Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

UKRI Security Management Plan and Certification Requirements

UKRI grant terms and conditions require every funded organisation to hold a security management plan and relevant certification (RGC 2.1), backed by a cybersecurity risk assessment. This guide explains what the requirement covers, how it relates to UKRI’s Trusted Research and Innovation conditions, and who is responsible for it.

UKRI’s standard grant terms and conditions require every organisation that receives UKRI funding to have a security management plan and to hold relevant certification providing an appropriate level of assurance. This is a standing condition of the award, not a one-off application requirement — it applies for the life of the grant, and it sits alongside a separate, narrower set of national-security clauses UKRI added to all its grant agreements in April 2024, part of the UK’s wider trusted research framework. This guide explains what UKRI’s own terms and conditions actually say, what the requirement covers, and where UKRI leaves the specifics to the receiving organisation to determine.

Where the requirement comes from

The requirement is written into UKRI’s published guidance on its full economic cost (FEC) grant terms and conditions, under Research Grant Condition RGC 2.1. UKRI’s own guidance states it directly: “Any Organisation in receipt of UKRI grant funding must have a security management plan and hold relevant certification to provide an appropriate level of assurance.” The same guidance adds that “a robust set of controls, based on a cybersecurity risk assessment, must be implemented.” The same or an equivalent condition also appears in UKRI’s training grant terms and conditions, so the requirement is not limited to standard research grants — it applies to organisations receiving UKRI training-grant funding as well.

Because this is a condition of grant, it attaches to the research organisation that holds the award (the university, institute, or other eligible body named on the offer letter), not to the individual principal investigator. In practice, responsibility for having a security management plan and holding the relevant certification sits with the organisation’s own IT security, information governance, or research office function, not with the PI personally — though the PI and the grant-holding department are still bound by the condition as signatories to the award.

What UKRI’s requirement actually covers

Read together, UKRI’s published guidance sets out three linked expectations for organisations receiving its funding:

  • A security management plan. A documented plan describing how the organisation manages security relevant to the funded research — UKRI’s guidance does not prescribe a specific template or format for this plan.
  • Relevant certification. The organisation must hold certification that provides UKRI with an appropriate level of assurance about its security posture. UKRI’s guidance uses this general phrase — “relevant certification” — without naming a specific mandated scheme (it does not, for example, specify ISO/IEC 27001 or Cyber Essentials by name in the wording quoted above). What counts as “relevant” is therefore a judgement the organisation and its funder relationship manager work out based on the nature of the research and the organisation’s existing security accreditation, rather than a single fixed checklist.
  • A cybersecurity risk assessment and controls. The plan and certification must be backed by an actual risk assessment, with controls implemented in response to it — not a paper exercise. UKRI’s broader Trusted Research and Innovation (TR&I) guidance also references building a positive cybersecurity culture through staff and student training, consistent with this condition.

Many UK research organisations already hold recognised UK information-security certifications for other reasons — for example, government-backed schemes such as Cyber Essentials or Cyber Essentials Plus, or the international standard ISO/IEC 27001 for information security management — and these are the kind of accreditation that would typically be pointed to when demonstrating compliance with RGC 2.1. This guide notes them as illustrative of the kind of certification UK institutions commonly hold, not as a requirement UKRI’s own text specifically names — check current UKRI guidance and your institution’s own compliance office before treating any particular scheme as the one UKRI expects.

For background on UKRI’s council structure and how its funding service works more broadly, see UKRI Grants: How the Nine Councils and Funding Service Fit Together and UKRI Funding: How UK Research and Innovation Works.

How this relates to Trusted Research and Innovation (TR&I)

The security management plan condition sits within UKRI’s wider Trusted Research and Innovation framework, which covers the broader set of risks UKRI expects funded organisations to manage: safeguarding intellectual property, protecting sensitive research and personal data, and ensuring international collaborations comply with export control law, sanctions, and related national-security legislation — the same category of obligation covered for export-controlled research at US institutions, though the UK’s specific statutory framework differs. In April 2024, UKRI added two new conditions to its standard grant terms and conditions to make TR&I expectations explicit, including adherence to statutory requirements and UK legislation and sanctions — with specific reference to export controls, the National Security and Investment Act 2021, and the Academic Technology Approval Scheme (ATAS) where relevant to a project’s staff and collaborators.

UKRI’s guidance also states that national-security clauses must be included in all grant agreements regardless of the technology area involved or which partners are named on the award — the clause is standard across the whole FEC grant portfolio, not something added only to projects UKRI judges to be higher-risk. Separately, UKRI’s terms and conditions also expect organisations to maintain adequate business continuity arrangements so that a security incident or other disruption causes minimal interruption to the funded project.

Who is responsible for what

Because the security management plan and certification are organisational, not project-specific, requirements, most UK research organisations meet them through existing institution-wide information-security governance rather than building something new for each individual UKRI award. In practice that usually means:

  • The organisation’s information security or IT governance function owns and maintains the security management plan and any underlying certification, in the same way it would for other funders or regulatory obligations.
  • The research/grants office confirms, as part of accepting a UKRI award, that the organisation meets RGC 2.1 and the related TR&I conditions — this is typically handled at the institutional level rather than re-verified separately for every grant.
  • The principal investigator and project team are responsible for project-specific elements that flow from the wider framework — for example, flagging where a project involves export-controlled technology, overseas collaborators subject to ATAS, or data/materials that raise National Security and Investment Act considerations — so the organisation can apply the right controls to that specific project.

Practical implications for research administrators

For a research administrator supporting a UKRI-funded project, the practical questions this condition raises are usually institutional rather than project-level:

  • Confirm your organisation’s existing position. Most established UK universities and research institutes will already have a security management plan and relevant certification in place as a matter of general institutional governance — the research office’s role is usually to confirm this exists and is current, not to create it from scratch for a single award.
  • Don’t confuse this with data security plans required by specific funders or data types. RGC 2.1 is a general organisational condition of UKRI funding. It is separate from project-specific data management or data security requirements that may apply because of the nature of the data being handled (for example, sensitive personal data, or data governed by a data access agreement with a third party).
  • Treat the April 2024 TR&I conditions as project-level flags. Unlike the general security management plan condition, export control status, ATAS requirements, and National Security and Investment Act considerations need to be assessed project by project, since they depend on the specific technology, collaborators, and countries involved.
  • Check current UKRI guidance directly before signing off compliance. UKRI periodically updates its standard terms and conditions (the FEC grant terms and conditions were last reissued in April 2024 at the time of writing) — always confirm the current published version and RGC clause numbering on ukri.org rather than relying on a cached copy, since clause numbers and wording can shift between reissues.

Frequently asked questions

Does the security management plan requirement apply to every UKRI grant?

Yes. UKRI’s guidance states the requirement applies to any organisation in receipt of UKRI grant funding, and the equivalent condition also appears in UKRI’s training grant terms and conditions. It is a standing condition of holding UKRI funding rather than something triggered only by certain project types.

Does UKRI specify which certification organisations must hold?

UKRI’s published guidance uses the general term “relevant certification” to provide “an appropriate level of assurance” — it does not name one specific mandated scheme in that clause. Organisations typically point to existing recognised UK or international information-security certification (such as Cyber Essentials, Cyber Essentials Plus, or ISO/IEC 27001) to demonstrate this, but confirm with your own institutional compliance office and current UKRI guidance what your organisation currently relies on and whether UKRI has specified anything more precisely for your award type.

Is the security management plan the same thing as UKRI’s Trusted Research and Innovation requirements?

No, though they’re related and often discussed together. The security management plan and certification condition (RGC 2.1) is a general organisational security-governance requirement. Trusted Research and Innovation is UKRI’s broader framework covering export control compliance, the National Security and Investment Act, ATAS, and safeguarding sensitive research and data in international collaboration — formalised as two additional grant conditions from April 2024. A funded organisation needs to meet both, but they are distinct conditions addressing different risks.

Who at a university is responsible for the security management plan under a UKRI grant?

UKRI’s terms and conditions place the obligation on the receiving organisation as a whole, not on the individual principal investigator. In practice, an institution’s information security or IT governance function typically owns the plan and certification, while the research/grants office confirms compliance as part of accepting the award, and PIs are responsible for flagging project-specific risk factors (export control, overseas collaboration, sensitive data) that the institution needs to manage under the wider framework.

What happens if an organisation cannot demonstrate a security management plan and certification?

UKRI’s public guidance does not set out a specific published sanction for this condition in isolation. As with other standard grant conditions, failure to meet terms and conditions of grant can affect an organisation’s standing with UKRI and its ability to hold or draw down funding — organisations should treat it as a genuine condition of the award, not an aspirational recommendation, and resolve any gap with their own governance function rather than assume it will not be checked.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →