Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Editorial · CASRAI · Compliance and regulatory

Netherlands Revises Knowledge Security Guideline for 2026

The Netherlands fully revised its National Knowledge Security Guideline on 9 July 2026, updating the threat assessment and adding a risk-indicator appendix.

Published 24 Jul 2026· 6 minute read

On 9 July 2026, the Dutch government published a fully revised Nationale Leidraad Kennisveiligheid (National Knowledge Security Guideline) — the first complete rewrite of the guideline since it was first issued in April 2022. The revision updates the document’s threat assessment with input from the Dutch intelligence and security services, sharpens the working definition of knowledge security, and folds the 2025 “Indicators for Risk Assessment of International Knowledge Security Cooperation” in as a formal appendix. It is published by the National Contact Point for Knowledge Security (Loket Kennisveiligheid), the joint initiative of several Dutch ministries that supports knowledge institutions on international-collaboration risk.

What changed in the July 2026 revision

The 2026 guideline is not a minor update — the Contact Point describes it as a full revision reflecting how much more mature institutional knowledge-security policy has become since 2022. The substantive changes are:

  • An updated threat assessment. The section describing the current risk landscape for international academic and research collaboration was refreshed in collaboration with the Netherlands’ intelligence and security services, rather than being carried over unchanged from 2022.
  • A sharper definition of knowledge security. The 2026 text clarifies the scope of the concept — preventing the unwanted transfer or misuse of sensitive knowledge and technology through international cooperation in ways that could affect national security — more precisely than the original.
  • A clearer split between binding and non-binding content. The guideline now distinguishes more explicitly between passages that function as genuine guidance (recommendations for governing boards to weigh) and passages that describe existing legal or regulatory frameworks that are separately binding (such as the EU’s dual-use export control regime). The Leidraad itself remains a guideline, not legislation.
  • More explicit treatment of the tension with academic core values. The revision gives more attention to the friction that can arise between knowledge-security measures and open science, academic freedom, and international collaboration — rather than treating risk mitigation as costless.
  • A new appendix: the 2025 risk-indicator framework. The document “Indicatoren voor Risico-inschatting Internationale Samenwerkingen Kennisveiligheid” (“Indicators for Risk Assessment of International Knowledge Security Cooperation”), first published separately in 2025, is now incorporated directly into the guideline as an appendix rather than standing as a stand-alone reference.

Both the Dutch and English versions of the revised guideline run to 63 pages and are published as PDFs on loketkennisveiligheid.nl.

What knowledge security means — and why it’s a separate policy track

In Dutch policy, knowledge security (kennisveiligheid) refers specifically to the risk that international scientific collaboration — joint research, visiting researchers, dual-degree programmes, technology transfer — is used by another state or actor in ways that affect the Netherlands’ national security, including undesired transfer of sensitive or dual-use knowledge and technology. The government’s own framing is explicit that the aim is to weigh the opportunities of international collaboration against these risks, not to restrict collaboration by default.

This is a genuinely distinct policy track from research integrity. Research integrity — questions of fabrication, falsification, plagiarism, and authorship disputes — in the Netherlands runs through the Netherlands Board on Research Integrity (LOWI) as a second-opinion body for institutional misconduct procedures. Knowledge security is a separate, geopolitical/national-security risk domain, coordinated instead through the National Contact Point for Knowledge Security and, where EU or national export-control law applies, through binding regulation rather than institutional self-governance. Institutions typically need both functions but should not conflate them: a LOWI case is about the conduct of research; a knowledge-security assessment is about who an institution partners with and what is shared.

Who the guideline is for, and what it asks institutions to do

The Nationale Leidraad Kennisveiligheid is written for governing boards, research leadership, international-office staff, and individual researchers at Dutch knowledge institutions — universities, universities of applied sciences, university medical centres, and public research institutes. It functions as a self-governance framework: institutions are expected to build their own knowledge-security policy and due-diligence practice using the guideline’s tools, rather than the guideline itself creating new legal obligations. Where a specific transfer or collaboration also falls under binding law — most notably the EU’s dual-use export control regime (Regulation (EU) 2021/821) — that legal obligation applies independently of, and takes precedence over, the guideline’s advisory content.

The newly incorporated risk-indicator appendix is the most directly operational part of the update for research administrators: it gives institutions a structured set of indicators to work through when assessing the risk profile of a specific proposed international collaboration, rather than relying on the general threat-assessment narrative alone.

How this compares to other countries’ research-security frameworks

The Netherlands’ guideline-based, institution-led model sits alongside a broader wave of national research-security policy activity. Canada’s National Security Guidelines for Research Partnerships (NSGRP) take a more directive approach tied to specific funding programmes and a sensitive-technology list. The EU’s dual-use export control regime, which also touches Dutch institutions directly, is a binding legal framework rather than guidance — see CASRAI’s overview of the EU Dual-Use Export Control Regulation 2021/821. In the United States, research-security obligations have moved through a mix of funder policy and export-control enforcement, covered in CASRAI’s guide to export control reform and research security. Read together, these show the same underlying pattern from different regulatory starting points: national governments are formalising how universities assess and document the risk in international scientific partnerships, with the Netherlands choosing an advisory, sector-owned guideline as its primary instrument rather than a mandatory clearance regime.

Frequently asked questions

Is the Nationale Leidraad Kennisveiligheid legally binding?

No. It is a guideline (leidraad) addressed to institutional governing boards, not legislation. Where a specific activity is separately covered by binding law — such as EU dual-use export controls — that legal obligation applies regardless of what the guideline recommends.

Does this replace the 2022 guideline?

Yes. The July 2026 version is a full revision of the original guideline first published in April 2022, not an incremental amendment; institutions should work from the 2026 text going forward.

How is this different from LOWI?

LOWI is the Netherlands’ second-opinion body for research misconduct cases — questions of fabrication, falsification, plagiarism, and authorship disputes. The Nationale Leidraad Kennisveiligheid addresses a separate risk domain: whether an international collaboration could result in unwanted transfer or misuse of sensitive knowledge or technology in a way that affects national security. Institutions generally need policies for both, run through different bodies.

Does the guideline apply to non-Dutch institutions?

Directly, no — it is addressed to Dutch knowledge institutions. Indirectly, any institution collaborating internationally with a Dutch university, university medical centre, or research institute may see the effects of it, since Dutch partners are now assessing those collaborations against an updated threat assessment and risk-indicator framework.

Where can I read the full guideline?

Both the Dutch and English versions are published by the National Contact Point for Knowledge Security at loketkennisveiligheid.nl and its English-language counterpart, english.loketkennisveiligheid.nl.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →