The NIH Research Security Training requirement, explained
Under NIH Guide Notice NOT-OD-26-017, every senior/key person on an NIH application with a due date on or after May 25, 2026 must have completed research security training within the previous 12 months — and the institution's Authorized Organizational Representative certifies this on the application. The requirement applies to all applicant institutions, regardless of size; there is no $50 million threshold.
What the training must cover
The CHIPS and Science Act's research-security training provisions (Title VI, Subtitle D) established the four topical areas that qualifying research security training must address:
- Cybersecurity — as it applies to research data, credentials, and infrastructure.
- Insider threats — the recognition, prevention, and reporting of insider risks to research.
- Foreign travel security — precautions and disclosure obligations for research-related international travel.
- Export controls — as they intersect with research activity and personnel.
Institutions may develop training in-house, adopt sector-provided training (for example, the training developed by the Federal Demonstration Partnership), or use offerings from federal agencies and non-profits. NIH does not certify specific training products; the institution certifies that its senior/key personnel have received qualifying training.
Who counts as senior/key personnel
The definition tracks the SF-424(R&R) Senior/Key Person Profile: the PD/PI(s) and any individual whose contribution is measurable, substantive, and central to the scientific development or execution of the project — regardless of dollars, title, or affiliation. Consultants, collaborators, and subaward personnel are covered when listed.
The 12-month recertification window
The AOR certifies at the moment of application submission that every senior/key person on that application has completed qualifying training within the preceding 12 months. Operationally this means:
- Each researcher's training completion has a rolling expiration.
- Every application resets the certification against the current window.
- Institutions must track completion by person, tied to submission date — not by cohort or annual cycle.
How this interacts with NSF and DOE requirements
NSF's research security training requirement took effect on December 2, 2025, and DOE's on May 1, 2025. All three requirements trace back to the CHIPS Act's research-security training provisions (Title VI, Subtitle D) and share the same four topical areas. A training program that satisfies one agency's criteria generally satisfies the others. The compliance work is not designing the training — it is proving, at the moment of submission, that each covered individual is inside the window.
Penalties and exposure
The AOR's certification on an NIH application is a statement to a federal agency. A knowingly false certification exposes the institution to False Claims Act liability, which the DOJ has used in a growing number of research disclosure cases. Recent university settlements have ranged from $313,574 (Research Foundation for SUNY, 2024) to $7.6 million (Cleveland Clinic Foundation, 2024), with cases going back to Van Andel Research Institute's $5.5 million settlement in 2019. See our FCA enforcement tracker for the full list, each linked to its DOJ press release.
What institutions should do now
- Confirm coverage. Identify every unit that submits NIH applications and every category of person who could be listed as senior/key personnel — including PIs, co-investigators, senior postdocs, and consultants.
- Adopt or approve training. Choose the training source(s) your institution will recognize as satisfying the four CHIPS-mandated topics. Document the decision.
- Track completion by individual, not by cohort. The certification is per-application and window-based. Institutional annual "compliance days" are insufficient on their own.
- Wire training status into the pre-submission check. AORs need to see, at the moment of submission, which senior/key persons on the current application are inside the 12-month window and which are not.
- Document your certification method. The institution's process for verifying training status is itself subject to scrutiny. Keep an evidence trail.
Frequently asked questions
What counts as "senior/key personnel" on an NIH application?
Anyone identified as senior/key personnel on the R&R Senior/Key Person Profile form — the PD/PI(s) and any individual contributing to the scientific development or execution of the project in a substantive, measurable way. Postdocs and other collaborators are typically included when their contributions rise to that threshold; NIH's guidance in NOT-OD-26-017 and the SF-424(R&R) instructions are authoritative.
Does the requirement apply to small institutions or only large research universities?
It applies to every applicant institution regardless of size. Unlike NSPM-33 program certification, there is no $50 million funding threshold. If your institution submits any NIH application with a due date on or after May 25, 2026, the training requirement applies to every senior/key person on that application.
What content must the training cover?
The CHIPS and Science Act's research-security training provisions (Title VI, Subtitle D) set the four required topics: cybersecurity, insider threats, foreign travel security, and export controls, as applicable to research. NIH accepts training that covers these four areas at a level appropriate to research security responsibilities. Institutions can develop training themselves, adopt sector-provided training, or use offerings from federal agencies and non-profits.
How does the 12-month recertification window actually work?
The certification is per-application: at the time the AOR submits, every senior/key person must have completed qualifying training within the previous 12 months. This creates a rolling-window compliance problem — training completions expire on a per-person basis, and each new application resets the certification against that person's most recent completion.
How does the NIH requirement interact with NSF and DOE parallel requirements?
NSF's Research Security Training requirement has been in effect since December 2, 2025; DOE's equivalent since May 1, 2025. All three trace to the CHIPS Act's research-security training provisions (Title VI, Subtitle D) and cover the same four topical areas, so a training that meets one agency's criteria generally meets the others — but institutions must track completion and window compliance against the specific certification each application requires.
What is the enforcement exposure for a false certification?
Sponsor certifications submitted to a federal agency are made 'true, complete, and accurate to the best of' the AOR's knowledge. A knowingly false certification can be pursued under the False Claims Act, which the DOJ has increasingly used in research disclosure cases (see our FCA enforcement tracker). Actual settlements have ranged from the low six figures to the low millions.
Primary sources
- NIH Guide Notice NOT-OD-26-017 — Research Security Training Requirement ↗
- CHIPS and Science Act of 2022 — research-security provisions (Title VI, Subtitle D) ↗
- NSF Research Security Training resources ↗
- DOE Research Security Training requirement ↗
- Federal Demonstration Partnership — Research Security materials ↗
ResearchSecurity.ai tracks RST completion against each researcher's certification window and surfaces gaps before the AOR signs.
How training compliance works →Verification for the institution certifying these disclosures.
Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.