Frameworks · Trusted CI Framework · NSF Research Cyberinfrastructure
Protect the science.
Keep the grant.
Your NSF funding depends on more than the science — proposals and reviews now expect a real cybersecurity program, and most research organizations run security as a sliver of one person's job. The Cyber Tackle Box™ platform holds the program reviewers look for — the plan, the policies, the evidence — and Lionfish & partner consultants can stand it up with you, without pulling your scientists off the science or forcing corporate lockdown on an open-research culture.
Technical evaluator? Skip the pitch — jump to the deep dive ↓
For the technical reader — the deep dive
- ▸Structure: 4 pillars (Mission Alignment, Governance, Resources, Controls) and 16 Musts — a program standard, not a control checklist.
- ▸NSF linkage: Research Infrastructure Guide §6.3 aligns major-facility cybersecurity guidance to the Framework; §4.6.6.3 names the four pillars as an IT management competency; CI Plans required in major-facility and mid-scale proposals.
- ▸Must 15 (baseline control set) became concrete on July 15, 2026: Trusted CI published an NSF Critical Controls ↔ CIS Controls v8.1 mapping, with 800-171 mappings planned.
- ▸2026 scope expansion: research security (NSPM-33) and secure use of AI.
- ▸In the Tackle Box: the 16 Musts as tracked milestones, governance document templates for research orgs, CIS v8.1 control tracking per the mapping, evidence for cooperative-agreement reviews.
Want to go deeper than a web page? Book a call — you'll be talking to a practitioner, not a salesperson.
Research cybersecurity, by the numbers
Sources: trustedci.org Framework core and 2026 program announcements; NSF Research Infrastructure Guide. Trusted CI's own cohorts are excellent — and rationed to a few facilities a year. We serve everyone who can't get a slot.
Who this is for
For the people who defend open science
Enterprise security templates don't fit organizations whose mission is openness. The Trusted CI Framework was built for research — and so is our delivery of it.
- ✓NSF major facilities and mid-scale projects whose proposals and reviews require a Cyberinfrastructure Plan spanning the facility life cycle — with cybersecurity competency named in the guide.
- ✓University research computing and HPC centers balancing open science against real threats, with a security 'team' that's one person's afternoon.
- ✓Research institutions facing NSPM-33 where research-security program requirements now threaten eligibility for all federal funding — not just one award.
Sound familiar?
The pain we hear on every first call
- !Governance artifacts from thin air. Policy, budget, asset classification, evaluation cadence — the Musts demand documents research orgs have never had to produce, with no staff to produce them.
- !Cohort capacity is rationed. Trusted CI's hands-on cohorts take a few facilities a year. Everyone else executes alone — or with us.
- !Soft-money security. Grant-funded organizations struggle to justify recurring security spend. A weak CI Plan risks awards worth hundreds of times the program's cost.
The platform
How the Cyber Tackle Box™ runs your Trusted CI program
The July 2026 NSF-to-CIS v8.1 mapping made 'adopt a baseline control set' (Must 15) concrete — and the Tackle Box tracks CIS v8.1 natively.
Program Document Templates
Master information security policy, asset classification, risk-acceptance records — the governance artifacts the 16 Musts require, pre-structured for research organizations.
Musts as Milestones
All 16 Musts tracked with owners, status, and dates — a live program dashboard for facility leadership and NSF reviews alike.
Findings → POA&Ms
Assessment findings and residual risks become assigned action plans — evidence of a program that evaluates and refines itself (Must 10).
Evidence & the Intel Hub
One timestamped evidence library for cooperative-agreement reviews, plus threat intelligence tuned to research infrastructure.
CI Plan Playbooks
Runbooks for building and maintaining the Cyberinfrastructure Plan NSF proposals require — aligned to RIG Section 6.3.
Training for Researchers
Awareness training that respects how scientists actually work — tracked per person, from a team with deep university partnerships (Purdue CERIAS, Ball State).
Software, services, or both
Two ways to work with Lionfish
The Cyber Tackle Box™ is a product you can run yourself. Our consulting team is a service you can add. Take either — or both. They're priced separately, and we'll tell you straight which one you actually need.
The platform — Cyber Tackle Box™
Software you run yourself: framework-mapped controls, policy templates, evidence, POA&Ms, and workforce training in one system of record. Your team (or your MSP) drives; the platform keeps everything organized and audit-ready.
Book a platform demoThe services — Lionfish & partner consultants
Add Lionfish & partner consultants — led by the team that trains certified CMMC assessors, backed by our vetted Trusted Partner Network — to run the gap assessment, drive remediation, and prepare you for the audit, by, with, and through your team, inside the same platform.
Book a readiness callFor MSPs & partners
Multi-tenant by design: run every client's compliance program from one console and add a services line without adding headcount. White-glove onboarding for your first clients.
Partner with usStraight answers
Trusted CI questions we answer every week
What is the Trusted CI Framework?
It's the NSF Cybersecurity Center of Excellence's minimum standard for cybersecurity programs at research organizations — 4 pillars (Mission Alignment, Governance, Resources, Controls) containing 16 'Musts.' Unlike control checklists, it defines what a functioning program looks like: leadership involvement, a named security lead, a real budget, documented policy, and a baseline control set.
Does NSF actually require this?
NSF requires proposals for new major facilities and mid-scale research infrastructure to include a Cyberinfrastructure Plan, and its Research Infrastructure Guide aligns the cybersecurity guidance (Section 6.3) to the Trusted CI Framework — it even names the Framework's four pillars as a management competency. There's no certificate, but program adequacy is reviewed with your award — which makes it as real as requirements get.
What changed in 2026?
Three things: Trusted CI expanded into research security (NSPM-33) and AI security; it launched regional summits; and in July 2026 it published a mapping from the NSF Critical Controls to CIS Controls v8.1 — with NIST 800-171 mappings planned. That mapping means facilities can finally satisfy 'adopt a baseline control set' with a concrete, trackable control library — which the Cyber Tackle Box supports natively.
We're a university with CUI research too — can one program cover both?
Yes, and it should. Federally funded research increasingly brings NIST 800-171 obligations alongside Trusted CI expectations and GLBA coverage of financial-aid data. The Tackle Box maps one control implementation across all of them, so the half-FTE running security isn't maintaining three parallel programs. Our university partnerships mean we already speak your governance.
Get in touch
Build a program NSF can read
Tell us about your facility or center, your award timeline, and who currently 'does security.' You'll get a straight program assessment within one business day.
- 1We reply within one business day — usually faster.
- 2A 30-minute call with someone who can actually answer your questions.
- 3A straight recommendation — even if it's that you don't need us yet.
Prefer to skip the form? Book a time directly or call 1-877-732-6772.