On August 20, 2026, the White House released the National Security Science and Technology Strategy (“NSSTS“), which establishes the Trump administration’s framework for maintaining US technological leadership and protecting critical and emerging technologies. The NSSTS is organized around four pillars: (1) focusing techno-strategic competition, (2) building technological resilience, (3) accelerating innovation, and (4) protecting national security science and technology.
For sanctions, export controls, investment screening, and data security practitioners, Pillar 4(Protect National Security S&T) is likely the most notable aspect of the NSSTS. The Trump administration signals its intention to continue using an increasingly integrated set of tools, including export controls, foreign investment review mechanisms, research security measures, and restrictions on data transfers to countries of concern, to prevent foreign adversaries from obtaining access to sensitive US technologies, know-how, and data.
Pillar 4 at a Glance
Pillar 4 states that the United States will protect its science and technology ecosystem from “foreign theft, diversion, and exploitation” while seeking to avoid unnecessary burdens on innovation. According to the strategy, key priorities include:
- Strengthening research security to protect US research institutions, personnel, and federally funded research from foreign exploitation, espionage, and improper influence.
- Modernizing foreign investment screening and security measures, reflecting the continued importance of the Committee on Foreign Investment in the United States (“CFIUS“) and related investment-security authorities as tools for protecting sensitive US technologies and infrastructure.
- Strengthening and streamlining export controls and related technology protection measures, with an emphasis on preventing adversaries from obtaining advanced US technologies while avoiding unnecessary friction for US innovation and cooperation with trusted partners.
- Maintaining restrictions on the transfer of sensitive US data to foreign adversaries, including through implementation of the Department of Justice’s Data Security Program.
Data Security Program Receives Renewed White House Support
One of the more interesting aspects of Pillar 4 is the strategy’s specific endorsement of the Data Security Program (“DSP“), which has received less public attention in recent months than export controls, outbound investment restrictions, and CFIUS.
The NSSTS notes that “[r]elevant agencies should continue prioritizing the Data Security Program, established in May 2025 in response to the national emergency President Trump declared through Executive Order 13873. Through the Data Security Program and other tools, the United States will protect government-related data and bulk genomic, geolocation, biometric, health, financial, and other sensitive personal data of Americans against foreign adversary access and exploitation.” The inclusion of this language underscores that the Trump administration views data security restrictions as a core element of the US technology protection framework alongside export controls and investment screening. The NSSTS also reflects the US government’s increasingly broad conception of national security risk, extending beyond traditional military technologies to include access to data involving sensitive personal information.