Hello, this is Ryuta Hamamoto from TIMEWELL.
"Has Japan suddenly decided to get strict about this?"
That question comes up in almost every conversation I have about research security. The answer runs the other way. Japan was one of the last to raise its hand, and that is not my impression, it is written down. The Cabinet Office procedures manual says that "ensuring research security constitutes a new undertaking for our country," and that Japan "has determined to carry out measures for ensuring research security equivalent to the advanced efforts of other countries"1. The government has documented, in its own words, that it is catching up.
This article lines up what the United States, Canada, the United Kingdom, France and Germany actually have in place, using primary sources, and then locates Japan on that map. If you work on international joint research, knowing what your counterpart takes for granted is every bit as practical as knowing how to fill in a form. For the regime as a whole, see the complete guide; for the Japanese procedure, due diligence in practice.
Why so many countries built such similar regimes at once
Before anything else, two terms that recur throughout this piece.
Research integrity covers the transparency and soundness of research activity, and Japan's procedures manual defines it as applying to "all research activities." Research security is far narrower: it applies to "research activities that the state or a research institution has determined should be protected"1. Integrity is the net you throw over everything. Security is the lock you fit to a small selection.
There is a reason the national regimes rhyme with one another. They share a blueprint. In June 2022 the G7 published the "G7 Common Values and Principles on Research Security and Research Integrity"2, produced by a working group under the G7 Science and Technology Ministers' Meeting known as SIGRE, with government and research community participants from each member country, Japan included. That document is the common design brief behind the regimes now running in each country.
It has two storeys. The ground floor holds seven common values for research integrity, among them academic freedom, institutional autonomy, open science, and transparency and disclosure. The upper floor holds eight principles for research security: balancing national and global interests; maintaining openness alongside security; collaboration and dialogue; proactive engagement; proportionality to risk; shared responsibility; accountability; and adaptability2.
That two-storey structure carries straight over into Japan's design. MEXT writes that "in ensuring research security, it is first important that researchers themselves and universities thoroughly implement measures for ensuring research integrity, namely securing transparency in research activities and autonomous risk management, as the foundation"3. Integrity first, security second, stated explicitly.
The single most quoted line in the G7 document is the one on shared responsibility: "no organisation can address research security alone"2. Japan's manual quotes the English phrase directly, then allocates roles across four layers: government, funding agencies, research institutions, and researchers1.
One more passage gets overlooked and should not be. The G7 document warns against overreaction in as many words: "disproportionate research security measures may lead to restrictions on science, academic freedom and openness. In the worst case, if researchers of a particular ethnicity are singled out, this could lead to racial profiling and the benefits of international collaboration could be lost"2. Tightening too much is presented as carrying the same weight of risk as not tightening at all. Skip that paragraph and you will end up operating a regime at odds with its own purpose.
The warning survives intact in the Japanese documents. Both the Cabinet Office manual and the MEXT material explicitly prohibit discriminatory treatment on grounds of nationality, race, religion, culture or the like13. What you look at is the content of the research and the relationships surrounding it, not attributes of the person. That is a structural commitment rather than a nicety, and when I help institutions write internal briefing material I put it on the first page.
Then there are the two slogans everyone reuses. Japan's manual cites "small yard, high fence" and "as open as possible, as closed as necessary" as the shared understanding across the major Western economies1. Fence a small garden and build the fence high. Stay open where you can, close only what you must. The starting position is that you do not try to protect everything, and Japanese practitioners deserve to hear that stated as plainly as their counterparts do.
If you want to know where your own export control arrangements currently stand before any of this, our free export compliance self-check is a quick way to find out.
Five countries, side by side
What follows draws on each government's primary sources together with the reference material appended to Japan's procedures manual, which notes that it is based on documents prepared by JST1.
The United States cuts by disclosure and by a dollar threshold
The American foundation is NSPM-33, the presidential memorandum of 14 January 2021 titled United States Government-Supported Research and Development National Security Policy4. Its backbone is disclosure: participants with a material effect on federally funded research must disclose affiliations, background and sources of support, and agencies were directed to develop policies on registration with digital persistent identifiers such as ORCID. Non-compliance can reach as far as termination of federal employment, contracts or awards, and suspension or debarment from federal funding.
The part that stands out most against Japan's approach is how institutional obligations are defined. Research institutions receiving more than 50 million dollars a year in federal science and engineering support must certify to funding agencies that they have established and operate a research security programme4. The design selects institutions by a monetary threshold, a very different instinct from Japan's programme-by-programme designation.
Building on that, on 5 June 2024 the NSF announced the TRUST framework, for Trusted Research Using Safeguards and Transparency5. It has three pillars: assessment of current appointments and positions, identification of non-compliance with disclosure requirements, and assessment of foreseeable national security considerations. The third is the genuinely new element. Roll-out is phased, starting with a fiscal 2025 pilot on quantum proposals applied after merit review, then the other critical technology areas named in the CHIPS and Science Act, then everything. An NSF official described it as a major step in shifting "from a culture of compliance to a culture of research security"5.
Support has moved in parallel with regulation. On 24 July 2024 the NSF announced 67 million dollars over five years for the SECURE centre, for Safeguarding the Entire Community of the U.S. Research Ecosystem6. It is led by the University of Washington with support from nine other institutions of higher education, and it serves as the nexus for five regional centres managed by six institutions of higher education6. Its role is to act as an information clearinghouse that equips the research community to identify and mitigate foreign interference. When MEXT describes this as an initiative setting up centres at six universities across the country3, it appears to be referring to those six institutions running the regional centres. Putting public money into shared infrastructure universities can actually use, rather than only writing rules for them, is the distinctively American move.
Canada runs on two public lists and an attestation
Canada operates in two stages. The National Security Guidelines for Research Partnerships, introduced in July 2021, require applications involving private sector partners to include a risk assessment form with a mitigation plan1. Funders first run an administrative risk review using open information and, where necessary, refer the file to national security agencies for advice. Notably, these guidelines do not designate specific countries or companies. Assessment is case by case.
The second stage is STRAC, the Policy on Sensitive Technology Research and Affiliations of Concern, in force since 1 May 20247. The government maintains two public lists, one of sensitive technology research areas and one of named research organisations, and applicants attest that no member of the research team involved in the funded activity is affiliated with, or receives funding or in-kind support from, a university, research institute or laboratory connected to military, national defence or state security entities that could pose a risk to Canada's national security7.
Public Safety Canada also runs a Research Security Centre advising universities, and federal funding has placed research security offices at a number of them, staffed with people experienced in intelligence analysis who review declarations1. Government publishes the lists, applicants attest, funding agencies decide. Of the five countries, this is the most procedurally legible arrangement.
The United Kingdom started with awareness and left the decision with universities
Britain's sequence is unlike the others. What came first was not regulation but a campaign. In 2019 the National Protective Security Authority and the National Cyber Security Centre launched Trusted Research, building out guidance for researchers, for senior leaders, on travel and international conferences, and as a checklist for starting international collaborations1. The repeated emphasis on advice being developed in consultation with universities and the research community is very much in character.
For advice on live cases, the Department for Science, Innovation and Technology hosts RCAT, the Research Collaboration Advice Team8, which advises institutions on national security risks in international research through a nominated contact at each one, usually the research office. MEXT's material counts five such locations across the country3.
On the statutory side, the National Security and Investment Act 2021 imposes mandatory notification for acquisitions in sensitive sectors9, which touches research security in the context of university spin-outs and acquisitions of research assets. UKRI, as a funder, expects universities to put risk assessment arrangements in place for international collaboration, and in some fields it assesses suitability and attaches mitigation measures as conditions1.
On top of all that, the UK states plainly that the final decision rests with universities as independent institutions1. Government advises, universities decide. Britain is the only one of the five that draws that line so explicitly.
France locks the place, not the project
The French regime has a different texture altogether. It runs under a framework called PPST, protection du potentiel scientifique et technique de la nation, grounded in article 413-7 of the penal code and operated through three instruments: decree no. 2011-1425 of 2 November 2011, the prime ministerial order of 3 July 2012, and the interministerial circular of 7 November 201210. Four harms define what is protected against: damage to France's economic interests, strengthening of a foreign country's armaments or weakening of national defence, contribution to proliferation of weapons of mass destruction and their delivery systems, and use for terrorist purposes. What gets protected is the most sensitive knowledge, expertise and technology where those threats could materialise10.
At its centre sits the ZRR, the zone à régime restrictif, or restricted zone. The state designates highly sensitive laboratories and comparable facilities as restricted zones, and both physical access and logical access through information systems require authorisation from the responsible minister10. Research institutions appoint security officers who run the regime with ministry counterparts, and on the funding side the Agence Nationale de la Recherche seeks a determination from the minister responsible for higher education where a candidate project involves international or industrial collaboration1.
Regulating by location rather than by programme or person, and wiring that regulation into the criminal law, is what makes France singular. Set against a Japanese manual that is explicitly guidance, it feels notably hard-edged. This is the country that built the high fence as an actual, physical fence.
Germany built it as an extension of research ethics
Germany has a national security strategy and a China strategy at government level, and the ministry responsible for research has published a position paper on research security1. The machinery that actually runs, though, sits in the academic community.
The DFG, Germany's main research funder, asks applicants to calls involving international collaboration to submit an additional self-assessment of research risks, based on its recommendations for dealing with risks in international cooperation1. Does the partner institution conduct research for military purposes? Is systematic data exfiltration foreseeable? Does the topic carry dangerous applications? What is the state of academic freedom in the partner country? Rather than drawing red lines around particular countries, the design forces the applicant through a step of reflection.
A second, separate mechanism sits alongside it. Recommendations on handling security-relevant research, introduced in 2014 by the German National Academy of Sciences Leopoldina with the DFG and revised in 2022, have led more than 120 German research institutions and learned societies to establish KEFs, committees on ethics in security-relevant research1. These interdisciplinary committees, including specialists in ethics, law and the humanities, advise on research areas carrying misuse risk. This is the academic community running the system itself rather than government pushing it down.
Of the five, Germany is the only one that arrives at research security through the tradition of dual-use research ethics, a concept I explain in what are dual-use items. Reading these documents side by side, what struck me was how much a regime's shape depends on which door a country walked in through: export control produces one thing, research ethics quite another, even when the vocabulary matches.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Four differences that actually matter in practice
Line the five countries up and the differences are more useful than the similarities. Four stand out to me.
First, who makes the final call varies by country. The UK places final decision-making with universities. Canada has funding agencies decide, referring to national security bodies where needed. In the US, the adequacy of mitigation measures is settled through discussion with the university. Japan has funding agencies and the supervising ministry confirm whether responses are sufficient and request more where they are not1. Where that centre of gravity sits is a fertile source of mismatched assumptions when you sit down with an overseas partner.
Second, whether a country maintains its own list of entities of concern. Canada publishes two: sensitive technology research areas, and named research organisations. Japan's manual, by contrast, defines "lists" as exactly two documents, METI's End User List and the United States consolidated screening list, and maintains no research-security-specific list of its own1. It began operating by borrowing lists that already existed.
Something has to be said alongside that. Appearing on any of these lists is a regulatory designation, not a judgment about the merits of the institution or the individual named. The manual is built so that meeting a verification item does not lead directly to exclusion; what it asks for is reasonable handling proportionate to the degree of risk, having first limited the technologies in scope1. It does not ask for zero risk, and running it as though it did would collide with the G7 warning quoted earlier. That point deserves repeating inside institutions, because it is the one most easily lost between the document and the desk.
Third, what unit each country narrows by. The US cuts institutions by a dollar threshold, France designates places, Canada cuts by lists of technology areas and organisations, Japan by designating programmes. The instruments differ completely, and yet none of them tries to protect everything. Small yard, high fence turns out to be less a single policy than a shared instruction each country implemented with whatever administrative machinery it already owned.
Fourth, which tradition each country connected from. The US and Canada came in through national security and funding conditions, France through criminal law and defence, the UK through awareness-raising and advice, Germany through research ethics. Same principles at the base, radically different structures on top, because each was grafted onto an existing regime. That, I suspect, is why lifting one country's approach wholesale into Japan tends not to work.
Where Japan stands: a late arrival, and reciprocity
With all that in view, Japan's position becomes easier to read.
In December 2025 a Cabinet Office expert panel finalised the "Procedures Manual for Ensuring Research Security"1. It takes the form of guidelines to be complied with rather than legislation, and states the reason: "because among G7 countries and other like-minded partners it is common to formulate guidelines rather than legislation"1. Even the choice of instrument is an act of alignment.
Scope is limited to Specified Research and Development Programs: competitive research funds premised on publication of results, which may involve technologies falling within the critical technology areas list, and which the supervising ministry has designated in consultation with the funding agency as particularly requiring prevention of technology leakage from an economic security standpoint1. In practice, application begins with five CREST research areas within JST's Strategic Basic Research Programs, and with the Acquisition, Technology and Logistics Agency's innovative science and technology initiative for security. One clarification, because this trips people up: only those five CREST areas are designated. Within the same Strategic Basic Research Programs, PRESTO and ACT-X are not in scope. Application starts with newly selected projects in FY2026. I traced how the designation came about in how research security became a condition of application.
The procedural skeleton is worth holding in mind. Risk management runs in four steps: risk verification, risk assessment, risk mitigation measures, and follow-up1. The entry point is due diligence, meaning advance checks on the background of a collaboration counterparty and of the parties themselves, and it runs to 13 verification items: education, research and employment history, funding received, support other than research funds, authorship position on published papers, patent applications, participation in foreign talent recruitment programmes, disciplinary history under the relevant guidelines, appearance on a list, affiliation with a listed institution, relationships with researchers at listed institutions, applicability of "non-resident" or "specified categories" status under security export control, and anything else the funding agency deems necessary. Items 3 to 8, plus items 10 and 11, cover the three years up to and including the year of application1. The people in scope are the PI, Co-PIs and research participants at the lead institution, students included1. I walk through the whole form in how to answer a research security questionnaire.
The "specified categories" item deserves a note of its own, because it is regularly misread. It classifies situations in which someone is under strong influence from a foreign government or corporate body, so that transfers of technology even to a resident may need a licence. METI states plainly that the categories are simply a way of grouping cases that require individual screening, and that falling within one does not mean the person is regarded as a security concern. Meeting the item and having a problem are two different things.
The manual is also clear about where responsibility lands. False declarations can be treated as improper receipt of funds, with consequences including restrictions on future applications. But where an institution has done what was required and a leak nonetheless occurs, the manual states that institutions and researchers do not bear responsibility for that outcome1. Do the work and you are not held to a result you could not guarantee.
One thing remains unsettled, and I would rather say so. The critical technology areas list that scope determinations are supposed to rely on has not yet been produced. Until it exists, the manual substitutes the 20 technology areas set out in the Basic Policy on Promotion of Research and Development of Specified Critical Technologies, adopted by cabinet decision on 30 September 20221: biotechnology, medical and public health, AI and machine learning, advanced computing, microprocessors and semiconductors, and more. A regime running while its central list is still unwritten is, accurately described, still taking shape.
And now the part I most want to get across: reciprocity.
MEXT defines its first category of programmes requiring research security measures as "research and development programmes where, in international joint research with countries sharing common values, measures equivalent to those of the counterpart country are required"3. It adds that "in conducting joint research with other countries, cases have begun to arise in which counterparts ask about the Japanese side's research arrangements"3.
This is not a story about domestic regulation. It is a story about not being admitted to the collaboration unless your counterpart can verify that you do something equivalent. The manual points the same way, explaining its purpose as demonstrating to the international community that Japan implements these measures, thereby building mutual trust with G7 countries and other like-minded partners and allowing international joint research to continue smoothly1. It adds that where a foreign research institution asks for research security measures, conducting risk management in line with the manual may be considered1. The reach extends well past the designated programmes.
Honestly, I think this is the real substance of the whole exercise. The paperwork is not there to satisfy a Japanese regulator. It is there to keep a seat at the international table. Received as a compliance burden, the regime is hard to accept. Received as an entry requirement, the reason to do it becomes obvious. For what it is worth, in the country examples annexed to the G7 best practices document of February 2024, the card Japan had to play was a checklist11. Going from there to a full procedures manual in under two years is, if anything, a fast catch-up. For related domestic developments, see Japan's security clearance regime.
The lists update on different schedules, in different languages
Turn this comparison into daily practice and one problem dominates.
Canada maintains its two lists. The US maintains the consolidated screening list. Japan maintains the End User List. Japan's due diligence items include whether a person appears on a list, whether they belong to a listed institution, and whether they have relationships with researchers at listed institutions, with the latter two covering the past three years including the year of application1. The manual adds that because entities not themselves listed may be caught where they are owned by listed entities or individuals, confirming ownership relationships is also desirable1.
So the practical task is to track several lists from several countries, each on its own update cycle, each with its own transliteration variants. And the population you are checking is not just the PI. It includes Co-PIs and research participants, students among them. The manual even specifies what "relationships" means: conducting joint or commissioned research, writing and publishing co-authored papers, and appearing as a named co-presenter at conferences1. Trace relationships to that depth and simple name matching stops being sufficient.
The bar is not unlimited, though. Due diligence may be carried out "using self-declared information, open source information and other information that each lead institution can ordinarily obtain"1. Nobody is asking universities to run investigations. The manual names the usable tools, from paper and patent databases to e-Rad, researchmap and the two lists, then adds that "where the information gathered using these tools alone makes adequate due diligence difficult, using commercial information analysis tools or commissioning investigations from firms may also be considered"1.
What we have built at TRAFEED lands squarely on that last sentence. It began as an AI agent for Japan's security export control regime, covering both list and catch-all controls, built on a knowledge graph of more than 200 million records, roughly 90 million papers, roughly 100 million patents and roughly 300,000 researchers, connected to corporate registries and national sanctions lists. As an AI agent in this field it is the first of its kind worldwide, as confirmed by our own research as of March 2026. In a joint validation with Okayama University using around 30,000 past screening records, AI determination accuracy exceeded 95 percent, on our own measurement. The technology holds Japanese Patent No. 7862062, and more than 20 organisations use it.
Lists updating on different schedules in different languages is a problem we have lived with on the export control side for years, which is why we extended from researcher information into shareholder and capital relationship research. Support for research integrity and research security is an area we are actively developing, and I am not going to claim it as shipped. The caveat that matters most: the final determination belongs to the research institution, or in a company's case to its export control officer. What we can do is assemble the material and leave it in a form that can explain, later, why a conclusion was reached.
What to take away
- The common values and principles the G7 agreed in June 2022 are the shared foundation under every national regime. At the centre sit shared responsibility, and the idea that openness and security are complementary
- The shared slogans are small yard, high fence and as open as possible, as closed as necessary. No country is trying to protect everything
- The centre of gravity for decisions differs. The UK puts it with universities, Canada with funding agencies, Japan with funding agencies and the supervising ministry
- Japan maintains no research-security-specific list of entities of concern and started by borrowing two existing lists. The critical technology areas list is unwritten, with 20 cabinet-decided technology areas standing in
- Reciprocity is the operational heart of this. Being able to show equivalent measures is becoming a condition of continued participation in international joint research
Reading these regimes side by side, the passage that stayed with me was the G7 warning. Overreaction is written up as carrying risk comparable to inaction. The people who designed the system built a brake into it, and losing that brake at the point of operation would be a waste of good drafting.
So my suggestion is narrow. Before you write another internal rule, find out what your counterpart country actually requires and what it assumes. Half the anxiety in this field comes from imagining a stricter world than the documents describe.
If you are working out where to start at your own organisation, talk to our TRAFEED team.
References and primary sources
Footnotes
-
Expert Panel on Ensuring Research Security and Research Integrity, "Procedures Manual for Ensuring Research Security," December 2025 (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/yushikisha/guidelines_v1.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33
-
G7 SIGRE Working Group, "G7 Common Values and Principles on Research Security and Research Integrity," June 2022 (Japanese provisional translation, Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/g7_sigre_values_jpn.pdf ↩ ↩2 ↩3 ↩4
-
MEXT, Science, Technology and Innovation Policy Bureau, "Direction of Concrete Measures on Research Security in MEXT-Related Programmes for Universities and Other Institutions," 18 December 2024 https://www.mext.go.jp/content/20241218-mxt_kagkoku-000039402_1-1rrr.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
The White House, "Presidential Memorandum on United States Government-Supported Research and Development National Security Policy" (NSPM-33), 14 January 2021 https://trumpwhitehouse.archives.gov/presidential-actions/presidential-memorandum-united-states-government-supported-research-development-national-security-policy/ ↩ ↩2
-
U.S. National Science Foundation, "NSF enhances research security with new TRUST proposal," 5 June 2024 https://www.nsf.gov/news/nsf-enhances-research-security-new-trust-proposal ↩ ↩2
-
U.S. National Science Foundation, "NSF-backed SECURE center will support research security," 24 July 2024 https://www.nsf.gov/news/nsf-backed-secure-center-will-support-research ↩ ↩2
-
Government of Canada, "Sensitive Technology Research and Affiliations of Concern" (STRAC) https://science.gc.ca/site/science/en/safeguarding-your-research/guidelines-and-tools-implement-research-security/sensitive-technology-research-and-affiliations-concern ↩ ↩2
-
UK Government, "Research Collaboration Advice Team" (RCAT) https://www.gov.uk/government/organisations/research-collaboration-advice-team ↩
-
UK Legislation, "National Security and Investment Act 2021" (2021 c.25) https://www.legislation.gov.uk/ukpga/2021/25/contents ↩
-
ANSSI (French National Cybersecurity Agency), "Protection du potentiel scientifique et technique de la nation (PPST)" https://cyber.gouv.fr/reglementation ↩ ↩2 ↩3
-
G7 SIGRE Working Group, "G7 Best Practices for Secure and Open Research," February 2024 (Japanese provisional translation, Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity/g7_sigte_practices_jpn.pdf ↩
