DoW / DoD requirements and timeline
Effective October 1, 2026, all senior / key personnel listed on DoW / DoD applications must certify that they have completed research security training within 12 months of the date of application submission.
Visit our Federal Transition and Policy Changes website for the latest updates and guidance.
Access the training by searching for “Research Security” in MyPath
Certain members of the University’s research community need to complete Research Security training. Learn more about the training program, including why it’s required and who needs to take it.
Topics on this page:
Per federal law (the CHIPS and Science Act of 2022) and regulations (NSPM-33), federal agencies are in the process of implementing research security training requirements. This training is intended to provide learners with information on research security risks and threats to the global research ecosystem — and the knowledge and tools necessary to protect against these risks. As federal agencies implement their research security training requirements, researchers will be required to certify to federal agencies that they have satisfied the agency’s training requirements.
Effective for NIH applications submitted for due dates on or after May 25, 2026, all senior/key personnel listed on an NIH grant application must certify to NIH that they have completed research security training within 12 months of the date of application submission.
In addition, all senior/key personnel who submit Other Support information to NIH (through Just-In-Time procedures, a Research Performance Progress Report (RPPR), or certain applications) must have completed research security training prior to submission. This training satisfies the NIH requirement that senior/key personnel complete training related to the disclosure of Other Support effective October 1, 2025.
Effective October 1, 2026, all senior / key personnel listed on DoW / DoD applications must certify that they have completed research security training within 12 months of the date of application submission.
To meet NSF certification requirements, all senior/key personnel (which include all PIs and faculty) identified in an application to NSF on or after October 10, 2025 must have completed Research Security training within one year prior to proposal submission.
To facilitate compliance, it is strongly recommended that all PIs and faculty currently engaged in NSF-funded research take this training by October 10, 2025.
To meet DOE certification requirements, all Covered Individuals (which include PIs and faculty) listed on DOE award applications as of May 1, 2025 must have completed Research Security training within one year prior to the date of an application to DOE.
Access the training by searching for “Research Security” in MyPath
Other federal funding agencies are in the process of implementing similar Research Security training requirements that apply to “Covered Individuals” (e.g. PIs, Co-PIs, project directors, senior/key personnel, and others identified as Covered Individuals by a federal funding agency). These requirements have not been finalized, and the Office of the Vice President for Research will update the research community as other agencies announce their requirements.
log into mypath
To access the training, search for “Research Security” in MyPath. The course will take approximately 1 hour and 35 minutes to complete.
The CHIPS and Science Act of 2022 (the “CHIPS Act”) requires that federal research agencies establish a requirement that each “Covered Individual” (discussed below) listed on a research application award certify to the agency as part of the application that they have completed research security training. It also requires that the University certify separately to the agency that such Covered Individual(s) have completed the training.
In response to the research security training mandate included CHIPS Act and in NSPM-33, the Office of Science and Technology Policy (OSTP) issued Research Security Program Guidelines (the “Guidelines”) in July 2024. The Guidelines provide the University must have a research security program that includes the following elements:
The Guidelines provide that the University must certify to federal agencies that it has implemented a research security training program for Covered Individuals and must certify to federal agencies that Covered Individuals have completed the training.
The U.S. government has defined “research security” as “safeguarding the research enterprise against behaviors aimed at misappropriating research and development to the detriment of national or economic security, related violations of research integrity, and foreign government interference.” Collectively, the laws, regulations, and University policies and procedures relating to research security aim to mitigate the threat to the U.S. research enterprise and individual researchers posed by parties who wish to take advantage of the culture of openness and collaboration of the U.S. research ecosystem. Research security training is designed to create awareness of, and protect against, these threats.
Per federal law, all Covered Individuals listed on applications for federal awards or otherwise designated by a federal agency will soon be required to complete research security training. Federal agencies are in the process of implementing their requirements.
During the period of October 1, 2025 through January 24, 2026, all senior/key personnel who submit Other Support information to NIH (i.e through Just-In-Time procedures, a Research Performance Progress Report (RPPR), or certain applications) must have completed research security training prior to submission. Completion will also satisfy the new NIH requirement relating to training on Other Support disclosures.
Beginning October 10, 2025, all senior/key personnel identified in NSF proposals must certify to NSF that they have completed research security training within one year prior to the proposal submission.
As of May 1, 2025, all Covered Individuals listed on DOE award applications must certify to DOE that they have completed research security training within one year of the application date. Additional Covered Individuals that later join a DOE award proposed on or after May 1, 2025 will also be required to take this training before participating in award activities.
A “Covered Individual” is defined by the CHIPS Act as “an individual who (a) contributes in a substantive, meaningful way to the scientific development or execution of a research and development project proposed to be carried out with a research and development award from a Federal research agency; and (b) is designated as a covered individual by the Federal research agency concerned.”
In practical terms, the vast majority of University faculty/investigators (e.g. PIs, Co-PIs, Senior Scientists, project directors, senior/key personnel etc.) who are conducting research efforts under a federal award are considered “Covered Individuals” under this definition. Federal agencies may expand the list of individuals designated as a “Covered Individual,” as specified in the applicable Notice of Funding Opportunity (NOFO) and/or terms and conditions of the federal award.
A transcript of the Research Security Federal Module is available here.
Approximately 1 hour and 35 minutes:
The “Research Security – Federal Module” is a one-hour, condensed training module of a four-hour research security training program previously developed by the National Science Foundation.
As of May 1, 2025, Covered Individuals on DOE award applications must have completed Research Security training within one year of the application date.
Beginning October 10, 2025, all senior/key personnel identified in NSF proposals must certify to NSF that they have completed Research Security training within one year prior to the proposal submission. Moving forward, applicable Covered Individuals must ensure that they have completed Research Security training within one year prior to the date of an application to DOE or NSF.
The Research Security Federal Module includes:
The Research Security University Module provides information on research security-related policies and concepts that are unique to the University of Rochester and includes information on:
The Office of Research and Project Administration (ORPA) is prohibited from submitting applications to NSF or DOE where applicable senior / key personnel or Covered Individuals have not satisfied their research security training requirements. Similar stipulations will apply to other federal proposals as applicable funding agencies implement their training requirements. The University will track training completion through MyPath.
Visit the University’s Research Security page. The University regularly updates and provides guidance on research security issues.
As the coordinator of several federal agency efforts relating to research security, the National Science Foundation also provides important information on research security issues.