Skip to content

Research Security Training

Access the training by searching for “Research Security” in MyPath

Certain members of the University’s research community need to complete Research Security training. Learn more about the training program, including why it’s required and who needs to take it.

Access the training in MyPath by searching for “Research Security”

Topics on this page:

Background

Beginning October 10, 2025, all senior/key persons identified in a proposal to the National Science Foundation (NSF) must certify to NSF that they have completed research security training within one year prior to the proposal submission.

As of May 1, 2025, all “Covered Individuals” (e.g. PIs, Co-PIs, project directors, co-project directors, senior/key personnel, project managers and others identified as Covered Individuals by the Department of Energy (DOE)) listed on DOE award applications must certify to DOE that they have completed research security training within one year prior to the application date. Additional Covered Individuals that later join a DOE award proposed on or after May 1, 2025 will also be required to take this training before participating in award activities.

Per federal law (the CHIPS and Science Act of 2022) and regulations (NSPM-33), other federal agencies are in the process of implementing similar Research Security training requirements.

NSF requirements and timeline

To meet NSF certification requirements, all senior/key personnel (which include all PIs and faculty) identified in an application to NSF on or after October 10, 2025 must have completed Research Security training within one year prior to proposal submission.

To facilitate compliance, it is strongly recommended that all PIs and faculty currently engaged in NSF-funded research take this training by October 10, 2025.

DOE requirements and timeline

To meet DOE certification requirements, all Covered Individuals (which include PIs and faculty) listed on DOE award applications as of May 1, 2025 must have completed Research Security training within one year prior to the date of an application to DOE.

Access the training by searching for “Research Security” in MyPath

Other federal agency training requirements

Other federal funding agencies are in the process of implementing similar Research Security training requirements that apply to “Covered Individuals” (e.g. PIs, Co-PIs, project directors, senior/key personnel, and others identified as Covered Individuals by a federal funding agency). These requirements have not been finalized, and the Office of the Vice President for Research will update the research community as other agencies announce their requirements.

Frequently asked questions

Why is research security training required?

The CHIPS and Science Act of 2022 (the “CHIPS Act”) requires that federal research agencies establish a requirement that each “Covered Individual” (discussed below) listed on a research application award certify to the agency as part of the application that they have completed research security training. It also requires that the University certify separately to the agency that such Covered Individual(s) have completed the training.

In response to the research security training mandate included CHIPS Act and in NSPM-33, the Office of Science and Technology Policy (OSTP) issued Research Security Program Guidelines (the “Guidelines”) in July 2024. The Guidelines provide the University must have a research security program that includes the following elements:

  1. Cybersecurity
  2. Foreign Travel Security
  3. Research Security Training
  4. Export Control Training

The Guidelines provide that the University must certify to federal agencies that it has implemented a research security training program for Covered Individuals and must certify to federal agencies that Covered Individuals have completed the training.

What is research security training?

The U.S. government has defined “research security” as “safeguarding the research enterprise against behaviors aimed at misappropriating research and development to the detriment of national or economic security, related violations of research integrity, and foreign government interference.” Collectively, the laws, regulations, and University policies and procedures relating to research security aim to mitigate the threat to the U.S. research enterprise and individual researchers posed by parties who wish to take advantage of the culture of openness and collaboration of the U.S. research ecosystem. Research security training is designed to create awareness of, and protect against, these threats.

Who needs to take research security training?

Per federal law, all Covered Individuals listed on applications for federal awards or otherwise designated by a federal agency will soon be required to complete research security training. Federal agencies are in the process of implementing their requirements.

Beginning October 10, 2025, all senior/key personnel identified in NSF proposals must certify to NSF that they have completed research security training within one year prior to the proposal submission.

As of May 1, 2025, all Covered Individuals listed on DOE award applications must certify to DOE that they have completed research security training within one year of the application date. Additional Covered Individuals that later join a DOE award proposed on or after May 1, 2025 will also be required to take this training before participating in award activities.

Other federal agencies are in the process of implementing similar Research Security training requirements. These requirements have not been finalized, and the Office of the Vice President for Research will update the research community as other agencies announce their requirements.

What is a “Covered Individual?”

A “Covered Individual” is defined by the CHIPS Act as “an individual who (a) contributes in a substantive, meaningful way to the scientific development or execution of a research and development project proposed to be carried out with a research and development award from a Federal research agency; and (b) is designated as a covered individual by the Federal research agency concerned.”

In practical terms, the vast majority of University faculty/investigators (e.g. PIs, Co-PIs, Senior Scientists, project directors, senior/key personnel etc.) who are conducting research efforts under a federal award are considered “Covered Individuals” under this definition. Federal agencies may expand the list of individuals designated as a “Covered Individual,” as specified in the applicable Notice of Funding Opportunity (NOFO) and/or terms and conditions of the federal award.

How do I access the training?
  • Open University of Rochester MyPath login page
  • Log in using your University of Rochester credentials
  • From the Home screen, use the search bar, type “Research Security” and press Enter
  • Click on the “Research Security Training” training that appears in the search results
  • Click “Request”
  • Click “Launch” on the first module and complete each of the three training modules in order
  • At the end of the third module, save or print the completion certificate for your records

A transcript of the Research Security Federal Module is available here.

How long will it take to complete the training?

Approximately 1 hour and 35 minutes:

  • Research Security Introduction: 5 minutes
  • Research Security – Federal Module: 1 hour to complete
  • Research Security – University Module: 30 minutes

The “Research Security – Federal Module” is a one-hour, condensed training module of a four-hour research security training program previously developed by the National Science Foundation.

How often will I be required to take this training?

As of May 1, 2025, Covered Individuals on DOE award applications must have completed Research Security training within one year of the application date.

Beginning October 10, 2025, all senior/key personnel identified in NSF proposals must certify to NSF that they have completed Research Security training within one year prior to the proposal submission. Moving forward, applicable Covered Individuals must ensure that they have completed Research Security training within one year prior to the date of an application to DOE or NSF.

What topics are included in the training?

The Research Security Federal Module includes:

  • an introduction to research security, including information on key federal regulations and the core values of academic research and their connection to research security
  • the importance of disclosure, including what disclosure is, the benefits of disclosure, the types of activities that should be disclosed, and consequences for failing to disclose activities
  • risk mitigation and management, including how to understand and mitigate risks associated with common international collaborative activities (such as sharing data or materials, or accepting an overseas appointment)
  • international collaboration, including engaging in international collaborations consistent with the core values of academic research

The Research Security University Module provides information on research security-related policies and concepts that are unique to the University of Rochester and includes information on:

  • The Faculty Conflict of Commitment and Interest Policy
  • Consulting activities
  • Simultaneous appointments
  • Foreign Talent Recruitment Programs
  • Disclosures to federal agencies
  • Research data and intellectual property
  • Information security
  • International visitors
  • International travel
  • Export control
  • The University’s research security program resources
What happens if I don’t complete the required training?

The Office of Research and Project Administration (ORPA) is prohibited from submitting applications to NSF or DOE where applicable senior / key personnel or Covered Individuals have not satisfied their research security training requirements. Similar stipulations will apply to other federal proposals as applicable funding agencies implement their training requirements. The University will track training completion through MyPath.

Where can I find more information research security issues?

Visit the University’s Research Security page. The University regularly updates and provides guidance on research security issues.

As the coordinator of several federal agency efforts relating to research security, the National Science Foundation also provides important information on research security issues.

Who may I contact for more information?
  • For substantive questions relating to research security, contact Joe Doyle (joe.doyle@rochester.edu), the University’s Research Security Officer.
  • For technical assistance relating to the research security training, contact mypathsupport@rochester.edu.