s condensed training module — a shorter, consolidated version of the four-module set, developed with input from NSF, NIH, DOE, and DOD, and explicitly recognized by NSF, NIH, DOE, DOD, and USDA as satisfying each agency’s respective research-security training mandate. For an institution managing awards across more than one of these agencies, the SECURE Center module is generally the most efficient single option to standardize on.
  • CITI Program’s Research Security course series — delivered through the same platform many institutions already use for RCR, human-subjects, and biosafety training, which simplifies completion tracking since it lands in the same institutional reporting feed as other mandatory research training. See the CITI Program guide for how CITI’s course catalog and completion-tracking mechanics work generally.

Because acceptance can still vary in practice by how an institution’s research security or sponsored-programs office has vetted a given course, confirm with that office which specific training your institution has designated as compliant before assuming any general “research security” course automatically counts toward the NSF requirement.

Effective date and the certification window

The training requirement took effect December 2, 2025. NSF allowed a brief transition window — proposals submitted between December 2 and December 31, 2025 could still use the prior Biographical Sketch and Current and Pending Support forms — but that grace period has closed; the updated certification requirements now apply to every NSF proposal. Training completion has to fall within the 12 months prior to the proposal’s submission date, which makes it a rolling requirement rather than a one-time box to check: a completion that was current for a proposal submitted last year will not necessarily still be current for one submitted this year, and institutional tracking needs to flag upcoming expirations rather than record a single completed/not-completed status per person.

How completion is certified and tracked

NSF’s mechanism is AOR-level certification, not a document the researcher uploads with the proposal itself: the AOR certifies, on the proposal’s Cover Sheet, that every identified senior/key person has completed qualifying training within the required window. That makes a per-person training-completion date a submission-blocking data point for a sponsored-programs office — if the office cannot produce a current completion date for every senior/key person named on a proposal, the AOR cannot make that certification and the proposal cannot go out. In practice this means institutions need the same kind of expiration-tracking system sponsored-programs offices already run for effort certification or IRB renewal windows, applied to a 12-month research-security training clock for every actively-proposing senior/key person.

How this compares to NIH’s and DOE’s requirements

NSF’s training requirement is one of three agency-specific implementations of the same CHIPS and Science Act authority, and the three do not automatically satisfy each other:

  • NIH‘s requirement (NOT-OD-26-017) applies to applications with due dates on or after May 25, 2026 — about six months later than NSF’s. See NIH Research Security Training Requirements for the full mechanics.
  • DOE‘s requirement (PF 2025-04 / FAL 2025-02) has been enforced for proposals submitted on or after May 1, 2025 — earlier than NSF’s.
  • All three use a 12-month validity window tied to the submission date, and all three accept the SECURE Center’s condensed module as one qualifying option, which is the practical reason it functions as a de facto cross-agency baseline for institutions managing awards from more than one of these funders.

A completion accepted by one agency is not automatically accepted by another simply because the content overlaps — each notice defines its own covered population, effective date, and certification mechanism. See the cross-agency research security training guide for the full side-by-side comparison.

How this fits into NSF’s broader Notice 149 obligations

Training is one of four things Notice 149 requires an AOR to certify before an NSF proposal can be submitted. The other three — Malign Foreign Talent Recruitment Program (MFTRP) certification, the Confucius Institute contract certification, and annual Foreign Financial Disclosure Reporting (FFDR) — are separate obligations with their own effective dates and certification mechanics, not part of the training requirement itself. For the complete Notice 149 picture, including the MFTRP annual re-certification via Research.gov, the Confucius Institute waiver process, and the FFDR reporting cycle, see NSF Research Security: What Notice 149 Requires Proposers to Certify.

Frequently asked questions

Does NSF require a specific research security training course?

No. NSF specifies the content the training must cover — cybersecurity, international collaboration, foreign interference, and rules on proper use of funds, disclosure, conflict of commitment, and conflict of interest — rather than mandating a single vendor or platform. Institutions can choose from the four government-wide modules, the SECURE Center’s condensed module, CITI Program’s Research Security series, or another course an institution’s research security office has independently confirmed covers the required content.

When did NSF’s research security training requirement take effect?

December 2, 2025. A short transition window let proposals submitted December 2–31, 2025 still use the prior Biographical Sketch and Current and Pending Support forms; that window has closed.

Who at an institution has to complete the training?

Proposers and individuals identified as senior/key personnel on an NSF proposal — not every member of a research team. The Authorized Organizational Representative certifies compliance on the proposal’s Cover Sheet.

How long does a completed training stay valid?

12 months from completion, measured against the proposal’s submission date. A completion has to fall within that rolling window at the time of each new submission, not just once at hire or once per grant.

Does completing NSF’s training also satisfy NIH’s or DOE’s requirement?

Not automatically, though the SECURE Center’s condensed module is explicitly recognized by NSF, NIH, DOE, DOD, and USDA and functions as a practical cross-agency option. Confirm against each specific agency’s notice before assuming a completion transfers, since covered population, effective date, and certification mechanics still differ by agency.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →