Covered Applications
Overview
Federal agencies may restrict the presence or use of certain software applications on devices and information technology used to perform federally sponsored activities. These restrictions are intended to reduce cybersecurity risks and protect federal information and information systems.
Requirements may be established through federal laws and regulations, agency guidance, contracts, grants, cooperative agreements, or other award terms and conditions.
Researchers performing federally sponsored activities may be required to comply with restrictions on covered applications on University-owned or personally owned devices used to perform the sponsored activity.
The Office of Research Security (ORS) assists researchers in identifying when these requirements apply and coordinates with the appropriate University offices to support compliance.
What Are Covered Applications?
The term covered application is used in certain federal requirements to identify software applications or services whose presence or use is prohibited or restricted on information technology within the scope of the applicable requirement.
One federal requirement, established under the No TikTok on Government Devices Act, restricts TikTok and certain successor applications or services developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.
Other federal agencies or award terms may establish additional restrictions on software, applications, or technologies.
Researchers should review the requirements applicable to their specific award and should not assume that the same restrictions apply to every federally sponsored activity.
When Might These Requirements Apply?
Covered application or similar software restrictions may apply when:
- Performing work under a federal contract or subcontract containing applicable restrictions.
- Performing research under a grant, cooperative agreement, or other award containing sponsor-specific application or technology restrictions.
- Using information technology subject to federal, sponsor, or contractual cybersecurity requirements.
- Using University-owned or personally owned devices to perform sponsored activities when those devices are within the scope of an applicable requirement.
- Other award terms or sponsor requirements restrict the presence or use of particular applications or technologies.
Applicable requirements depend on the sponsoring agency, award type, specific terms and conditions, information technology involved, and other circumstances of the activity.
Common Requirements
Depending on the applicable federal or sponsor requirement, researchers may be required to:
- Remove or refrain from installing covered applications on devices subject to the requirement.
- Refrain from using covered applications in connection with certain federally sponsored activities.
- Follow sponsor or contractual cybersecurity requirements.
- Use computing, devices, systems, or other information technology that meet applicable University and sponsor requirements.
- Coordinate with appropriate University offices regarding devices or systems used to perform covered activities.
The specific requirements depend on the applicable federal authority and the terms and conditions of the award.
Personally Owned Devices
Some federal requirements may apply to personally owned devices when those devices are used to perform covered activities.
For example, certain federal contract requirements apply to information technology used or provided by a contractor in performing the contract, including equipment provided by contractor employees, subject to the scope and exceptions established by the applicable requirement.
Researchers should not assume that personally owned devices are excluded from sponsor or contractual cybersecurity requirements.
How ORS Can Help
The Office of Research Security assists researchers by:
- Reviewing applicable sponsor, award, contract, and subcontract requirements.
- Identifying whether covered application or similar technology restrictions apply to a research activity.
- Helping researchers understand which activities, devices, systems, or other information technology may be within the scope of applicable requirements.
- Identifying overlapping research cybersecurity, information protection, or other sponsor requirements, when applicable.
- Coordinating with Research Computing & Informatics (RCI), DoIT and/or SBM-IT, the Office of Sponsored Programs, and other appropriate University offices when technical or administrative implementation is required.
- Providing research-specific guidance throughout the proposal, award, and research lifecycle.
Federal Authorities & Sponsor Requirements
Federal requirements addressing covered applications include Federal Acquisition Regulation (FAR) 52.204-27, Prohibition on a ByteDance Covered Application, which applies to certain federal contracts and subcontracts.
Federal agencies may also establish covered application or similar technology restrictions through grant, cooperative agreement, or other award terms and conditions.
Requirements may differ by sponsor, award type, applicable federal authority, and the information technology involved. Researchers should review the terms applicable to their specific activity and contact ORS when assistance is needed determining whether a requirement applies.
Related Guidance
| Reference Guide | Description |
|---|---|
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Federal Contract Information (FCI) | Learn about Federal Contract Information and contractual safeguarding and cybersecurity requirements that may apply to federal contracts and subcontracts. |
| Covered Telecommunications Equipment & Services | Learn about federal restrictions on certain telecommunications and video surveillance equipment and services that may affect federally funded research and University activities. |
| Kaspersky Lab Covered Entities | Learn about federal restrictions involving certain Kaspersky Lab hardware, software, and services that may affect federally funded research and other University activities. |
Need Assistance?
If your research is subject to sponsor or award requirements restricting covered applications, software, services, or other technologies, or you are uncertain whether such restrictions apply to your research activities or devices, contact the Office of Research Security.
ORS will assist in identifying applicable research-specific requirements and coordinate with the appropriate University offices when technical or administrative implementation is required.