The AOR's guide to the May 25 RST certification
From the AOR's chair, the practical shape of NIH's Research Security Training requirement (NOT-OD-26-017) is not "did our institution offer training?" — it is "for this application, on this submission date, has every senior/key person completed qualifying training within the previous 12 months?" The answer has to be defensible on demand, per application.
What the certification actually says
For applications with a due date on or after May 25, 2026, the AOR's submission carries an institutional certification that all senior/key personnel on the application have completed research security training meeting the four CHIPS-mandated topical areas (cybersecurity, insider threats, foreign travel security, export controls) within the prior 12 months. The full statutory basis is on the NIH RST explainer.
Why the "window" changes what pre-submission review has to do
Under the old norm, training compliance was cohort-based: the institution ran an annual training day, everyone attended, and the check-box was cleared until the next year. The 12-month window under NOT-OD-26-017 breaks that pattern in three ways:
- Compliance is per person, per submission date. A senior/key person who trained on July 1, 2025 is compliant for applications submitted through June 30, 2026 — and out of window on July 1, 2026, regardless of what other people at the institution did.
- Each new application resets the certification. There is no "annual sign-off" that covers the year. The AOR's signature on this application certifies to this submission date.
- The gap is invisible until you look person-by-person, application-by-application. An institution can be at 100% training completion overall and still have applications in the queue that will fail the certification.
The operational check the AOR needs before signing
- List every senior/key person on the application — including any added late in preparation.
- For each, retrieve the most recent qualifying training completion date. "Qualifying" per the institution's documented decision on which training content meets the four CHIPS-mandated topics.
- Compute: is completion date > (submission date − 12 months)? If yes for all, the training certification is defensible. If no for any, the AOR should not sign.
- Document that this check was made — not only that it was passed.
How institutions are getting this wrong
The failure modes are consistent across the pre-May-25 preparation cycle we have watched:
- Treating training as an annual institutional event rather than a per-person rolling window.
- Assuming that a training platform's "completed" flag implies "within window." It rarely does.
- Skipping the check for consultants and subaward personnel who become senior/key on the application even though they are not on the institution's payroll.
- Documenting the outcome ("training compliant") without documenting the check that produced it — leaving no defense if the certification is later questioned.
Why this is not just an NIH problem
NSF's parallel requirement has been in effect since December 2, 2025; DOE's since May 1, 2025. All three trace to the CHIPS Act's research-security training provisions (Title VI, Subtitle D) and share the same four topical areas. A training program that meets one agency's standard generally meets the others — but the per-application, per-window certification is now the recurring operational task across every federal science funder.
The verification layer
None of this is complicated. It is simply too voluminous to do by hand at institutional scale. A verification layer that sits between the training-record system and the pre-submission queue can turn "am I certifying truthfully?" into a page the AOR reads in ten seconds. Whether that layer is ResearchSecurity.ai or built in-house, the requirement is the same: per person, per submission, documented.
Verification for the institution certifying these disclosures.
Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.