Skip to content

Reference Library

Browse and search all federal research security policies, guidance, and compliance requirements.

Showing 25 of 148 items — page 4 of 6
Department of Energy RTES Office|
ActiveDOE

RTES presented on research security risk reviews during a COGR meeting in October 2023, noting that much of the agency's portfolio includes critical and emerging technologies. Among the areas noted as potential targets were Advanced batteries, Advanced computing, Advanced engineering materials, Advanced manufacturing, Artificial intelligence/machine learning, Autonomous systems and robotics, Biotechnologies, Quantum information technologies, Next generation renewable energy generation and storage and Semiconductors and microelectronics.

Agency Risk Review Processes
NIST|
ActiveNIST

Published August 2023 by NIST, this report integrates several U.S. government policies and guidelines to develop a framework for an integrated, risk-balanced approach for safeguarding international science and technology from undue foreign interference.

NIST StandardsG7 & Multilateral Initiatives
National Institute of Standards and Technology (NIST)|
DraftNIST

An initial public draft issued by NIST in August 2023 that summarizes feedback NIST received on institutions of higher education (IHE) cybersecurity challenges and includes resources and possible next steps. Per the final research security program guidelines published July 9, 2024, institutions are to implement a cybersecurity program one year after publication of the final version of this NIST cybersecurity resource. Federal research funding agencies, working with NIST and IHEs via the Federal Demonstration Partnership (FDP), are currently developing cybersecurity guidelines that align with NIST 8481 for use in RSPs.

NIST Standards
Department of Defense|
ActiveDW

Issued June 29, 2023 by DoD. The document includes: 1. A Policy on Risk-based Security Reviews of Fundamental Research, 2. A Decision Matrix to Inform Fundamental Research Proposal Mitigation (Amended May 5, 2025), 3. A list of foreign institutions identified as engaging in problematic activity (Part 3, Table 1, Amended June 24, 2025), and 4. A list of foreign talent recruitment programs identified as posing a threat to U.S. national security interests (Part 3, Table 2). The Decision Matrix contains four factors for assessing senior/key personnel disclosures: a. Participation in foreign talent recruitment programs, b. Current or prior funding from foreign countries of concern (FCOCs), c. Filing a patent in an FCOC or on behalf of an FCOC-connected entity, or in a non-FCOC country, without disclosure, and d. Associations or affiliations with organizations on U.S. Entity (trade restriction) and other indicated (U.S. restricted) lists.

Agency Risk Review ProcessesMitigation StrategiesAgency Disclosure Policies
National Institutes of Health (NIH)|
ActiveNIH

Issued June 12, 2023, this Notice implements additional disclosure and post-award reporting requirements for small business concerns (SBCs) participating in the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs regarding covered relationships. It also serves as notification of NIH's due diligence program to assess security risks and to deny award where foreign relationships meet the risk criteria prohibiting funding. The requirements apply to competing applications submitted for due dates on or after September 5, 2023.

Agency Disclosure PoliciesPost-Award ReportingAgency Risk Review Processes
National Academies|
ActiveFederal

A June 2023 report issued by the National Academies providing recommendations that U.S. institutions of higher education can take to identify and mitigate risks associated with foreign-funded language and culture institutes on campus. A companion highlights summary is also available.

Confucius Institute & Entity Restrictions
National Academies|
ActiveFederal

A highlights summary of the National Academies' June 2023 report on foreign-funded language and culture institutes at U.S. institutions of higher education. It condenses the practices and recommendations institutions can use to identify and mitigate risks associated with such institutes on campus.

Confucius Institute & Entity Restrictions
JASON Group (commissioned by NSF)|
ActiveNSF

A March 2023 report issued by JASON and commissioned by NSF. Provides definitions of Research Integrity as adherence to accepted values and principles -- objectivity, honesty, openness, accountability, fairness, and stewardship -- that guide the conduct of research. Research Security is protecting the means, know-how, and products of research until they are ready to be shared. JASON suggests research security does not vary across disciplines, but the consequences of breaches in research security and the measures taken to prevent breaches will differ. Key points include an emphasis on training researchers on risks in international collaborations, the need to encourage collaboration with international organizations that are also concerned with research security, and avoiding creating a reputation of racial profiling or using the research security programs to disadvantage anyone based on ethnicity or nationality.

Research Security Reports & AssessmentsG7 & Multilateral Initiatives
NASA|
ActiveNASA

The NASA Proposer's Guide (February 2023) includes similar language to the Wolf Amendment in a footnote of section 2.16, Current and Pending Support. Per the footnote, 'China or Chinese-owned Company' means the People's Republic of China (PRC), any company owned by the PRC, or any company incorporated under the laws of the PRC. Chinese universities and other similar institutions are considered to be incorporated under the laws of the PRC and, therefore, the funding restrictions apply to grants and cooperative agreements that include bilateral participation, collaboration, or coordination with Chinese universities.

Common Disclosure Forms
NSF|
ActiveNSF

February 2023. Outlines advanced monitoring and verification activities of NSF proposals and awards. The guidelines largely serve to provide transparency and identify guardrails NSF has put in place around the use of data analytics to monitor and validate information disclosed (e.g., in biosketches and current and pending support). For example, the activities are not investigative and cannot be incorporated into the merit review process. Sources of information include SCOPUS, Web of Science, and the U.S. Patent and Trademark Office Patent Database.

Agency Risk Review ProcessesAgency Disclosure Policies
OSTP / NSTC Research Security Subcommittee|
SupersededFederal

Draft standards for research security programs published for comment in February 2023 by OSTP/the NSTC Research Security Subcommittee. The document was superseded by the final standard guidelines published on July 9, 2024. The following are related documents and comments from higher education associations.

RSP Standards & Guidelines
National Academies of Sciences, Engineering, and Medicine|
ActiveDW

Issued in January 2023 by the National Academies, this report outlines recommended conditions that should be in place for the Department of Defense to consider granting a waiver to allow an institution of higher education (IHE) hosting a Confucius Institute (CI) to continue receiving agency funding, as contemplated under the FY2020 NDAA. A companion highlights summary is also available.

Confucius Institute & Entity RestrictionsNDAA Provisions
NSF (in collaboration with NIH, DoE, DoD, FBI)|
ActiveFederal

Research security training developed by institutions and organizations under cooperative agreements funded by NSF in collaboration with the National Institutes of Health (NIH), Department of Energy (DoE), and Department of Defense (DoD), with engagement from the Federal Bureau of Investigation (FBI). The training consists of 4 modules: 1.) What is Research Security?; 2.) Disclosure; 3.) Manage and Mitigate Risk; 4.) International Collaboration.

Federal Training Modules
National Academies of Sciences, Engineering, and Medicine|
ActiveFederal

The National Academies of Sciences, Engineering, and Medicine's National Science, Technology, and Security Roundtable, called for in the Fiscal Year 2020 National Defense Authorization Act, explored issues related to protecting U.S. national and economic security while ensuring the open exchange of ideas and the international talent.

Research Security Reports & AssessmentsInternational Research Security Policy
National Academies of Sciences, Engineering, and Medicine|
ActiveDW

A highlights summary of the National Academies' January 2023 report on waiver criteria for the Department of Defense regarding institutions of higher education that host a Confucius Institute. It condenses the recommended conditions the report suggests should be in place for DoD to consider granting a waiver allowing a hosting institution to continue receiving agency funding.

Confucius Institute & Entity RestrictionsNDAA Provisions
National Aeronautics and Space Administration (NASA), via Federal Demonstration Partnership (FDP)|
ActiveNASA

A September 2022 NASA presentation (at 49:32 in the recorded Federal Demonstration Partnership federal agency updates session) in which NASA clarified how it applies the Wolf Amendment restriction. NASA explained that it defines a 'Chinese-owned company' as any company owned by China, or any company incorporated under the laws of China, and that Chinese universities and similar institutions are considered to be incorporated under the laws of China and are therefore subject to the funding restrictions.

Other Authorization ActsInternational Research Security Policy
U.S. Congress|
ActiveFederal

September 2022. Requires agencies to implement a due diligence program to assess security risks for SBIR and STTR proposals. Disclosure requirements include information on foreign ties, business relationships, investment, and ownership. [Source: AAU, January 2024].

Other Authorization ActsAgency Disclosure Policies