NSPM-33 Research Security Programs

Your institution needs a research security program. We build them.

Federal compliance deadlines are active, and agencies are conditioning awards on demonstrated program maturity. SYSWERX delivers scored gap assessments, program architecture, and continuous compliance operations — purpose built for research universities and institutions.

Federal Mandate in Effect

Institutions receiving >$50M/yr in federal science and engineering support must certify a research security program under NSPM-33 — and training certifications are already enforced at NSF, DOE, and NIH. 178 universities clear the threshold, carrying $60.6B in federal research funding (NSF HERD FY2024).

Most research universities face the same challenge: NSPM-33 compliance is mandatory, the four-pillar requirement is complex, and building a program from scratch takes time you don't have. A dedicated Research Security Officer runs $120–180K/yr in salary alone — and still leaves you with a single point of failure across cybersecurity, foreign travel, training, and export control. There is a faster path.
4
Mandatory program pillars under NSPM-33
18 mo
Maximum window to implement once agency policies take effect (OSTP, July 2024)
3–6 mo
Avg time for SYSWERX to deliver a gap assessment and roadmap
$60.6B
Federal R&D concentrated in the 178 covered universities (NSF HERD FY2024)
The Four Mandatory Pillars

Cybersecurity

NIST-aligned controls for federally funded research systems and data. Required by all major agencies.

Foreign Travel Security

Pre-travel risk assessments, briefings, and post-travel debriefing workflows for research personnel.

Research Security Training

Annual security training and materials for covered individuals. The CHIPS Act §10634 mandates certification before proposal submission.

Export Control Training

ITAR/EAR training and compliance workflows for covered individuals working with controlled technologies and international collaborations.

What We Deliver
1

Scored Gap Assessment

A quantified baseline across all four pillars, scored against federal certification criteria. Your VPR walks away with a defensible answer to "where are we?" for the first time.

2

Institutional Program Architecture

Policy framework, org-chart recommendations, workflow designs, and a 12–18 month prioritized roadmap tailored to your specific agency mix and research portfolio.

3

Stakeholder Alignment

Structured sessions with VPR, Provost, General Counsel, and IT Security. Most compliance efforts stall at internal alignment — we move it forward.

4

Continuous Compliance Operations

Ongoing training delivery, disclosure support, regulatory monitoring, and an incident-response retainer. The program runs without requiring you to staff and retain rare expertise.

How we engage

A two-phase path to a certified program.

Stand up a defensible program quickly, then keep it running without building rare expertise in-house.

Phase 1 · Consulting

Gap Assessment + Program Architecture

Establish where you stand and the roadmap to compliance.
  • Four-pillar scored findings report
  • 12–18 month implementation roadmap
  • Stakeholder alignment sessions
  • Operational in 3–6 months
Phase 2 · Managed Services

Continuous Compliance Operations

Keep the program current, staffed, and audit-ready.
  • Annual research security training delivery
  • Research security workshops — policy and baseline
  • Insider threat awareness program review
  • Disclosure support
  • Incident response advisement
  • Foreign travel briefing cadence
  • Risk mitigation plan advisement
Already have a program?

Take advantage of our managed services.

Most institutions have a program on paper. We make sure it holds up to a federal reviewer — and stays that way.

Managed services

Independent Program Review

You built it — but has it been tested? NSF, DOD, and NIH expectations have evolved since most programs launched. A third party assessment identifies gaps before a federal reviewer does, and gives you something defensible to put in front of an auditor or agency sponsor.

Managed services

Foreign Travel Program Support

Most programs have a travel policy. Few have the capacity to deliver individualized, CI-informed pre-travel briefings and risk assessments at scale. We cover threat environment, device protocols, elicitation awareness, and post-travel debriefing — so your researchers leave informed and your program has documentation to show for it.

Managed services

Annual Compliance Certification Briefing

Every covered institution faces the same annual pressure point: proving to agency sponsors that the program is real, current, and functioning. We assemble the evidence, check it against the latest OMB and agency guidance, and deliver an executive summary ready for your Provost, VPR, or Board. You get a defensible record. You get your time back.

Get started

Ready to assess your research security posture?

Request a complimentary consultation and let's talk about where your program stands — and where we can take it.