Research Cybersecurity Program Effective Practices for Covered Higher Education Institutions

A Federal Demonstration Partnership/EDUCAUSE Proposal, February 2026

Abstract

In response to National Security Presidential Memorandum 33 (NSPM-33), the Office of Science and Technology Policy (OSTP) produced guidance for federal funding agencies regarding the research security program (RSP) requirements that they would have to apply to higher education institutions covered by NSPM-33. The OSTP guidance included cybersecurity among the elements that institutional RSPs would need to address, but it did not clearly identify how covered institutions could satisfy the cybersecurity provision of the RSP requirements.

Recognizing the potential compliance problems that uncertainty about RSP requirements in relation to research cybersecurity could produce, EDUCAUSE worked with the Federal Demonstration Partnership (FDP), a collaborative organization involving higher education research administrators and federal funding agency representatives, to develop a proposed set of research cybersecurity program effective practices to inform institutional compliance with the NSPM-33 RSP requirements. The proposed effective practices stress throughout the necessity of institutional discretion to determine how a covered institution conducts research cybersecurity. With that in mind, the document makes clear that the effective practices assume institutional discretion to deviate from the proposed reference set of controls as research considerations dictate, so long as the institution documents its rationale and the compensating measures it deploys.

Download Resources