U.S. NSTC NSPM-33 — National Security Presidential Memorandum 33: Research Security

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
U.S. NSTC NSPM-33 — National Security Presidential Memorandum 33 is a U.S. federal policy directive that strengthens research security and integrity at institutions conducting federally funded research. The memorandum establishes comprehensive requirements intended to protect sensitive research from foreign interference and promote transparency, accountability, and responsible conduct within the research ecosystem.
Published by the White House and overseen by the National Science and Technology Council (NSTC), NSPM-33 applies to federal executive agencies, research institutions, and universities receiving federal research funding. It addresses key areas including cybersecurity controls, risk management procedures, disclosure requirements for conflicts of interest and foreign relationships, and oversight of research personnel and data.
Organizations typically implement NSPM-33 by updating internal policies, enhancing cybersecurity and data protection measures, improving due diligence processes, and establishing programs for compliance oversight and risk reporting. Many integrate NSPM-33 requirements with broader frameworks such as NIST SP 800-171 or institutional compliance programs to ensure alignment with federal research security expectations.
Why it Matters
NSPM-33 establishes comprehensive research security requirements tosafeguard federally funded research and protect national innovationecosystems.
Key benefits include:
- Strengthen research security governance
Promoteconsistent oversight of research security processes and helporganizations identify and mitigate emerging threats across researchactivities.
- Enhance compliance with federal mandates
Enableorganizations to meet federal research security requirements,reducing the risk of funding disruptions and reputational harm.
- Improve protection of sensitive information
Supportsafeguards that reduce unauthorized access to confidential orproprietary research data and intellectual property.
- Increase transparency and accountability
Establishreporting and disclosure standards that improve clarity regardingexternal collaborations, financial interests, and researcheraffiliations.
- Promote operational resilience
Enable researchorganizations to better prepare for, respond to, and recover fromincidents affecting research integrity or security.
How it Works
The U.S. NSTC NSPM-33 – National Security Presidential Memorandum33: Research Security framework structures research securityrequirements around core governance domains such as risk management,disclosure, and due diligence. NSPM-33 establishes a set ofregulatory and security controls that address the identification,assessment, and mitigation of risks related to foreign influence,conflicts of interest, and protection of federally funded researchactivities. The framework also specifies mandatory processes forinformation disclosure, research integrity, and compliancemonitoring, which integrate into the broader research lifecycle.
Organizations implement NSPM-33 by establishing procedures forvetting research personnel and collaborators, maintaining systems fordisclosing significant relationships or support, and integratingsecurity controls to protect sensitive research data. Routineactivities include conducting risk assessments, mapping compliancerequirements into internal governance programs, monitoring adherenceto disclosure policies, and managing incident response related tobreaches or noncompliance. These steps support ongoing researchsecurity, accountability, and regulatory compliance with federalmandates.
SmartSuite enables operationalization of NSPM-33 by providing controllibraries aligned to framework requirements, facilitating disclosureand conflict tracking, and supporting policy governance.Organizations leverage SmartSuite’s risk registers for ongoingthreat assessment, automate evidence collection to demonstratecompliance, and employ dashboards and reporting tools to monitorsecurity posture and audit readiness, ensuring effective managementof research security and compliance obligations.
Key Elements
- Research Security Program Governance
Establishesorganizational responsibility, oversight structures, and leadershiproles for safeguarding research activities.
- Disclosure and Transparency Requirements
Outlinesprotocols for reporting outside affiliations, financial interests,and potential conflicts in research personnel.
- Foreign Engagement Risk Assessment
Describesprocesses for evaluating and mitigating risks posed by internationalcollaborations and partnerships.
- Information Security Safeguards
Specifiesrequirements for protecting sensitive research data and controllingaccess to research environments.
- Researcher Training and Awareness
Defines mandatoryeducation and awareness initiatives targeting research integrity,security, and compliance topics.
- Compliance Monitoring and Enforcement
Organizesmechanisms for oversight, periodic review, and enforcement ofinstitutional research security practices.
Framework Scope
U.S. NSTC NSPM-33 — National Security Presidential Memorandum 33 isadopted by research institutions, universities, and entities managingfederally funded research activities. It governs research securitypolicies, compliance controls, and management of sensitive researchdata, and is typically applied when enhancing research securityoversight, addressing risk management, and supporting assuranceprograms for federally supported research environments.
Framework Objectives
U.S. NSTC NSPM-33 outlines objectives to safeguard research securityand promote strong risk management in federally funded research.
Protect sensitive research data through robust cybersecurity andsecurity controls
Strengthen governance and oversight of research activities andpartnerships
Enhance compliance with federal regulations and institutionalpolicies
Promote effective risk management and reduce vulnerabilities inresearch environments
Support operational resilience by establishing consistent researchsecurity protocols
Improve audit readiness and transparency for research securityprograms NSPM-33 aligns with U.S. federal research securityrequirements and is often integrated with frameworks like NIST SP800-53, ISO 27001, and CMMC. Organizations, particularly researchinstitutions and federal grant recipients, implement NSPM-33 to meetfederal security mandates, enhance institutional security governance,and ensure compliance with funding agency expectations.
Framework in Context
NSPM-33 aligns withU.S. federal research security requirements and is often integratedwith frameworks like NIST SP 800-53, ISO 27001, and CMMC.Organizations, particularly research institutions and federal grantrecipients, implement NSPM-33 to meet federal security mandates,enhance institutional security governance, and ensure compliance withfunding agency expectations.
Common Framework Mappings
NSTC NSPM-33 is often mapped to other security and complianceframeworks to strengthen research security, support regulatoryalignment, and enable efficient cross-framework risk management andreporting for federal contractors and research institutions.
Mapped frameworks include:
CIS Critical Security Controls
CMMC
FERPA
FISMA
GDPR
HIPAA
ISO/IEC 27001
NIST Cybersecurity Framework
NIST SP 800-53
SOC 2
- ClassificationCategoryOtherDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentDirectiveSectorGovernment SectorIndustryGovernment & Public Sector
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherThe White House (Office of Science and Technology Policy)
- VersioningVersion2021Effective DateJanuary 14, 2021Issue DateJanuary 14, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
NSPM-33 is publicly available via official White House/NSTC government publications. License included with platform
How SmartSuite Supports NSPM-33
Manage research security compliance by organizing NSPM-33 requirements, tracking research governance controls, and maintaining documentation supporting protection of federally funded research and sensitive technologies.
Research Security Governance Library
Structure NSPM-33 requirements covering research security programs, disclosure obligations, and institutional oversight.
Federally Funded Research Project Tracking
Track federally funded research projects, participating institutions, and associated security obligations.
Researcher Disclosure and Reporting Obligations
Manage researcher disclosures, affiliations, and reporting obligations required for research security compliance.
Foreign Collaboration and Risk Monitoring
Track international partnerships, collaborations, and potential research security risks.
Training and Awareness Programs
Manage researcher security training programs and track completion for compliance verification.
Research Security Posture and Federal Oversight Reporting
Provide dashboards showing research security posture, disclosure status, and readiness for federal oversight reviews.
Related frameworks

CMMC 2.0 sets cybersecurity requirements to protect controlled unclassified information for DoD contractors and suppliers.

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For U.S. NSTC NSPM-33 (Research Security)
NSTC NSPM-33 establishes requirements and guidelines to protect U.S. federally funded research from foreign government interference and exploitation. The memorandum aims to safeguard the integrity of research environments, mitigate security risks, and promote responsible information sharing across research institutions.
Yes, compliance with NSPM-33 is mandatory for organizations receiving federal research funding in the United States. Federal agencies have incorporated the memorandum’s requirements into grant, contract, and cooperative agreement terms with recipient organizations.
NSTC NSPM-33 applies to universities, research institutions, and federal contractors receiving federal funding for research projects. The requirements cover activities involving sensitive or controlled research, particularly those at risk of foreign influence, regardless of the research domain.
Key concepts in NSPM-33 include research security programs, foreign talent program disclosures, conflict of interest disclosures, and standardized risk assessment processes. Required artifacts include documented security policies, training materials, and comprehensive disclosure forms from researchers and staff.
Organizations must establish or enhance research security programs that align with NSPM-33 directives, including developing policies, processes for risk identification, security training programs, and ongoing monitoring mechanisms. Implementation typically involves collaboration among compliance, security, research administration, and IT teams.
NSPM-33 complements existing federal regulations such as the National Industrial Security Program (NISPOM) and Controlled Unclassified Information (CUI) requirements. It fills research-specific gaps by standardizing disclosure and security expectations across federally funded projects, creating a unified baseline.
Ongoing compliance includes maintaining up-to-date disclosure records, conducting periodic research security training, performing regular program reviews, and promptly reporting potential risks or breaches. Organizations must also continuously monitor and update their research security controls as federal guidance evolves.
SmartSuite can help organizations manage NSTC NSPM-33 compliance by enabling configurable workflows for risk tracking, documenting and reviewing security controls, collecting and centralizing researcher disclosures, and supporting evidence collection for audits. Automated task management, comprehensive reporting, and centralized document repositories support ongoing audit readiness and help demonstrate compliance to federal agencies.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

