The Research Collaboration Advice Team (RCAT) is the UK government’s dedicated advisory service for institutions navigating national-security risk in international research collaborations. It is easy to conflate RCAT with the Trusted Research framework because the two are closely linked and RCAT actively promotes Trusted Research uptake — but they are not the same thing. Trusted Research is a set of principles and guidance; RCAT is the operational body institutions actually contact for case-by-case advice. This guide covers what RCAT does, who staffs it, how institutions engage it, and exactly where the line between RCAT and Trusted Research sits.
What RCAT Is
RCAT is run by the UK Department for Science, Innovation and Technology (DSIT). It was established in 2021 to meet demand from the academic sector for clearer government advice on the changing research-security landscape, and its advisory service formally launched in March 2022. RCAT’s role is to provide UK research institutions with a confidential, trusted point of contact for navigating the ambiguities of internationalised research risk management — particularly cases involving potential state-linked interference, technology transfer risk, or attempts to circumvent export controls and sanctions through academic channels.
RCAT operates alongside, and refers institutions to, other parts of the UK’s research-security architecture, including the National Protective Security Authority (NPSA), the National Cyber Security Centre (NCSC), and UK Research and Innovation (UKRI) — the bodies that publish and maintain Trusted Research guidance and Trusted Research and Innovation materials. RCAT is the advisory front door; those other bodies are, among other things, the source of the underlying framework RCAT advises institutions to apply.
What RCAT Does
Per DSIT’s own description of the service and its published RCAT 2026 update report, RCAT’s work sits under three strategic priorities:
- Trusted advice on specific cases. RCAT advisers work directly with institutions on individual, case-by-case national-security concerns arising from a proposed or ongoing international research collaboration — for example, a partnership, visiting-researcher arrangement, or funding offer that raises questions about the partner’s affiliations, the sensitivity of the technology involved, or an underlying due-diligence gap.
- Building research-security culture. RCAT works with institutions to develop their understanding and application of Trusted Research principles — training, policy development support, and education on adversarial tactics and proportionate safeguards — rather than case advice alone.
- Sector intelligence. By aggregating (and anonymising) the issues raised across its caseload, RCAT builds a picture of emerging risks and reports that understanding back to both the sector and government, which in turn informs how Trusted Research guidance itself gets updated.
Advice most frequently sought, per the 2026 update, concerns technology areas including advanced materials, artificial intelligence, communications, synthetic biology, advanced robotics, and quantum technology — reflecting where research institutions currently see the most ambiguity about collaboration risk.
Staff, Structure, and Scale
As of the RCAT 2026 update, the team comprises 19 staff, including 13 advisers, based across Birmingham, Cardiff, Edinburgh, London, and Salford — a deliberately distributed footprint intended to put advisers within reach of institutions outside London and the South East. Since the service launched in March 2022, RCAT reports having engaged more than 155 research institutions, conducted over 3,800 individual engagements, and managed over 500 cases.
DSIT has published RCAT’s growth and impact in a series of corporate reports: an initial progress made from 2022 to 2023 report, and the RCAT 2026 update, published 20 March 2026, which is the current authoritative source for the figures in this guide.
How Institutions Engage RCAT
Engagement is voluntary and, per DSIT’s own account of its caseload, predominantly self-initiated: the majority of RCAT’s cases are raised by university contacts themselves, typically through an institution’s research office rather than by individual researchers approaching RCAT directly. RCAT describes the relationships it builds with institutional research offices as confidential and ongoing, rather than one-off transactions triggered only when a problem has already surfaced — institutions that engage early, before a partnership is finalised, get more useful advice than institutions that engage only after a concern has already materialised.
In practice, this means the natural entry point is an institution’s own research office, export control officer, or research-security lead making contact with RCAT (via the RCAT pages on GOV.UK) to discuss a specific proposed collaboration, partner organisation, or funding offer — not a standardised online intake form for individual academics. Institutions that have not yet engaged RCAT and are uncertain whether a specific case warrants it should treat “does this collaboration raise a national-security question we can’t confidently answer internally” as the practical trigger for making contact.
The 2025 Sector Maturity Survey
In summer 2025, RCAT surveyed institutions with existing RCAT engagement on their research-security maturity, building on a comparable survey it ran in 2023. The 2025 results, reported in the RCAT 2026 update, showed self-reported sector maturity improving since 2023: institutions reported increased confidence in handling research-security questions and more widespread development of formalised, written research-security policies, rather than ad hoc case-by-case handling. RCAT frames this as evidence that its case-advice and culture-building work are reinforcing each other — institutions that have been through the case-advice process appear more likely to subsequently formalise policy, which in turn is intended to reduce how often they need case-by-case advice for materially similar situations in future.
RCAT vs. Trusted Research: What’s the Actual Difference
The two terms get used almost interchangeably in casual conversation, but they describe different things, and the distinction matters for anyone deciding who to contact about what.
| Trusted Research framework | RCAT | |
|---|---|---|
| What it is | A set of principles and published guidance on proportionate, risk-based research-security decision-making | An operational advisory team within DSIT that institutions contact directly |
| Who owns/runs it | Guidance developed with NPSA and UKRI | DSIT (Department for Science, Innovation and Technology) |
| What it produces | Published guidance documents, principles, and due-diligence checklists an institution applies itself | Individualised, case-specific advice from a named adviser, plus training and sector reporting |
| When you’d use it | Designing or reviewing an institution’s own research-security policy against a recognised standard | You have a specific collaboration, partner, or funding offer and need advice on that particular case |
| Relationship | RCAT actively promotes and helps institutions operationalise Trusted Research principles — “building research-security culture” is one of RCAT’s three strategic priorities — but RCAT is the advisory mechanism, not the framework itself. | |
A useful shorthand: Trusted Research answers “what should our policy say,” while RCAT answers “what should we do about this specific collaboration.” Institutions typically need both — a written policy grounded in Trusted Research principles, and a working relationship with RCAT for the cases that policy alone can’t resolve. This guide should be read alongside CASRAI’s Trusted Research framework dictionary entry rather than in place of it; the two pages cover different layers of the same UK research-security landscape.
Note also that RCAT is distinct from a Trusted Research Environment (TRE), a term that despite the similar name refers to something unrelated: a secure, “bring the analysis to the data” technical environment for controlled access to sensitive datasets (health records, for example), not a national-security advisory service. The shared word “trusted” is a frequent source of confusion between three genuinely distinct things — the Trusted Research framework, RCAT, and Trusted Research Environments — and institutions should be precise about which one they mean.
How RCAT Fits with NSPM-33 and Export Control Compliance
RCAT is a UK-specific mechanism, but institutions with US collaborations or federal funding will recognise the underlying problem from the US side: NSPM-33’s research security program requirements impose a broadly analogous set of foreign-influence disclosure and risk-management obligations on covered US institutions, and export control regimes such as EAR and ITAR raise comparable case-by-case questions about specific international collaborations and deemed exports. UK institutions with US partners, or US institutions with UK partners, may find both frameworks relevant to the same underlying collaboration, and should not assume compliance with one satisfies the other.
Frequently Asked Questions
Is engaging RCAT mandatory?
No. Engagement with RCAT is voluntary. It is not a statutory approval body, and contacting RCAT is not a legal precondition for entering an international research collaboration. It is a resource institutions choose to use, most often through their research office, to get advice on a specific case.
Who at an institution should contact RCAT?
Per DSIT’s own description of its caseload, most cases are raised by university contacts — in practice this is typically a research office, research-security lead, or export control officer, rather than an individual researcher approaching RCAT independently about their own project.
Does RCAT replace the need for a written research-security policy?
No. RCAT’s own stated priorities distinguish case-by-case advice from the separate goal of helping institutions build formalised research-security policy grounded in Trusted Research principles. RCAT’s 2025 survey findings link stronger institutional maturity to having formalised policies, not to case-by-case advice alone.
Is RCAT only relevant to certain research areas?
RCAT will advise on any collaboration raising a national-security question, but its published 2026 update notes that advice is most frequently sought on advanced materials, artificial intelligence, communications, synthetic biology, advanced robotics, and quantum technology — areas widely recognised as higher-sensitivity dual-use technology domains.
How is RCAT different from an export control office?
An institution’s export control function typically administers compliance with specific statutory regimes (in the UK, for example, strategic export controls and sanctions law). RCAT’s remit is broader and advisory rather than compliance-administrative: it covers national-security risk in collaborations generally, including cases that may not trigger a formal export-control licensing requirement at all but still warrant a risk assessment.
Sources
- DSIT, Research Collaboration Advice Team (RCAT) 2026 update, GOV.UK, published 20 March 2026.
- DSIT, Research Collaboration Advice Team (organisation page), GOV.UK.
- DSIT, Research Collaboration Advice Team: progress made from 2022 to 2023, GOV.UK corporate report.







