# DNA synthesis biosecurity screening

Screening every DNA and RNA synthesis order against a curated database of dangerous pathogen and toxin sequences before it is manufactured — commercial compliance-automation platforms and cryptographically privacy-preserving nonprofit screening tools that gene-synthesis providers like Twist Bioscience now run on every incoming order, driven by an October 2026 US regulatory deadline dropping the flagging threshold to 50 base pairs.

Source: https://en.bioecon.ru/technology/dna-synthesis-biosecurity-screening/
Updated: 2026-08-18



## Overview and value chain

Markers: [EC: EU dual-use export control framework for synthetic nucleic acids | OECD: Biotech and health | Regulator: FDA (USA)]

DNA synthesis biosecurity screening checks every incoming gene- or oligo-
synthesis order against a continuously updated database of sequences of
concern — fragments of known pathogens, toxins and other regulated biological
agents — before a provider manufactures the DNA, and separately verifies the
customer's credentials to legitimately order such material. The US 2026
regulatory framework tightens the mandatory flagging threshold from 200 to 50
base pairs by October 2026, an order-of-magnitude increase in how small a
suspicious fragment must be caught. One commercial screening platform reports
screening tens of thousands of constructs with turnaround times under three
seconds and zero false positives validated against 67 million base pairs of
real synthesis data. This sits downstream of the DNA-writing technology
covered in genomics-dna-design.md — a compliance and risk-screening layer that
runs on top of a synthesis order, not the synthesis chemistry itself.

Key directions of DNA synthesis biosecurity screening:
1. **Sequence-of-concern screening (Sequence-of-Concern Screening):**
   real-time comparison of an order's DNA/RNA sequence against a curated,
   continuously updated database of pathogen and toxin fragments.
2. **Customer and order compliance automation (Compliance Automation):**
   automated verification of customer credentials and institutional
   legitimacy alongside the sequence check, reducing manual compliance
   review time for synthesis providers.
3. **Privacy-preserving cryptographic screening (Privacy-Preserving
   Screening):** screening protocols that check a sequence against a
   controlled-agent database without exposing the customer's proprietary
   sequence data to the screening operator.
4. **Cross-jurisdiction compliance (Cross-Jurisdiction Compliance):**
   screening databases and annotations that incorporate both US framework
   requirements and other national export-control regimes for providers
   selling internationally.

### Sectoral value chain

```
[synthesis order submitted] ──> [sequence screening] ──> [customer verification] ──> [order cleared/flagged]
                                        │
                              (sequence-of-concern database match)
                                        │
                                        ▼
[DNA/RNA manufactured] <─── [compliance record logged] <──┘
```

### Value chain levels

| Level | Description | Key inputs/outputs |
|:---|:---|:---|
| **Order intake** | customer submits a DNA/RNA sequence for synthesis | **In:** sequence data, customer info. **Out:** screening request. |
| **Sequence screening** | comparing the sequence against a threat database | **In:** sequence data, sequence-of-concern database. **Out:** match/no-match result. |
| **Customer verification** | confirming the orderer's institutional legitimacy | **In:** customer credentials. **Out:** verified/flagged customer status. |
| **Risk assessment** | evaluating flagged matches for genuine biosecurity risk | **In:** match result, context data. **Out:** clear, escalate or deny decision. |
| **Compliance logging** | recording the screening decision for regulatory audit | **In:** screening decision. **Out:** auditable compliance record. |
| **Order fulfillment** | manufacturing the cleared DNA/RNA sequence | **In:** cleared order. **Out:** synthesized DNA/RNA product. |

Cross-cutting technologies:
- **Sequence-of-concern screening (Sequence-of-Concern Screening):**
  continuously curated pathogen/toxin fragment databases with real-time
  matching algorithms.
- **DNA order compliance automation (Order Compliance Automation):**
  software that automates customer credential checks alongside sequence
  screening.
- **Distributed oblivious PRF screening (Privacy-Preserving Cryptography):**
  cryptographic protocols that screen a sequence without revealing it to the
  screening service.

---

## US

The US anchors both the regulatory driver and the leading commercial and
government-affiliated screening providers, following an October 2026
deadline that sharply tightens flagging requirements.

### October 2026 threshold tightening, commercial compliance SaaS, government-research-institute screening services
- **50-base-pair flagging deadline:** providers and manufacturers must begin
  flagging synthesis orders at 50 base pairs by October 2026, down from a
  200-base-pair threshold, under the US biosecurity framework.
- **Biosecurity Modernization and Innovation Act (2026):** proposed
  legislation (S. 3741) would mandate that all gene-synthesis providers
  screen orders and customers, establish a dangerous-sequence registry, and
  create a NIST governance sandbox for testing biosecurity tools.
- **Commercial and institute-run screening services:** a Columbia University
  spinout offers an end-to-end compliance-automation SaaS platform used by
  synthesis providers, while an applied-research institute's commercial
  ThreatSEQ web service — adopted by Twist Bioscience — won an R&D 100 Award
  for its continuously curated screening database.

---

## CN

No confirmed Chinese-based screening-tool vendor was found; Chinese synthesis
providers instead adopt international (largely Swiss- or US-developed)
screening tools to meet dual-jurisdiction compliance requirements.

### export-control-driven compliance adoption, dual-jurisdiction screening, IGSC consortium membership
- **Export-control compliance:** Chinese export-control regulations create a
  de facto requirement for DNA-synthesis-for-export providers to assess
  whether a sequence falls under controlled or sensitive categories.
- **International tool adoption:** a Shanghai-based high-throughput DNA
  synthesis provider adopted a Swiss-developed open-source screening tool
  specifically to maintain compliance across both US and Chinese regulatory
  systems — evidence of cross-border tool adoption rather than a domestic
  screening-vendor market.
- **International Gene Synthesis Consortium membership:** major Chinese and
  other Asian synthesis providers have joined the IGSC, signaling adoption of
  international screening norms even without a confirmed domestic screening
  *tool* vendor.

---

## EU

Switzerland hosts two of the field's most prominent screening-tool
developers, both structured as nonprofit foundations providing free,
internationally available tools rather than commercial SaaS products.

### Swiss nonprofit foundation model, free open-source and privacy-preserving tools, international standard-setting role
- **Common Mechanism (Basel-adjacent Swiss foundation):** launched May 2024
  as a free, open-source synthesis-screening package more robust against
  evasion attempts — including AI-generated sequences — than basic
  sequence-matching approaches, spun out of a US biosecurity nonprofit into
  an independent Swiss foundation.
- **Privacy-preserving cryptographic screening (Basel, Switzerland):** a
  Swiss-foundation-run service uses distributed oblivious pseudorandom
  function cryptography so a sequence can be screened against a controlled
  database without exposing the customer's proprietary sequence data to the
  screening operator itself.
- **EU dual-use export control:** the EU's dual-use goods export control
  framework governs synthetic nucleic acid exports, the regulatory backdrop
  against which the two Swiss-based tools operate internationally.

---

## Leading companies and research institutes

| Company / Institute | Country | Key products / platforms | Tech features | Status 2026 |
|:---|:---|:---|:---|:---|
| **Aclid** | 🇺🇸 USA | *End-to-end gene-synthesis compliance platform* | Columbia University spinout; real-time screening, sub-3-second turnaround; customers incl. Ansa Biotechnologies | Commercial |
| **Battelle** | 🇺🇸 USA | *ThreatSEQ™ DNA screening web service* | R&D 100 Award winner; continuously curated Sequence of Concern database; adopted by Twist Bioscience | Commercial |
| **IBBIS** | 🇨🇭 Switzerland | *Common Mechanism (commec)* | Free, open-source; robust against AI-generated sequence evasion; adopted by Dynegene (China) for dual-jurisdiction compliance | Research |
| **SecureDNA** | 🇨🇭 Switzerland | *Distributed Oblivious PRF screening system* | Zero false positives validated against 67M base pairs; privacy-preserving cryptographic screening | Research |

---

## Tech stack and innovations

The category's technical core is a continuously updated threat database
paired with a matching algorithm fast and robust enough to run on every
synthesis order without materially slowing production.

1. **Sequence-of-concern database curation (Biocuration Pipeline):**
   - Databases of pathogen and toxin sequence fragments require continuous
     updating as new sequences of concern are identified, a labor-intensive
     curation process one commercial provider has spent decades building.
   - Screening algorithms must catch both exact matches and near-matches
     designed to evade simple string-matching, including sequences
     deliberately altered or AI-generated to slip past basic screening.
2. **Real-time compliance automation (Order Screening Pipeline):**
   - Screening now runs as an automated step in the order-intake pipeline
     rather than a manual review, delivering risk assessments in seconds so
     it does not become a synthesis-provider bottleneck.
   - Customer credential verification runs alongside sequence screening,
     since a benign sequence ordered by an illegitimate customer is still a
     biosecurity risk the screening step must catch.
3. **Privacy-preserving screening cryptography (Distributed Oblivious PRF):**
   - Cryptographic protocols let a screening service confirm whether a
     sequence matches a controlled database without the screening operator
     ever seeing the customer's actual proprietary sequence — addressing
     synthesis providers' IP-confidentiality concerns about third-party
     screening.
   - This is the technical innovation that made free, third-party screening
     tools viable for commercial gene-synthesis providers unwilling to
     expose proprietary customer sequences to an external screening service.

---

## Value chains and production pipelines

### Industrial pipeline of a screened gene-synthesis order

```
┌───────────────────────────┐      ┌───────────────────────────┐
│ 1. Order submission        │ ───> │ 2. Sequence screening      │
└───────────────────────────┘      └───────────────────────────┘
                                                 │
                                                 ▼
┌───────────────────────────┐      ┌───────────────────────────┐
│ 4. Risk assessment         │ <─── │ 3. Customer verification  │
└───────────────────────────┘      └───────────────────────────┘
              │
              ▼
┌───────────────────────────┐      ┌───────────────────────────┐
│ 5. Compliance logging     │ ───> │ 6. Order fulfillment      │
└───────────────────────────┘      └───────────────────────────┘
```

#### Stage 1: Order submission
A customer submits a DNA or RNA sequence to a gene-synthesis provider,
triggering the automated screening pipeline before manufacturing begins.

#### Stage 2: Sequence screening
The submitted sequence is compared in real time against a continuously
curated sequence-of-concern database, checking for matches to known
pathogen, toxin or other regulated agent fragments down to the 50-base-pair
threshold.

#### Stage 3: Customer verification
In parallel, the ordering customer's institutional credentials are checked
against known-legitimate-customer criteria, catching the case of a benign
sequence ordered by an illegitimate or unverifiable customer.

#### Stage 4: Risk assessment
Any sequence or customer match is escalated for risk assessment, evaluating
whether the flagged result represents a genuine biosecurity concern or a
benign false positive requiring manual review.

#### Stage 5: Compliance logging
The screening decision — cleared, escalated or denied — is logged into an
auditable compliance record, the documentation regulatory frameworks require
providers to maintain.

#### Stage 6: Order fulfillment
Cleared orders proceed to synthesis, with the DNA or RNA manufactured and
shipped to the customer once the compliance record is complete.

