Regulations

The CHIPS & Science Act research-security provisions

In force since Aug 9, 2022 Last reviewed: 2026-07-18

The CHIPS and Science Act of 2022 (Public Law 117-167), signed August 9, 2022, codified the research-security framework directed by NSPM-33 into federal law. The research-security provisions live in Division B, Title VI, Subtitle D — including §10632 (Malign Foreign Talent Recruitment Program prohibitions), §10633 (foreign gifts and contracts disclosure), and the research security training provisions in the same subtitle. Together they made the NSPM-33 framework statutory and enforceable, and added specific obligations — notably MFTRP — that NSPM-33 alone did not include.

The research-security provisions

§10631 — OSTP research security policy

Establishes the Office of Science and Technology Policy's ongoing responsibility to lead and coordinate federal research security policy across science-funding agencies — the source of the NSPM-33 Implementation Guidance and the government-wide research security framework.

§10632 — Malign Foreign Talent Recruitment Programs

Prohibits federal research awards to any individual who is a party to a malign foreign talent recruitment program (MFTRP) as defined by the statute, and requires institutions to certify — per federal research award — that no covered individuals are participating in such a program. Definitional detail on the MFTRP page.

§10633 — Foreign gifts and contracts

Reinforces disclosure of foreign gifts and contracts above statutory thresholds under Section 117 of the Higher Education Act, and expands the Department of Education's enforcement authority. Section 117 filings are public and are a routine input to enforcement investigations.

Research security training (Title VI, Subtitle D)

The CHIPS Act's research-security training provisions require federal science-funding agencies to mandate research security training covering the four topical areas (cybersecurity, insider threats, foreign travel security, export controls). This is the statutory basis for the NIH, NSF, and DOE RST requirements.

What CHIPS made binding that NSPM-33 alone did not

  • Statutory force. NSPM-33 was executive direction to agencies; CHIPS is federal law directly applicable to institutions.
  • MFTRP certification. The per-award certification of no covered individuals was a CHIPS addition, not part of the original NSPM-33 four elements.
  • Enforceable training requirements. The Title VI training provisions turned "training should be provided" into "agencies must require certified training."

Interaction with NSPM-33 and the disclosure standard

OSTP's NSPM-33 Implementation Guidance and the CHIPS statutory requirements are read together in practice. Institutions with total federal science and engineering support above $50 million per year are expected to certify a research security program covering NSPM-33's four elements; every applicant institution, regardless of size, is subject to the CHIPS training and MFTRP obligations and the Common Forms disclosure standard that took effect in January 2026.

What institutions should do now

  1. Map obligations by function. §10632 (MFTRP), §10633 (Section 117), and the Title VI training provisions each touch a different institutional function. Know which office owns each.
  2. Wire MFTRP certification into the pre-award workflow. Per-award, per-covered-individual — not an annual attestation.
  3. Confirm training compliance is per-application, not per-year. The 12-month window is a submission-time gate.
  4. Reconcile Section 117 filings with disclosures. Foreign contracts filed at the institutional level should reconcile with individual researcher disclosures. Divergences are audit findings.

Frequently asked questions

Which parts of the CHIPS and Science Act govern research security?

The research security provisions live in Division B, Title VI, Subtitle D. Key sections include §10631 (research security policy at OSTP), §10632 (Malign Foreign Talent Recruitment Program prohibitions), and §10633 (foreign gifts and contracts disclosure through Section 117), together with the research security training provisions in the same subtitle.

Is CHIPS just NSPM-33 restated?

No — CHIPS made NSPM-33-style requirements binding federal law rather than executive-branch direction, and it added specific obligations NSPM-33 did not include (the MFTRP prohibition being the most consequential). OSTP's NSPM-33 Implementation Guidance and the CHIPS statutory requirements are read together in practice.

What does MFTRP under CHIPS actually prohibit?

CHIPS §10632 prohibits federal research awards to individuals who are participating in a "malign foreign talent recruitment program" as defined by the statute — and requires institutions to certify, per award, that no covered individuals are so participating. See the MFTRP explainer for the definitional detail.

What is Section 117 in relation to CHIPS §10633?

Section 117 of the Higher Education Act requires institutions to disclose foreign gifts and contracts above certain thresholds. CHIPS §10633 tightened the reporting standard and reinforced Department of Education enforcement authority. Public records under Section 117 (available at the Foreign Gifts and Contracts Report) are also a widely used input to enforcement.

ResearchSecurity.ai tracks RST completion against every researcher's certification window — so no application goes out with a training gap the AOR didn't see.

How training compliance addresses the CHIPS requirement →
Founding Partner Program

Verification for the institution certifying these disclosures.

Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.