This monthly briefing provides high-level visibility into developments across RRCoP, this RORS award, and the broader research security landscape. Please contribute if you have community items that you'd like to see in this summary.
Community Upcoming Events
Get your dates added to this community calendar by emailing: info@researchcybersecurity.org
Regulated Research Community of Practice (RRCoP)
Delivered a Recap of Resources, and a live response of the December edition of 'Ask The Assessor'. [view recording]
Upcoming: January 14 AI use cases for compliance & Cybersecurity Considerations
Research on Research Security (RoRS) Cybersecurity Readiness for NSPM-33
Began a page categorizing the research topics
Developed a meta-community events calendar, highlighting events across the research ecosystem including:
Research cybersecurity & research security program meetings
Higher education cybersecurity and compliance communities
Cyberinfrastructure (CI) workshops, webinars, and training
Federal briefings (NSF, NIST, CISA, DOE, NIH)
Conferences and calls for proposals (CFPs)
Large community convenings (EDUCAUSE, FDP, CARCC, Internet2)
Consider joining the mailing list to get involved.
SECURE Center
Monthly research security briefings provide valuable community updates
National Academies
(Sept '25) New Report Identifies Policy Options to Improve Federal Research Regulations, Bolster U.S. Scientific Competitiveness [View Entire Report]
Association of American Universities (AAU)
(Sept '25) Published The Financial Accountability in Research (FAIR) Model developed by Joint Associations Group on Indirect Costs (JAG)
(February '25) Published Breaking Down the Costs of Federal Research at Universities
Internet2
Delivered "CIO Perspectives on Research Data Security and CMMC Compliance" [View Synopsis]
Upcoming: Delivering a new series on Research Cybersecurity Programs starting Jan. 20, 2026
EDUCAUSE / FDP
Shared clean draft 2.0 of Proposed Research Cybersecurity Guidelines for NSPM-33 Research Security Program Requirements
COGR
(November '25) Published Research Security Regulations: Practical Considerations for Technology Transfer Professionals
Regulated Research Community of Practice (RRCoP)
GTRI delivered a session on building a cybersecurity-forward culture that drew 171 attendees. Recording is posted.
Ask the Assessor published guidance on when Dedicated Labs and Specialized Equipment are appropriate for CUI.
Upcoming: December 10 Ask The Assessor Live & Recap of Valuable Resources
Research on Research Security (RoRS) Cybersecurity Readiness for NSPM-33
This new NSF award # 2537044 focuses on how institutions are meeting NSPM-33’s cybersecurity expectations. We’ve opened the project, set up a simple landing page, and are locking in the first questions that will shape the baseline. The work stays aligned with the broader landscape through tight coordination with the SECURE Center and Trusted CI. Consider joining the mailing list to get involved.
SECURE Center
Monthly research security briefings provide valuable community updates
A consolidated training module was released, replacing several distributed materials
Kicking off the Research Security Mentorship Workshop Series
Trusted CI: The NSF Cybersecurity Center of Excellence
The NSF Cybersecurity Summit ran October 20–23, drawing strong engagement across the community.
EDUCAUSE
Led the cybersecurity work group and published outcome as the public-comment version of Proposed Research Cybersecurity Guidelines for NSPM-33 Research Security Program Requirements in partnership with Federal Demonstration Partnership (FDP)
Published DFARS Changes to Integrate CMMC Requirements Effective November 10, a concise rundown of what shifted and why it matters.
The RISC community group hosted Mike Corn to discuss Research Security, the Research Infrastructure Guide, and the NSF Critical Control Set, with the recording posted.
Coalition for Academic Scientific Computation (CASC)
Published a position paper “NIST SP 800-171 – Guidance for Research Computing and Data Centers”