Regulations

NSPM-33 & research security program certification

Expected 2026–27 · CHIPS Act codification in force since 2022 Last reviewed: 2026-07-18

National Security Presidential Memorandum 33 (NSPM-33), issued January 14, 2021, directs federal agencies that fund science and engineering research to require, from institutions receiving more than $50 million per year in federal science support, a certified research security program covering four elements: cybersecurity, foreign travel security, research security training, and export control training. The CHIPS and Science Act of 2022 (research-security provisions in Title VI, Subtitle D) codified NSPM-33's direction into statutory requirements.

The four required program elements

Per the OSTP NSPM-33 Implementation Guidance (January 2022), a covered institution's research security program must address:

  1. Cybersecurity. Institutional protection of research data, credentials, and research computing infrastructure. Alignment with existing federal guidance (NIST SP 800-171 for CUI, and the DFARS 7012 clause where applicable).
  2. Foreign travel security. Institutional program for disclosure, review, and support of research-related international travel by covered personnel.
  3. Research security training. The four topical areas (cybersecurity, insider threats, foreign travel security, export controls) required by the CHIPS Act's research-security training provisions and enforced through the NIH, NSF, and DOE RST requirements.
  4. Export control training. Institutional training for personnel who touch export-controlled research or technology.

Who has to certify a program

The certification requirement is triggered at more than $50 million per year in total federal science and engineering funding — a threshold that applies at the institution level. Institutions below that threshold remain subject to disclosure requirements (Common Forms/SciENcv, sponsor-specific certifications) but not the program certification. The higher threshold is why the population of "NSPM-33 institutions" is a small set of research-intensive universities, academic medical centers, and independent institutes — the same set now confronting the enforcement risk we track on the FCA tracker.

Status: what is in force vs. what is expected

NSPM-33 itself is a presidential directive to agencies, not directly to institutions. The binding requirements flow through:

  • CHIPS and Science Act research-security provisions (Title VI, Subtitle D — in force since Aug 9, 2022) — codify research security requirements into law and direct OSTP to lead implementation.
  • OSTP NSPM-33 Implementation Guidance (January 2022) — the four required program elements.
  • Agency-level certification mechanisms — NSF, DOE, NIH, and DoD are each rolling out certification requirements on their own timetables. Final government-wide certification is expected in the 2026–27 window.

Institutions should be building the program to the four-element standard now. Waiting for the final agency form of the certification generally means waiting past the point where the program can be stood up thoughtfully.

How disclosure requirements interlock with the program

NSPM-33 also directed the standardization of disclosure through what became the Common Forms and SciENcv requirements that rolled out across 2026 (three-phase implementation, system enforcement from May 8, 2026). The program certification and the disclosure certifications are two arms of the same framework: the program is how the institution generates and defends every certification the AOR signs. Program certification without disclosure verification leaves the certification hollow; disclosure verification without a program leaves it un-auditable.

What institutions should do now

  1. Confirm coverage. Determine whether your institution is above the $50M federal science-and-engineering threshold. If so, the program requirement applies; if not, disclosure requirements still do.
  2. Inventory the four elements. For each of cybersecurity, foreign travel security, research security training, and export control training — identify the responsible office, the current-state program, and the gap to the OSTP guidance.
  3. Stand up governance. A named research security lead (often reporting to the VP for Research), a working group across the four functions, and a defined escalation to institutional leadership.
  4. Build the evidence layer. Program certification will not be a one-time attestation — agencies will expect the institution to be able to show, on demand, that the program continues to function.
  5. Wire it to disclosure verification. The program's credibility depends on the disclosures the AOR certifies. Verification (of Current & Pending, of publications, of appointments, of training) is what makes program certification more than paperwork.

Frequently asked questions

What is NSPM-33 in one sentence?

National Security Presidential Memorandum 33 (January 2021) directs federal science-funding agencies to strengthen protection of federally funded research and development from foreign-government interference — including through disclosure requirements and, for larger institutions, a certified research security program.

Who is covered by the research security program requirement?

Institutions of higher education and other research organizations that receive more than $50 million per year in total federal science and engineering support are expected to certify a research security program. Smaller institutions are not exempt from disclosure requirements — only from the program-certification requirement.

What are the four required program elements?

Per the NSPM-33 Implementation Guidance from OSTP: (1) cybersecurity; (2) foreign travel security; (3) research security training (see NIH RST, NSF, DOE requirements); and (4) export control training. Institutions certify that programs covering these four areas are in place and functioning.

Is program certification actually in force yet?

The framework was directed in 2021 and made binding by the CHIPS and Science Act in 2022 (research-security provisions in Title VI, Subtitle D). Individual agencies (NSF, DOE, NIH, DoD) are rolling out the certification mechanism on their own timetables; final government-wide certification requirements are expected in the 2026–27 window. Institutions should be building the program now, not waiting for the final form.

How does NSPM-33 relate to disclosure requirements like Common Forms / SciENcv?

NSPM-33 also directed the standardization of researcher disclosure — the Common Forms (biosketch, current & pending) and the ORCID/eRA Commons linkage that rolled out through 2026 (see the Common Forms explainer for the three-phase timeline). Program certification and disclosure requirements are two arms of the same framework: the program is how the institution defends its certifications.

ResearchSecurity.ai gives NSPM-33-covered institutions a verified disclosure trail and evidence-graded certification readiness — so program certification rests on evidence you can point at.

How disclosure verification supports NSPM-33 →
Founding Partner Program

Verification for the institution certifying these disclosures.

Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.