U.S. NSTC NSPM-33 — National Security Presidential Memorandum 33: Research Security

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
U.S. NSTCNSPM-33 — National Security Presidential Memorandum 33 is a U.S.federal policy directive that strengthens research security andintegrity at institutions conducting federally funded research. Thememorandum establishes comprehensive requirements intended to protectsensitive research from foreign interference and promotetransparency, accountability, and responsible conduct within theresearch ecosystem.
Published by theWhite House and overseen by the National Science and TechnologyCouncil (NSTC), NSPM-33 applies to federal executive agencies,research institutions, and universities receiving federal researchfunding. It addresses key areas including cybersecurity controls,risk management procedures, disclosure requirements for conflicts ofinterest and foreign relationships, and oversight of researchpersonnel and data.
Organizationstypically implement NSPM-33 by updating internal policies, enhancingcybersecurity and data protection measures, improving due diligenceprocesses, and establishing programs for compliance oversight andrisk reporting. Many integrate NSPM-33 requirements with broaderframeworks such as NIST SP 800-171 or institutional complianceprograms to ensure alignment with federal research securityexpectations.
Why it Matters
NSPM-33establishes comprehensive research security requirements to safeguardfederally funded research and protect national innovation ecosystems.
Key benefitsinclude:
• Strengthen research security governance
Promoteconsistent oversight of research security processes and helporganizations identify and mitigate emerging threats across researchactivities.
• Enhance compliance with federal mandates
Enableorganizations to meet federal research security requirements,reducing the risk of funding disruptions and reputational harm.
• Improve protection of sensitive information
Supportsafeguards that reduce unauthorized access to confidential orproprietary research data and intellectual property.
• Increase transparency and accountability
Establishreporting and disclosure standards that improve clarity regardingexternal collaborations, financial interests, and researcheraffiliations.
• Promote operational resilience
Enable researchorganizations to better prepare for, respond to, and recover fromincidents affecting research integrity or security.
How it Works
The U.S. NSTCNSPM-33 – National Security Presidential Memorandum 33: ResearchSecurity framework structures research security requirements aroundcore governance domains such as risk management, disclosure, and duediligence. NSPM-33 establishes a set of regulatory and securitycontrols that address the identification, assessment, and mitigationof risks related to foreign influence, conflicts of interest, andprotection of federally funded research activities. The frameworkalso specifies mandatory processes for information disclosure,research integrity, and compliance monitoring, which integrate intothe broader research lifecycle.
Organizationsimplement NSPM-33 by establishing procedures for vetting researchpersonnel and collaborators, maintaining systems for disclosingsignificant relationships or support, and integrating securitycontrols to protect sensitive research data. Routine activitiesinclude conducting risk assessments, mapping compliance requirementsinto internal governance programs, monitoring adherence to disclosurepolicies, and managing incident response related to breaches ornoncompliance. These steps support ongoing research security,accountability, and regulatory compliance with federal mandates.
SmartSuiteenables operationalization of NSPM-33 by providing control librariesaligned to framework requirements, facilitating disclosure andconflict tracking, and supporting policy governance. Organizationsleverage SmartSuite’s risk registers for ongoing threat assessment,automate evidence collection to demonstrate compliance, and employdashboards and reporting tools to monitor security posture and auditreadiness, ensuring effective management of research security andcompliance obligations.
Key Elements
• Research Security Program Governance
Establishesorganizational responsibility, oversight structures, and leadershiproles for safeguarding research activities.
• Disclosure and Transparency Requirements
Outlinesprotocols for reporting outside affiliations, financial interests,and potential conflicts in research personnel.
• Foreign Engagement Risk Assessment
Describesprocesses for evaluating and mitigating risks posed by internationalcollaborations and partnerships.
• Information Security Safeguards
Specifiesrequirements for protecting sensitive research data and controllingaccess to research environments.
• Researcher Training and Awareness
Definesmandatory education and awareness initiatives targeting researchintegrity, security, and compliance topics.
• Compliance Monitoring and Enforcement
Organizesmechanisms for oversight, periodic review, and enforcement ofinstitutional research security practices.
Framework Scope
U.S. NSTCNSPM-33 — National Security Presidential Memorandum 33 is adoptedby research institutions, universities, and entities managingfederally funded research activities. It governs research securitypolicies, compliance controls, and management of sensitive researchdata, and is typically applied when enhancing research securityoversight, addressing risk management, and supporting assuranceprograms for federally supported research environments.
Framework Objectives
U.S. NSTCNSPM-33 outlines objectives to safeguard research security andpromote strong risk management in federally funded research.
• Protect sensitive research data through robust cybersecurity andsecurity controls
• Strengthen governance and oversight of research activities andpartnerships
• Enhance compliance with federal regulations and institutionalpolicies
• Promote effective risk management and reduce vulnerabilities inresearch environments
• Support operational resilience by establishing consistentresearch security protocols
• Improve audit readiness and transparency for research securityprograms NSPM-33 aligns with U.S. federal research securityrequirements and is often integrated with frameworks like NIST SP800-53, ISO 27001, and CMMC. Organizations, particularly researchinstitutions and federal grant recipients, implement NSPM-33 to meetfederal security mandates, enhance institutional security governance,and ensure compliance with funding agency expectations.
Common Framework Mappings
NSTC NSPM-33 isoften mapped to other security and compliance frameworks tostrengthen research security, support regulatory alignment, andenable efficient cross-framework risk management and reporting forfederal contractors and research institutions.
Mappedframeworks include:
CIS CriticalSecurity Controls
CMMC
FERPA
FISMA
GDPR
HIPAA
ISO/IEC 27001
NISTCybersecurity Framework
NIST SP 800-53
SOC 2
- ClassicifationCategoryOtherDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentDirectiveSectorGovernment SectorIndustryGovernment & Public Sector
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherThe White House (Office of Science and Technology Policy)
- VersioningVersion2021Effective DateJanuary 14, 2021Issue DateJanuary 14, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
NSPM-33 is publicly available via official White House/NSTC government publications. License included with platform
How SmartSuite Supports NSPM-33
Manage research security compliance by organizing NSPM-33 requirements, tracking research governance controls, and maintaining documentation supporting protection of federally funded research and sensitive technologies.
Research Security Governance Library
Structure NSPM-33 requirements covering research security programs, disclosure obligations, and institutional oversight.
Federally Funded Research Project Tracking
Track federally funded research projects, participating institutions, and associated security obligations.
Researcher Disclosure and Reporting Obligations
Manage researcher disclosures, affiliations, and reporting obligations required for research security compliance.
Foreign Collaboration and Risk Monitoring
Track international partnerships, collaborations, and potential research security risks.
Training and Awareness Programs
Manage researcher security training programs and track completion for compliance verification.
Research Security Posture and Federal Oversight Reporting
Provide dashboards showing research security posture, disclosure status, and readiness for federal oversight reviews.
Related frameworks

CMMC 2.0 sets cybersecurity requirements to protect controlled unclassified information for DoD contractors and suppliers.

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For U.S. NSTC NSPM-33 (Research Security)
NSTC NSPM-33 establishes requirements and guidelines to protect U.S. federally funded research from foreign government interference and exploitation. The memorandum aims to safeguard the integrity of research environments, mitigate security risks, and promote responsible information sharing across research institutions.
Yes, compliance with NSPM-33 is mandatory for organizations receiving federal research funding in the United States. Federal agencies have incorporated the memorandum’s requirements into grant, contract, and cooperative agreement terms with recipient organizations.
NSTC NSPM-33 applies to universities, research institutions, and federal contractors receiving federal funding for research projects. The requirements cover activities involving sensitive or controlled research, particularly those at risk of foreign influence, regardless of the research domain.
Key concepts in NSPM-33 include research security programs, foreign talent program disclosures, conflict of interest disclosures, and standardized risk assessment processes. Required artifacts include documented security policies, training materials, and comprehensive disclosure forms from researchers and staff.
Organizations must establish or enhance research security programs that align with NSPM-33 directives, including developing policies, processes for risk identification, security training programs, and ongoing monitoring mechanisms. Implementation typically involves collaboration among compliance, security, research administration, and IT teams.
NSPM-33 complements existing federal regulations such as the National Industrial Security Program (NISPOM) and Controlled Unclassified Information (CUI) requirements. It fills research-specific gaps by standardizing disclosure and security expectations across federally funded projects, creating a unified baseline.
Ongoing compliance includes maintaining up-to-date disclosure records, conducting periodic research security training, performing regular program reviews, and promptly reporting potential risks or breaches. Organizations must also continuously monitor and update their research security controls as federal guidance evolves.
SmartSuite can help organizations manage NSTC NSPM-33 compliance by enabling configurable workflows for risk tracking, documenting and reviewing security controls, collecting and centralizing researcher disclosures, and supporting evidence collection for audits. Automated task management, comprehensive reporting, and centralized document repositories support ongoing audit readiness and help demonstrate compliance to federal agencies.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

