Federal Research Security Framework
Introduction
Over the past decade, the federal government has developed a coordinated research security framework to strengthen transparency, safeguard federally funded research, protect research integrity, and support responsible international collaboration. Rather than creating a single government-wide research security program, federal agencies have implemented common policy principles through sponsor-specific requirements, proposal certifications, disclosure obligations, research security training, and award terms and conditions.
Today, agencies including the National Institutes of Health (NIH), National Science Foundation (NSF), Department of Energy (DOE), Department of Defense (DoD), National Aeronautics and Space Administration (NASA), and U.S. Department of Agriculture (USDA) each administer research security programs that reflect their statutory authorities and research portfolios while implementing common federal objectives.
The Office of Research Security (ORS) assists investigators in understanding this evolving federal framework and complying with sponsor-specific requirements throughout the proposal, award, and post-award lifecycle.
Evolution of the Federal Research Security Framework
The modern federal research security framework developed over several years through a series of presidential directives, federal legislation, and agency implementation activities.
Although research security requirements vary among federal agencies, they are derived from a common federal policy framework. Understanding how this framework developed helps investigators interpret current sponsor requirements, anticipate future changes, and appreciate the broader context for institutional research security programs.
| Year | Milestone | Significance |
|---|---|---|
| 2018–2020 | Early Research Security Initiatives | NIH foreign influence activities, JCORE established, increased emphasis on transparency and disclosure. |
| 2021 | NSPM-33 | Established a government-wide research security framework and directed agencies to implement consistent requirements. |
| 2022 | CHIPS and Science Act | Codified many NSPM-33 requirements into law, including research security training and MFTRP prohibitions. |
| 2023–2024 | Agency Implementation | Agencies developed Common Forms, disclosure requirements, institutional research security expectations, and implementation guidance. |
| 2025–2026 | Sponsor-Specific Programs | NIH, NSF, DOE, DoD, NASA, USDA, and other agencies implemented research security training, certifications, sponsor-specific guidance, and risk-based review processes. |
Major Federal Milestones
2018–2020: Increasing Focus on Research Security
Federal agencies began expanding efforts to strengthen research security in response to concerns regarding the protection of federally funded research, transparency of research support, and inappropriate foreign influence within the U.S. research enterprise.
Key developments during this period included:
- NIH's Foreign Influence Initiative
- NSF's JASON Report and research security recommendations
- Establishment of the Joint Committee on the Research Environment (JCORE)
- Increased emphasis on disclosure of foreign relationships and research support
- Development of agency-specific research security policies
These initiatives laid the foundation for a coordinated government-wide research security strategy.
2021: National Security Presidential Memorandum 33 (NSPM-33)
NSPM-33 established the first government-wide framework for strengthening research security across federally funded research.
The memorandum directed federal research agencies to implement consistent requirements related to:
- Disclosure of outside professional appointments and affiliations
- Current and Pending (Other) Support
- Foreign Talent Recruitment Programs
- Research security programs at research institutions
- Research security training
- Digital Persistent Identifiers (DPIs)
- Standardized disclosure requirements
NSPM-33 emphasized transparency while supporting continued international scientific collaboration.
2022: CHIPS and Science Act
The CHIPS and Science Act codified many NSPM-33 requirements into federal law and directed agencies to implement additional research security requirements.
Major provisions included:
- Prohibition on participation in Malign Foreign Talent Recruitment Programs for certain federally funded researchers
- Government-wide research security training requirements
- Standardized disclosure requirements
- Expanded agency research security responsibilities
- Institutional research security program expectations
2023–Present: Federal Agency Implementation
Following NSPM-33 and the CHIPS and Science Act, federal research sponsors began implementing sponsor-specific research security programs through proposal guidance, award terms and conditions, certifications, and institutional requirements.
Although implementation varies among agencies, common areas include:
- Standardized disclosure requirements
- Research security training
- Foreign talent recruitment program certifications
- Risk-based review of international research activities
- Evaluation of foreign appointments, affiliations, and research support
- Research data protection expectations
- Sponsor-specific certifications and prior approval requirements
- Post-award reporting and ongoing compliance
A significant milestone in implementation occurred on July 9, 2024, when the White House Office of Science and Technology Policy (OSTP) issued the Final Guidelines for Research Security Programs at Covered Institutions, establishing government-wide expectations for institutional research security programs required under NSPM-33.
Federal agencies continue to refine and expand their research security programs through sponsor-specific proposal guidance, certifications, training requirements, disclosure obligations, and award conditions. ORS monitors these developments and updates institutional guidance as federal policies evolve.
Sponsor-Specific Implementation
Although federal agencies share a common research security foundation established through NSPM-33 and related federal requirements, each sponsor implements these requirements differently. ORS maintains both Sponsor Disclosure Requirements and Sponsor Research Security Guidance to help investigators understand agency expectations throughout the proposal and award lifecycle.
| Federal Sponsor | Sponsor Disclosure Requirements | Sponsor Research Security Guidance |
|---|---|---|
| National Institutes of Health (NIH) | View NIH Disclosure Requirements | View NIH Research Security Guidance |
| National Science Foundation (NSF) | View NSF Disclosure Requirements | View NSF Research Security Guidance |
| Department of Defense (DoD) | View DoD Disclosure Requirements | View DoD Research Security Guidance |
| Department of Energy (DOE) | View DOE Disclosure Requirements | View DOE Research Security Guidance |
| National Aeronautics and Space Administration (NASA) | View NASA Disclosure Requirements | View NASA Research Security Guidance |
Disclosure Requirements explain what investigators must report (e.g., Biographical Sketches, Current and Pending Support, Other Support, Common Disclosure Forms, and sponsor certifications).
Research Security Guidance explains each sponsor's research security policies, proposal and award requirements, training expectations, and activities that may require institutional review.
The Role of the Office of Research Security
ORS supports investigators by:
- Monitoring changes in federal research security policies and regulations
- Developing institutional guidance and educational resources
- Assisting investigators with sponsor-specific research security requirements
- Coordinating institutional reviews involving international collaborations, export controls, research data protection, and other research security considerations
- Supporting proposal development, award management, and post-award compliance
The objective of ORS is to help investigators navigate evolving federal requirements while facilitating responsible, collaborative, and internationally engaged research.
Related ORS Resources
- Federal Sponsor Research Security Guidance
- Federal Sponsor Disclosure Requirements
- Research Security Training
- International Collaborations
- Export Controls
- Research Data Protection & Security
Key Federal Policy Documents
The following documents established and continue to govern the federal research security framework.
| Document | Significance |
|---|---|
| National Security Presidential Memorandum 33 (NSPM-33) | Established the federal research security framework. |
| NSPM-33 Implementation Guidance (2022) | Directed federal agencies on implementing NSPM-33 requirements. |
| Guidelines for Research Security Programs at Covered Institutions (2024) | Established government-wide expectations for institutional research security programs. |
| CHIPS and Science Act (2022) | Codified major research security requirements into federal law. |
|
National Defense Authorization Acts (FY2021–FY2023) |
Expanded statutory research security authorities across federal agencies. |
Historical Publications & Reports
The following publications influenced the development of today's federal research security framework and continue to provide valuable background for understanding research security policy.
| Publication | Contribution |
|---|---|
| Summary of the White House Summit of the Joint Committee on the Research Environment (JCORE) (2019) | Early federal coordination on research security. |
| Enhancing the Security and Integrity of America's Research Enterprise (OSTP, 2020) | Early federal strategy document. |
| Recommended Practices for Strengthening the Security and Integrity of America's Science and Technology Research Enterprise (NSTC, 2021) | Foundation for NSPM-33 implementation. |
| Protecting Critical and Emerging U.S. Technologies from Foreign Threats (NCSC, 2021) | National security context for research protection. |
| Safeguarding International Science: Research Security Framework (NIST, 2023) | Framework for balancing research openness and security. |
| Safeguarding the Research Enterprise (JASON Report) (2024) | Independent assessment of research security risks and recommendations. |
| G7 Best Practices for Secure & Open Research (2024) | International best practices supporting secure global research collaboration. |
Research Security Framework at Stony Brook University
Federal research security requirements established through NSPM-33 and subsequent federal legislation are implemented at Stony Brook University through a coordinated Research Security Program administered by the Office of Research Security.
The program integrates:
- Federal sponsor disclosures
- Research security reviews
- Export controls
- International engagements
- Research cybersecurity
- Research security training
- Research data protection
- Organizational Conflict of Interest
- Foreign travel security
See the Related ORS Resources above for additional guidance.