NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
10 CFR 73.54 Programme Requirements
Establish, implement, and maintain a cyber security program that provides high assurance that digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions, and support systems and equipment which if compromised would adversely impact those functions, are adequately protected against cyber attacks up to and including the design basis threat.
- Approved Cyber Security Program description
- Scope statement identifying SSEP functions
- Mapping of systems to SSEP categories
- Approval by senior responsible officer
- Scope limited to safety systems excluding security and emergency preparedness
- Support systems not evaluated
- Program description not updated after digital upgrades
Develop and maintain a written cyber security plan that implements the cyber security program and is incorporated into the physical security plan, subject to NRC approval. Amendments require formal change control under 10 CFR 50.90 or 73.54(c) as applicable.
- Approved Cyber Security Plan
- NRC approval correspondence
- Plan amendments and submissions
- Configuration management of plan documents
- Plan not aligned with current organization or technology
- Amendments not submitted under proper change process
- Document control insufficient
Ensure that the cyber security program is established, implemented, and maintained by a senior level officer accountable for the overall management of the program, with adequate resources, authority, and access to senior management.
- Designation of senior responsible officer
- Reporting line to senior management
- Resource allocation evidence
- Program governance charter
- Senior responsible officer not formally designated
- Reporting line through IT only
- Insufficient resources documented in periodic reviews
Define and document cyber security roles, responsibilities, and lines of authority for personnel involved in implementing the cyber security program, including the Cyber Security Assessment Team and supporting functions.
- Cyber Security Assessment Team charter
- Position descriptions and qualifications
- Training and qualification records
- RACI for cyber activities
- CSAT charter outdated
- No engineering representation on CSAT
- Qualifications not periodically re verified
Provide initial and continuing cyber security training and awareness for personnel performing cyber security related responsibilities, with role specific qualification requirements for the Cyber Security Assessment Team and support functions.
- Training plan and curricula
- Completion records by role
- Qualification cards
- Refresher training schedule
- Training generic and not role specific
- Refresher cycle exceeded
- Contractors with CDA access untrained
Conduct a review of the cyber security program at least every 24 months, including an evaluation of the effectiveness of the program in protecting Critical Digital Assets, with results documented and findings tracked to closure.
- Biennial program review report
- Reviewer qualifications and independence
- Findings and corrective actions
- Closure evidence
- Review performed by program owner without independence
- Findings open beyond corrective action deadlines
- Review scope incomplete
Access Control + Media + Devices
Implement access control + authentication + removable media controls per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.1 (Access Control) + Section B.1.7 (System and Communications Protection - Portable Media Controls). Access control must (a) enforce unique user identification + authentication + authorisation for all CDA access including engineering + operations + maintenance + administrative + vendor access, (b) implement multi-factor authentication for privileged access + remote access + access to highest-assurance security levels, (c) enforce least privilege + separation of duties + emergency-access procedures with audit, (d) manage shared accounts only where individual identification is operationally infeasible with compensating monitoring, (e) restrict and log remote access via authorised pathway only (jump host + PAM + session recording + JIT approval). Authentication crede
- unique user IDs + MFA configuration at higher security levels + remote access via PAM + session recording
- removable media policy + sandboxed transfer station evidence + chain of custody
- USB port disabling configuration where feasible + workforce discipline training records
- shared accounts on CDA workstations
- removable media transfer without sandbox + chain of custody
- vendor remote access via persistent VPN without PAM
Attack Mitigation and Monitoring
Provide the capability to detect, respond to, and recover from cyber attacks on Critical Digital Assets, including identification of indicators, containment, eradication, recovery, and restoration of compromised assets.
- Detection technology configurations
- Incident response procedures specific to CDAs
- Recovery runbooks
- Sample incident records
- Detection limited to IT and not CDA enclaves
- Recovery runbooks untested
- No coordination with engineering for restoration
Ensure that the capability to perform safety, security, and emergency preparedness functions is maintained or restored following a cyber attack, with manual or independent backup measures available to compensate for compromised digital functions.
- Documented manual or analog backup procedures for SSEP functions
- Equipment for manual operation
- Operator training for backup actions
- Periodic exercises validating backups
- Manual backups exist on paper but not in operator simulator scenarios
- Equipment unavailable or out of calibration
- Exercises not conducted
Maintain the cyber security program through ongoing monitoring and assessment activities to ensure that the security controls remain effective and that the defensive architecture continues to provide high assurance of protection.
- Continuous monitoring procedures
- Vulnerability assessment results
- Periodic effectiveness reviews
- Trend analysis
- Monitoring focused on IT only
- Vulnerability assessments not performed for CDAs
- Effectiveness reviews not documented
Critical Digital Asset Identification
Identify and maintain the inventory of Critical Digital Assets (CDAs) per 10 CFR 73.54(b)(1) + (b)(2). CDAs are digital computer and communication systems and networks associated with (a) safety-related and important-to-safety functions, (b) security functions, (c) emergency preparedness functions including offsite communications, (d) support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions. CDA identification process must (a) review all digital assets per system + subsystem + component, (b) determine each assets contribution to safety + security + EP functions, (c) document the determination + rationale + evidence per asset, (d) maintain the CDA inventory under configuration management with periodic review, (e) reassess when systems are added + modified + replaced + when functional analysis changes. Boundary definiti
- CDA inventory under configuration management with periodic review
- determination evidence per CDA covering safety + security + EP functions analysis
- boundary documentation between CDA and non-CDA networks
- reassessment evidence for system changes + modifications
- under-scoped CDA inventory missing important-to-safety or EP support systems
- boundary undocumented or not enforced
- CDA reassessment skipped on system change
Critical Digital Assets and Defensive Architecture
Analyze digital computer and communication systems and networks, and identify those assets that must be protected from cyber attacks. Identify Critical Systems and the Critical Digital Assets within them whose compromise could adversely affect safety, security, or emergency preparedness functions.
- Critical Systems list
- Critical Digital Asset inventory with attributes
- CDA scoping methodology
- Periodic refresh of inventory
- CDA inventory not reflecting modifications
- Support assets that could affect SSEP not classified as CDAs
- No attribute level data for assets
Establish, implement, and maintain a defensive architecture consisting of five concentric defensive levels separated by security boundaries with deterministic data flow controls, such that traffic from less secure to more secure levels is restricted and one way isolation is enforced between the highest and second highest levels.
- Defensive architecture diagram showing levels 0 through 4
- Deterministic device configuration evidence (data diodes between level 4 and 3)
- Boundary device rule sets
- Architecture review records
- Bidirectional flow between levels 4 and 3
- Boundary rules permit broad protocols
- Architecture diagrams outdated
Implement and maintain the security controls of RG 5.71 Appendix B and C or equivalent (NEI 08 09 Appendices D and E) for each Critical Digital Asset, addressing technical, management, and operational controls, with documented basis for any alternative measures or risk informed tailoring.
- Per CDA control assessment
- Control implementation evidence
- Alternative measure justifications
- Risk informed analysis where used
- Per CDA assessment incomplete
- Alternative measures unjustified
- Operational controls not tied to procedures
Apply defense in depth protective strategies to provide multiple layers of administrative, technical, and physical controls so that compromise of any single control does not adversely impact safety, security, or emergency preparedness functions.
- Control overlay matrix showing administrative, technical, and physical layers
- Per CDA defense in depth analysis
- Compensating control documentation
- Overlay matrix not maintained
- Single point of failure controls without compensating layers
- Physical controls excluded from cyber analysis
Cybersecurity Plan and Programme
Establish and submit a cybersecurity programme per 10 CFR 73.54(a) + 73.54(d) for NRC review and approval. The licensee must provide high assurance that digital computer and communication systems and networks are adequately protected against cyber attacks up to and including the design basis threat as described in 10 CFR 73.1. Programme establishment per 73.54(a) requires (a) analyse digital computer and communication systems and networks and identify those associated with safety-related and important-to-safety functions + security functions + emergency preparedness functions including offsite communications + support systems and equipment which if compromised would adversely impact safety + security or emergency preparedness functions (Critical Digital Assets or CDAs), (b) protect those identified CDAs from cyber attacks that would adversely impact the design function. Cybersecurity Pla
- approved Cybersecurity Plan as submitted to NRC + NRC approval evidence
- programme establishment evidence per 73.54(a)(1)
- programme maintenance + review schedule + update history
- operational reality matching submitted plan with change-management for variations
- operational drift from submitted plan
- no formal change-management for plan variations
- plan submitted but programme implementation incomplete
Defensive Architecture
Implement Defensive Architecture per 10 CFR 73.54(c) using a defense-in-depth approach with multiple layers of protection. NRC RG 5.71 Appendix B describes the recommended Defensive Architecture with five Security Levels (Levels 4 + 3 + 2 + 1 + 0 with 4 highest assurance) separated by Security Boundary Devices (deterministic one-way data flow at the highest assurance boundaries and stateful protocol-aware enforcement at lower-assurance boundaries). Levels approximately correspond to (a) Level 4: safety + important-to-safety + security functions CDAs, (b) Level 3: emergency preparedness + balance-of-plant CDAs supporting Level 4, (c) Level 2: site IT networks supporting plant operations, (d) Level 1: corporate IT networks, (e) Level 0: external networks. Network segregation must (a) physically separate CDA networks from non-CDA networks where deterministic one-way enforcement is required,
- authoritative architecture diagrams per RG 5.71 Appendix B 5-level model
- boundary device inventory with unidirectional gateway at highest assurance + stateful FW at lower
- traffic policy documentation + monitoring + alerting
- verification of physical separation from Level 0/1 untrusted networks
- stateful firewall used where unidirectional gateway should be
- boundary device monitoring incomplete
- direct connection between Level 4 CDA and Level 0/1 networks (severe finding)
Incident Reporting and Records
Report cyber security events to the NRC consistent with 10 CFR 73.77, including notifications within prescribed timelines for events that adversely affect or could adversely affect the ability of the licensee to maintain Safety, Security, and Emergency Preparedness functions.
- Cyber event reporting procedure
- Sample NRC notifications with timelines
- Operations center 24 hour capability
- Coordination with corrective action program
- Reporting timelines miscategorized
- Operations center unaware of 73.77 thresholds
- Reports incomplete or delayed
Retain records relating to the cyber security program including assessments, modifications, training, audits, drills, incidents, and changes for a period that meets NRC retention requirements and supports inspection by the NRC.
- Records retention schedule
- Sample records by category
- Access controls protecting safeguards information
- Inspection readiness binder
- Records dispersed across sites without index
- Safeguards Information markings inconsistent
- Inspection preparation reactive rather than continuous
Monitoring, IR, Reporting, Contingency
Operate monitoring + assessment + incident response + contingency per 10 CFR 73.54(c) + NRC RG 5.71 Appendix C + 10 CFR 73.77 (Cybersecurity Event Notification + reporting requirements established by 2015 final rule). Monitoring per RG 5.71 must (a) continuous monitoring of CDA networks + hosts + applications via OT-aware sensors + EDR where supported + SIEM correlation + threat intelligence, (b) periodic assessment via cybersecurity audits + penetration testing + tabletop exercises + control effectiveness measurements. Incident Response per RG 5.71 Appendix C must (a) document IR plan covering scenarios + roles + activation + containment + recovery + post-incident review + integrate with broader physical security + emergency preparedness response, (b) IR team including cybersecurity + plant operations + engineering + safety + EP + Public Affairs + legal + executive leadership, (c) 24x7
- continuous monitoring architecture with OT-aware sensors + SIEM + threat intel
- IR plan + team + 24x7 capability + tabletop and technical exercise evidence
- 10 CFR 73.77 reporting decision tree + on-call duty officer + NRC Operations Center contact procedure + practiced procedure
- contingency plan + backup/recovery + integration with EP
- 10 CFR 73.77 reporting decision tree absent or unfamiliar to on-call
- monitoring limited to network perimeter (no host + device telemetry on CDAs)
- no tabletop exercise in 12+ months
Programme Oversight and Records
Operate programme oversight + independent review + documentation + training + supply chain per 10 CFR 73.54(d) + (g) + NRC RG 5.71 Appendix C. Programme oversight per 73.54(d)(2) requires the cybersecurity programme to be (a) reviewed as a component of the physical security programme + maintained for the life of operating licence per 73.54(g), (b) independently reviewed at least every 24 months + assessed for effectiveness against the cybersecurity plan + and against current threats + technology + organisational changes, (c) management review of programme metrics + control performance + incident trends + audit findings with documented closure tracking. Documentation per 73.54(d) + (e) must (a) maintain records sufficient to demonstrate compliance with the cybersecurity plan + maintain change history + assessment results + incident records + training records, (b) records preservation for
- biennial independent review reports + closure tracking
- management review records + programme metrics
- training records (initial + annual refresher + role-specific) + tabletop participation
- supply chain cybersecurity requirements in procurement + vendor assessment + vendor monitoring + verified-clean media procedures
- biennial independent review by people too close to programme producing soft findings
- training generic IT not nuclear-CDA specific or not refreshed
- procurement does not include cybersecurity requirements for CDA-relevant systems
Regulatory Guide 5.71 Appendix C Security Controls
Personnel with access to critical digital assets must receive cyber security awareness and role-based training.
- Defence-in-depth architecture diagrams for safety and security functions
- Incident response procedures aligned to RG 5.71 Appendix C
- Configuration management baseline records for CDAs
- Continuous monitoring coverage gaps for legacy safety-related systems
- CDA inventory incomplete for support systems and balance-of-plant equipment
- Defence-in-depth boundaries inadequately documented or enforced
Licensees must develop and maintain a cyber security incident response plan with defined procedures.
- Defence-in-depth architecture diagrams for safety and security functions
- Incident response procedures aligned to RG 5.71 Appendix C
- Configuration management baseline records for CDAs
- Cyber security training and awareness records for personnel
- Cyber Security Plan documented under 10 CFR 73.54(e)
- Defence-in-depth boundaries inadequately documented or enforced
- Insider threat considerations not integrated with access authorisation programme
- Configuration management drift between as-built and as-documented states
- Continuous monitoring coverage gaps for legacy safety-related systems
Licensees must have procedures to recover and restore critical digital assets following a cyber security event.
- Defence-in-depth architecture diagrams for safety and security functions
- Incident response procedures aligned to RG 5.71 Appendix C
- Configuration management baseline records for CDAs
- Cyber security training and awareness records for personnel
- Cyber Security Plan documented under 10 CFR 73.54(e)
- Defence-in-depth boundaries inadequately documented or enforced
- Insider threat considerations not integrated with access authorisation programme
- Configuration management drift between as-built and as-documented states
Licensees must maintain configuration management for critical digital assets throughout their lifecycle.
- Incident response procedures aligned to RG 5.71 Appendix C
- Configuration management baseline records for CDAs
- Cyber security training and awareness records for personnel
- Cyber Security Plan documented under 10 CFR 73.54(e)
- Continuous monitoring coverage gaps for legacy safety-related systems
- CDA inventory incomplete for support systems and balance-of-plant equipment
- Defence-in-depth boundaries inadequately documented or enforced
- Insider threat considerations not integrated with access authorisation programme
Licensees must implement continuous monitoring mechanisms to detect anomalies and potential cyber security events.
- Cyber Security Plan documented under 10 CFR 73.54(e)
- Critical Digital Asset (CDA) inventory and classification register
- Defence-in-depth architecture diagrams for safety and security functions
- Incident response procedures aligned to RG 5.71 Appendix C
- Configuration management baseline records for CDAs
- Cyber security training and awareness records for personnel
- Configuration management drift between as-built and as-documented states
- Continuous monitoring coverage gaps for legacy safety-related systems
- CDA inventory incomplete for support systems and balance-of-plant equipment
Security Controls Implementation
Implement security controls per 10 CFR 73.54(c) consistent with NRC Regulatory Guide 5.71 Appendix B (Technical and Operational Cyber Security Controls) + Appendix C (Cyber Security Programme Controls). Technical controls per Appendix B cover (a) access control including unique identification + authentication + authorisation + concurrent session control + remote access + wireless restrictions + portable and mobile device controls, (b) audit and accountability including event types + content + storage + reporting + analysis + retention, (c) configuration management including baselines + least functionality + change control + verification, (d) system and information integrity including malicious code protection + monitoring + spam protection + flaw remediation + integrity verification, (e) defence-in-depth including boundary protection + isolation + monitoring at boundaries + protection fr
- mapping evidence to RG 5.71 Appendix B technical/operational controls + Appendix C programmatic controls per CDA
- control-by-control evidence library with documentation + screenshots + scan results + policies + records
- internal sampling against RG 5.71 controls + closure of identified gaps
- evidence not mapped to RG 5.71 control IDs producing inspection-time scramble
- internal sampling skipped + gaps surface only during NRC inspection
- Appendix C programmatic controls treated less seriously than Appendix B technical controls
Technical Controls for Critical Digital Assets
Implement access controls for Critical Digital Assets including unique user identification, authentication appropriate to the asset, role based authorization, separation of duties, and recertification of access on a defined cycle.
- Identity and access management procedures for CDAs
- MFA evidence for privileged access
- Role matrix
- Recertification records
- Shared accounts on engineering workstations
- MFA not feasible documented without compensating control
- Recertification overdue
Generate, protect, and review audit logs from Critical Digital Assets and supporting boundary devices for events relevant to security including access, privilege use, configuration changes, and anomalous activity, with retention and review procedures.
- Audit logging standard for CDAs
- Log collection architecture
- Review procedure and schedule
- Retention configuration
- CDAs lack logging capability without compensating control
- Logs reviewed only after incidents
- Retention insufficient for forensic needs
Apply configuration management to Critical Digital Assets including baseline configurations, change control with security impact analysis, configuration verification, and integration with the corrective action program for deviations.
- Baseline configuration documents per CDA
- Change records with security impact analysis
- Configuration verification evidence
- Corrective action program records for deviations
- Baselines not maintained
- Security impact analysis missing in modifications
- Configuration verification ad hoc
Control the use of portable media and mobile devices in the protected and vital areas including authorization, scanning at trusted scanning stations, restrictions on connection to CDAs, and tracking of devices used for maintenance activities.
- Portable media procedure
- Trusted scanning station configuration
- Authorization records for device use
- Inventory of plant approved devices
- Scanning station bypassed in time pressured maintenance
- Vendor laptops not tracked
- Devices reused across levels without sanitization
Manage supply chain risk for Critical Digital Assets and related services including procurement security requirements, vendor assessments, integrity verification, counterfeit detection, and end of life management for hardware and software.
- Procurement requirements for CDAs
- Vendor security assessments
- Integrity verification at receipt
- End of life planning
- Supply chain provisions not flowed down to suppliers
- Integrity checks only on safety related equipment
- End of life software still in use on CDAs
Vulnerability and Configuration Management
Operate vulnerability management + configuration management + baseline control + patching per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.3 (Configuration Management) + Section B.1.6 (System and Information Integrity). Configuration management must (a) establish documented baseline configurations per CDA class + version, (b) enforce change control with engineering + cybersecurity + operations review for CDA changes, (c) maintain inventory of CDAs at component level + with configuration attributes + ownership, (d) detect configuration drift via authenticated scanning + integrity monitoring + alerting on deviation, (e) protect baselines + change documentation under access control. Vulnerability management must (a) consume NRC vulnerability advisories + ICS-CERT advisories + vendor advisories + CISA KEV + sector ISAC, (b) assess applicability to CDAs + assign severity considering C
- baseline configurations + change control records + drift detection evidence
- vulnerability advisory consumption (NRC + ICS-CERT + vendor + KEV) + applicability assessment + remediation
- patch test lab + production deployment record + compensating controls for unpatchable systems
- vulnerability management metrics + age tracking + management review
- no patch test lab matching CDA topology + safety configuration
- compensating controls undocumented + not approved + not reassessed
- ICS-CERT advisories not consumed or not actioned
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.