TRAFEED

What Is NSPM-33? A Beginner's Guide to the US Research Security Framework, Its 2026 Deadlines, and the Due Diligence It Requires

Published2026-07-26Ryuta Hamamoto

A plain-language guide to NSPM-33, the US National Security Presidential Memorandum-33, written for researchers, research administrators and compliance staff. It covers the four elements of a research security program, the annual 50-million-dollar threshold, the deadlines phasing in across 2025 and 2026, the due diligence and list screening required to comply, and how Japan is building a parallel framework behind the United States, plus how TRAFEED is preparing for this territory, all grounded in official primary sources.

What Is NSPM-33? A Beginner's Guide to the US Research Security Framework, Its 2026 Deadlines, and the Due Diligence It Requires
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

When I talk with university research administration offices, URAs and industry-academia liaison staff, one comment has come up more and more over the past year or two: "Our US collaborators have started asking us for paperwork we never had to submit before." One of the regimes sitting behind that shift is the subject of this article, NSPM-33.

The name alone looks forbidding, but the substance is surprisingly simple. In this article I will start from what NSPM-33 actually is and why it came into being, then move to what it concretely asks of research institutions, what falls due and when across 2026, and what investigation you will actually need to carry out in order to comply. I will follow the official primary sources in order and unpack the jargon as I go, so that a researcher, research administrator or compliance officer can follow the thread even on a first read.

At the end, having established that the United States moved first and that Japan is building a framework in the same direction, let me also explain how we are preparing for this territory with TRAFEED.

One note on method. I will state dates and figures as fact only where I could confirm them in official primary sources, and where I could not, I will say plainly "confirm with the official source." Research security is not about condemning a counterpart or a regime. It is about the procedures that let legitimate research continue, and I will keep that posture throughout.

What NSPM-33 is

NSPM-33 stands for National Security Presidential Memorandum-33. Issued on 14 January 2021, it is a US presidential memorandum aimed at strengthening the security of federally funded research1.

A presidential memorandum is a document by which the president directs policy to the federal agencies. It is not a statute, but because the departments and agencies build their own rules to conform to it, its practical weight is comparable to that of law.

The background to NSPM-33 is the tension between the principle of openness in science and technology and the newer environment of economic security. Publish results widely and collaborate across borders with a diverse set of partners. That open research environment is precisely what has driven science forward, and it remains a value worth protecting. At the same time, once leadership in science and technology became an input directly tied to a nation's economy and security, it became necessary to look at the risk that parts of that open environment might be used in unintended ways.

The important point here is that NSPM-33 is not a regime that says "let us stop doing open research." Quite the opposite. In order to keep open research going, it makes the source of funding and the identity of collaborators transparent and verifies only what needs to be verified. Understanding it as a regime built on that logic makes the whole picture easier to grasp. Nor does it single out any particular country or researcher as dangerous. It is constructed so that whoever the person is, and wherever they are from, they go through the same procedure.

What NSPM-33 asks of research institutions

So what does NSPM-33 ask of research institutions? The pillar is the establishment of a research security program.

NSPM-33 requires research institutions receiving more than 50 million dollars a year in federal science and engineering (S&E) support to certify to their funding agencies that they have established and operate a research security program1. This threshold of more than 50 million dollars and the certification framework are set out in Section 4(g) of NSPM-33, and can be confirmed on the official page of the US National Science Foundation (NSF) as well1.

As the "more than 50 million dollars a year" scale suggests, the institutions in scope are the research universities and similar bodies that take in large volumes of federal funding. Rather than imposing certification uniformly on every research institution, the design asks the larger players to build out their systems first.

The substance of a research security program was fleshed out by the text of NSPM-33 and by the implementation guidance that OSTP (the Office of Science and Technology Policy) and NSTC (the National Science and Technology Council) subsequently published on 4 January 20221. It is generally organised into the following four elements.

# The four elements of a research security program What it covers
1 Cybersecurity Information security measures to protect research data and systems
2 Foreign travel security Protecting information and devices on overseas trips, managing travel records
3 Research security training Awareness-raising and training for researchers and students
4 Export control training Understanding and communicating export control regulations and procedures

These four elements derive from the text of NSPM-33 and the OSTP/NSTC implementation guidance of 4 January 2022. That said, the NSF official page does not lay the four elements out in an explicit enumerated list, so I recommend confirming the exact scope of each element against the implementation guidance itself and against each funding agency's rules. In this article too, please read the four-element framework as widely cited but with the details best confirmed at the source.

Put loosely, it helps to think of it as four pillars: a mechanism to protect information (cyber), a defence for when people move (travel), a mechanism to develop people (training), and a mechanism to comply with the law (export control education).

The fact that export control is one of the four elements is not something universities can overlook. Whether the technology handled in the course of research could be subject to export control comes up without fail in joint research and in accepting international students. For anyone who wants to quickly check whether their own organisation's technology or transactions might touch export control, our free export control self-check should help you establish where you stand, and should sharpen the resolution of the discussion that follows.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What falls due in 2026

This is probably the point most people care about most. But let me be honest: if you rely only on official primary sources, organising the dates requires some care.

First, let me line up the fixed dates I could confirm officially.

  • Mandatory research security training took effect on 2 December 2025. This is based on the NSF Important Notice (IN-149) issued on 10 July 20252.
  • On malign foreign talent recruitment programs (MFTRP), the ban on participation by senior and key personnel took effect on 20 May 2024, and annual certification by PIs (principal investigators) and co-PIs began on 7 June 20252.

On top of that comes the other main subject of this article, the research security program certification for institutions above 50 million dollars. This is designed to phase in, based on the Research Security Programs Standard Requirement that OSTP published on 9 July 2024, once it has been incorporated into each funding agency's policies3. Implementation is expected to fall in 2026, but the exact date for institutional certification must be confirmed against each funding agency's rules, such as the NSF PAPPG (Proposal and Award Policies and Procedures Guide).

Here I want to make one thing clear. A specific deadline of "July 2026" is sometimes cited, but in this round of official primary source checking I could not substantiate that date. It is probably easy to confuse it with one of the "July dates" in the record, such as 10 July 2025, when NSF issued Important Notice IN-149, or 9 July 2024, when OSTP published the standard requirement.

Accordingly, this article does not assert an exact date by which institutions above 50 million dollars must complete their research security program certification. Be sure to confirm this against each funding agency's latest rules. Conversely, what is fixed, such as the 2 December 2025 effective date for research security training and the 7 June 2025 start of MFTRP annual certification, are the parts you can prepare for with confidence.

As for the legal underpinning of the regime, the CHIPS and Science Act of 2022 is the relevant statute. Provisions on research security are placed within that Act, and it is said to set out research security policy, requirements relating to foreign talent recruitment, and a ban on participation in malign foreign talent recruitment programs4. For the individual section numbers (roughly Sections 10631 to 10638 are cited), I recommend a final check against the statutory text.

What investigation compliance actually requires

With the overall picture in view, we can move to the most practical question: what does the front line actually need to investigate? Let me line up the verification items that NSPM-33 and related regimes require, from the perspective of a university or research institution.

1. Organising researcher disclosures For each individual researcher, get to a state where you can disclose, without gaps, outside research funding, affiliated institutions, titles, foreign travel, and in-kind support. In the United States, to standardise this disclosure, use of the SciENcv (Science Experts Network Curriculum Vitae) electronic CV system and the federally unified Common Forms (specifically the Biographical Sketch and the Current & Pending (Other) Support) is being promoted34. When a Japanese university conducts joint research with a US partner, submission in these formats may be requested.

2. Due diligence on collaborators and researchers For the counterparty in a joint research relationship, verify the institution's funders and control relationships and the counterpart researcher's background. "Due diligence" may be an unfamiliar term, but in essence it means "properly investigating, before a transaction or collaboration, who the counterpart is, and with whom and how they are connected."

3. List screening Match researchers and counterpart institutions against each country's regulatory lists to check whether they appear on them. In Japan the representative example is METI's End User List, and in the United States it is the consolidated screening list (which bundles together the Entity List, the SDN List and others). The important point here is that you need to trace not just the name that appears on a list, but the relationship between that counterpart and the subject. There are situations where the researcher in front of you appears on no list at all, yet following their co-authors or joint research ties leads to a listed institution, and that has to be checked.

4. Confirming applicability of malign foreign talent recruitment programs (MFTRP) Confirm that a researcher does not participate in a foreign talent recruitment program treated as problematic under the regulations, with PIs and co-PIs certifying this annually. As noted above, this annual certification began on 7 June 20252.

5. Building out the four elements and managing training records For the four elements of cybersecurity, foreign travel security, research security training and export control training, build out the systems and keep records of who received training and when. Given that research security training became mandatory (effective 2 December 2025), you will want to systematise the management of training records early2.

6. Confirming applicability of deemed export (Foreign Exchange and Foreign Trade Act) This is a point specific to Japanese universities. Under Japan's Foreign Exchange and Foreign Trade Act (the Foreign Exchange Act), even within the country, providing sensitive technology to a person who is in a position under strong influence from a foreign government or entity can be subject to export control licensing. In labs that accept many international students and foreign-national researchers, this check is indispensable. The specific procedures for deemed export and university export control are set out in University Export Control and Deemed Export, which you may want to read alongside this.

7. Determining whether you are subject to certification Determine whether your own institution receives more than 50 million dollars a year in federal science and engineering support, that is, whether it falls under the NSPM-33 certification requirement, and keep continuously tracking the latest policies and important notices from NSF and other funding agencies.

You will notice that almost none of this is a one-off task. Regimes get updated, and researcher affiliations and joint research relationships shift. It is closer to reality to see NSPM-33 compliance not as "set it up once and you are done," but as an operation you keep tracking.

We have developed TRAFEED precisely as a mechanism to support this work of investigating, recording, and continuously tracking, the same work involved in export control classification and counterparty screening. Research security due diligence feels to me like a territory where this challenge appears in a purer form.

The United States moved first, and Japan is preparing in the same direction

We have looked at the US regime so far, but this is not "only an American story." Japan is building a framework in the same direction.

Lining up Japan's moves chronologically makes the structure clear. First, in December 2021, the Integrated Innovation Strategy Promotion Council of the Cabinet Office adopted its "Policy on Ensuring Research Integrity," building a system that asks researchers to disclose outside funding, affiliations, conflicts of interest and the like5. "Research integrity" refers to the conduct required of researchers and institutions in order to maintain the soundness, fairness and transparency of research, so the process began with building that foundation.

Next, in May 2022, the clarification and strengthening of deemed export management under the Foreign Exchange Act took effect. This reorganised as subject to licensing the provision of sensitive technology to those in a non-resident-like position within the country, specifically to categories that include residents under strong influence from a foreign government or entity6.

And then there is the flow that some readers have pointed out to me, the preparation of a Cabinet Office "Procedures Manual for Ensuring Research Security" (said to be dated Reiwa 7, that is, December 2025). However, for this manual, I could not pin down the corresponding Cabinet Office page and confirm its official title, publication timing and content in this round of primary source checking. In terms of direction, the structure is consistent: the United States moved first with NSPM-33, and Japan is progressively strengthening its framework of disclosure, due diligence and education, moving from "research integrity" to "research security." For the manual's official title and content, the surest approach is to confirm against the source at the Cabinet Office CSTP (www8.cao.go.jp/cstp)7.

Laid out this way, you can see the United States and Japan facing the same challenge with the same kinds of procedures, offset in time. Organise disclosure, verify the counterpart, provide education, keep records. The names and details of the regimes differ, but the information base they require overlaps to a striking degree. Understanding this structure reveals that investment made to comply with one regime pays off for the other as well.

For readers who want to know a bit more about Japan's research security framework, I would also point you to Research Security Due Diligence, which organises the due diligence the Cabinet Office manual requires; The Basics of Research Integrity and Research Security, where you can gently confirm the concepts themselves; and A Comparison of Research Security Regimes Across Countries, which lines the different national regimes up side by side.

Let me offer my own view here. For Japanese universities, research security is a matter of "defence," but it is at the same time a matter of the "admission ticket." Given that the partner countries in joint research have their procedures in place, there will be situations where, if we do not have ours in place, we simply become less likely to be chosen as a research partner in the first place. Rather than shrinking back and reducing international joint research, the best fit for reality is to see this as preparation for continuing that research with confidence.

How we are preparing with TRAFEED

Finally, let me talk about our own work.

TRAFEED is a service we have developed as an AI agent for export control. At its centre are classification (determining whether the technology being handled falls under export control) and the investigation of counterparties and other parties. We have confirmed, through our own (internal) research as of March 2026, that it is the world's first AI agent in Japan's security export control domain (list regulations and catch-all regulations)8.

Looking over the investigation items that NSPM-33 and Japan's research security require, what struck us strongly is that export control and research security overlap deeply on a single point: confirming who the counterpart is, and with whom and how that counterpart is connected. The names of the regimes differ, but the information base they need is almost the same.

Concretely: back-checks on researchers and collaborators, verification of international students and new business counterparties, research into the information of researchers, shareholders and funders, and screening against various lists, including Japan's End User List and the US consolidated screening list. These map directly onto the mechanisms TRAFEED has built up for export control. In particular, the work of tracing not just names themselves but co-authorship and transaction relationships as a network in order to surface whether a relationship exists tends to reach volumes that are unrealistic by hand, and that is exactly the part we want to support with technology.

I want to emphasise that this is not about handing judgment to a machine. Just as the final classification decision in export control is made by each organisation's export control officer, in research security too the final judgment is made by the research institution's export control and research security officers. TRAFEED's role is to assemble the material behind that decision, completely, with sources attached, in a short time, and to leave a trail that can later explain why the conclusion was what it was. Building an audit-ready record is a part we designed in from the very beginning on the export control side.

One note: we sometimes cite a figure of "95% or higher" for the accuracy of TRAFEED's investigation support, but this is the result of an internal study using past screening data, and it is a figure premised on the final classification and risk assessment in actual operation being made by each organisation's officer. Just as the regime itself is not "something for condemning counterparts or researchers," we think of our tool, too, as something for supporting the parties who are continuing to conduct legitimate research and transactions.

Summary

Let me line up the key points to hold onto about NSPM-33 and research security.

  • NSPM-33 is a US presidential memorandum issued on 14 January 2021. It requires research institutions receiving more than 50 million dollars a year in federal science and engineering support to establish a research security program and certify it to their funding agencies
  • A research security program is said to comprise four elements: cybersecurity, foreign travel security, research security training and export control training (the details are best confirmed against the implementation guidance itself)
  • Fixed dates include research security training becoming mandatory (effective 2 December 2025) and MFTRP annual certification beginning (7 June 2025). Certification for institutions above 50 million dollars is expected to fall in 2026, but a specific date such as "July 2026" needs to be confirmed officially
  • The investigation required for compliance is wide-ranging: organising disclosures, due diligence on collaborators, list screening, confirming MFTRP applicability, building out the four elements, confirming deemed export, and determining certification applicability, all premised on continuous tracking
  • The United States moved first, and Japan is building its framework in the same direction, from research integrity to deemed export to research security. It is defence, and at the same time preparation for continuing international joint research

There remain parts of the dates and section numbers that need confirmation, but the direction is clear. Verify the counterpart, organise disclosure, keep records. If you are unsure how to run that work, please reach out to our TRAFEED team. The features for research security are still at the stage of being grown, so hearing what is actually causing difficulty on the ground would be genuinely valuable to us.

References and primary sources

Footnotes

  1. National Science Foundation, "Research Security" (including the issuance of NSPM-33 on 14 January 2021, the research security program certification for institutions above 50 million dollars a year under NSPM-33 Section 4(g), and the OSTP/NSTC implementation guidance of 4 January 2022) https://www.nsf.gov/research-security 2 3 4

  2. National Science Foundation, "Research Security" and Important Notice IN-149 (mandatory research security training effective 2 December 2025 / IN-149 issued 10 July 2025; MFTRP ban on participation by senior and key personnel effective 20 May 2024; annual certification by PIs and co-PIs beginning 7 June 2025) https://www.nsf.gov/research-security 2 3 4

  3. OSTP (Office of Science and Technology Policy), "Research Security Programs Standard Requirement," published 9 July 2024. The research security program certification for institutions above 50 million dollars is designed to phase in after being incorporated into each funding agency's policies based on this standard requirement. Specific institutional certification deadlines should be confirmed against each funding agency's rules (NSF PAPPG, etc.). Note: at the time of writing, direct retrieval of the source text was partly restricted, and details are best reconfirmed against the source 2

  4. CHIPS and Science Act of 2022 (Subtitle D, Research Security, roughly Sections 10631 to 10638; research security policy, requirements relating to foreign talent recruitment, ban on participation in malign foreign talent recruitment programs, etc.). For disclosure practice, use of SciENcv and the federally unified Common Forms (Biographical Sketch / Current & Pending (Other) Support) is being promoted. Section numbers are best confirmed against the statutory text 2

  5. Integrated Innovation Strategy Promotion Council, "Policy on Ensuring Research Integrity Against New Risks Accompanying the Internationalisation and Opening of Research Activities," December 2021 and others (Cabinet Office) https://www8.cao.go.jp/cstp/kokusaiteki/integrity.html

  6. METI, Trade Control Department, Security Export Control Policy Division, "On the Clarification of Deemed Export Management" (applied from May 2022) https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf

  7. Cabinet Office, Council for Science, Technology and Innovation (CSTP), "Research Integrity" portal. The official title, publication timing and content of the document said to be the Cabinet Office "Procedures Manual for Ensuring Research Security (December 2025)" should be confirmed against the source https://www8.cao.go.jp/cstp/kokusaiteki/integrity.html

  8. The "world's first" claim refers to an AI agent in Japan's security export control domain (list regulations and catch-all regulations), confirmed by TIMEWELL (internal) research as of March 2026. The AI classification accuracy of 95% or higher is an internal study using past screening data, and is a figure premised on the final classification and risk assessment in actual operation being made by each organisation's export control and research security officers.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles