• Skip to primary navigation
  • Skip to main content

USC Department of Contracts and Grant

University of Southern California
  • Home
    • Pre-Award Overview
    • Post-Award Overview
    • Subawards Overview
    • Explore DCG Resources
    • Feedback
    • Service Agreements
  • Pre-Award
    • Complete Proposal
    • Roles and Responsibilities
    • Find Funding
    • Review Funding
    • Compliance Requirements
    • Route in Cayuse SP
    • DCG Review
    • Sponsor Review
    • Post Submission
  • Post-Award
    • Roles and Responsibilities
    • Award Setup
    • Award Guidance
    • Outgoing Subawards
    • Progress Reports and Deliverables at USC
    • Award Closeout
  • Subawards
    • Defining Subawards
    • Outgoing Subawards at Proposal Stage
    • Setting Up and Modifying Outgoing Subawards
    • Monitoring of Subawards
    • DCG Contacts for Questions on Outgoing Subawards
    • Forms
  • DCG Training
    • Training for Principal Investigators
    • Training for Research Administrators
    • Training for Cayuse SP
    • MicroLearning Videos
  • Resources
    • General Guidance
    • Roles and Responsibilities Made Easy
    • Roles and Responsibilities in Research Administration
    • USC Policies and Training Programs
    • Common Forms and Templates
    • Sponsor Resources for Research Administrators
    • Notifications Regarding Federal Directives
    • USC Research Administration Navigator Use
    • USC Research Administration Navigator FAQ
    • Prompt Engineering for RA Navigator
  • Directory
You are here: Home / Announcements / NIH Security Best Practices for Users of NIH Controlled Access Data Repositories (CADRs)

NIH Security Best Practices for Users of NIH Controlled Access Data Repositories (CADRs)

April 6, 2026

Announcement: Effective February 25, 2026, all downloads of data from NIH designated Controlled-Access Data Repositories (CADR), must meet a set of stringent cybersecurity standards found in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800.171. These cybersecurity standards, which were first applied to NIH genomic repositories beginning in January 2025, now extend to all NIH CADRs, and must be met in connection with any download of data from NIH-designated CADR’s. 

To review a list of NIH-designated CADR’s to which these standards now apply, please visit https://grants.nih.gov/policy-and-compliance/policy-topics/sharing-policies/accessing-data/requirements.

At present, investigators may utilize a compliant solution managed by USC Keck Managed Services (KMS). Researchers interested in this option should contact Research Compliance or USC Stevens Center to initiate the process. USC Cybersecurity is continuing to evaluate additional service providers and will share updates as more options become available. In addition, compliant solutions are offered by certain external service providers, listed below. Please be aware that compliant solutions may involve costs and require several weeks to implement prior to the download of data.

Available Service Providers:

USC:
• Keck Managed Services (KMS)

*Additional service providers under assessment: FY 27 implementation

External:
• AnVIL
• BioData Catalyst

Please click here for the USC one-page guidance document for institution-specific information.

Questions?
If you have any questions, please contact Michelle Goff in the Office of Ethics and Compliance at cullenm@usc.edu.

Filed Under: Announcements

USC Office of Research and Innovation
Department of Contracts and Grants
3720 S. Flower St.
Los Angeles, CA 90089-0701

University of Southern California - Content managed by DCG
  • Privacy Notice - Notice of Non-Discrimination