“Responsible conduct of research” (RCR) is the umbrella term U.S. federal funders use for structured training in the ethical and professional standards expected of anyone conducting funded research — covering areas such as research misconduct, data management, authorship, peer review, mentoring, and conflicts of interest. It is sometimes shortened in search and in casual institutional usage to “research conduct,” but the two funders that actually mandate it — NIH and NSF — both use the fuller “responsible conduct of research” (NIH) or “responsible and ethical conduct of research,” RECR (NSF) phrasing in their own policy text, and the specific requirements differ meaningfully between them. This guide covers what each funder requires, what changed with NSF’s newer research-security training obligation, and — the part institutional research offices actually struggle with — how RCR completion gets tracked, verified, and reported once training has happened.
For the broader concept of maintaining research integrity across an institution, see the CASRAI Dictionary’s research integrity and research misconduct entries, and the Research integrity and misconduct domain.
NIH’s RCR training requirement
NIH’s requirement dates to a 2009 policy update (NOT-OD-10-019) and applies to all trainees, fellows, participants, and scholars receiving support through any NIH training award, individual or institutional career development award, research education grant, or dissertation research grant — in practice, the F, K, T, and R25 mechanisms. The requirement has three fixed components:
- At least eight contact hours of instruction.
- A genuine in-person or live-discussion component. NIH is explicit that online coursework alone does not satisfy the requirement — face-to-face discussion and active engagement between participants and faculty is expected to remain a core feature, though live video conferencing that supports real discussion can count.
- Recurring instruction — undertaken at least once during each career stage (e.g., graduate, postdoctoral, faculty), and no less frequently than once every four years.
Individual NIH institutes and centers (NIMH, NIAID, and others) publish their own implementation guidance on top of this baseline, so award recipients should check their specific funding institute’s requirements rather than assuming the government-wide minimum is the whole story.
NSF’s RECR training requirement
NSF’s requirement long predates NIH’s in one sense — a training plan for undergraduates, graduate students, and postdoctoral researchers supported on NSF awards has been required since the America COMPETES Act of 2007. What changed is scope: the CHIPS and Science Act of 2022 amended that authority (42 U.S.C. § 1862o-1) to extend the training requirement to faculty and other senior personnel as well, effective for proposals submitted or due on or after July 31, 2023. At the point of proposal submission, the submitting institution must certify it has an RECR education plan covering everyone named, including senior personnel.
The CHIPS Act also expanded required training content beyond the traditional RCR topics to include mentorship and mentoring training, and — separately from the training-content change — introduced research-security-related obligations discussed below. Unlike NIH, NSF does not require an in-person component: online training, including the CITI Program’s RCR/RECR modules, is accepted as sufficient on its own, provided it covers the required subject matter.
NSF Research Security Training — now a separate, active requirement
A distinct and newer obligation, separate from RECR training content, has since taken effect: under Section 10634 of the CHIPS and Science Act, NSF now requires a dedicated Research Security Training certification for senior/key personnel named on an NSF proposal. Per NSF Important Notice No. 149, the training requirement itself took effect October 10, 2025 (as part of the 2025 Proposal & Award Policies and Procedures Guide), and the associated certification requirement — each senior/key person certifying they’ve completed training meeting NSF’s specified content areas within the 12 months prior to submission — took effect December 2, 2025. As of this writing, both are live, current obligations for NSF proposals, not upcoming ones. Training must cover cybersecurity, international collaboration and foreign-interference risk, and rules on proper use of funds, disclosure, conflict of commitment, and conflict of interest. NSF, NIH, DOE, DOD, and USDA all recognize a shared condensed module (from the NSF-funded SECURE Center) as satisfying each agency’s own version of this requirement — a rare point of actual cross-agency standardization worth knowing about if your institution works across multiple federal sponsors.
See also the CASRAI Dictionary’s research security policy and NSPM-33 entries, and the Research security domain, for the broader compliance landscape this training requirement sits inside.
RCR training, research security training, and COI disclosure are related but distinct tracks
These three obligations are frequently conflated because they overlap in personnel scope and because a single training platform (CITI, for instance) often delivers modules for all three — but they are legally and administratively separate requirements, with separate certification logic, separate renewal cadences, and, at NIH, a separate in-person rule that applies to RCR but not to research security or COI training:
- RCR/RECR training — ethics-of-research-conduct content; NIH (8 hrs, in-person component, career-stage/4-year cadence) and NSF (broader topic content, online acceptable, faculty/senior personnel since July 2023).
- Research security training — NSF-specific certification (see above); distinct content areas (cybersecurity, foreign interference, export awareness); 12-month currency window, not a 4-year one.
- Conflict of interest disclosure — an annual or per-proposal financial/relationship disclosure obligation, not primarily a training requirement, though many institutions bundle a short COI training module with it.
A research office tracking compliance for a single PI across all three needs to track three different things that happen to share a name in casual use (“compliance training”) but don’t share a renewal clock, a content standard, or in NIH’s case, a delivery-mode rule.
What “CITI RCR training” actually satisfies
The CITI Program’s RCR course series is the most widely used commercial provider of this training and covers the standard RCR topic areas (research misconduct, data management, authorship, peer review, mentoring, conflicts of interest). It is fully online. That makes it sufficient, on its own, to satisfy NSF’s RECR requirement — but it does not, by itself, satisfy NIH’s requirement, because NIH’s in-person/live-discussion component cannot be met through an asynchronous online course regardless of provider. Institutions commonly use CITI as the online component or knowledge baseline and supplement it with a locally organized discussion series to meet NIH’s rule — the two requirements are not interchangeable even though the same word (“RCR”) describes both.
The part that’s actually hard: tracking and verifying completion across institutions
Almost every research-office page on this topic stops at “here is who needs how many hours, how often.” The harder, less-discussed problem is operational: RCR-family requirements are person-level, time-bound, and funder-specific, but the record of who has met which requirement, and when it expires, typically lives in whatever system delivered the training — an LMS, a CITI transcript, a departmental spreadsheet — with no standard way to expose that record to the systems that actually need to consume it: a sponsored-programs office preparing a proposal certification, a subrecipient-monitoring workflow on a multi-institution award, or a CRIS/RIM system that’s supposed to hold an authoritative view of a researcher’s compliance status alongside their other research-activity metadata.
This gets materially harder on collaborative and multi-institution awards. A lead institution certifying RECR compliance for senior personnel at several subrecipient universities has no standard, machine-readable way to ask “has this specific named person met NSF’s RECR requirement as of this date, and when does that status expire?” and get a verifiable answer back from the subrecipient’s own systems — it’s usually a manual email-and-spreadsheet exchange, repeated per award, per institution, per requirement type, because the underlying records aren’t structured or interoperable in the first place.
What a workable, standardized record would need to express, at minimum:
- A stable identifier for the person (an ORCID iD is the obvious existing candidate — it’s already the de facto person-identifier anchor across CRIS interoperability) rather than a name string that has to be manually matched across systems.
- A specific requirement identifier — which funder, which rule (NIH RCR vs. NSF RECR vs. NSF Research Security Training are not the same claim), not just a generic “completed compliance training” flag.
- An effective date and an explicit expiry or next-due date, since the cadence differs by requirement (four years for NIH RCR, twelve months for NSF research security).
- An attesting party and evidence pointer — who verified it (the training provider, the home institution’s research office) and where the underlying record lives, so a receiving institution or CRIS doesn’t have to take the assertion on faith.
ORCID’s own record model illustrates both the opportunity and the gap: ORCID already has a “Qualification” affiliation type distinct from formal Education, which is a plausible place to assert a completed training credential — but it’s a free-text, self- or institution-asserted affiliation, not a structured record with funder-specific requirement codes or expiry logic, and it isn’t currently used this way in practice. Similarly, CERIF — the data model behind CRIS interoperability and referenced in CASRAI’s research-information-systems domain — can represent a person record‘s participation in structured research activities, but there’s no widely adopted, funder-agnostic controlled vocabulary today for “RCR requirement met” as a discrete, exchangeable data element the way there is for, say, a research output or a funding entity. That gap — not the compliance rules themselves, which are well documented by NIH and NSF directly — is the open problem for anyone trying to make RCR compliance status portable across a multi-institution award rather than re-verified by hand on every proposal.
Until a standard for that exists, the practical mitigation most research offices use is keeping RCR/RECR/research-security completion dates in whatever system of record already holds other person-level research-administration data (a CRIS person record, an HR/eRA system, or a dedicated compliance-training LMS with reporting), and treating cross-institution verification on collaborative awards as a proposal-preparation task rather than something the underlying systems currently do for you.
Frequently asked questions
What is responsible conduct of research?
It’s the set of ethical and professional standards — covering research misconduct, data management, authorship, peer review, mentoring, and conflicts of interest — that federal funders require researchers to be trained in as a condition of certain awards. NIH and NSF both mandate it, under somewhat different rules; see the sections above.
What are NIH’s RCR requirements?
At least eight contact hours of training with a genuine in-person or live-discussion component (online-only doesn’t satisfy it), repeated at least once per career stage and no less often than every four years, for anyone supported on an NIH F, K, T, or R25 award. See NOT-OD-10-019.
What are NSF’s RCR training requirements?
NSF (which calls this “responsible and ethical conduct of research,” RECR) requires a training plan for undergraduates, graduate students, and postdocs on NSF awards, and — since July 31, 2023, under the CHIPS and Science Act — for faculty and other senior personnel too. Unlike NIH, online-only training (e.g., CITI) is acceptable.
Does CITI training satisfy RCR requirements?
It satisfies NSF’s RECR requirement on its own, because NSF accepts online-only delivery. It does not, by itself, satisfy NIH’s requirement, because NIH requires an in-person or live-discussion component that an asynchronous CITI course doesn’t provide.
What is RCR compliance, and how is it verified?
“RCR compliance” generally means an institution can demonstrate that everyone required to complete RCR/RECR training under a given award has done so, within the applicable time window. In practice this is verified through certifications made at proposal submission and progress reporting, backed by institutional training records — there is currently no standardized, machine-readable cross-institution format for this verification; see the tracking section above.
Is NSF’s Research Security Training the same as RCR/RECR training?
No. It’s a separate certification requirement, introduced under Section 10634 of the CHIPS and Science Act, covering different content (cybersecurity, foreign-interference risk, export awareness) with a shorter, twelve-month currency window, applying specifically to senior/key personnel named on NSF proposals. It took effect in late 2025 and is a current, active requirement as of this writing.
Related CASRAI resources
See also the Integrity & Compliance pillar page for the broader cluster this guide belongs to, and the dictionary domains for Compliance and regulatory, Research integrity and misconduct, Research security, and Mentorship, training, and career stages.







