- Introduction
- Research Security Involves Responsibilities Across the Institution
- 1. Are Our Policies Current and Aligned With Applicable Requirements?
- 2. Do Researchers Understand Their Disclosure Responsibilities?
- 3. Is Our Research Security Training Current and Relevant?
- 4. Can We Identify and Evaluate Collaborations That May Require Additional Review?
- 5. How Effectively Could We Document Our Research Security Practices?
- 6. Do We Have a Clear Process for Addressing Potential Gaps?
- Turning Readiness Questions Into Action
- Supporting Research Security Education
Introduction
Research security continues to receive increased attention across the federal research landscape. Depending on the agency, award, and institutional responsibilities involved, research security expectations may extend beyond individual investigators to include institutional policies, training programs, disclosure processes, documentation, and risk-management practices.
Recent federal action illustrates this increased attention. On August 17, 2026, the U.S. Department of War announced that it had directed 30 domestic academic institutions to review certain academic, financial, and research collaborations with foreign entities of concern. Those institutions must assess potential exposure involving sensitive or export-controlled research, implement mitigation measures when needed, and report their findings and actions to the department by August 31, 2026.
The action applies specifically to the institutions that received notifications. It does not establish an equivalent audit requirement for every research institution. However, it provides a timely opportunity for the broader research community to evaluate whether existing programs can identify relevant risks, support accurate disclosures, document institutional practices, and respond appropriately when concerns arise.
Research Security Involves Responsibilities Across the Institution
Research security focuses on protecting government-supported research and development from foreign government interference, misappropriation, and related threats to research integrity and national or economic security. Federal research security efforts also recognize the importance of balancing these safeguards with international collaboration in science and engineering.
Managing these priorities may require coordination among research administrators, investigators, compliance professionals, export control personnel, information security teams, institutional leaders, and other stakeholders.
Institutions should therefore avoid treating research security as a single policy, an annual training assignment, or an isolated responsibility within one administrative office. An effective program connects applicable requirements with the decisions made by researchers and the personnel who support them.
The following questions can help institutions evaluate their current practices and identify areas that may require additional attention.
1. Are Our Policies Current and Aligned With Applicable Requirements?
Research security expectations have evolved through legislation, government-wide guidance, agency policies, and funding conditions. Depending on the sponsor, relevant areas may include disclosure requirements, foreign talent recruitment programs, research security training, supporting documentation, institutional certifications, information sharing, and risk assessment.
For example, the U.S. National Science Foundation implemented policy updates effective December 2, 2025, covering research security assessments, supporting documentation, training certifications, malign foreign talent recruitment programs, and certain institutional relationships. These requirements apply to NSF proposals and awards and should not be automatically treated as identical to those of every federal sponsor.
A periodic policy review can help determine whether institutional policies:
- Reflect current requirements from the agencies supporting the institution’s research.
- Clearly define responsibilities for researchers and institutional personnel.
- Address applicable foreign affiliations, appointments, support, and collaborations.
- Explain applicable restrictions involving malign foreign talent recruitment programs.
- Establish procedures for reviewing potential research security concerns.
Align related requirements across research administration, conflicts of interest and commitment, export compliance, and information security.
Because sponsor requirements and award conditions may differ, researchers and administrators also need to know where to locate the terms that apply to a particular proposal or award.
Technical accuracy alone does not make a policy effective. Institutions should also consider whether policies use clear language, provide practical examples, explain how to report questions or concerns, and identify appropriate points of contact.
2. Do Researchers Understand Their Disclosure Responsibilities?
Accurate and complete disclosure is a central part of research security. Depending on the sponsor and activity, disclosure obligations may address current and pending support, outside appointments, affiliations, in-kind contributions, foreign funding, and other resources or activities.
Researchers need clear guidance on:
- What information they must disclose.
- When disclosures must be submitted or updated.
- How requirements may differ among sponsors.
- Where institutional and federal disclosure obligations overlap.
- Whom to contact when they are uncertain whether an activity is reportable.
Providing a form or policy may not be enough. Researchers need sufficient context and examples to recognize activities, relationships, and resources that could trigger disclosure requirements.
Institutions may also consider whether their internal processes allow authorized personnel to compare relevant information across proposals, conflict-of-interest or conflict-of-commitment disclosures, outside activity reports, biographical sketches, current and pending support documents, and other institutional records.
Differences among records do not necessarily indicate wrongdoing. They may, however, identify information that requires clarification or correction.
3. Is Our Research Security Training Current and Relevant?
Training can help researchers and institutional personnel understand the purpose of research security requirements and apply them appropriately. Depending on the sponsor, award, and individual’s role, completing research security training may also be an applicable requirement.
For proposals subject to its updated policies, NSF requires research security training certifications from proposers and individuals identified as senior or key personnel. NSF permits training on cybersecurity, international collaboration, foreign interference, proper use of funds, disclosure, conflicts of commitment, and conflicts of interest. These policies became effective December 2, 2025.
Institutions should evaluate whether their training program:
- Reaches the individuals subject to applicable requirements.
- Addresses disclosure, collaboration, risk mitigation, and researcher responsibilities.
- Reflects current federal and institutional policies.
- Includes role-specific information where appropriate.
- Provides instructions for reporting questions or concerns.
- Allows the institution to document assignment and completion.
- Includes refresher training when appropriate.
A course completion record can demonstrate that training occurred, but readiness also depends on whether learners understand how the information relates to their work. Institution-specific examples, supplementary guidance, and accessible points of contact can help connect general training with local policies and procedures.
4. Can We Identify and Evaluate Collaborations That May Require Additional Review?
International collaboration makes important contributions to research and scientific progress. Research security should not create a presumption that international relationships are inherently inappropriate. NSF describes its approach as balancing research security with international collaboration while fostering transparency, disclosure, and practices consistent with research integrity.
At the same time, institutions need consistent and documented methods for identifying activities or relationships that may require additional review. Relevant considerations may include:
- The source and terms of foreign funding or support.
- Undisclosed affiliations or appointments.
- Participation in a foreign talent recruitment program.
- Access to controlled information, technology, equipment, or data.
- Foreign travel connected to a research activity.
- Potentially conflicting contractual, employment, or intellectual property obligations.
- Relationships involving entities subject to applicable federal restrictions.
An effective review should focus on relevant facts, applicable requirements, and documented risk factors. It should not rely on assumptions about an individual’s nationality, ethnicity, or country of origin.
Institutions should also define who conducts these reviews, how decisions are documented, when concerns are escalated, and what mitigation measures may be appropriate.
5. How Effectively Could We Document Our Research Security Practices?
Policies and procedures are only part of institutional readiness. An institution may also need to demonstrate how it implements them.
Relevant documentation may include:
- Current policies and standard operating procedures
- Training assignments and completion records
- Disclosure submissions and updates
- Reviews of relevant affiliations or collaborations
- Risk assessments and mitigation decisions
- Communications with researchers
- Internal escalation and reporting records
- Corrective actions and follow-up activities
Institutions should consider how efficiently they can retrieve records that demonstrate their policies, training, reviews, decisions, and follow-up actions. They should also assess whether records maintained by different offices provide a consistent account of the institution’s practices.
NSF, for example, requires proposers and recipients to maintain supporting documentation related to foreign appointments, employment with foreign institutions, foreign talent recruitment programs, and information reported as current and pending support for senior or key personnel. That documentation must be available to NSF upon request.
An institutional readiness review does not need to replicate a federal audit. It could begin with a representative sample of records, a process walkthrough, or a tabletop exercise involving the offices that would respond to a research security inquiry.
6. Do We Have a Clear Process for Addressing Potential Gaps?
Even a mature research security program may identify outdated disclosures, inconsistent records, unclear responsibilities, or training gaps. Finding a gap does not automatically establish deliberate wrongdoing. The institution’s response should nevertheless be consistent, timely, and appropriately documented.
A defined response process may address:
- Who receives and evaluates the concern.
- What information must be collected.
- Which institutional offices should participate.
- Whether a sponsor or agency must be contacted.
- What corrective or mitigating actions may be appropriate.
- How the institution documents its review and final decision.
- Whether the matter indicates a broader policy, training, or systems issue.
Institutions should distinguish among administrative errors, misunderstandings, policy violations, and matters that may require formal investigation. Applying the same response to every issue can create unnecessary burden and prevent the institution from concentrating resources on concerns that present greater risk.
Turning Readiness Questions Into Action
Research security readiness is not a one-time exercise. Institutions may need to revisit their programs as federal requirements change, funding portfolios evolve, and new forms of collaboration emerge.
A practical review can start with several actions:
- Identify the federal agencies supporting the institution’s research.
- Map applicable requirements to institutional policies and processes.
- Confirm who owns each research security responsibility.
- Review whether training reaches the intended audiences.
- Test whether relevant records can be located and reconciled.
- Establish a schedule for reviewing policies, training, and procedures.
- Provide researchers with clear guidance and accessible support.
The goal should not be to discourage legitimate international collaboration. It should help researchers pursue collaboration with appropriate transparency, awareness, and institutional support.
Supporting Research Security Education
CITI Program offers online Research Security courses for researchers, research administrators, compliance personnel, institutional officials, students, and other members of the research community. Training options address topics such as disclosure, international collaboration, risk mitigation, research security requirements, and researcher responsibilities.
Explore CITI Program’s Research Security courses to find training options that may support your organization’s education and training needs.
This article is intended for educational purposes and does not constitute legal or regulatory advice. Institutions should consult applicable agency requirements, award terms, institutional policies, and qualified counsel or compliance professionals when evaluating their responsibilities.