Research security training is a category of mandatory federal training, distinct from Responsible Conduct of Research (RCR) or human-subjects training, aimed at helping researchers and institutions recognize and respond to foreign-interference, undisclosed-support, and information-security risks in federally funded research. It has become a real compliance obligation only recently: the CHIPS and Science Act of 2022 (Section 10634, 42 U.S.C. 19234) directed federal research agencies to require training as a condition of funding, building on the disclosure framework set out in National Security Presidential Memorandum 33 (NSPM-33). As of mid-2026, NIH, NSF, and DOE have each issued their own implementing notice with its own effective date, covered population, and accepted training options — this page explains the requirement category as a whole and how the agency-specific versions relate to each other; for the full mechanics of a specific agency’s requirement, see the dedicated NIH guide linked below.
What research security training covers
Across agencies, the substantive content is broadly consistent, even though the governing notices and enforcement mechanics differ. Typical modules address:
- Foreign interference and talent-recruitment program risk — recognizing recruitment attempts, undisclosed foreign affiliations, and the Malign Foreign Talent Recruitment Program (MFTRP) prohibition that several agencies now require researchers to certify against.
- Disclosure obligations — correctly completing Current and Pending (Other) Support, biographical sketch, and foreign-component disclosures, since a training requirement and a disclosure requirement are frequently paired in the same agency notice.
- Cybersecurity awareness — basic protection of research data, systems, and controlled information from unauthorized access or exfiltration.
- Conflict of commitment and conflict of interest — distinguishing an undisclosed outside commitment (time, resources, intellectual property) from a financial conflict of interest, and understanding when each must be reported.
- Where applicable, export control and international-travel awareness — DOE’s version, for example, explicitly folds in international-collaboration and travel risk alongside the core modules above.
This is a narrower, newer obligation than Responsible Conduct of Research (RCR) training, which covers research ethics topics like authorship, data management, and mentoring, and it is not a substitute for it — institutions generally track the two as separate requirements even when the same training platform (most commonly the CITI Program) delivers both.
Which federal agencies currently require it
The CHIPS and Science Act’s Section 10634 authority applies government-wide, but each agency has rolled out its own notice on its own timeline rather than a single uniform federal rule. As of mid-2026:
- NIH — governed by Guide notice NOT-OD-26-017, “Research Security Training Requirements for NIH,” applying to applications with due dates on or after May 25, 2026. Every individual listed as senior/key personnel must complete training within the 12 months prior to submission. See NIH Research Security Training Requirements for the full mechanics, including how NOT-OD-26-017 differs from the earlier, narrower NOT-OD-25-133 Other Support Disclosure training requirement, and how it relates to the rest of NIH’s senior/key-personnel training picture (RCR, FCOI, mentoring plans) covered in NIH Senior/Key Personnel Training Requirements.
- NSF — governed by NSF Important Notice No. 149, “Updates to NSF Research Security Policies” (dated June 30, 2025, updated November 24, 2025), which bundles the MFTRP prohibition and certification, a research security training requirement, foreign financial disclosure, and Confucius Institute certification into one policy update. NSF does not mandate a single vendor; it accepts a defined set of training modules covering the same core content areas.
- DOE — governed by Policy Flash PF 2025-04 / Financial Assistance Letter FAL 2025-02, “Research Security Training Requirements for all R&D Financial Assistance Awards,” dated October 7, 2024. Covered individuals listed on a DOE R&D financial-assistance application must complete training within 12 months prior to submission; secondary university research-office guidance describes enforcement beginning for proposals submitted on or after May 1, 2025. The applicant organization certifies completion as part of its Current and Pending Support disclosure certification.
Other federal research agencies are expected to issue their own implementing notices under the same Section 10634 / NSPM-33 authority as their research-security programs mature — check the specific agency’s own guide or grants policy statement rather than assuming a requirement that applies to NIH, NSF, or DOE automatically extends to a different funder.
Who has to complete it
The covered population is narrower than “everyone who touches federally funded research” at every agency that has implemented this so far — it is generally the individuals actually named on the application or award, not the full research team. NIH’s requirement covers senior/key personnel specifically; DOE’s covers individuals listed on the R&D financial-assistance application; NSF’s applies to the personnel subject to its MFTRP certification and disclosure obligations. Institutions with active NIH, NSF, and DOE portfolios should not assume a single completed course satisfies all three agencies automatically — while the content overlaps substantially, each agency’s notice defines its own covered population, validity window, and certification mechanism, and a completion has to be current and mapped to the right requirement at the time of submission.
Training options that satisfy the requirement
Institutions generally have a choice of accepted training rather than a single mandated course, though the accepted list differs by agency notice:
- SECURE Center Consolidated Training Module — a free, roughly one-hour module built collaboratively with NSF, NIH, DOE, and DoD input, positioned as a cross-agency baseline option. DOE recognizes it as one compliant option without mandating it; it is also accepted toward NIH’s requirement.
- CITI Program’s Research Security course series — delivered through the same platform many institutions already use for RCR, human-subjects, and biosafety training, which simplifies tracking since completions land in the same institutional reporting feed. See the CITI Program guide for how CITI’s course catalog and completion-tracking mechanics work generally.
- Agency-specific modules — NSF, for example, has published its own set of training modules that independently satisfy its Notice 149 requirement.
Because acceptance varies by agency and by notice, the safest practice is to confirm which specific course(s) an institution’s research security or sponsored-programs office has designated as compliant for each funder, rather than assuming any general “research security” course automatically counts.
How completion is certified and tracked
The certification mechanics generally involve two layers: the individual attests to having completed current training (commonly reported through a biographical sketch tool such as SciENcv), and the institution’s Authorized Organizational Representative (AOR) certifies compliance as part of the application’s signed face page or Current and Pending Support disclosure. Because the requirement is tied to a rolling validity window (12 months for both NIH and DOE) rather than a one-time completion, institutional research-administration or research-security offices typically need a tracking system that flags upcoming expirations well before a covered individual’s next submission deadline, not just a static completed/not-completed record.
How this fits with an institution’s broader research-security posture
Research security training is one piece of a wider compliance picture that most research-intensive institutions are building out under NSPM-33 and the CHIPS and Science Act, alongside foreign-component and other-support disclosure, Malign Foreign Talent Recruitment Program screening, export-control review, and — for institutions handling controlled unclassified information — Cybersecurity Maturity Model Certification (CMMC) requirements on the federal-contracting side. Related CASRAI pages cover these adjacent obligations in more depth:
- NSPM-33 — the presidential memorandum establishing the government-wide research-security disclosure baseline this training requirement builds on.
- Research security policy — what an institutional research security policy typically covers.
- Malign Foreign Talent Recruitment Program (MFTRP) — the prohibition and certification obligation frequently paired with training requirements.
- US-China Research Collaboration: Research Security and Compliance Concerns — the broader policy context driving this requirement category.
- Export Control Reform and Research Security — the adjacent export-control compliance obligations.
- Foreign component disclosure and Conflict of Commitment (COC) — the disclosure concepts research security training is designed to make researchers aware of.
- CMMC Compliance for Universities — the parallel cybersecurity-certification obligation on the federal-contracting side.
Frequently asked questions
Is research security training the same at every federal agency?
No. The content areas overlap substantially — foreign interference, disclosure, cybersecurity, conflict of commitment — but each agency (NIH, NSF, DOE, and others as they roll out their own notices) sets its own effective date, covered population, validity period, and list of accepted courses under its own implementing notice. A completion accepted by one agency is not automatically accepted by another.
Is research security training the same as Responsible Conduct of Research (RCR) training?
No. RCR training addresses research ethics broadly (authorship, data management, mentoring, peer review) and has existed as an NIH and NSF requirement for specific trainee populations for years. Research security training is a newer, narrower requirement focused on foreign-interference, disclosure, and information-security risks, implementing the CHIPS and Science Act of 2022 and NSPM-33. Institutions generally track the two separately even when the same platform delivers both.
Who typically has to complete research security training?
Generally the individuals actually named on the application or award — senior/key personnel for NIH, the individuals listed on the application for DOE, and the personnel subject to certification and disclosure obligations for NSF — rather than every member of a research team.
Does one completed course satisfy every agency’s requirement?
Not automatically. Some courses, like the SECURE Center Consolidated Training Module, are explicitly recognized by more than one agency, but institutions should confirm which specific course an agency’s notice accepts before assuming a completion transfers across funders.
How long does a research security training completion remain valid?
Where a specific window has been published, it is commonly 12 months (NIH and DOE both use a 12-month validity period tied to the application submission date). Confirm the current window against the specific agency’s own notice, since this is an actively-revised policy area.







