Skip to content
Wednesday, October 7, 2026
Dark BiotechnologyBIOTECH · GENETICS · DEVICES
Research

How U.S. Biosecurity Policy Screens Synthetic DNA Orders

U.S. synthetic DNA biosecurity rests on a voluntary screening framework issued by the Department of Health and Human Services in October 2023, which asks gene synthesis providers and their customers to screen orders for sequences of concern down to 50 nucleotides, per the guidance published by…

Dr. Charlotte Meyer · June 4, 2026 · 8 min read
ShareXFacebookLinkedInTelegramEmail
A gloved researcher pipetting samples at a stainless-steel lab bench under cool white light, safety glasses pushed up, no visible labels or logos.
A gloved researcher pipetting samples at a stainless-steel lab bench under cool white light, safety glasses pushed up, no visible labels or logos.

U.S. synthetic DNA biosecurity rests on a voluntary screening framework issued by the Department of Health and Human Services in October 2023, which asks gene synthesis providers and their customers to screen orders for sequences of concern down to 50 nucleotides, per the guidance published by the Administration for Strategic Preparedness and Response.

What problem is synthetic nucleic acid screening trying to solve?

The policy exists to make it harder for a bad actor to order the genetic material of a dangerous pathogen from a commercial provider. as CIDRAP reported when the first guidance appeared in 2010, the document called on suppliers to screen both customers and the DNA sequences they order, and to investigate further if those steps raise concerns. The concern is specific: synthetic biology is not constrained by the requirement of using existing genetic material, so ordered DNA can, in principle, be assembled into regulated pathogens.

The 2010 baseline reflected the industry of its time. It recommended that providers of synthetic double-stranded DNA screen orders to detect sequences of 200 base pairs or longer unique to regulated agents, such as Biological Select Agents and Toxins or Commerce Control List agents, according to ASPR's summary of the earlier guidance. That threshold left most short oligonucleotides and single-stranded orders outside the recommended net, and the commercial landscape has since moved toward faster, cheaper synthesis of shorter fragments across more vendors and benchtop instruments.

What has not changed is the underlying logic. Screening is a choke point: a small number of providers sit between sequence design and physical DNA, and checking orders at that point is cheaper than trying to police every downstream user. The policy question is how far the net should extend, and who is obliged to hold it.

What did the 2023 HHS framework actually change?

The revised guidance expanded both the definition of what is screened and the set of entities asked to screen, per ASPR. The key changes are best read as a list:

  1. A definition of sequences of concern that includes all sequences contributing to pathogenicity or toxicity, whether from regulated or unregulated agents, rather than only select-agent sequences.
  2. Best practices for all entities involved in the synthesis, use, and transfer of nucleic acids containing sequences of concern, covering providers and customers such as institutions, principal users, end users, and third-party vendors.
  3. Best practices for manufacturers of benchtop nucleic acid synthesis equipment and the institutions where such instruments are used.
  4. A smaller recommended screening window of 50 nucleotides, down from 200 base pairs.
  5. Coverage of all synthetic nucleic acid order types, meaning single- and double-stranded forms of both DNA and RNA.

The revision followed a stakeholder process documented in a peer-reviewed review in Applied Biosafety, which describes how comments solicited through Federal Register notices in 2020 and 2022 informed the drafting, and notes that an executive order later directed departments and agencies to support implementation of the framework. In other words, the technical content came from HHS, while the executive branch pushed agencies to fold it into procurement and research funding expectations.

The review also records the scale of the consultation: the 2020 notice drew 15 unique responses totaling 220 pages, and the 2022 notice drew 26 responses totaling 79 pages. That is a small but engaged comment base, dominated by providers, universities, and security policy specialists.

Who has to follow the framework, and who does not?

No one is legally required to follow it, which is the central caveat in any description of U.S. synthetic DNA biosecurity. The framework sets recommended baseline standards for the gene and genome synthesis industry and for manufacturers of benchtop nucleic acid synthesis devices, per ASPR, and details best practices for customers handling sequences of concern. A provider that screens nothing violates no federal rule directly, although it may become ineligible for federal contracts as agencies implement procurement preferences.

In practice, the major commercial providers screen orders, because customers, especially pharmaceutical companies and universities, increasingly require it contractually, and because an unnamed provider that ships a dangerous sequence to a bad actor faces reputational and legal exposure no guidance is needed to imagine. The International Gene Synthesis Consortium, an industry body formed in 2009, has promoted a common screening protocol for both sequences and customers since before either U.S. guidance existed.

The gaps are structural rather than accidental. Providers outside the United States operate under different expectations, used-equipment markets put benchtop synthesizers in settings no vendor tracks, and fragment ordering across multiple providers can defeat per-order screening if no provider sees enough of a sequence to flag it. These are the known limits of a voluntary regime, acknowledged in the guidance's own framing of risk minimization rather than prevention.

How does screening work at the order level?

Screening under the framework has two legs, and both must clear. The first is customer screening: providers are asked to verify that the ordering institution and the individuals behind it are legitimate, watching for red flags such as unverifiable affiliations, unusual shipping instructions, or orders inconsistent with a stated research purpose, as described in the original 2010 guidance coverage. The second leg is sequence screening: each ordered sequence is compared against databases of regulated agents and, under the 2023 definition, broader sequences of concern.

The 50-nucleotide window matters because it forces screening of short oligonucleotides, the commodity product of the modern synthesis industry. Assembly methods can stitch many short fragments into a full gene, so a window that ignores short orders leaves an obvious route around sequence screening. The framework's extension to single-stranded DNA and to RNA closes the same kind of gap for order types that the 2010 rules did not contemplate.

When a screen flags an order, the expected flow is follow-up with the customer, escalation if concerns are not resolved, and, where warranted, contact with federal authorities, mirroring the 2010 process CIDRAP described. What the framework does not do is define enforcement: there is no dedicated inspectorate for screening failures, and the consequences run through contracts, funding conditions, and existing select-agent and export-control law.

How do institutions fit into the framework?

Customers carry obligations of their own, which is the part of the guidance most often missed by laboratories that think of screening as the vendor's job. The framework details best practices for customers of synthetic nucleic acids, meaning institutions, principal users, end users, and third-party vendors, regarding screening orders for sequences of concern and for responsibly handling the use and transfer of synthetic nucleic acids containing such sequences, per ASPR. In practice that means an institution ordering a flagged sequence should expect follow-up questions, and an institution transferring sequences of concern onward inherits screening-like responsibilities it may not have planned for.

For universities, the practical implementation question is where the obligation lands organizationally. Environmental health and safety offices, biosafety committees, and procurement functions each touch a piece of the order lifecycle, and the framework does not assign the responsibility to any one of them. Institutions that centralize DNA purchasing through an approved-provider list, with screening requirements written into the contract, effectively extend the framework's baseline down to the bench without inventing new local bureaucracy.

For companies, the calculus is similar but runs through supplier qualification. A vendor's screening posture, whether it screens to the 2023 definition of sequences of concern and whether it vets customers as well as sequences, is now a standard line in procurement due diligence, because the downstream user of an unscreened order inherits the reputational exposure that comes with it. The framework made no one legally responsible, and it made everyone contractually accountable instead.

What should industry readers watch next?

The pressure points are procurement and rulemaking rather than the guidance itself. Agencies were directed to encourage adoption, which in practice means screening commitments showing up in federal grant conditions and contract clauses, a shift the Applied Biosafety review flags as an expected impact on the research community. Separately, rulemaking conversations around nucleic acid synthesis equipment and export jurisdictions continue in other forums, and any move from recommended to mandatory screening would change the cost calculus for small providers most of all.

For companies ordering DNA, the practical reading is straightforward: screening requirements arrive through customer contracts today, and the framework is the reference text those contracts point to. Knowing whether a vendor screens to the 2023 definition, and whether it screens customers as well as sequences, is now a routine supplier-qualification question.

This article is intended for general informational purposes only and does not constitute medical advice, regulatory guidance, or a recommendation for any product or course of action.

Sources

  1. Screening Framework Guidance for Providers and Users of Synthetic Nucleic Acids — U.S. Department of Health and Human Services, Administration for Strategic Preparedness and Response
  2. Enhancing Gene Synthesis Security: An Updated Framework for Synthetic Nucleic Acid Screening and the Responsible Use of Synthetic Biological Materials — Applied Biosafety (PMC)
  3. HHS guidance aims to prevent misuse of synthetic DNA — CIDRAP, University of Minnesota

More from our brands

Part of the VUGA Network