Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

NSPM-33 Research Security Program Requirements: The Four Mandated Elements

What NSPM-33’s four required research security program elements (cybersecurity, foreign travel security, training, export control) actually require institutions to build and operate.

TL;DR: Institutions that trigger National Security Presidential Memorandum-33’s (NSPM-33) research security program requirement must operate a program covering four mandated elements: cybersecurity, foreign travel security, research security training, and export control training. Each element is a distinct operational build, not a single policy document — this guide walks through what each one actually requires an institution to have in place, day to day, separate from the certification deadline mechanics covered in our companion piece on the real 2026 RSP deadline.

Where This Requirement Comes From

NSPM-33, signed in January 2021, directed the White House Office of Science and Technology Policy (OSTP) to coordinate a government-wide approach to research security. OSTP’s July 9, 2024 “Research Security Programs Standard Requirement” guidance is the document that actually specifies the four elements covered on this page. It applies to any institution of higher education, national laboratory, federally funded research and development center, or nonprofit research institution that receives more than $50 million per year in federal science and engineering support, measured across the two most recently completed fiscal years. Below that threshold, an institution isn’t exempt from research-security obligations generally — export control law, foreign-component disclosure, and agency-specific personnel training mandates still apply — but the standalone, four-element research security program (RSP) requirement is specifically triggered by the $50 million figure.

For the certification timeline itself — why there is no single universal “July 2026” date, and how each funding agency’s own effective date sets an institution’s actual 18-month certification clock — see NSPM-33 Research Security Programs: The Real 2026 Deadline, and DoD’s January Memo. This page assumes an institution already knows it is covered and focuses on what “operational” actually means for each of the four required elements.

What “Operational” Means, Before Getting Into Each Element

OSTP’s guidance is explicit that a compliant program has these four elements functioning, not merely documented. In practice, reviewers and an institution’s own certifying officials tend to look for the same three things under each element: a written policy or procedure, a named office or role with actual responsibility for running it, and evidence the process gets used — logs, records, completed reviews, tracked exceptions — rather than a policy that exists only on paper. A program that has four well-written policy documents and no evidence any of the four processes has actually been used by a real case is not “operational” in the sense OSTP’s guidance means, and an institution’s certification is a representation made directly to the federal government about that operational status — see the False Claims Act exposure discussion in the companion deadline piece linked above.

Element 1: Cybersecurity

The cybersecurity element requires safeguards for federally funded research data and the systems that store or process it, consistent with the institution’s broader information-security posture — OSTP’s guidance does not hand institutions a brand-new, research-security-specific cybersecurity standard to build from scratch; it requires that federally funded research be brought inside whatever information-security controls the institution already runs, and that those controls actually extend to research systems specifically, which is where gaps commonly show up (a research lab running its own file server outside central IT’s management, for instance, is a common practical failure point). For institutions that also hold Department of Defense contracts involving controlled unclassified information, this element overlaps with — but is not the same obligation as — Cybersecurity Maturity Model Certification (CMMC); see CMMC Compliance for Universities for how that separate, contract-driven requirement works. Operationally, this element typically means: an inventory of which systems and data stores hold federally funded research information, defined access controls and incident-reporting procedures for those systems, and a documented line of responsibility between the research security program and the institution’s central information-security office (rather than the two operating as unconnected silos).

Element 2: Foreign Travel Security

This element requires a process for covered individuals to report foreign travel connected to their federally funded research, plus a mechanism to flag higher-risk travel for additional review. Operationally, institutions generally need: a defined reporting requirement (who has to report, what trips count as “connected to” federally funded research, and how far in advance), a review step that screens reported travel against known higher-risk factors — destination, purpose, any overlap with export-controlled technology the traveler works with — and a record of what was reported and reviewed, since the evidence-of-use standard above applies here too. This is a narrower, funding-tied obligation than a university’s general international-travel-registration policy (many institutions already register all international travel for duty-of-care and insurance reasons); the research-security foreign-travel element specifically needs to interface with that broader system rather than duplicate it, so that federally funded travelers are captured and reviewed under this element even when the general travel-registration system exists for unrelated reasons.

Element 3: Research Security Training

The training element requires institution-wide training addressing research security risks, insider-threat awareness, and reporting channels. This is the institutional program element of the four — it is a distinct obligation from the individual, per-proposal training-certification mandates that NSF, NIH, DOE, and other agencies have separately layered on under CHIPS and Science Act Section 10634 (42 U.S.C. § 19234), which require a named senior/key person to complete specific training within a rolling window before an agency will accept their proposal. Those personnel-level requirements are covered in depth in Research Security Training: What It Is and Which Agencies Require It and, for NSF specifically, NSF Research Security Training Requirements. An institution can satisfy this RSP element’s training component and still have individual senior/key personnel with lapsed NSF or NIH training certifications, and vice versa — the two are tracked, and certified, on separate systems, even though a single training platform (many institutions use the same CITI Program deployment for both) can deliver the content for each.

Operationally, the RSP training element typically means training reaches beyond the narrower senior/key-personnel population the agency-specific mandates cover — closer to everyone with meaningful exposure to federally funded research, including staff who handle sensitive data or materials but aren’t named on a proposal — and that the institution can show completion records and content coverage as evidence, not just a completion percentage.

Element 4: Export Control Training and Integration

The fourth element requires institutional awareness of, and compliance processes for, the export-control obligations — the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR) — that intersect with the institution’s federally funded research portfolio. Export control is its own long-established compliance area with its own licensing, technology-control-plan, and deemed-export mechanics; what this RSP element specifically requires is that the research security program integrate with — not duplicate or bypass — an institution’s existing export control office and processes. See ITAR US Munitions List: What It Is and How It Applies to University Research and Embargoed Countries List for Export Control for the underlying regulatory mechanics, and Export Control Reform and Research Security for how export control policy has been evolving alongside the broader research-security push. Operationally, integration typically means: export control screening is a standard step when federally funded research involves controlled technology, foreign national researchers, or international collaborators; export control training is required for personnel working in export-controlled research areas; and the export control office and the research security program office share information rather than running fully separate review processes that could each miss what the other catches.

How the Four Elements Fit Into an Institution’s Broader Research-Security Posture

None of these four elements exists in isolation from an institution’s other federal research-security obligations. The disclosure requirements NSPM-33 also drives — current and pending support, biographical sketch, and conflict-of-commitment disclosures — are a separate but related obligation, covered in NSPM-33 disclosure: what US researchers must report in 2026. The Malign Foreign Talent Recruitment Program (MFTRP) prohibition and certification is a separate obligation several agencies have layered onto individual proposals. And for institutions with significant Department of Defense funding, the four RSP elements run alongside DoD’s own January 2026 standardization memo and the 2026 Component Decision Matrix, which govern DoD-specific risk review rather than the government-wide RSP requirement. The broader policy backdrop driving all of this — including the foreign-talent-recruitment concerns behind the training and travel elements specifically — is covered in US-China Research Collaboration: Research Security and Compliance Concerns and Thousand Talents Program and Research Security.

A research security office building out all four elements typically ends up coordinating across several existing institutional functions that predate NSPM-33 — central IT/information security (cybersecurity), international travel/risk management (foreign travel security), the training-compliance office that already runs RCR and human-subjects training (research security training), and export control (export control training and integration) — rather than standing up four entirely new functions from scratch. The RSP requirement’s real administrative work is often less about inventing new capability and more about formalizing the connections between programs that already exist, documenting them, and making sure each one actually covers federally funded research specifically.

Practical Checklist for Building Out Each Element

  • Cybersecurity: Confirm central IT’s controls actually extend to every system and data store touching federally funded research; document the connection between the research security office and information security.
  • Foreign travel security: Define what travel counts as “connected to” federally funded research, set a reporting deadline ahead of travel, and build a review step for higher-risk trips — don’t assume a general university travel-registration system alone satisfies this without a research-security-specific review layer.
  • Research security training: Extend training beyond the narrower agency-specific senior/key-personnel population to reach the broader group with federally funded research exposure, and keep completion records as certifiable evidence.
  • Export control training and integration: Make export control screening a standard step for federally funded projects involving controlled technology or foreign nationals, and make sure the export control office and research security office actually share information.
  • Across all four: Keep documentation — policy, assigned responsibility, and usage evidence — for each element, since certification represents that the program is operational, not merely drafted.

Frequently Asked Questions

Are all four RSP elements new requirements institutions have to build from nothing?

Not usually. Most covered institutions already have some version of cybersecurity controls, international travel registration, compliance training infrastructure, and an export control office. The RSP requirement is largely about formalizing, documenting, and connecting those existing functions specifically to federally funded research, and showing evidence each one is actually operating — not standing up four brand-new offices.

Is the research security training element the same as NSF’s or NIH’s training-certification requirement?

No. The RSP training element is an institution-wide program requirement under NSPM-33’s $50 million-threshold RSP obligation. NSF’s, NIH’s, and DOE’s training mandates are separate, narrower requirements tied to individual senior/key personnel named on a specific proposal, under CHIPS and Science Act Section 10634. An institution tracks and certifies these separately; satisfying one does not automatically satisfy the other. See Research Security Training: What It Is and Which Agencies Require It.

Does the export control element replace an institution’s existing export control office?

No. OSTP’s guidance requires the research security program to integrate with export control processes and provide export control training where relevant — it does not replace ITAR/EAR compliance obligations or an institution’s existing export control function, which continues to operate under its own licensing and technology-control-plan requirements.

What evidence does an institution need to certify these elements as “operational”?

Generally a written policy or procedure for each element, a named office or role responsible for running it, and records showing the process has actually been used — completion logs, travel reviews conducted, export control screenings performed — rather than policy documents alone.

Where can I find the certification deadline for my institution?

There is no single universal date. Each federal funding agency set its own RSP-policy effective date, and covered institutions get up to 18 months from that agency’s effective date to implement and certify. See NSPM-33 Research Security Programs: The Real 2026 Deadline, and DoD’s January Memo for the full timeline mechanics.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →