August 2024. Assists agency staff in assessing grant applications and ongoing awards for potential foreign interference. Factors considered include: (1) current or past participation in a malign foreign talent recruitment program, which is prohibited by law, (2) undisclosed current or prior funding from a foreign country of concern (FCOC), or connected entity (currently China, Russia, North Korea, and Iran (higher risk)) or other foreign country (lower risk) and, (3) Indicators of an undisclosed current or past affiliation with an institution or entity located in or connected to a FCOC (higher-risk/mitigation) or foreign country (lower-risk/mitigation). Per the matrix, mitigation is either required, recommended, suggested, or not required based on the timing of the engagement and if accurate and complete disclosure information was provided. Mitigation conditions include: (1) specific award conditions, (2) modification of terms and conditions of award, (3) suspension, termination, or withdrawal of an award, (4) conversion from advance payment to reimbursement, and (5) recovery of funds.
Reference Library
Browse and search all federal research security policies, guidance, and compliance requirements.
A COGR overview published in July 2024 summarizing the requirements of the White House OSTP Final Guidelines for Research Security Programs at Covered Institutions across the four required research security program focus areas. It serves as a plain-language companion summary to the OSTP RSP Guidelines memorandum issued July 9, 2024.
Final Research Security Program (RSP) Guidelines published on July 9, 2024, via a memorandum to the heads of federal research funding agencies. Federal agencies are directed to implement the guidelines and provide time for institutional implementation. The four required areas are: cybersecurity, foreign travel security, research security training, and export control training. Agencies are coordinating implementation under a memorandum of agreement and anticipated to issue the requirements in early 2026.
June 2024. NSF initiated a proposal risk review process similar to that of DoD but with some notable differences. NSF's process will focus on critical technologies, beginning with a pilot of quantum technologies proposals in FY25, expanding to other key technologies in phase 2, and scaling up for all key technologies identified in the CHIPS and Science Act in phase 3. NSF will evaluate Three Criteria: 1. Appointments and positions with U.S. proscribed parties (e.g., U.S. BIS Entity List) and currently party to a MFTRP; 2. Non-disclosures of appointments, activities, and financial support; and 3. Potential foreseeable national security applications of the research. NSF will consider only current foreign appointments and affiliations and is not considering co-authorship in risk assessment.
Additional information on NSF's Trusted Research Using Safeguards and Transparency (TRUST) proposal risk review process, presented at the Federal Demonstration Partnership (FDP) meeting in May 2024. The document walks through how NSF's TRUST review operates, including its phased rollout beginning with a pilot of quantum proposals and the three criteria NSF evaluates when assessing proposals for research security risk.
A summary of the NSF-funded workshop 'Responsible Collaboration Through Appropriate Research Security' held at Rice University's Baker Institute for Public Policy in May 2024. Discusses challenges and opportunities in the emerging field of RoRS and provides recommendations to guide NSF's new RoRS program.
Frequently asked questions about DARPA's Fundamental Research Risk-Based Security Review Program (FRR-BS), issued May 2024.
A matrix developed to assist in determining if specific activities are required to be disclosed and what form is appropriate for reporting. Last updated May 2024.
A survey issued by COGR in April 2024 documenting research institutions' experiences with DoD's policy for risk-based security reviews of fundamental research.
A March 2024 report commissioned by NSF and issued by the JASON group. Recommends NSF adopt a dynamic approach for identifying potentially sensitive research topics as they arise and weigh the balance between the protective benefits and the unintended negative consequences of controls on sensitive research. It is suggested that the identification of sensitive projects proposed to NSF occurs most naturally before peer or panel review. Specific mitigation strategies for sensitive research projects should be negotiated and agreed upon by the principal investigator (PI), NSF, and the institution and be proportionate to the assessed risk, relative to the associated costs.
Joint comments submitted by ACE, AAU, APLU, COGR, and EDUCAUSE on February 26, 2024 in response to the proposed CMMC rule.
Per Section 10631 of the CHIPS and Science Act, this document issued in February 2024 from the White House OSTP provides definitions of both foreign talent recruitment programs (FTRPs) and malign foreign talent recruitment programs (MFTRPs) [pages 4-6] and what is not considered an FTRP. A foreign talent recruitment program is any program, position, or activity that includes compensation in the form of cash, in-kind compensation, including research funding, promised future compensation, complimentary foreign travel, things of non de minimis value, honorific titles, career advancement opportunities, or other types of remuneration or consideration directly provided by a foreign country at any level or their designee, or an entity based in, funded by, or affiliated with a foreign country.
A February 2024 biannual update from the Fast Track Action Subcommittee on Critical and Emerging Technologies of the NSTC that defines critical and emerging technologies (CETs), which are a subset of advanced technologies that have a significant impact on U.S. national security. [List of CETs is outlined on pages 8-11]
A congressional hearing held in February 2024 with representatives from the White House (OSTP), NSF, NIH, and DoE examining federal science agency actions to secure the U.S. science and technology enterprise.
Published February 2024, this document outlines best practices agreed upon by G7 member nations for maintaining secure and open research.
Issued by the White House OSTP in February 2024, this policy requires federal agencies to use the Common Forms for current and pending support and biosketches, noting that NSF will serve as steward. Deviation from the common disclosure forms will require Office of Management and Budget (OMB)/Office of Information and Regulatory Affairs (OIRA) review and clearance under the Paperwork Reduction Act (PRA).
An updated one-hour condensed and consolidated federal research security training module offered by the SECURE Center. NSF, NIH, DoD, DOE, and USDA have indicated that the condensed module meets their research security requirements. The SCORM files (for upload in the institution's learning management systems), Storyline file, and transcript can also be found on the website. The training includes two, four or six editable html-based files that can be modified to supply institution-specific contact information and links to resources. A preview version can be viewed on the website and a version that offers a certificate of completion is now available.
A summary document from AAU, updated in January 2024, that references key federal documentation that has been developed to address foreign influence in research.
A condensed and consolidated one-hour version of the four federal training modules developed by the University of Michigan in collaboration with Ohio State University, Stanford University, and Duke University. Other academic institutions or organizations can download for their use. The training includes two editable html-based files that can be modified to supply institution-specific contact information and links to resources. SCORM files, Storyline file, and written version of the narrative are available.
A 2024 report by the National Academies: Sciences, Engineering and Medicine examining international talent programs in the context of the changing global environment.
The proposed rule for the CMMC Program published in December 2023, which was superseded by the final rule in October 2024. On July 13, 2026, the U.S. Department of War (DoW) announced it is suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to go into effect on November 10, 2026, while Phase I self-assessment requirements remain in place. In the interim, the Department will enforce cybersecurity compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, focused on cyber hygiene. The announcement notes that contractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012 despite the suspension.
Issued November 14, 2023, this Notice provides clarification regarding findings of foreign involvement with countries of concern related to grants and cooperative agreements under the NIH, CDC, and FDA SBIR and STTR programs. It clarifies the specific changes to competing application instructions first implemented in NOT-OD-23-139, which apply to competing applications submitted for due dates on or after September 5, 2023.
A November 2023 supplement to the NSPM-33 Implementation Guidance that provides definitions of terms used throughout the guidance and related policy documents.
The common form for federal-wide use for current and pending (other) support disclosure, created as directed by NSPM-33 with NSF serving as steward. The form includes certification by each senior/key person at the time of submission that they are not a party to a malign foreign talent recruitment program as defined in the CHIPS and Science Act of 2022. As of November 2025, the form has been implemented by NSF and the National Aeronautics and Space Administration (NASA).
The common form for federal-wide biographical sketch disclosure, created as directed by NSPM-33 with NSF serving as steward. Includes certification by each senior/key person at the time of submission that they are not a party to a malign foreign talent recruitment program as defined in the CHIPS and Science Act of 2022. As of November 2025, the form has been implemented by NSF and NASA.