The National Institute of Standards and Technology (NIST) is a U.S. government agency that develops standards, frameworks, and best practices to advance technology, innovation, and cybersecurity. NIST publishes a variety of cybersecurity and information security standards that may apply to research environments, with specific requirements varying based on the sponsor, contractual obligations, type of research, and sensitivity of the data involved.
For research involving sensitive data or federally regulated information (which, for example, may include data obtained from NIH database of Genotypes and Phenotypes (dbGaP) or genomic data repositories (GDS)), the University of Miami employs a risk-based approach to cybersecurity informed by the NIST Cybersecurity Framework (CSF). The CSF provides a strategic foundation for identifying, protecting, detecting, responding to, and recovering from cybersecurity threats. Depending on project-specific requirements, researchers may be required to comply with different NIST publications, agency-specific cybersecurity requirements, or contractual security obligations. The University works with researchers to identify applicable requirements and implement appropriate safeguards based on the project's risk profile and compliance needs.
The University's use, storage, processing, or transmission of Controlled Unclassified Information (CUI) in sponsored research must comply with the security requirements of NIST SP 800-171, which establish the safeguards necessary to protect CUI and meet applicable federal security and compliance obligations. Additional information about CUI is available in the FAQs below.
The Graphic converts NIST SP 800-171 Revisions 3 from a list of individual security requirements into a resource-planning and responsibility-assignment framework, showing whether each control is primarily achieved through governance, technology configuration, software capability, operational security practice, or physical infrastructure. This makes it easier to communicate compliance requirements to researchers, IT leadership, and institutional stakeholders. Through the Research Security Program (RSP), the University brings together key stakeholder offices—including Information Security, Information Technology, Research Administration, Export Control, and other institutional partners—to develop and maintain secure research environments that support compliance with federal regulations, sponsor requirements, and University policies while enabling secure and responsible research.
One of the mechanisms to achieve research security and/or export control protections for information is through NIST SP 800-171 ("NIST 800") compliance. NIST SP 800-171 is a set of standards cybersecurity established by the National Institute of Standards and Technology. The standards are guidelines for Federal agencies when entering into agreements with other organizations, when sensitive (but not classified) information may be involved in the research. Some projects require the implementation of these standards, either because of the subject matter or because the contract requires it. You are responsible for ensuring NIST SP compliance.
Before you apply for a grant or contract, determine whether research requires NIST 800 compliance. The following situations generally require NIST 800 compliance:
If you need to be NIST 800 compliant:
University of Miami Secure Enclave Cost Estimation Researchers planning to use the University of Miami Secure Enclave to meet NIST and Department of Defense (DoD) cybersecurity requirements should use the information below to estimate project costs. Costs are based on the required cybersecurity level and the computational resources needed for the project. Additional endpoint and device security costs may apply ; investigators should consult University IT Security to obtain project-specific estimates. NIST Cybersecurity Levels and Secure Enclave Costs The Secure Enclave provides varying levels of security controls to support federal cybersecurity requirements and protect sensitive research data. Projects involving unique security requirements or high-risk federal contracts should consult University IT early during proposal development to determine required controls and associated costs. Secure Enclave Computing Resources and Pricing In addition to cybersecurity compliance costs, researchers may require dedicated computing resources within the Secure Enclave environment. Select the tier that best aligns with your project's storage and performance requirements. Need Assistance?
NIST
LevelData
TypeSecurity
Framework
AlignmentCMMC
EquivalentTypical
Research
ActivitiesInitial
Year
CostAnnual
Ongoing
Cost
1
Public / Non-Sensitive Data
Basic IT Controls
Below CMMC
Publicly available data with no restricted information
$5,000
$0
2
Federal Contract Information (FCI)
FAR 52.204-21
CMMC Level 1
Limited datasets, identifiable information, and protected data
$25,000
$5,000
3
Controlled Unclassified Information (CUI) – Moderate Risk
NIST SP 800-171
CMMC Level 2
NIH controlled-access datasets such as dbGaP and NIAGADS
$100,000
$50,000
4
High-Risk / Critical DoD Programs
NIST SP 800-172
CMMC Level 3
Sensitive CUI and certain federal defense contracts
Contact UM IT Security
Tier
CPU Cores
Memory (RAM)
Storage
Annual Cost
Monthly Cost
Small
4
32 GB
1 TB
$700
$58.33
Medium
8
64 GB
3 TB
$1,400
$116.67
Large
16
128 GB
5 TB
$3,900
$325.00
Extra Large
32
256 GB
10 TB
$5,300
$441.67
For assistance, contact UM IT Security or the Office of Research Administration before proposal submission.
What is Controlled Unclassified Information (CUI)? CUI is information that the U.S. Government has determined requires protection or dissemination controls pursuant to applicable laws, regulations, or government-wide policies, but that is not classified information. CUI may be created by, owned by or shared with federal agencies and can include information provided to the University through sponsored projects, contracts, cooperative agreements, subawards, or data use agreements. Examples of CUI may include: When the University receives, stores, processes, or transmits CUI, it must protect the information in accordance with applicable federal requirements. This often includes compliance with NIST SP 800-171, which establishes security requirements for safeguarding CUI in nonfederal information systems and organizations. Click these links for additional CUI resources and the CUI Registry to review the different categories of CUI in the National Archives. The National Institute of Standards and Technology (NIST) Cybersecurity and Privacy Program develops and maintains an extensive collection of standards, guidelines, recommendations, and research on the security and privacy of information and information systems. Click these links for additional NIST SP Resources and the latest revision of NIST SP 800-171 . Although the latest revision of NIST 800 is revision 3, the DOD is has released a memo regarding deviation to continue using revision 2. For new agreements with the DOD, if you do not see a DOD deviation clause in your agreement, ask Sponsored Programs and your DOD contact to get a deviation included in the agreement. For assistance with any of these activities, questions related to NIST 800 compliance, or questions about research security in general, reach out to the Research Security & International Engagement team at RSIE@miami.edu or 305-243-6339.
NIST Cybersecurity Framework provides a common language and structure for understanding and improving security across teams, leadership, and partners. For additional information:
The NIST Cybersecurity Framework (CSF) 2.0 is generally voluntary and is designed as guidance to help organizations manage and reduce cybersecurity risk, not as a universal certification or one-size-fits-all checklist. That said, NIST-aligned practices may effectively become necessary when a sponsor, contract, data type, or research environment requires specific cybersecurity safeguards. UM’s research security materials also note that research-related cybersecurity is tied to evolving federal requirements, including expectations under NSPM-33.
NIST CSF 2.0 is intended for organizations of all types and sizes, not just critical infrastructure or large enterprises. NIST specifically positions the framework as a tool for organizations to understand, assess, prioritize, and communicate cybersecurity risk. At the University of Miami, this can include researchers, study teams, research administrators, IT staff, leadership, and support units that handle sensitive data or support research systems. UM describes research security as a shared institutional responsibility involving faculty, staff, students, and administrators.
NIST CSF gives organizations a common structure and language for managing cybersecurity risk. It helps organizations identify what needs protection, improve safeguards, detect issues sooner, respond effectively, and recover more efficiently through the six functions of Govern, Identify, Protect, Detect, Respond, and Recover. It also supports more consistent decision-making across technical and non-technical teams by helping organizations prioritize risk, improve communication, and align cybersecurity with broader organizational risk management. For UM, that matters because research security spans cybersecurity, disclosure, international collaboration, export control, and federal requirements, all of which benefit from a shared risk-based approach.
Not every study is required to formally adopt NIST CSF by name. However, your study may still need NIST-aligned safeguards if it involves sensitive data, sponsor-specific security terms, restricted systems, or other federal research security expectations. At UM, cybersecurity expectations increase when research involves PHI, PII, non-public University data, secure storage needs, restricted access, encryption, or approved institutional systems. UM’s data handling guidance specifically calls for strong safeguards around storage, access, encryption, and approved platforms for sensitive data. If the study is federally funded, includes sensitive research data, or is connected to a secure research environment, it is a good idea to confirm requirements with the appropriate UM offices before data collection or system access begins. This is especially important because federal research security expectations are expanding, including training and institutional compliance requirements.
Projects may need enhanced protections when they involve non-public University data, PHI, PII, sensitive research data, external sponsor requirements, or secure computing environments. UM’s data handling guidance and research security materials both emphasize using the right security level for the research being conducted.
Higher expectations commonly apply to PHI, PII, confidential or non-public University information, and research data that must be stored in controlled or approved systems. UM specifically directs employees and research teams to safeguard these data types and avoid unapproved storage methods.
Yes. UM states that employees with access to PHI must complete HIPAA Privacy & Security Awareness training, and PHI should not be stored on unapproved mobile devices or unsanctioned platforms.
Yes. Research security guidance emphasizes that international collaboration can create additional risk and should be managed in a way that protects research integrity, intellectual property, and sensitive systems while preserving open science.
UM’s research security program, Information Security Office, and related compliance and IT resources are intended to help the University community navigate cybersecurity expectations and apply the right safeguards for research systems and data.
If a sponsor references federal cybersecurity or research security expectations, those requirements should be reviewed carefully because they may impose project-specific obligations beyond UM’s standard baseline practices. UM’s research security and cybersecurity pages note that federal requirements are evolving and may affect researchers directly.
No. NIST CSF 2.0 is designed for use across the organization, and UM similarly frames research security as a shared institutional responsibility involving leadership, administration, researchers, and technical teams.
Training depends on the type of data, sponsor requirements, and systems involved. At a minimum, UM points users to cybersecurity awareness resources, and projects involving PHI require HIPAA-related training; federally funded research may also trigger separate research security training requirements. Contact the Research Security and International Engagement (RSIE) team for guidance on applicable training requirements and compliance obligations. Reach us at RSIE@miami.edu or 305-243-6339.