TL;DR: Under National Security Presidential Memorandum-33 (NSPM-33) and the July 2024 OSTP implementation guidelines, US institutions receiving more than $50 million per year in federal research and development funding must establish an operational research security program (RSP) with four required components, then certify compliance to their funding agencies. Contrary to how it’s often summarized, there is no single government-wide “July 2026” deadline — each federal funding agency set its own RSP-policy effective date, and institutions get up to 18 months from that agency’s effective date to implement and certify. July 2026 is the commonly-cited approximation because several major agencies’ policies took effect around January 2025. Separately, on January 7, 2026, the Department of Defense issued its own memorandum, “Fundamental Research Security Initiatives and Implementation,” standardizing research-security practices across DoD components — a related but distinct development from the government-wide NSPM-33 RSP requirement.
What NSPM-33 Actually Requires, and the $50 Million Threshold
NSPM-33, signed in January 2021, directed the White House Office of Science and Technology Policy (OSTP) to coordinate a government-wide approach to research security. OSTP issued interim implementation guidance in January 2022, then final “Research Security Programs Standard Requirement” guidelines in a July 9, 2024 memorandum to the heads of federal research agencies.
The threshold: an institution of higher education, national laboratory, federally funded research and development center, or nonprofit research institution that receives more than $50 million per year in federal science and engineering support, based on its two most recently completed fiscal years, must establish and operate a research security program. Institutions below that threshold are not exempt from research-security obligations generally (individual funder requirements like export control, foreign-component disclosure, or agency-specific training can still apply) — the $50 million figure specifically triggers the standalone, formal RSP requirement.
There Is No Single “July 2026” Deadline — Here Is the Real Timeline
The OSTP guidelines are a framework for federal funding agencies to adopt, not a self-executing deadline that applies uniformly to every institution on the same calendar date. Each agency (NSF, NIH, DOE, DoD, and others) had to translate the OSTP framework into its own agency-specific policy, on its own schedule, with its own effective date. Institutions then have up to 18 months after that agency’s effective date to implement their research security program and formally certify its implementation and compliance back to the agency.
Because several major funding agencies set effective dates around January 2025, adding 18 months lands many institutions’ certification deadlines around July 2026 — which is why that date circulates widely in research-compliance planning documents as a shorthand or “representative” deadline. But an institution whose primary federal sponsor set a different effective date has a different certification date, potentially months earlier or later. Research administrators should not treat July 2026 as a hard, universal cutoff; the operative deadline is your institution’s applicable funding agency’s effective date plus 18 months, and multi-agency-funded institutions may be tracking several distinct dates at once.
What “Operational” Means: The Four Required RSP Components
OSTP’s guidelines specify that a compliant research security program must include, at minimum, these four elements:
- Cybersecurity — safeguards for federally funded research data and systems, consistent with the institution’s broader information-security posture.
- Foreign travel security — a process for covered individuals to report foreign travel connected to their federally funded research, including a mechanism to flag higher-risk travel.
- Research security training — institution-wide training addressing research security risks, insider threats, and reporting channels (this is the institutional program element; it is distinct from the individual senior/key-personnel training-certification mandates NSF, NIH, DOE, and other agencies have separately layered on via CHIPS and Science Act Section 10634 — see the differentiation note below).
- Export control training and integration — awareness of, and compliance processes for, export-control obligations (ITAR/EAR) that intersect with the institution’s federally funded research portfolio.
“Operational” means the institution has these four elements actually functioning — documented policies, assigned responsibility, and evidence of use — not merely a written plan sitting in a drawer. The certification an institution submits attests to this operational status, not just intent to comply.
Certification and False Claims Act Exposure
Institutions certify RSP implementation and compliance directly to the federal agency (or agencies) from which they receive research funding, typically through the same disclosure and certification channels used for other NSPM-33-related requirements (see our companion piece on what US researchers must disclose under NSPM-33 in 2026). Because this is a formal certification made to the federal government, falsely certifying that an RSP exists, or that it is compliant when it is not, can expose the certifying institution to liability under the federal False Claims Act — a materially higher-stakes consequence than a routine compliance finding, and a reason institutional research offices, general counsel, and sponsored-programs offices are treating RSP certification as a governance-level exercise rather than a checkbox exercise.
DoD’s January 7, 2026 Memo: Standardizing Research Security Across the Department
Separately from the government-wide NSPM-33 RSP timeline above, the Department of Defense’s Under Secretary of Defense for Research and Engineering (USD(R&E)) issued a memorandum on January 7, 2026, “Fundamental Research Security Initiatives and Implementation,” directed specifically at how DoD components manage DoD-funded fundamental research. Universities receive roughly 54% of DoD’s fundamental research funding and industry roughly 15%, so the memo’s reach extends well beyond DoD’s own components to the institutions it funds.
The memo lays out nine initiatives moving DoD from ad hoc, component-by-component research-security practices toward a standardized, enforceable, and more data-driven compliance regime:
- Excluding entities on the Chinese Military Companies list, or with documented IP-theft histories, from DoD funding.
- Enhanced compliance auditing and reporting — annual spot checks of research awards carrying mitigation measures, plus semiannual enforcement reporting.
- A department-wide repository centralizing fundamental research risk reviews across DoD components (rather than each component tracking its own in isolation).
- An annual data call requiring DoD components to report research-security activities to OUSD(R&E).
- A formal process for nominating foreign entities conducting significant military-relevant R&D to the Section 1286 list.
- Standardized training for research-security personnel, with OUSD(R&E) tasked to “explore standardized training requirements” department-wide.
- Grant transparency requirements, including grant-number acknowledgment in resulting publications and development of a common research database.
- A one-year damage assessment evaluating cases raised in House Select Committee on the CCP investigations, examining technology transfer and institutional security gaps.
- Automated vetting and continuous-monitoring capabilities, with the Chief Digital and Artificial Intelligence Office (CDAO) developing automated screening and pattern-recognition tools.
The memo’s own risk-review criteria are elaborated further in DoD’s 2026 Component Decision Matrix, published March 9, 2026, which our companion guide covers in detail (expanded Prohibited Entity Lists, the new equipment-sourcing restriction, and the current mitigation-outcome categories).
How the DoD Memo Relates to — and Differs From — the NSPM-33 RSP Requirement
These are two related but separate compliance tracks, and research administrators should not conflate them:
- The NSPM-33 research security program requirement is a government-wide OSTP framework applying to any qualifying institution above the $50 million threshold, regardless of which agency funds it, with each agency setting its own effective date and 18-month certification clock.
- The DoD January 2026 memo is DoD-internal policy governing how DoD components and DoD program offices manage risk review, auditing, entity exclusion, and training standardization specifically for DoD-funded fundamental research. It does not itself establish or reset an institution’s NSPM-33 RSP certification deadline.
In practice, an institution that receives DoD fundamental research funding above the $50 million threshold is tracking both: its NSPM-33 RSP certification date (set by whichever agency’s effective date governs, which may or may not be DoD’s) and DoD’s own evolving component-level review requirements under the January 2026 memo and the March 2026 Decision Matrix.
How This Differs From Personnel Training-Certification Requirements
casrai.org already covers the individual, senior/key-personnel training-certification mandates that NSF, NIH, DOE, and other agencies have rolled out under CHIPS and Science Act Section 10634 — see Research Security Training: What It Is and Which Agencies Require It and NSF Research Security Training Requirements. Those requirements govern whether a named individual (a senior/key person on a specific proposal) has completed a specific training module before an agency will accept a proposal or make an award.
The RSP operational deadline covered in this piece is a different, broader obligation: it requires the institution as a whole to have a functioning four-part research security program, of which institutional training is only one component, and it applies based on the institution’s total federal research funding rather than to any single proposal or award. An institution can be fully compliant on individual senior/key-personnel training certifications for a given NSF or NIH proposal and still be out of compliance on its broader NSPM-33 RSP certification, and vice versa — they are tracked, and certified, separately.
Action Checklist for Research Administrators
- Confirm whether your institution crosses the $50 million federal S&E funding threshold based on the two most recently completed fiscal years.
- Identify the effective date each of your institution’s major federal funding agencies set for its own NSPM-33 RSP policy, and calculate that agency’s specific 18-month certification deadline — don’t rely on “July 2026” as a universal date.
- Confirm all four RSP components (cybersecurity, foreign travel security, research security training, export control training/integration) are operational, documented, and evidenced, not just drafted.
- If your institution receives DoD fundamental research funding, separately track the January 7, 2026 memo’s initiatives and the March 2026 Component Decision Matrix — these are DoD-specific and run on their own timeline, alongside your NSPM-33 RSP certification.
- Route RSP certification through institutional governance (general counsel, sponsored programs, research security office) given the False Claims Act exposure attached to false certification.
Frequently Asked Questions
Is July 2026 a real, hard deadline for research security programs?
Not universally. It is the certification date for institutions whose governing federal funding agency set its RSP policy effective date around January 2025 (18 months earlier). Institutions must confirm their own applicable agency’s effective date rather than assuming July 2026 applies to them.
How is the $50 million threshold measured?
Based on the institution’s federal science and engineering support over its two most recently completed fiscal years — not a single-year snapshot.
Does the DoD’s January 2026 memo change the NSPM-33 RSP certification deadline?
No. The memo is a DoD-internal standardization effort covering risk review, auditing, entity exclusion, and training across DoD components and DoD-funded fundamental research. It runs alongside, not in place of, each institution’s agency-specific NSPM-33 RSP certification deadline.
What happens if an institution certifies an RSP that isn’t actually operational?
Because RSP certification is a formal representation made to the federal government, a false certification can expose the institution to liability under the federal False Claims Act, in addition to any funding-agency-level compliance consequences.







