We'd like to hear from you!
This briefing provides high-level visibility into developments across RRCoP, this RORS award, and the broader research security landscape. Please contribute if you have community items that you'd like to see in this summary.
Community Upcoming Events
Get your dates added to this community calendar by emailing: info@researchcybersecurity.org
Regulated Research Community of Practice (RRCoP)
Upcoming: NSF SECURE Center & SECURE Analytics June 10 at 11 am PT / 2 pm ET [Join]
Recent Webinars:
Dynamic Documentation: Wiki, Document as Code, and Scripted SSPs [Recording]
A journey of developing Security Guidance for High-Performance Computing (HPC) [Recording]
Enhancing Institutional Cybersecurity Through 14 Controls [Recording]
February '26 From Learning Assessment to the Real Deal - How UCSD Approached the CMMC L2 Assessment [Recording]
January '26 AI for Compliance Use Cases & Cybersecurity Considerations [Recording]
Consider joining the mailing list to get involved
Research on Research Security (RoRS) Cybersecurity Readiness for NSPM-33
We're now looking for research participants!
Consider joining the mailing list to get involved.
“CMMC isn't just an IT Project. It is an organizational transformation disguised as a cybersecurity compliance project.”
-Rob Groome, CIO, USC-ICT
Summit7’s Podcast "That CMMC Show” February 3, 2026
SECURE Center
Monthly research security briefings provide valuable community updates
Center for Research Security & Integrity (CRSI)
(Feb 2026) Are Research Security Policies in the US Working? A Case Study on Research Collaborations with PRC Defense Laboratories and US Federally Sponsored Research
Trusted CI
Call for Proposals for the NSF Cybersecurity Summit are open through June 30th
Internet2
Delivered:
(Jan.) The Changing Risk Landscape for Research Security: Why “Not My Responsibility” No Longer Works
(Feb.) Securing Research in the Cloud: Setting the Stage for Institutional Success
(Mar.) Stakeholder Identification & Governance Alignment Workshop
(Mar.) Accelerating Research Through Security: Reducing Risk by Empowering Researchers
(Apr.) Real World Secure Research Environment Implementations and Lessons Learned
(Apr) Patterns for Secure Research Enclaves
(May) AWS Approach to Secure Research Environments
(May) Security Controls — from Interpretation to Review
(Mar) Blog Article "Secure Research Environments Phase 1: What We're Up Against"
EDUCAUSE
RISC (Regulated Information Security Compliance) Community Group - (April) NIH Requirements: What They Mean for HPCs
(April 28 - May 1) Hosted Annual Cybersecurity Privacy Professionals Conference with presentations on NSPM-33, CMMC, and a full-day workshop around Aligning Culture to your regulated research program.
COGR
Regulated Research Community of Practice (RRCoP)
Delivered a Recap of Resources, and a live response of the December edition of 'Ask The Assessor'. [view recording]
Upcoming: January 14 AI use cases for compliance & Cybersecurity Considerations
Research on Research Security (RoRS) Cybersecurity Readiness for NSPM-33
Began a page categorizing the research topics
Developed a meta-community events calendar, highlighting events across the research ecosystem including:
Research cybersecurity & research security program meetings
Higher education cybersecurity and compliance communities
Cyberinfrastructure (CI) workshops, webinars, and training
Federal briefings (NSF, NIST, CISA, DOE, NIH)
Conferences and calls for proposals (CFPs)
Large community convenings (EDUCAUSE, FDP, CARCC, Internet2)
Consider joining the mailing list to get involved.
SECURE Center
Monthly research security briefings provide valuable community updates
National Academies
(Sept '25) New Report Identifies Policy Options to Improve Federal Research Regulations, Bolster U.S. Scientific Competitiveness [View Entire Report]
Association of American Universities (AAU)
(Sept '25) Published The Financial Accountability in Research (FAIR) Model developed by Joint Associations Group on Indirect Costs (JAG)
(February '25) Published Breaking Down the Costs of Federal Research at Universities
Internet2
Delivered "CIO Perspectives on Research Data Security and CMMC Compliance" [View Synopsis]
Upcoming: Delivering a new series on Research Cybersecurity Programs starting Jan. 20, 2026
EDUCAUSE / FDP
Shared clean draft 2.0 of Proposed Research Cybersecurity Guidelines for NSPM-33 Research Security Program Requirements
COGR
(November '25) Published Research Security Regulations: Practical Considerations for Technology Transfer Professionals
Regulated Research Community of Practice (RRCoP)
GTRI delivered a session on building a cybersecurity-forward culture that drew 171 attendees. Recording is posted.
Ask the Assessor published guidance on when Dedicated Labs and Specialized Equipment are appropriate for CUI.
Upcoming: December 10 Ask The Assessor Live & Recap of Valuable Resources
Research on Research Security (RoRS) Cybersecurity Readiness for NSPM-33
This new NSF award # 2537044 focuses on how institutions are meeting NSPM-33’s cybersecurity expectations. We’ve opened the project, set up a simple landing page, and are locking in the first questions that will shape the baseline. The work stays aligned with the broader landscape through tight coordination with the SECURE Center and Trusted CI. Consider joining the mailing list to get involved.
SECURE Center
Monthly research security briefings provide valuable community updates
A consolidated training module was released, replacing several distributed materials
Kicking off the Research Security Mentorship Workshop Series
Trusted CI: The NSF Cybersecurity Center of Excellence
The NSF Cybersecurity Summit ran October 20–23, drawing strong engagement across the community.
EDUCAUSE
Led the cybersecurity work group and published outcome as the public-comment version of Proposed Research Cybersecurity Guidelines for NSPM-33 Research Security Program Requirements in partnership with Federal Demonstration Partnership (FDP)
Published DFARS Changes to Integrate CMMC Requirements Effective November 10, a concise rundown of what shifted and why it matters.
The RISC community group hosted Mike Corn to discuss Research Security, the Research Infrastructure Guide, and the NSF Critical Control Set, with the recording posted.
Coalition for Academic Scientific Computation (CASC)
Published a position paper “NIST SP 800-171 – Guidance for Research Computing and Data Centers”