Other
DETAIL

U.S. NSTC NSPM-33 — National Security Presidential Memorandum 33: Research Security

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

U.S. NSTCNSPM-33 — National Security Presidential Memorandum 33 is a U.S.federal policy directive that strengthens research security andintegrity at institutions conducting federally funded research. Thememorandum establishes comprehensive requirements intended to protectsensitive research from foreign interference and promotetransparency, accountability, and responsible conduct within theresearch ecosystem.

Published by theWhite House and overseen by the National Science and TechnologyCouncil (NSTC), NSPM-33 applies to federal executive agencies,research institutions, and universities receiving federal researchfunding. It addresses key areas including cybersecurity controls,risk management procedures, disclosure requirements for conflicts ofinterest and foreign relationships, and oversight of researchpersonnel and data.

Organizationstypically implement NSPM-33 by updating internal policies, enhancingcybersecurity and data protection measures, improving due diligenceprocesses, and establishing programs for compliance oversight andrisk reporting. Many integrate NSPM-33 requirements with broaderframeworks such as NIST SP 800-171 or institutional complianceprograms to ensure alignment with federal research securityexpectations.

Why it Matters

NSPM-33establishes comprehensive research security requirements to safeguardfederally funded research and protect national innovation ecosystems.

Key benefitsinclude:

•  Strengthen research security governance

Promoteconsistent oversight of research security processes and helporganizations identify and mitigate emerging threats across researchactivities.

•  Enhance compliance with federal mandates

Enableorganizations to meet federal research security requirements,reducing the risk of funding disruptions and reputational harm.

•  Improve protection of sensitive information

Supportsafeguards that reduce unauthorized access to confidential orproprietary research data and intellectual property.

•  Increase transparency and accountability

Establishreporting and disclosure standards that improve clarity regardingexternal collaborations, financial interests, and researcheraffiliations.

•  Promote operational resilience

Enable researchorganizations to better prepare for, respond to, and recover fromincidents affecting research integrity or security.

How it Works

The U.S. NSTCNSPM-33 – National Security Presidential Memorandum 33: ResearchSecurity framework structures research security requirements aroundcore governance domains such as risk management, disclosure, and duediligence. NSPM-33 establishes a set of regulatory and securitycontrols that address the identification, assessment, and mitigationof risks related to foreign influence, conflicts of interest, andprotection of federally funded research activities. The frameworkalso specifies mandatory processes for information disclosure,research integrity, and compliance monitoring, which integrate intothe broader research lifecycle.

Organizationsimplement NSPM-33 by establishing procedures for vetting researchpersonnel and collaborators, maintaining systems for disclosingsignificant relationships or support, and integrating securitycontrols to protect sensitive research data. Routine activitiesinclude conducting risk assessments, mapping compliance requirementsinto internal governance programs, monitoring adherence to disclosurepolicies, and managing incident response related to breaches ornoncompliance. These steps support ongoing research security,accountability, and regulatory compliance with federal mandates.

SmartSuiteenables operationalization of NSPM-33 by providing control librariesaligned to framework requirements, facilitating disclosure andconflict tracking, and supporting policy governance. Organizationsleverage SmartSuite’s risk registers for ongoing threat assessment,automate evidence collection to demonstrate compliance, and employdashboards and reporting tools to monitor security posture and auditreadiness, ensuring effective management of research security andcompliance obligations.

Key Elements

•  Research Security Program Governance

Establishesorganizational responsibility, oversight structures, and leadershiproles for safeguarding research activities.

•  Disclosure and Transparency Requirements

Outlinesprotocols for reporting outside affiliations, financial interests,and potential conflicts in research personnel.

•  Foreign Engagement Risk Assessment

Describesprocesses for evaluating and mitigating risks posed by internationalcollaborations and partnerships.

•  Information Security Safeguards

Specifiesrequirements for protecting sensitive research data and controllingaccess to research environments.

•  Researcher Training and Awareness

Definesmandatory education and awareness initiatives targeting researchintegrity, security, and compliance topics.

•  Compliance Monitoring and Enforcement

Organizesmechanisms for oversight, periodic review, and enforcement ofinstitutional research security practices.

Framework Scope

U.S. NSTCNSPM-33 — National Security Presidential Memorandum 33 is adoptedby research institutions, universities, and entities managingfederally funded research activities. It governs research securitypolicies, compliance controls, and management of sensitive researchdata, and is typically applied when enhancing research securityoversight, addressing risk management, and supporting assuranceprograms for federally supported research environments.

Framework Objectives

U.S. NSTCNSPM-33 outlines objectives to safeguard research security andpromote strong risk management in federally funded research.

•  Protect sensitive research data through robust cybersecurity andsecurity controls

•  Strengthen governance and oversight of research activities andpartnerships

•  Enhance compliance with federal regulations and institutionalpolicies

•  Promote effective risk management and reduce vulnerabilities inresearch environments

•  Support operational resilience by establishing consistentresearch security protocols

•  Improve audit readiness and transparency for research securityprograms NSPM-33 aligns with U.S. federal research securityrequirements and is often integrated with frameworks like NIST SP800-53, ISO 27001, and CMMC. Organizations, particularly researchinstitutions and federal grant recipients, implement NSPM-33 to meetfederal security mandates, enhance institutional security governance,and ensure compliance with funding agency expectations.

Common Framework Mappings

NSTC NSPM-33 isoften mapped to other security and compliance frameworks tostrengthen research security, support regulatory alignment, andenable efficient cross-framework risk management and reporting forfederal contractors and research institutions.

Mappedframeworks include:

CIS CriticalSecurity Controls

CMMC

FERPA

FISMA

GDPR

HIPAA

ISO/IEC 27001

NISTCybersecurity Framework

NIST SP 800-53

SOC 2

At a Glance
NSPM-33 – Research Security
  • checklist
    Classicifation
    Category
    info
    Other
    Domain
    info
    Risk Management
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Guidance
    Legal Instrument
    info
    Directive
    Sector
    info
    Government Sector
    Industry
    info
    Government & Public Sector
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    The White House (Office of Science and Technology Policy)
  • published_with_changes
    Versioning
    Version
    info
    2021
    Effective Date
    info
    January 14, 2021
    Issue Date
    info
    January 14, 2021
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

NSPM-33 is publicly available via official White House/NSTC government publications. License included with platform

Official Resources
NSTC NSPM-33 Implementation Guidance
Provides detailed guidance on implementing security measures under NSPM-33.
chevron_forward
NSTC Research Security Programs Overview
Outlines key elements of research security programs as per NSPM-33.
chevron_forward
NSTC Policy and Regulation Updates
Describes updates to research security policies under NSPM-33.
chevron_forward
SMARTSUITE

How SmartSuite Supports NSPM-33

Manage research security compliance by organizing NSPM-33 requirements, tracking research governance controls, and maintaining documentation supporting protection of federally funded research and sensitive technologies.

Research Security Governance Library

Structure NSPM-33 requirements covering research security programs, disclosure obligations, and institutional oversight.

Federally Funded Research Project Tracking

Track federally funded research projects, participating institutions, and associated security obligations.

Researcher Disclosure and Reporting Obligations

Manage researcher disclosures, affiliations, and reporting obligations required for research security compliance.

Foreign Collaboration and Risk Monitoring

Track international partnerships, collaborations, and potential research security risks.

Training and Awareness Programs

Manage researcher security training programs and track completion for compliance verification.

Research Security Posture and Federal Oversight Reporting

Provide dashboards showing research security posture, disclosure status, and readiness for federal oversight reviews.

Related frameworks

CMMC 2.0

CMMC 2.0 sets cybersecurity requirements to protect controlled unclassified information for DoD contractors and suppliers.

Learn More
arrow_forward
NIST 800-171 Rev.2

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

Learn More
arrow_forward
FISMA

FISMA is a U.S. law requiring federal agencies and contractors to secure government information systems and manage cybersecurity risks.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For U.S. NSTC NSPM-33 (Research Security)

What is NSTC NSPM-33 used for?

NSTC NSPM-33 establishes requirements and guidelines to protect U.S. federally funded research from foreign government interference and exploitation. The memorandum aims to safeguard the integrity of research environments, mitigate security risks, and promote responsible information sharing across research institutions.

Is compliance with NSTC NSPM-33 required for organizations?

Yes, compliance with NSPM-33 is mandatory for organizations receiving federal research funding in the United States. Federal agencies have incorporated the memorandum’s requirements into grant, contract, and cooperative agreement terms with recipient organizations.

What entities or research activities does NSTC NSPM-33 apply to?

NSTC NSPM-33 applies to universities, research institutions, and federal contractors receiving federal funding for research projects. The requirements cover activities involving sensitive or controlled research, particularly those at risk of foreign influence, regardless of the research domain.

What are the key concepts and artifacts required by NSTC NSPM-33?

Key concepts in NSPM-33 include research security programs, foreign talent program disclosures, conflict of interest disclosures, and standardized risk assessment processes. Required artifacts include documented security policies, training materials, and comprehensive disclosure forms from researchers and staff.

How do organizations implement NSTC NSPM-33 requirements?

Organizations must establish or enhance research security programs that align with NSPM-33 directives, including developing policies, processes for risk identification, security training programs, and ongoing monitoring mechanisms. Implementation typically involves collaboration among compliance, security, research administration, and IT teams.

How does NSPM-33 relate to other research security frameworks?

NSPM-33 complements existing federal regulations such as the National Industrial Security Program (NISPOM) and Controlled Unclassified Information (CUI) requirements. It fills research-specific gaps by standardizing disclosure and security expectations across federally funded projects, creating a unified baseline.

What are the ongoing compliance requirements under NSTC NSPM-33?

Ongoing compliance includes maintaining up-to-date disclosure records, conducting periodic research security training, performing regular program reviews, and promptly reporting potential risks or breaches. Organizations must also continuously monitor and update their research security controls as federal guidance evolves.

How would SmartSuite support NSTC NSPM-33?

SmartSuite can help organizations manage NSTC NSPM-33 compliance by enabling configurable workflows for risk tracking, documenting and reviewing security controls, collecting and centralizing researcher disclosures, and supporting evidence collection for audits. Automated task management, comprehensive reporting, and centralized document repositories support ongoing audit readiness and help demonstrate compliance to federal agencies.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward