Read theMandate

DocumentsAgency rules2026-06048 › Text 5 of 12

Nuclear Regulatory Commission

Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors

The text of the rule, page 5 of 12. 24 headings, 13,205 words, quoted as the Federal Register prints them.

Read it at the Federal Register →

← A. IntroductionContentsList of Subjects →

D. Changes to Part 26, Subpart N

Section 26.709 makes the recordkeeping and reporting requirements in subpart N of part 26 applicable to licensees and other entities of facilities licensed under part 53 that elect not to implement the requirements in subpart M of part 26 or elect to implement the requirements in Sec. 26.605(b).

This final rule amends Sec. 26.711(c) and (d) to make these requirements applicable to licensees or other entities described in Sec. 26.3(f). Section 26.711(c) provides protection to individuals subject to part 26 by enabling an individual's right to review FFD- related information and correct any inaccurate or incomplete information. Section 26.711(d) requires, in part, that any FFD-related information shared with other licensees or other entities is correct and complete. E. Changes to Part 26, Subpart O

Most of the changes to part 26 are new or revised substantive provisions that establish a regulatory obligation or prohibition or are conforming edits to reflect the addition of part 53. The only new provision that is not substantive, such that violation of it would not result in a criminal penalty, is Sec. 26.601. Therefore, the NRC is adding Sec. 26.601 to the list of regulations in Sec. 26.825(b) to which criminal sanctions do not apply.

10 CFR Part 50

A. Section 50.160: Emergency Preparedness for Small Modular Reactors, Non-Light-Water Reactors, and Non-Power Production or Utilization Facilities

This final rule revises Sec. 50.160(b)(3) and (c)(2) to make that section applicable to applicants and licensees under part 53. Section 50.160 provides an alternative to other part 50 emergency preparedness requirements focused on large light-water reactors to provide an optional emergency preparedness framework specifically for small modular reactors (SMRs) and other new technologies. These alternative emergency preparedness requirements adopt a performance-based, technology-inclusive, risk-informed, and consequence-oriented approach. Commercial nuclear reactor applicants complying with Sec. 50.160 must submit as part of the application the analysis used to determine whether the criteria in Sec. 53.1109(g)(2)(i)(A) and (B) are met and, if they are met, the size of the plume exposure pathway emergency planning zone (EPZ). An EPZ bounds the area surrounding a facility within which detailed planning is needed to implement predetermined, prompt protective actions. The criterion in Sec. 53.1109(g)(2)(i)(A) is that public dose, as defined in Sec. 20.1003, is projected to exceed 10 mSv (1 rem) TEDE over 96 hours from the release of radioactive materials from the facility considering accident likelihood and source term, timing of the accident sequence, and meteorology. The criterion in Sec. 53.1109(g)(2)(i)(B) is that pre-determined, prompt protective measures are necessary. These are the same criteria that are in Sec. 50.33(g)(2)(i)(A) and (B) and are used to assess the need for and size of an EPZ in applications under parts 50 and 52.

Applicants choosing to comply with Sec. 50.160 must determine the radiological releases from the facility that are evaluated in the determination of the plume exposure pathway EPZ. Applicants should consider quantitative and qualitative information on the potential radiological releases that make up the spectrum of accidents used to develop the basis for the applicant's site-specific EPZ. This information is derived from the licensing basis. The NRC plans to update the risk-informed approach in RG 1.242 for part 53 while maintaining its flexibility for using information already developed and available in licensing-basis documents, including PRA results, deterministic dose quantities, accident timing, target set analyses, mitigation capabilities, and site-specific factors such as meteorology.

Applicants choosing to comply with Sec. 50.160 must determine the radiological releases from the facility that are evaluated in the radiological dose assessment to inform the determination of the plume exposure pathway EPZ size. In its Safety Analysis Report, the applicant will describe the LBEs relevant to the facility and consider these LBEs as candidates for the spectrum of accidents used to develop the site- specific EPZ. The LBEs assessed include a wide range of events that are appropriate for considering in the facility's emergency preparedness and response planning. In addition, Sec. 50.160(b)(1)(iv)(A)(2) requires licensees to be capable of implementing their approved emergency response plan in conjunction with their safeguards contingency plan.

An appropriate EPZ and pre-determined, prompt protective measures are elements of an effective emergency plan. The EPZ size is primarily informed by the consequences and release characteristics of the LBEs derived from the safety case. Each licensee should ensure that its emergency plan documents the onsite protection strategies and, as warranted, off-site preparedness capabilities to reasonably respond to, monitor, and protect against the potential events associated with the facility. The characteristics of seismic and security events should be provided in the analysis required by Sec. 53.1109(g)(2), but the calculated dose consequences may be, but do not need to be, explicitly considered in the EPZ size determination in the same manner as LBE consequences, if the consequences from these events are less than the consequences from the LBEs. Rather, the characteristics of these events (consequence, timing, radionuclides of release) may be discussed and used to justify that the EPZ size and pre-determined, prompt protective measures to address the LBEs are sufficient to ensure that capabilities exist to reduce consequences of those events.

Part 53 applicants and licensees should consider security events in their EPZ-sizing analysis under Sec. 53.1109(g)(2). If any such events lead to consequences greater than licensing-basis events already being considered in the EPZ size justification and would warrant preplanned prompt protective measures, then the applicant or licensee should include the security event(s) in its EPZ-sizing analysis or provide an adequate alternate method(s) for addressing them. If any of the events do not lead to consequences greater than licensing-basis events already being considered in the EPZ size justification or would not warrant preplanned prompt protective measures, then the applicant or licensee would not need to include those events in the EPZ-sizing analysis. B. Appendix B to Part 50: Quality Assurance Criteria for Nuclear Power Plants and Fuel Reprocessing Plants

This final rule amends appendix B to part 50 to make it applicable to applicants and licensees under part 53. This results in the need for some revisions to recognize differences in terminology between parts 50 and 53. Namely, the term “design bases,” which is defined in Sec. 50.2, is not used in part 53. For this reason, this final rule adds text in both section III, “Design Control,” and section IV, “Procurement Document Control,” to refer to “functional design criteria, as defined in Sec. 53.020,” as the part 53 equivalent of the term “design bases.” C. Appendix E to Part 50: Emergency Planning and Preparedness for Production and Utilization Facilities

This final rule amends appendix E to part 50 to make it applicable to

applicants and licensees, under part 53, that choose to comply with the requirements in appendix E to part 50 and the planning standards of Sec. 50.47(b) in accordance with Sec. 53.855. Because the regulations contained in Sec. 50.160 are not applicable to large LWR designs, NRC has revised appendix E to recognize the applicability of the appendix to part 53 applicants and licensees. The conforming changes made to appendix E allow its use in conjunction with Sec. 50.47 to provide emergency preparedness framework for large LWR or other designs under part 53.

10 CFR Part 73

A. Section 73.100: Technology-Inclusive Requirements for Physical Protection of Licensed Activities at Commercial Nuclear Plants Against Radiological Sabotage

Section 73.100 provides a performance-based regulatory framework for the design, implementation, and maintenance of a physical protection program and security organization for certain commercial nuclear plants licensed under part 53. The current Sec. 73.55 physical security requirements for nuclear power reactors licensed under part 50 and part 52 use a combination of performance criteria (e.g., Sec. 73.55(b)(1) through (3)) and numerous prescriptive requirements developed to achieve performance objectives (e.g., Sec. 73.55(k)(5)(ii)). By contrast, in the performance-based approach to physical security for part 53, performance objectives and requirements are the primary bases for regulatory decision-making, giving the licensee the flexibility to determine how to demonstrate compliance with the established performance criteria for an effective physical protection program. This physical protection program provides reasonable assurance that activities involving SNM are not inimical to the common defense and security and do not constitute an unreasonable risk to the public health and safety.

Section 73.100(a) requires each part 53 licensee that elects to demonstrate compliance with this section rather than Sec. 73.55 to implement the requirements therein through a graded approach based on achievability of target sets. For licensees that identify achievable target sets, all of the requirements of Sec. 73.100 apply, and must be implemented prior to initial fuel load into the reactor (or, for a fueled manufactured reactor, before initiating the removal of the features to prevent criticality required under Sec. 53.620(d)(1)). For licensees that demonstrate they have no achievable target sets, the requirements are further graded based on whether that demonstration relies on the implementation of active measures, such as operator action, mitigative action, detection, assessment, or armed response. Licensees that do not rely on active measures are exempt from the remaining requirements of Sec. 73.100 (but must still meet physical protection requirements for SNM or radioactive material, as applicable). Licensees that rely on active measures may limit the scope of their physical protection program by ensuring that the credited active measures will be implemented when needed in response to threats.

Based on experience from recent new reactor licensing reviews, the NRC recognizes that licensees may seek to receive unirradiated fuel onsite before carrying out the security requirements in Sec. 73.100. However, these security requirements must be implemented at some point before reactor operation to address the increased risk arising from irradiated fuel onsite. This final rule makes clear that part 53 applicants and licensees using Sec. 73.100 may bring unirradiated nuclear fuel onsite and protect it in accordance with the NRC's requirements for physical protection of SNM of moderate and low strategic significance under Sec. 73.67 until initial fuel load into the reactor (or, for a fueled manufactured reactor, until initiating the removal of the features to prevent criticality required under Sec. 53.620(d)(1)).

Section 73.100(b) outlines the general performance objective and design requirements of the licensee physical protection program. A licensee's program is required to provide protection against any deliberate act within the design-basis threat (DBT) of radiological sabotage, including spent fuel sabotage, that could directly or indirectly endanger the public health and safety by exposure to radiation. The physical protection program is supported by the AA program, cybersecurity program, and IMP to demonstrate compliance with the general performance objective of Sec. 73.100(b).

Section 73.100(b)(2) was developed, in part, from Sec. 73.55(b)(3). To satisfy the general performance objective of Sec. 73.100(b)(1), the physical protection program must protect against the DBT of radiological sabotage. The existing fleet of LWR satisfies this objective by preventing significant core damage and spent fuel sabotage. Some non-LWR reactor licensees' physical protection programs may be designed to prevent a significant release of radionuclides from any source. Therefore, the performance objective focuses on radiological sabotage in general, rather than a specific focus on core damage or spent fuel sabotage, to be technology-inclusive and allow for flexibility for different reactor technologies.

Under Sec. 73.100(b)(2)(ii), licensees must provide defense in depth in achieving performance requirements through the integration of engineered systems, administrative controls, and management measures. This requirement applies defense-in-depth concepts as part of the physical protection program to ensure the capability to demonstrate compliance with the performance objective of Sec. 73.100(b)(1) is maintained in the changing threat environment. The defense-in-depth philosophy applies to measures against intentional acts as required by Sec. 73.100(b), and the designs of physical security systems should employ defense in depth through systems diversity, independence, and separation under Sec. 73.100(b)(2). The most common defense-in-depth measures apply concepts of redundancy, diversity, independence, and safety margin to ensure systems reliability and availability. The defense-in-depth philosophy applies to the design of a physical protection program, which integrates engineered controls and administrative controls, to provide protection against the DBT for radiological sabotage.

Section 73.100(b)(3) requires a physical protection program that prevents the release of radionuclides from any source from exceeding the dose reference values defined in Sec. 53.210 of this chapter. Dose reference values are intended to assess the performance of systems for design basis scenarios. These values were not originally designed for application to security events. However, because of the analogous nature of the design basis accident and design basis threat concepts, the application of dose reference values to design basis security events is a logical extension of this well-established NRC licensing tool. There are two dose reference values, but typically the 2-hour 25 rem TEDE value is the most limiting and will, therefore, be the focus of an applicant's assessment. Although this provides less prescriptive defense in depth in achieving performance requirements, the 2-hour 25 rem dose reference value remains protective of public health and safety.

A Part 53 applicant or licensee could voluntarily choose to establish or maintain a physical protection program

that prevents significant core damage or spent fuel sabotage (in other words prevent consequences in excess of the DBA consistent with 10 CFR 73.55), and this program will meet the new performance metric without additional analyses.

The NRC notes that the 25 rem TEDE reference dose was originally introduced as a screening criterion in proposed Sec. 53.860 (89 FR 86918), such that below 25 rem TEDE licensees would not be required to meet the provisions of Sec. Sec. 73.55 or 73.100. For the final rule, the NRC relocated the 25 rem TEDE reference dose to the requirements of Sec. 73.100(b)(3), in response to public comments. The Commission's use of the 25 rem TEDE reference value for this assessment does not imply that the Commission considers it to be an acceptable limit for a security event, but only that it represents a reference value to be used for evaluating plant features and site characteristics.

Section 73.100(b)(4) requires the physical protection program to be designed and implemented to achieve and maintain the reliability and availability of SSCs required for demonstrating compliance with specified performance requirements. These physical protection performance requirements were informed by Sec. 73.55(b) and the Commission's Advanced Reactor Policy Statement.

The performance objective of protecting against the DBT of radiological sabotage is achieved by the design and implementation of the physical protection program, maintained at all times, with the following required performance capabilities in the provisions in Sec. 73.100(b)(4): intrusion detection, intrusion assessment, security communication, security response, protecting against land and waterborne vehicle bomb assaults, and access control portals. The physical protection program must maintain the reliability and availability of SSCs relied upon for demonstrating compliance with the performance requirements. The terms “reliability and availability” are intended to describe defense in depth in a performance-based manner and are critical elements for demonstrating compliance with the requirement for protection against the DBT of radiological sabotage as described in Sec. 73.100(b)(2).

The first element, “intrusion detection,” is provided through the use of detection equipment, patrols, access controls, and other program elements and provides notification to the licensee that a potential threat is present and where the threat is located.

The second element, “intrusion assessment,” provides a mechanism through which the licensee identifies the nature of the threat detected. This is accomplished through the use of video equipment, patrols, and other program elements that provide the licensee with timely information about the threat for use in determining how to respond.

The third element, “security communication,” provides a mechanism through which the licensee communicates the necessary information to the response force to ensure effectiveness of the physical protection program. This is accomplished through the redundant, independent, and diverse design of physical security and/or plant SSCs relied on for onsite and offsite security communications. The continuity and integrity of communications should account for the DBT's ability to affect the reliability and availability of communications.

The fourth element, “security response,” provides a mechanism through which the licensee is capable of timely security response to interdict and neutralize threats up to and including the DBT of radiological sabotage. The security response may include the use of onsite armed responders, law enforcement responders (local, State, or Federal), or other offsite armed responders (e.g., licensee proprietary or contract security personnel who are positioned offsite), or a combination thereof, as appropriate.\10\ The licensee must provide protection against any element of the DBT, to include those that do not rise to the full capability of the DBT. Structures, systems, and components relied on to provide delay functions must be designed to provide for timely response to adversary attacks with adequate defense in depth. Delay allows the licensee to take necessary actions to counter any attempt by the threat to advance toward the protected target or target set element. The overall response objective is to place the threat in a condition from which the threat no longer has the potential for, or capability of, doing harm to the protected target.

\10\ The NRC's security regulations for commercial nuclear power reactors have historically considered onsite armed responders to be the only acceptable method for interdicting and neutralizing threats up to and including the DBT of radiological sabotage. This final rule permits advanced power reactor licensees to use any interdiction and neutralization method, which is an extension of the Commission's position in SRM-SECY-17-0100, “Security Baseline Inspection Program Assessment Results and Recommendations for Program Efficiencies,” dated October 8, 2018, and SRM-SECY-20-0070, “Technical Evaluation of the Security Bounding Time Concept for Operating Nuclear Power Plants,” dated June 6, 2024. Under this final rule, a licensee retains the responsibility to detect, assess, interdict, and neutralize threats up to and including the DBT of radiological sabotage, but may rely on law enforcement or other offsite armed responders as a method for fulfilling the required interdiction and neutralization capabilities. For licensees that choose to rely on law enforcement to fulfill these capabilities, this final rule does not create any NRC regulatory jurisdiction over, or requirements for, law enforcement.

The fifth element, “protecting against land and waterborne vehicle bomb assaults,” provides a mechanism through which the licensee is capable of protecting the plant against the DBT vehicle bomb assault. The methods that are relied on to protect against a DBT land vehicle and waterborne vehicle bomb assault must be designed to protect the reactor building, structures containing safety or security-related systems, and components from explosive effects.

The sixth element, “access control portals,” provides a mechanism through which the licensee is capable of detecting and denying unauthorized access to persons and pass-through of contraband materials (e.g., weapons, incendiary devices, explosives) to protected areas. Integrity of the access control system is maintained through licensee oversight and ensures that attempts to circumvent or bypass the established process will be detected and access denied.

The performance requirements permit the applicant or licensee to determine how to design the physical protection program to protect the plant against the DBT of radiological sabotage without prescriptive requirements such as those currently found in Sec. 73.55. RG 5.97, “Guidance for Technology-Inclusive Requirements for Physical Protection of Licensed Activities at Commercial Nuclear Plants,” has been developed by the NRC to describe one acceptable approach to demonstrate compliance with requirements in Sec. 73.100.

Section 73.100(b)(5) requires the licensee to identify target sets. Target sets are defined in RG 5.81, “Target Set Identification and Development for Nuclear Power Plants,” Revision 2, as the minimum combination of equipment, operator actions, and/or structures that, if all are prevented from performing their intended safety function or prevented from being accomplished, barring extraordinary actions by plant operations, would likely result in a release of radionuclides from any source that would exceed the dose reference values defined in Sec. 53.210. The licensee must further identify which of its target sets are “achievable” (i.e., those that are within the capabilities of the DBT and,

if destroyed or disabled, can lead to a significant offsite release of radionuclides that cannot be mitigated).

Section 73.100(b)(6) requires that each licensee perform a site- specific analysis for the purpose of identifying and analyzing site- specific conditions that affect the design of the onsite physical protection program.

Section 73.100(b)(7) requires licensees to implement a performance evaluation program, which ensures that a licensee will periodically test and evaluate the effectiveness of the physical protection program to protect against the DBT. This program will ensure that licensees are able to demonstrate that the physical protection program satisfies the response requirements of Sec. 73.100 and that the site's protective strategy effectively protects against the DBT. Licensee performance evaluations will include methods to assess, test, and challenge the integration of the physical protection programs functions and demonstrate the effectiveness of security plans, licensee protective strategy, and implementing procedures in accordance with Sec. 73.100(g).

Section 73.100(b)(8) requires licensees to implement an AA program in accordance with Sec. 73.56. Section 73.100(b)(9) requires licensees to establish, maintain, and implement protection against a cyberattack based on either the cybersecurity program described in Sec. 73.110 or the program described in existing Sec. 73.54.

Section 73.100(b)(10) requires an IMP that monitors the initial and continuing trustworthiness and reliability of individuals granted or retaining unescorted access or unescorted AA to a protected or vital area. The IMP must also implement defense-in-depth methodologies to minimize the potential for an insider (active, passive, or both) to adversely affect the licensee's capability to protect against radiological sabotage. Because no one element of the AA program, FFD program, cybersecurity program, or physical protection program would, by itself, provide the level of protection against the insider necessary to demonstrate compliance with the performance objective of Sec. 73.100(b), the effective integration of these programs is a necessary requirement to achieve defense in depth against the potential insider.

Section 73.100(b)(11) requires that the licensee have the capability to track, trend, correct, and prevent recurrence of failures and deficiencies in the implementation of the requirements in Sec. 73.100.

Section 73.100(b)(12) requires the coordination of the security plans and associated procedures with other onsite plans to manage the safety and security interface during normal or emergency operations.

Section 73.100(b)(13) requires firearms background check requirements for all members of the security organization whose official duties require access to covered weapons or who inventory enhanced weapons.

Section 73.100(c) was developed from Sec. 73.55(c)(7), “Security implementing procedures,” and Sec. 73.55(d), “Security organization,” and outlines the requirements for the composition, equipping, and training of the security organization. The purpose of the security organization is to effectively implement the physical protection program. Individuals assigned to perform physical protection or contingency response duties must be trained, equipped, and qualified to perform assigned duties and responsibilities.

Section 73.100(d) establishes a performance requirement for searches of personnel, vehicles, and materials for the protection against radiological sabotage. The requirement describes broad categories of material (explosives, firearms, incendiary devices, etc.) to be detected and prevented from entry into the protected area; specific items that will be prohibited are not prescribed in the regulation but will be stated in the licensee security plans with detailed descriptions being identified in implementation procedures.

Section 73.100(e) requires a training and qualification program, described in the training and qualification plan, that ensures personnel are able to effectively perform their assigned security- related job duties. This high-level requirement allows flexibility in how the licensee chooses to train its security personnel. One method for accomplishing this requirement would be to provide a training and qualification program that is equivalent to appendix B to part 73.

Section 73.100(f) requires periodic security reviews of the physical protection program to ensure effective implementation of the program by independent individuals. The evaluation process provides a systematized approach for assessing the physical protection program as a basis for further development and improvement. Program reviews should be designed to ensure that the physical protection program maintains effectiveness and demonstrates compliance with NRC requirements. Section 73.100(f)(1) was developed from Sec. 73.55(m) and requires review of each element of the physical protection program. Section 73.100(f)(2) requires licensees to perform self-assessments of physical protection program functions to ensure that the capability to detect, assess, interdict, and neutralize the DBT of radiological sabotage is maintained. Section 73.100(f)(3) requires an audit of the effectiveness of the physical protection program; security plans; implementing procedures; cybersecurity programs; management of the safety/security interface activities; the testing, maintenance, and calibration program; and response commitments by local, State, and Federal law enforcement authorities. Section 73.100(f)(4) requires that results and recommendations, management findings, and any actions taken be documented and maintained to be available for inspection by the NRC. These reviews are independent of the ongoing performance evaluations described in Sec. 73.100(b)(7) and (g).

Section 73.100(g) requires that licensee performance evaluations, described in Sec. 73.100(b)(7), include methods appropriate and necessary to assess, test, and challenge the integration of the physical protection program's functions to protect against the DBT. The performance evaluations must also address the licensee's measures to protect against cyberattacks, in accordance with the required cybersecurity plan, and engineered systems designed to protect against the DBT standalone ground vehicle bomb attack.

Section 73.100(h) establishes performance requirements for maintaining security SSCs relied on to perform security functions to protect against the DBT. It requires that corrective actions and compensatory measures be taken by a licensee in response to a degradation of security equipment or failure of the equipment to perform its intended functions. The licensee must maintain the SSCs described in its design and licensing basis to ensure that they are reliable and available.

Section 73.100(i) establishes requirements for the suspension of security measures in response to emergency and extraordinary conditions. The requirements of this paragraph, which were developed from Sec. 73.55(p), are intended to provide flexibility to a licensee for taking reasonable actions that depart from a security plan in an emergency when such actions are immediately needed to protect the public health and safety and no action consistent with license conditions and TS that can provide adequate or equivalent protection is immediately apparent in accordance with Sec. 53.740(h).

Section 73.100(j) establishes requirements regarding the inspection, retention and maintenance of records required to be kept by the NRC regulations, orders, or license conditions. These requirements are developed from Sec. 73.55(q). B. Section 73.110: Technology-Inclusive Requirements for Protection of Digital Computer and Communication Systems and Networks

Section 53.860(d) requires that a licensee establish, implement, and maintain a cybersecurity program in accordance with Sec. 73.54 or Sec. 73.110. Part 53 applicants and licensees may demonstrate compliance with either of these sections, regardless of whether they elect to comply with the physical security requirements in Sec. 73.55 or Sec. 73.100.

Section 73.110 establishes requirements for the development and maintenance of a cybersecurity program for commercial nuclear plants licensed under part 53. This section implements a graded approach to determine the level of cybersecurity protection required for digital computers, communication systems, and networks. The section is informed by: (1) the operating experience from power reactors and insights from cyber-related assessments of fuel cycle facilities; and (2) the existing Sec. 73.54 framework, which addresses some of the basic issues for cybersecurity regardless of the type of reactor. Differences between the Sec. 73.54 requirements and those in Sec. 73.110 are primarily based on the implementation of a consequence-based approach to cybersecurity that provides flexibility to accommodate the wide range of reactor technologies to be assessed by the NRC. A graded approach based on consequences is intended to account for the differing risk levels among reactor technologies. Specifically, the section requires licensees to demonstrate protection against cyberattacks in a manner that is commensurate with the potential consequences from those attacks.

Safety and security must be considered together in the design process such that, where possible, security issues are effectively resolved through design and engineered security features, as stated in 10 CFR 53.440(f). This approach ensures considerations are given for safety and security together throughout the plant's lifetime, including the design process and prior to implementing changes to plant configurations, to ensure risks are effectively managed. The requirements in Sec. 73.110 align with this approach by requiring licensees to evaluate whether a cyberattack could lead to the consequences outlined in the rule. This evaluation helps determine whether enhancements to the design basis or physical protection system are warranted. Incorporating cybersecurity strategies and design features early in the design process can be significantly more efficient and cost-effective than retrofitting these measures after the plant has been designed or constructed.

Under Sec. 73.110(a), licensees need to ensure that digital computer and communications systems and networks associated with safety, security, and emergency preparedness functions are adequately protected against a potential cyberattack that would result in: (1) offsite radiation doses that would endanger public health and safety (i.e., the resulting consequence exceeds the reference dose values in Sec. 53.210); or (2) adversely impacting \11\ the security functions necessary to prevent unauthorized removal of material or radiological sabotage. Security digital assets include those used for nuclear MC&A. A cyberattack that results in the consequence defined in Sec. 73.110(a)(1) requires the protection of digital assets associated with safety, security, and emergency preparedness functions. Emergency preparedness functions are included within the scope of this final rule because they are essential for recovering from and mitigating the consequences of radiological sabotage that may result from a successful cyberattack, as required by Sec. 73.110(d)(2) and (d)(3) (i.e., they are part of the defense-in-depth strategy). Digital assets associated with safety-related and non-safety-related but safety-significant systems that perform or support safety functions are within the scope of this final rule as these systems are needed to satisfy the safety criteria in Sec. 53.210 and Sec. 53.220 per Sec. 53.460.

\11\ As defined in Regulatory Guide 5.71, “Cybersecurity Programs for Nuclear Power Reactors,” Revision 1, adverse impact means a direct deleterious effect on safety-related, important-to- safety, security, or emergency preparedness functions; or the operation of systems, networks, and associated equipment; or the integrity and confidentiality of data and software. Examples include loss or impairment of function; reduction in reliability; reduction in ability to detect, delay, assess or respond to malevolent activities; reduction of ability to call for or communicate with offsite assistance; or the reduction in emergency response ability to implement appropriate protective measures in the event of a radiological emergency. If the direct or indirect compromise of a support system causes a safety-related, important-to-safety, security, or emergency preparedness system or support system to actuate or “fail safe” and not result in radiological sabotage (i.e., causes the system to actuate properly in response to established parameters and thresholds), this is not considered to be an adverse impact.

Section 73.110(b) requires licensees to protect the communication system and networks associated with the functions described in Sec. 73.110(a)(1) and (a)(2) from cyberattacks. To accomplish this, the licensee will establish, implement, and maintain a cybersecurity program for protecting digital assets within the scope of Sec. 73.110 that makes use of risk insights, including threat information, and considers the resulting level of consequences of the threats. If the outcome of the assessment by the licensee under Sec. 73.110(b)(1) revealed that a potential cyberattack would not compromise any digital assets that support safety, security, and emergency preparedness functions and therefore would not result in the consequences listed in Sec. 73.110(a) (e.g., would not exceed the reference dose values), then only a narrow set of the cybersecurity program requirements in Sec. 73.110(d) and (e) would apply. For example, the licensee would only need to develop a cybersecurity program that implements the following requirements:

Analyze modifications of any asset before implementation to demonstrate compliance with the potential consequences in Sec. 73.110(a);

Ensure employees and contractors are aware of cybersecurity requirements and have some level of cybersecurity training;

Evaluate and manage cybersecurity risks to the plant;

Review the cybersecurity plan for any required changes; and,

Retain records of the cybersecurity plan along with any plan changes.

Section 73.110(c) through (e) were developed from Sec. 73.54(a)(2), and (c) through (h), respectively.

The requirements address the need for the licensee to develop a cybersecurity program that implements a defense-in-depth protective strategy as required by Sec. 73.110(d)(2). A defense-in-depth protective strategy for cybersecurity is represented by collections of complementary and redundant security controls that establish multiple layers of protection to safeguard critical digital assets. Under a defense-in-depth protective strategy, the failure of a single protective strategy or security control should not result in the compromise of safety and security functions. C. Section 73.120: Access Authorization Program for Commercial Nuclear Plants

Section 73.120 addresses AA for certain commercial nuclear plants licensed under part 53. The language in Sec. 73.120 provides an alternate approach to the existing framework for AA under

Sec. Sec. 73.56 and 73.57, commensurate with risk and consequences to public health and safety. It is available to part 53 applicants and licensees who demonstrate compliance with Sec. 73.100(a)(1)(i). The requirements in Sec. 73.120 are similar to the existing AA program elements for those NRC-licensed facilities issued additional security measures (ASMs) orders and for materials licensees under Sec. 37.21. Applicants not meeting Sec. 73.100(a)(1)(i) will need to establish, implement, and maintain a full AA program, including an IMP, in accordance with Sec. 73.56.

Section 73.120(a) is based on an applicant demonstrating that they do not exceed the dose reference values defined in Sec. 53.210, as demonstrated through compliance with Sec. 73.100(a)(1)(i). Section 73.120(b) identifies the categories of individuals who are subject to an AA program in accordance with this section. The applicability statement in Sec. 73.120(b)(1)(i) encompasses individuals whom the licensee intends to grant unescorted access to the facilities' most sensitive areas, consistent with Sec. 73.56(b)(1)(i) for power reactors and the ASM orders and license conditions issued to any NRC- licensed facility or material licensee. Sections 73.120(b)(1)(ii) through (iv) are consistent with Sec. 73.56(b)(1)(ii) through (iv), respectively. The program will include individuals who may be onsite or offsite (e.g., remote operators or information technology staff) and have virtual access to important plant operational and communication systems based upon assigned duties and responsibilities. An individual who has remote access to plant equipment and communication systems may have trusted privileges greater than the personnel at the plant site. Section 73.120(b)(1)(iii) states that offsite law enforcement personnel on official duty are not subject to the licensee AA program.

Section 73.120(c) provides general performance objectives and requirements largely consistent with the AA program requirements for nuclear power reactors under Sec. 73.56 and provides licensees and applicants the flexibility in establishing their AA program to demonstrate compliance with various performance objectives.

Section 73.120(c)(1) includes background investigation requirements consistent with Sec. 37.25, as well as ASMs and license conditions that are applied to non-power reactor licensees. Background investigations include important elements to establish the trustworthiness and reliability of an individual, such that they do not constitute an unreasonable risk to public health and safety or the common defense and security. These include the following: (1) personal history disclosure, (2) verification of true identity, (3) employment history evaluation, (4) unemployment/military service/education, (5) credit history evaluation, (6) character and reputation evaluation, and (7) Federal Bureau of Investigation criminal history record check.

Section 73.120(c)(2) establishes behavioral observation requirements, which are an awareness initiative for recognizing behaviors adverse to the safe operation and security of the facility through observing the behavior of others in the workplace and reporting aberrant behavior or changes in behavior that might reflect negatively on an individual's trustworthiness or reliability. Maintaining behavioral observation will assist and/or improve worker safety and reduce the risk of an insider threat. This requirement in Sec. 73.120(c)(2) is a scaled version of the full BOP required under Sec. 73.56(f).

Section 73.120(c)(2) provides licensees greater flexibility to implement behavioral observation options for individuals granted unescorted access to the commercial nuclear plant's protected area. Such options on reporting questionable behavior may include a program similar to the Department of Homeland Security's program, “If you see something, say something,” or to a corporate behavioral awareness program. Commensurate with the potential lower safety and security risks of a commercial nuclear plant that does not exceed the dose reference values defined in Sec. 53.210, as demonstrated through compliance with Sec. 73.100(a)(1)(i), Sec. 73.120(c)(2) does not require the establishment of a comprehensive training program for behavioral observation (i.e., initial and refresher training including knowledge checks) as required for power reactors under Sec. 73.56 and part 26. Under Sec. 73.120(c)(2)(ii), behavioral observation can be performed in-person or remotely by video, and identified behavior of concern must be reported to plant supervision. The remote access alternative to face-to-face interactions provides substantial flexibility for licensees and applicants. Any video conferencing or other acceptable electronic means promoting face-to-face interaction for those individuals working remotely will demonstrate compliance with this regulation.

Section 73.120(c)(3) captures and maintains the self-reporting of legal actions as an essential performance element to enhance the licensee's behavioral observation initiative similar to the current requirements under Sec. 73.56(g), assuring that personnel who are granted and who maintain unescorted access are trustworthy and reliable.

Section 73.120(c)(4) provides a scalable approach for granting and maintaining unescorted access. One component not included from Sec. 73.56 is the need for a psychological assessment and reassessment under Sec. 73.56(e) for granting unescorted access and Sec. 73.56(i)(v)(B) for individuals who perform one or more of the job functions described in Sec. 73.120(b)(1)(ii) for maintaining unescorted access. Moreover, the requirement permits criminal history updates to be completed within 10 years of the last review, compared to the 3- or 5-year reinvestigation periodicity for personnel at an operating commercial nuclear plant. In addition, no credit check re-evaluation is required for these individuals.

The continued need to maintain unescorted access will be evaluated on an annual basis by the reviewing official. Guidance in RG 5.95, “Access Authorization Program for Commercial Nuclear Plants,” specifies that this evaluation should be based on a compilation of personnel interactions as described in the licensee's or applicant's policy and procedures for behavioral observation and the maintenance of an approved AA list.

Section 73.120(c)(5) requires licensees and applicants to determine when a person no longer requires the need for unescorted access or no longer satisfies the AA requirement found within this section. Guidance in RG 5.95 further explains that licensees have the flexibility to terminate unescorted access to specific areas of the site if individuals lack the continued need for that access to perform their duties and responsibilities.

Section 73.120(c)(6) is consistent with the purpose of Sec. 37.23(e) and includes the individual's right to correct and complete information as required under Sec. 37.23(g). The section includes a requirement for designating a reviewing official. The language provides clarity regarding the roles and responsibility of a reviewing official, who is the only individual authorized to make unescorted access determinations.

Section 73.120(c)(7) aligns with the corresponding requirements under Sec. 37.23(f), and Sec. 73.120(c)(8) aligns with the corresponding requirements under Sec. 37.31. These requirements encompass the roles and responsibilities for licensees, applicants, and, if applicable,

the contractor/vendors to establish, implement, and maintain a system of files and records to ensure personal information is not disclosed to unauthorized persons.

Section 73.120(c)(9) aligns with the requirements of Sec. 37.33.

Section 73.120(c)(10) requires licensees, applicants, and contractors or vendors to maintain the records that are required by the regulations in this section and retain them for a period of 3 years after the record is superseded or no longer needed. The record retention period of 3 years is consistent with Sec. 37.23(h), contrasting with the 5-year retention period under Sec. 73.56(o). Records maintained in any database(s) must be available for NRC review, consistent with the requirements found under Sec. 73.56(o)(6)(ii).

V. Opportunities for Public Participation

The NRC published the proposed rule on October 31, 2024 (89 FR 86918), and the comment period was open until December 30, 2024. On November 22, 2024 (89 FR 92609), the NRC extended the public comment period by an additional 60 days to February 28, 2025, to allow more time for members of the public and other stakeholders to develop and submit their comments.

The NRC hosted two public meetings to engage with external stakeholders on the proposed rule and associated draft guidance documents during the public comment period. The first public meeting was held on November 19, 20, and 21, 2024. The second public meeting was held on January 8, 2025. A summary of both public meetings is available in ADAMS, as provided in the “Availability of Documents” section. The feedback from these public meetings informed the development of this final rule.

VI. Public Comment Analysis

The NRC prepared a summary and analysis of public comments (“Comment Response Document for the Final Rule: Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors,” Volumes I and II) received on the proposed rule and draft RGs, as referenced in the “Availability of Documents” section. In response to the proposed rule and draft RGs, the NRC received 152 unique comment submissions. They can be generally separated into the following classes of stakeholders:

Industry Groups and Licensees--68 comment submissions

Non-Government Organizations--14 comment submissions

States, Tribes, and Local Governments--3 comment submissions

General Public/Individuals--67 comment submissions

The public comment submissions are available from the Federal e- Rulemaking website at https://www.regulations.gov under Docket ID NRC- 2019-0062. Responses to the public comments, including a summary of how this final rule and the guidance changed as a result of the public comments, can be found in the public comment response documents as indicated in the “Availability of Documents” section of this document.

For more information about the associated guidance documents, see the “Availability of Guidance” section of this document.

VII. Regulatory Flexibility Certification

The Regulatory Flexibility Act of 1980, as amended at 5 U.S.C. 601 et seq, requires that agencies consider the impact of their rulemakings on small entities and, consistent with applicable statutes, consider alternatives to minimize these impacts on the businesses, organizations, and government jurisdictions to which they apply.

In accordance with the Small Business Administration's (SBA's) regulation at 13 CFR 121.903(c), the NRC has developed its own size standards for performing an RFA analysis and has verified with the SBA Office of Advocacy that its size standards are appropriate for NRC analyses. The NRC size standards at Sec. 2.810, “NRC size standards,” are used to determine whether an applicant or licensee qualifies as a small entity in the NRC's regulatory programs.

Number of Small Entities Affected

The NRC is currently not aware of any known small entities as defined in Sec. 2.810 that are planning to apply for a commercial nuclear plant ESP, CP, OL, ML, or COL under part 53 that would be impacted by this final rule. Based on this finding, the NRC has determined that the final rule does not have a significant economic impact on a substantial number of small entities.

Economic Impact on Small Entities

Although the NRC is not aware of any small entities that are affected by the final rule, there is a possibility that future applications for a commercial nuclear plant permit or license could be submitted by small entities. Commercial nuclear plants of a size operated by a small entity would most likely be used to support electrical demand for military bases or small remote towns and would provide process heat, so they would not directly compete with a larger commercial nuclear plant that would typically produce electricity for the grid. As a result of these differing purposes, the NRC would expect that small and large entities would not be in direct competition with each other.

Therefore, the NRC concludes that this final rule will not have a significant economic impact on a substantial number of small entities.

VIII. Regulatory Analysis

The NRC has prepared a final regulatory analysis for this rule. The analysis examines the costs and benefits of the alternatives considered by the NRC. The regulatory analysis is available as indicated in the “Availability of Documents” section of this document. The conclusion from the analysis is that this final rule and associated guidance will result in net averted costs to the industry and the NRC of $152 million using a 7-percent discount rate and $203 million using a 3-percent discount rate, using a 66-year analysis period. Detailed information on the costs and cost savings is presented in Table 1.

Table 1--Total Costs and Cost Savings of Final Rule

[In 2024 dollars]

Undiscounted Discounted (7%) Discounted (3%)

Attribute Costs

Industry Total......................................... $63,823,000 $11,078,000 $25,492,000 NRC Total.............................................. 35,942,000 5,499,000 13,630,000 Net.................................................... 99,765,000 16,577,000 39,122,000

Annualized............................................. ................. 1,174,000 1,368,000

Attribute Cost Savings

Industry Total......................................... (346,524,000) (139,576,000) (203,353,000) NRC Total.............................................. (55,609,000) (28,685,000) (38,582,000) Net.................................................... (402,133,000) (168,261,000) (241,935,000) Annualized............................................. ................. (11,915,000) (8,461,000)

Attribute Net Cost Savings

Industry Net........................................... (282,700,000) (128,500,000) (177,860,000) NRC Net................................................ (19,670,000) (23,190,000) (24,950,000) Net.................................................... (302,370,000) (151,690,000) (202,810,000) Annualized............................................. ................. (10,741,000) (7,093,000)

Qualitative Benefits................................... Improvements in Knowledge, Regulatory Efficiency, and

Increased Public Confidence.

IX. Backfitting and Issue Finality

This section describes the backfitting and issue finality implications of this final rule and the final guidance documents described in section XVIII, “Availability of Guidance,” in this document, as applied to pertinent NRC approvals and certain applicants that reference NRC approvals in their applications. The NRC's current backfitting provisions associated with nuclear power plants appear in Sec. 50.109, “Backfitting,” and apply to CPs and OLs under part 50. Issue finality provisions (analogous to the backfitting provisions in Sec. 50.109) for approvals under part 52 are located in various provisions of part 52. The NRC Management Directive 8.4, “Management of Backfitting, Forward Fitting, Issue Finality, and Information Requests,” describes the Commission's policies on backfitting and issue finality.

This final rule provides a regulatory scheme for entities to apply for approvals under part 53. The part 50 backfitting provisions and part 52 issue finality provisions apply to actions taken by the NRC under part 50 or part 52, respectively, or actions taken by the NRC under other parts of 10 CFR chapter I that, for holders of certain approvals under part 50 or part 52, inextricably affect their activities regulated under part 50 or part 52. Issuance and implementation of part 53 will not constitute actions taken under part 50 or part 52. Also, part 53 does not allow an applicant to reference approvals issued under part 50 or part 52. Therefore, the issuance and implementation of part 53 will not affect part 50 or part 52 entities' activities regulated under part 50 or part 52. Therefore, the addition of part 53 through this final rule is not within the scope of the part 50 backfitting and part 52 issue finality provisions.

The NRC is also making conforming changes to parts 1, 2, 10, 11, 19, 20, 21, 25, 26, 30, 40, 50, 51, 70, 72, 73, 74, 75, 95, 140, 150, 170, and 171 to reflect the addition of part 53. These changes do not meet the definition of “backfitting” in Sec. 50.109 or Sec. 70.76, “Backfitting,” because the changes do not modify or add to the systems, structures, components, or design of a facility or to the procedures or organization required to operate a facility under part 50 or 70. These changes do not meet the definition of “backfitting” in Sec. 72.62, “Backfitting,” because the changes do not add, eliminate, or modify the SSCs of an independent spent fuel storage installation (ISFSI) or the procedures or organization required to operate an ISFSI. These changes do not inextricably affect activities regulated under parts 50, 52, 70, or 72. Therefore, the changes to parts 1, 2, 10, 11, 19, 20, 21, 25, 26, 30, 40, 50, 51, 70, 72, 73, 74, 75, 95, 140, 150, 170, and 171 do not constitute backfitting under parts 50, 70, or 72 or affect the issue finality of an approval under part 52.

The NRC is issuing nine final guidance documents that provide guidance on the methods acceptable to the NRC for complying with aspects of this final rule. Further, as discussed in the guidance documents, applicants and licensees are not required to comply with the positions set forth in the guidance. Therefore, the final guidance documents do not constitute backfitting under part 50 or affect the issue finality of any approval issued under part 52.

X. Cumulative Effects of Regulation

The NRC seeks to minimize any potential negative consequences resulting from the cumulative effects of regulation (CER). The CER describes the challenges that licensees, or other impacted entities such as State partners, may face while implementing new regulatory positions, programs, or requirements (e.g., rules, generic letters, backfits, inspections). The CER is an organizational effectiveness challenge that may result from a licensee or impacted entity implementing a number of complex regulatory actions, programs, or requirements within limited available resources.

The goals of the NRC's CER effort were met throughout the development of this final rule. The NRC engaged with external stakeholders at public meetings and solicited public comments on the proposed rule and associated draft guidance documents. The NRC also held numerous public meetings prior to publication of the proposed rule and published numerous versions of preliminary proposed rule language. Although the use of part 53 is voluntary, the NRC included in the proposed rule a request for feedback related to CER. Specifically, the NRC requested feedback on the implementation and potential unintended consequences of the proposed rule. The NRC received two comment submissions in response to these CER questions, but no comments required a change to the rule.

XI. Plain Writing

The Plain Writing Act of 2010 (Pub. L. 111-274) requires Federal agencies to write documents in a clear, concise, and well-organized manner. The NRC has

written this document to be consistent with the Plain Writing Act as well as the Presidential Memorandum, “Plain Language in Government Writing,” published June 10, 1998 (63 FR 31885).

XII. Environmental Assessment and Final Finding of No Significant Environmental Impact

The Commission has determined under the National Environmental Policy Act of 1969, as amended, and the Commission's regulations in subpart A of part 51, that this rule is not a major Federal action significantly affecting the quality of the human environment, and, therefore, an EIS is not required. The basis of this determination reads as follows: the implementation of the final rule will not have a significant impact on the environment. The final rulemaking has requirements that are administrative in application, matters of procedure, or provide an equivalent level of safety as existing requirements; therefore, there will be similar environmental impacts from the implementation of the part 53 regulations as there are for existing requirements.

The NRC requested the views of States on the draft environmental assessment on the proposed rule. The NRC received three comment submissions from States (two comment submissions from the State of New York and one comment submission from the State of Utah), one of which commented on the draft environmental assessment. The NRC received three additional comment submissions related to the draft environmental assessment in the proposed rule. The NRC addressed the comments from the States, along with the other comments on the proposed rule, as discussed in Section VI, “Public Comment Analysis.” None of these comments resulted in changes to the environmental assessment.

The determination of this environmental assessment is that there will be no significant environmental impacts to the public from this action. The environmental assessment and finding of no significant impact are available as indicated under the “Availability of Documents” section.

XIII. Paperwork Reduction Act

This final rule contains new and amended collections of information that are subject to the Paperwork Reduction Act of 1995 (44 U.S.C. 3501 et seq.). The collections of information were approved by the Office of Management and Budget, approval numbers 3150-0274 (part 53), 3150-0146 (part 26), 3150-0271 (part 50), 3150-0002 (part 73), 3150-0278 (NRC Forms 361, 361A, 361N, and 361S), 3150-0104 (NRC Forms 366, 366A, and 366B), 3150-0277 (NRC Form 396), 3150-0276 (NRC Form 398), and 3150- 0272 (NRC Forms 893 and 894). The changes to parts 2, 10, 11, 19, 20, 21, 25, 30, 40, 51, 70, 72, 74, 75, 95, 140, 150, 170, and 171 do not contain any new or amended collections of information subject to the Paperwork Reduction Act of 1995. Existing collections of information were approved by the Office of Management and Budget, approval numbers 3150-0062 (part 11), 3150-0044 (part 19), 3150-0014 (part 20), 3150- 0035 (part 21), 3150-0046 (part 25), 3150-0017 (part 30), 3150-0020 (part 40), 3150-0021 (part 51), 3150-0009 (part 70), 3150-0132 (part 72), 3150-0123 (part 74), 3150-0055 (part 75), 3150-0047 (part 95), 3150-0039 (part 140), and 3150-0032 (part 150).

The burden to the public for these information collections is estimated to average 2,257 hours per response for part 53, 9 hours per response for part 26, 4,383 hours per response for part 50, 1,502 hours per response for part 73, and 2 hours per response for NRC Forms 893 and 894, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the information collection. Other identified information collections (NRC Forms 361, 366, 396, and 398) are not estimated to impose burden during the next 3 years.

The information collection is being conducted to evaluate applications for, issue, and regulate operations under part 53 licenses and exercise its oversight functions in an effective and efficient manner to ensure protection of public health and safety, the promotion of the common defense and security, and the protection of the environment. Information will be used by the NRC to make decisions regarding applications and license amendments, assess licensee compliance with part 53, and take corrective actions as needed. Responses to this collection of information are mandatory for licensees choosing to comply with part 53. Confidential and proprietary information submitted to the NRC is protected in accordance with NRC regulations at 10 CFR 9.17(a) and 10 CFR 2.390(b).

You may submit comments on any aspect of these information collections, including suggestions for reducing the burden, by the following methods:

Federal Rulemaking Website: Go to https://www.regulations.gov and search for Docket ID NRC-2019-0062.

Mail comments to: FOIA, Library, and Information Collections Branch, Office of the Chief Information Officer, Mail Stop: T-6 A10M, U.S. Nuclear Regulatory Commission, Washington, DC 20555-0001 or to the OMB reviewer at OMB Office of Information and Regulatory Affairs (3150-0274), Attention: Desk Officer for the Nuclear Regulatory Commission, 725 17th Street NW, Washington, DC 20503.

Public Protection Notification

The NRC may not conduct or sponsor, and a person is not required to respond to, a collection of information unless the document requesting or requiring the collection displays a currently valid OMB control number.

XIV. Executive Orders

The following are E.O.s that are related to this final rulemaking.

A. Executive Order 12866: Regulatory Planning and Review (as Amended by Executive Order 14215: Ensuring Accountability for All Agencies)

This action is a significant regulatory action under section 3(f) of E.O. 12866 and therefore was submitted to OMB for review.

B. Executive Order 14154: Unleashing American Energy

NRC has examined this final rule and has determined that it is consistent with the policies and directives outlined in E.O. 14154.

C. Executive Order 14192: Unleashing Prosperity Through Deregulation

This action is a deregulatory action as defined by E.O. 14192. An E.O. 14192 deregulatory action is defined as “an action that has been finalized and has total costs less than zero.” The final rule and associated guidance will result in net cost savings to the industry and the NRC of $152 million using a 7-percent discount rate and $203 million using a 3-percent discount rate, over the 66-year analysis period. The annualized costs are approximately $1.17 million per year at a 7 percent discount rate, and $1.37 million per year at a 3 percent discount rate. The annualized cost savings are approximately $11.9 million per year at a 7 percent discount rate, and $8.46 million per year at a 3 percent discount rate. Therefore, the net cost savings are estimated at $10.7 million per year at a 7 percent discount rate and $7.09 million per year at a 3 percent discount rate. Accordingly, this final rule has total costs less than zero, and therefore is an E.O. 14192 deregulatory action. Details on the estimated costs of this final rule can be found in Section

VIII of this document, “Regulatory Analysis.”

D. Executive Order 14270: Zero-Based Regulatory Budgeting To Unleash American Energy

E.O. 14270, “Zero-Based Regulatory Budgeting to Unleash American Energy,” requires the NRC to insert a conditional sunset date into all new or amended NRC regulations provided the regulations are (1) promulgated under the AEA, the Energy Reorganization Act of 1974, as amended, or the NWPA; (2) not statutorily required; and (3) not part of the NRC's permitting regime. The NRC determined that the regulatory changes in this rule are statutorily required to comply with NEIMA, necessary for the reasonable assurance of adequate protection of public health and safety, and part of the NRC's regulatory permitting scheme authorized by the AEA. Therefore, the NRC views this rulemaking to be outside the scope of E.O. 14270 and did not insert conditional sunset dates for the regulatory changes in this final rule.

XV. Congressional Review Act

This final rule is a rule as defined in the Congressional Review Act (5 U.S.C. 801-808). However, the Office of Information and Regulatory Affairs in the Office of Management and Budget has found that it does not meet the criteria at 5 U.S.C. 804(2).

XVI. Criminal Penalties

This final rule includes federal regulations that will be enforceable by criminal penalty, as authorized by Section 223 of the AEA. Therefore, per E.O. 14294, these regulations constitute “criminal regulatory offenses.”

For the purposes of Section 223 of the AEA, the NRC is issuing this final rule that will add a new 10 CFR part 53 and amend 10 CFR parts 19, 20, 21, 25, 26, 30, 40, 50, 70, 72, 73, 74, 95, and 140 under one or more of Sections 161b, 161i, or 161o of the AEA. Willful violations of the regulations in these parts will be subject to criminal enforcement, other than those listed in Sec. 19.40(b), Sec. 20.2402(b), Sec. 21.62(b), Sec. 25.39(b), Sec. 26.825(b), Sec. 30.64(b), Sec. 40.82(b), Sec. 50.111(b), Sec. 53.9010(b), Sec. 70.92(b), Sec. 72.86(b), Sec. 73.81(b), Sec. 74.84(b), Sec. 95.63(b), or Sec. 140.89(b). Criminal penalties as they apply to regulations in part 53 are discussed in Sec. 53.9010.

XVII. Voluntary Consensus Standards

The National Technology Transfer and Advancement Act of 1995, Public Law 104-113, requires that Federal agencies use technical standards that are developed or adopted by voluntary consensus standards bodies unless the use of such a standard is inconsistent with applicable law or otherwise impractical. In this final rule, the NRC will revise its regulations by adding a risk-informed, technology- inclusive regulatory framework for commercial advanced nuclear reactors. This action does not constitute the establishment of a standard that contains generally applicable requirements.

XVIII. Availability of Guidance

As discussed in section II, Background, of this document, the NRC's development of part 53 built upon activities such as those described in SECY-19-0117. Because a number of those activities are ongoing to support new reactor applications under the existing regulatory framework of 10 CFR parts 50 and 52, the NRC staff identified in its response to SRM-SECY-20-0032 that the timing of guidance document development to support the part 53 rulemaking was a key risk and uncertainty to publishing the final part 53 rule. To mitigate this risk, the NRC engaged external stakeholders to ensure a common prioritization of the development of these guidance documents and to work diligently on those that would be needed to support this rulemaking, forthcoming applications, or broader efforts such as the Advanced Reactor Demonstration Program being sponsored by the DOE. The NRC also recognizes that guidance development to support part 53 and advanced reactors will continue as the industry and NRC learn lessons from licensing reviews and operating experience.

The NRC is issuing nine guidance documents for the implementation of the requirements in this rulemaking. The guidance is available in ADAMS under the Accession Numbers as indicated under the “Availability of Documents” section in this document.

RG 5.81, Revision 2, “Target Set Identification and Development for Nuclear Power Reactors” (nonpublic)

This regulatory guide (RG) was issued in draft form as Draft Regulatory Guide (DG)-5071 with the proposed rulemaking on Alternative Physical Security Requirements for Advanced Reactors (RIN 3150-AK19; Docket ID NRC-2017-0227) on August 9, 2024. (89 FR 65226). In addition, some sections from DG-5072, “Guidance for Alternative Physical Security Requirements for Small Modular Reactors and Non-Light-Water Reactors,” which was also issued with the same rulemaking, have been incorporated into RG 5.97, “Guidance for Technology-Inclusive Requirements for Physical Protection of Licensed Activities at Commercial Nuclear Plants.” The changes to these guidance documents are a result of the NRC's resolution of public comments on the 10 CFR part 53 proposed rule that requested the NRC address comments made on the proposed Alternative Physical Security Requirements for Advanced Reactors rule. As a result, the NRC addressed the public comments received on those draft guidance documents that were incorporated into the guidance documents for this final rulemaking. Those comment responses can be found in “Comment Response Document for the Final Rule: Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors,” Volume II.

RG 1.254, Revision 0, “Technology-Inclusive Identification of Licensing Events for Commercial Nuclear Plants”

This RG describes an acceptable approach for identifying licensing events that can be used to inform the design basis, licensing basis, and content of applications for commercial nuclear plants, including large LWRs and non-LWRs. It applies to nuclear power reactor designers, applicants, and licensees of commercial nuclear plants applying for permits, licenses, certifications, and approvals under parts 50, 52, and 53. In this RG, the term “licensing events” is used in a generic sense to refer to collections of designated event categories such as, but not limited to AOOs, DBAs, DBEs, and postulated accidents. Specifically, this RG provides an acceptable approach for: (1) conducting a comprehensive and systematic search for initiating events; (2) using a systematic process to delineate a comprehensive set of event sequences; (3) grouping initiating events and event sequences into designated licensing event categories; and (4) providing assurance that the set of licensing events is complete.

RG 5.95, Revision 0, “Access Authorization Program for Commercial Nuclear Plants”

This RG describes a method that the staff considers acceptable to comply with requirements in Sec. 73.120, “Access authorization program for commercial nuclear plants,” related to an AA program. This document provides guidance and is one NRC-approved method (not the only method) for meeting regulatory requirements for part 53. The language in Sec. 73.120 provides flexibility through availability of the use of an alternate approach, commensurate

with risk and consequence to public health and safety, for part 53 applicants who demonstrate compliance with Sec. 73.100(a)(1)(i).

RG 5.96, Revision 0, “Establishing Cybersecurity Programs for Commercial Nuclear Plants Licensed Under 10 CFR part 53”

This RG describes an approach the NRC staff deems acceptable for complying with the Commission's regulations for establishing, implementing, and maintaining a cybersecurity program at commercial nuclear plants licensed under part 53. This guidance provides an approach for meeting the requirements of Sec. 73.110, “Technology- inclusive requirements for protection of digital computer and communication systems and networks.”

RG 5.97, Revision 0, “Guidance for Technology-Inclusive Requirements for Physical Protection of Licensed Activities at Commercial Nuclear Plants”

This RG describes methods and approaches that the NRC staff considers acceptable for meeting the physical security requirements of 10 CFR part 53 and 10 CFR 73.100.

RG 5.99, Revision 0, “Fatigue Management for Nuclear Power Plant Personnel at Commercial Nuclear Plants Licensed Under 10 CFR part 53”

This RG describes methods that the NRC staff considers acceptable for addressing certain aspects of FFD programs established at commercial nuclear facilities licensed under part 53. This guidance, in conjunction with the existing RG 5.73, “Fatigue Management for Nuclear Plant Personnel,” provides comprehensive guidance regarding acceptable methods for the development and implementation of licensee fatigue management programs.

The NRC is issuing the following interim staff guidance (ISG) documents for the implementation of NRC staff review of applications under the requirements in this rulemaking:

DRO-ISG-2023-01, “Operator Licensing Programs”

This ISG provides guidance for the review of tailored operator licensing programs that are submitted for review consistent with the technical requirements of Sec. 53.730(g). This guidance primarily addresses the review of operator licensing examination processes to facilitate the ability of reviewers to assess whether a proposed approach to the testing of licensed operators and trainees reflects sound assessment testing practices that are suitable for the screening of competent licensed operators. Additionally, this ISG provides further review guidance in other areas such as licensed operator continuing training and proficiency programs.

DRO-ISG-2023-02, “Interim Staff Guidance Augmenting NUREG-1791, `Guidance for Assessing Exemption Requests from the Nuclear Power Plant Licensed Operator Staffing Requirements Specified in 10 CFR 50.54(m),' for Licensing Commercial Nuclear Plants under 10 CFR part 53”

This ISG provides guidance for the review of customized facility operator staffing plans that are submitted for review consistent with the technical requirements of Sec. 53.730(f). This ISG is structured as a companion document to the existing NUREG-1791 and adapts the existing HFE-based methodologies of that document for use in the evaluation of staffing plans that will be submitted within the context of part 53 facilities. Additionally, this ISG provides further guidance to address other staffing-related considerations, such as provisions for engineering expertise.

DRO-ISG-2023-03, “Development of Scalable Human Factors Engineering Review Plans”

This ISG applies to the HFE review of applications for OLs, COLs, DCs, and standard design approvals for commercial nuclear plants submitted under part 53. The purpose of this ISG is to facilitate NRC understanding of an acceptable method for developing a scalable (i.e., application-specific) plan for the review of these applications for compliance with applicable HFE requirements. The ISG describes a process and provides implementation guidance for the NRC to tailor HFE review plans to each application to achieve an effective and efficient review.

The NRC has identified future guidance activities that need to be completed after this final rule is published to support advanced reactor applications and NRC reviews. This includes issuance of revisions or part 53-related companions to already available guidance documents after the final part 53 rule is published.

XIX. Availability of Documents

The documents identified in the following table are available to interested persons through one or more of the following methods, as indicated.

ADAMS accession No./web

Document link/Federal Register

citation

Final Rule Documents

Federal Register Notice, “Final Rule: Risk- ML26042A232.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors,” dated

March, 2026. “Environmental Assessment for the Final ML26042A231.

Rule--Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors,” dated March, 2026. “Regulatory Analysis for the Final Rule: ML26042A230.

Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors,” March, 2026. “Comment Response Document for the Final ML26042A229.

Rule: Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors,” Volume I, dated March, 2026. “Comment Response Document for the Final ML26042A228.

Rule: Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors,” Volume II, dated March, 2026.

Information Collection Documents

Supporting Statement for Information ML25230A038.

Collection Analysis--10 CFR Part 53. Supporting Statement for Information ML25230A037.

Collection Analysis--10 CFR Part 26. Supporting Statement for Information ML25232A004.

Collection Analysis--10 CFR Part 50. Supporting Statement for Information ML25230A039.

Collection Analysis--10 CFR Part 73. Supporting Statement for Information ML25230A034.

Collection Analysis--NRC Form 361S. Supporting Statement for Information ML25230A035.

Collection Analysis--NRC Form 366. Supporting Statement for Information ML25245A175.

Collection Analysis--NRC Form 396. Supporting Statement for Information ML25245A176.

Collection Analysis--NRC Form 398.

Supporting Statement for Information ML25230A036.

Collection Analysis--NRC Form 893 and 894. Final Rule--Part 26 Burden Tables for Risk- ML25282A045.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors. Final Rule--Part 50 Burden Tables for Risk- ML25282A044.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors. Final Rule--Part 53 Burden Tables for Risk- ML25282A046.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors. Final Rule--Part 73 Burden Tables for Risk- ML25282A043.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors. NRC Form 361S, “Part 53 Plant Event ML25230A030.

Notification Worksheet”. NRC Form 366, “Licensee Event Report ML25230A031.

(LER)”. NRC Form 366A, “Licensee Event Report ML25230A032.

(LER) Continuation Sheet”. NRC Form 366B, “Licensee Event Report ML25231A040.

(LER) (Failure Continuation)”. NRC Form 396, “Certification of Medical ML25245A149.

Examination by Facility Licensee”. NRC Form 398, “Personnel Qualification ML25245A173.

Statement--Licensee”. NRC Form 893, “Single Positive Test Form, ML25230A033.

10 CFR Part 26, Subpart M FFD Program”. NRC Form 894, “Annual Reporting Form, 10 ML25231A039.

CFR Part 26, Subpart M FFD Program”.

Regulatory Guidance Documents

RG 1.254, “Technology-Inclusive ML25232A005.

Identification Of Licensing Events For

Commercial Nuclear Plants,” dated March,

2026. RG 5.81, “Target Set Identification and ML24229A186.

Development for Nuclear Power Reactors,”

Revision 2, (non-public) dated March, 2026. RG 5.95, “Access Authorization Program for ML25232A007.

Commercial Nuclear Plants,” dated March,

2026. RG 5.96, “Establishing Cybersecurity ML25232A008.

Programs For Commercial Nuclear Plants

Licensed Under 10 CFR Part 53,” dated

March, 2026. RG 5.97, “Guidance for Technology- ML25232A009.

Inclusive Requirements for Physical

Protection of Licensed Activities at

Commercial Nuclear Plants,” dated March,

2026. RG 5.99, “Fatigue Management For Nuclear ML25232A010.

Power Plant Personnel At Commercial

Nuclear Plants Licensed Under 10 CFR Part

53,” dated March, 2026.

ISG Documents

DRO-ISG-2023-01, “Operator Licensing ML25232A011.

Programs,” dated March, 2026. DRO-ISG-2023-02, “Interim Staff Guidance ML25232A023.

Augmenting NUREG-1791, `Guidance for

Assessing Exemption Requests from the

Nuclear Power Plant Licensed Operator

Staffing Requirements Specified in 10 CFR

50.54(m),' for Licensing Commercial

Nuclear Plants under 10 CFR Part 53,”

dated March, 2026. DRO-ISG-2023-03, “Development of Scalable ML25232A022.

Human Factors Engineering Review Plans,”

dated March, 2026.

Other References

American National Standards Institute https://webstore.ansi.org/

(ANSI)/American Nuclear Society (ANS)-3.4- Standards/ANSI/

2013, “Medical Certification And ansians2013.

Monitoring Of Personnel Requiring Operator

Licenses For Nuclear Power Plants”. ASME/ANS RA-S-1.4-2021, “Probabilistic https://www.asme.org/codes-

Risk Assessment Standard for Advanced Non- standards/find-codes-

Light Water Reactor Nuclear Power Plants”. standards/probabilistic-

risk-assessment-standard-

for-advanced-non-light-

water-reactor-nuclear-

power-plants/2021/pdf. ASCE/SEI 43-19, “Seismic Design Criteria https://doi.org/10.1061/

for Structures, Systems, and Components in 9780784415405.

Nuclear Facilities”. EO 12866, “Regulatory Planning and 58 FR 190.

Review,” dated September 30, 1993. EO 14154, “Unleashing American Energy,” 90 FR 8353.

dated January 20, 2025. EO 14192, “Unleashing Prosperity Through 90 FR 9065.

Deregulation,” dated February 6, 2025. EO 14270, “Zero[dash]Based Regulatory 90 FR 15643.

Budgeting to Unleash American Energy,”

dated April 15, 2025. EO 14300, “Ordering the Reform of the 90 FR 22587.

Nuclear Regulatory Commission,” dated May

29, 2025. Federal Register notice--Final policy 60 FR 42622.

statement, “Use of Probabilistic Risk

Assessment Methods in Nuclear Regulatory

Activities; Final Policy Statement,”

dated August 16, 1995. Federal Register notice--Final rule, 74 FR 28112.

“Consideration of Aircraft Impacts for

New Nuclear Power Reactors,” dated June

12, 2009. Federal Register notice--Final rule, 73 FR 16966.

“Fitness for Duty Programs,” dated March

31, 2008. Federal Register notice--Final rule, 72 FR 49352.

“Licenses, Certifications, and Approvals

for Nuclear Power Plants,” dated August

28, 2007. Federal Register notice--Final rule, 53 FR 23203.

“Station Blackout,” dated June 21, 1988. Federal Register notice--Final rule, 60 FR 36953.

“Technical Specifications,” dated July

19,1995. Federal Register notice--Guidance, 84 FR 57554.

“Mandatory Guidelines for Federal

Workplace Drug Testing Programs--Oral/

Fluid,” dated October 25, 2019. Federal Register notice--Policy Statement, 50 FR 32138.

“Policy Statement on Severe Reactor

Accidents Regarding Future Designs and

Existing Plants,” dated August 8, 1985.

Federal Register notice--Policy Statement, 51 FR 30028.

“Safety Goals for the Operation of

Nuclear Power Plants; Policy Statement;

Correction and Republication,” dated

August 21, 1986. Federal Register notice--Policy Statement, 82 FR 2402.

“Tribal Policy Statement,” dated January

9, 2017. Federal Register notice--Policy Statement, 73 FR 60612.

“Policy Statement on the Regulation of

Advanced Reactors,” dated October 14,

2008. Federal Register notice--Policy Statement, 76 FR 34773.

“Final Safety Culture Policy Statement,”

dated June 14, 2011. Federal Register notice--Proposed rule, 87 FR 12254.

“Regulatory Improvements for Production

and Utilization Facilities Transitioning

to Decommissioning,” dated March 3, 2022. Federal Register notice--Proposed rule, 89 FR 86918.

“Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors,” dated October 31, 2024. Federal Register notice--Proposed rule; 89 FR 92609.

extension of comment period, “Risk-

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors,” dated

November 22, 2024. Federal Register notice--Public meeting, 86 FR 67669.

“Reporting Requirements for Nonemergency

Events at Nuclear Power Plants,” dated

November 29, 2021. International Commission on Radiological https://www.icrp.org/

Protection (ICRP), Publication 2 publication.asp?id=icrp%20

“Permissible dose for internal publication%202.

radiation,” dated 1960. ICRP, Publication 26 “Recommendations of https://www.icrp.org/

the ICRP,” dated 1977. publication.asp?id=ICRP%20

Publication%2026. ICRP, Publication 30 “Limits for Intakes https://www.icrp.org/

of Radionuclides by Workers,” dated 1979. publication.asp?id=ICRP%20

Publication%2030%20

(Index). Letter to Chairman Hanson, NRC, “Final ML22319A104.

Letter on Draft 10 CFR Part 53 Rulemaking

Language,” dated November 22, 2022. Letter to Chairman Hanson, NRC, “Fourth ML22196A292.

Interim Letter on 10 CFR Part 53

Rulemaking Language,” dated August 2,

2022. Letter to Chairman Hanson, NRC, ML21140A354.

“Preliminary Proposed Rule Language For

10 CFR Part 53, Regulation of Advanced

Nuclear Reactors, Interim Report,” dated

May 30, 2021. Letter to Chairman Hanson, NRC, ML22040A361.

“Preliminary Rule Language For 10 CFR

Part 53, Subpart F, `Requirements for

Operations,' Interim Report,” dated

February 17, 2022. Letter to Chairman Rempe, ACRS, “Response ML22249A073.

to the Advisory Committee on Reactor

Safeguards, `Fourth Interim Letter on 10

CFR Part 53 Rulemaking Language,' ” dated

September 30, 2022. Letter to Chairman Rempe, ACRS, “Response ML22063A012.

to the Advisory Committee on Reactor

Safeguards Letter on Preliminary Rule

Language for 10 CFR Part 53, Subpart F,

`Requirements for Operations,' Interim

Report,” dated March 30, 2022. Letter to Chairman Sunseri, ACRS, “Part ML20311A006.

53, Licensing and Regulation of Advanced

Nuclear Reactors,” dated November 24,

2020. Letter to Chairman Svinicki, NRC, “10 CFR ML20295A647.

Part 53, Licensing and Regulation of

Advanced Nuclear Reactors,” dated October

21, 2020. National Library of Medicine, National https://

Institutes of Health, Workshop Summary, www.ncbi.nlm.nih.gov/books/

“The Evolution of Telehealth: Where Have NBK207141/.

We Been and Where Are We Going?,” dated

November 2012. NEI 18-04, Rev. 1, “Risk-Informed ML19241A472.

Performance-Based Technology-Inclusive

Guidance for Non-Light Water Reactors,”

dated August 2019. NEI 22-05, Rev. 0, “Technology Inclusive ML24032A237.

Risk Informed Change Evaluation

(TIRICE),” dated January 2024. Nuclear Innovation Alliance (NIA), https://

“Clarifying `Major Portions' of a Reactor www.nuclearinnovationallia

Design in Support of a Standard Design nce.org/clarifying-major-

Approval,” dated April 2017. portions-reactor-design-

support-standard-design-

approval. NRC, “Advanced Reactor Vision and ML16356A670.

Strategy: Safely Achieving Effective and

Efficient Non-Light Water Reactor Mission

Readiness,” dated December 2016. NRC, “A Regulatory Review Roadmap for Non- ML17312B567.

Light Water Reactors,” dated December

2017. NRC, “Manufacturing License ML-1 for ML20070J215.

Production of Up to Eight Floating Nuclear

Plants,” dated September 30, 1982. NRC, “Report to Congress: Advanced Reactor ML12158A398 (cover letter)

Licensing,” dated August 2012. ML12153A014 (report). NRC, “Risk-Informed and Performance-Based ML21069A003.

Human-System Considerations for Advanced

Reactors,” dated March 2021. NRC Form 890, “Single Positive Test Form” ML25044A086. NRC Form 891, “Annual Reporting for Drug ML26016A656.

and Alcohol Tests”. NRC Form 892, “Annual Fatigue Reporting ML22013B250.

Form”. NRC Public Meeting Summary, “Public ML25014A024.

Meeting to Discuss the Part 53 Risk-

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors

Rulemaking--Proposed Rule” (November 19,

20, and 21, 2024), dated January 14, 2025. NRC Public Meeting Summary, “Public ML25042A010.

Meeting to Discuss the Part 53 Risk-

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors

Rulemaking--Proposed Rule” (January 8,

2025), dated January 24, 2025. NUREG-0880, “Safety Goals for Nuclear ML071770230.

Power Plant Operation,” dated May 1983. NUREG/CR-2601, “Technology, Safety and ML14023A046 (package).

Costs of Decommissioning Reference Light

Water Reactors Following Postulated

Accidents” dated November 1982. NUREG-1530, Revision 1, “Reassessment of ML22053A025.

NRC's Dollar Per Person-Rem Conversion

Factor Policy, Final Report,” dated

February 2022. NUREG-1860, Volumes 1 and 2, “Feasibility ML080440170

Study for a Risk-Informed and Performance- ML080440215.

Based Regulatory Structure for Future

Plant Licensing,” dated December 2007.

NUREG/BR-0058, Revision 5, “Regulatory ML17100A480.

Analysis Guidelines of the U.S. Nuclear

Regulatory Commission,” dated April 2017. NUREG/CR-5884, “Revised Analyses of ML14008A187.

Decommissioning for the Reference

Pressurized Water Reactor Power Station,”

dated November 1995. NUREG/CR-6187, Volume 1, “Revised Analyses ML14008A186.

of Decommissioning for the Reference

Boiling Water Reactor Power Station,”

dated July 1996. PNNL, Technical Letter Report, “The Use of ML18081A607.

Electronic Communications to Perform

Determinations of Fitness,” dated August

2017. Pre-decisional DG, ML22276A149.

“Technology[dash]Inclusive,

Risk[dash]Informed, and

Performance[dash]Based Methodology for

Seismic Design of Commercial Nuclear

Plants,” dated October 3, 2022. Research Information Letter 2021-04, ML21113A066.

“Feasibility Study on a Potential

Consequence-Based Seismic Design Approach

for Nuclear Facilities,” dated April 2021. RG 1.110, Revision 1, “Cost-Benefit ML13241A052.

Analysis for Radwaste Systems for

Light[dash]Water-Cooled Nuclear Power

Reactors,” dated October 2013. RG 1.134, Revision 4, “Medical Assessment ML14189A385.

Of Licensed Operators Or Applicants For

Operator Licenses At Nuclear Power

Plants,” dated September 2014. RG 1.174, “An Approach for Using ML17317A256.

Probabilistic Risk Assessment in Risk-

Informed Decisions on Plant-Specific

Changes to the Licensing Basis,” Revision

3, dated January 2018. RG 1.208, “A Performance-Based Approach to ML070310619.

Define the Site-Specific Earthquake Ground

Motion,” dated March 2007. RG 1.232, “Guidance for Developing ML17325A611.

Principal Design Criteria for Non-Light-

Water Reactors,” Revision 0, dated April

2018. RG 1.233, Revision 0, “Guidance for a ML20091L698.

Technology-Inclusive, Risk-Informed, and

Performance-Based Methodology to Inform

the Licensing Basis and Content of

Applications for Licenses, Certifications,

and Approvals for Non-Light-Water

Reactors,” dated June 2020. RG 1.247, “Acceptability of Probabilistic ML21235A008.

Risk Assessment Results for Non-Light-

Water Reactor Risk-Informed Activities,”

issued March 2022 for trial use. RG 5.71, “Cybersecurity Programs for ML22258A204.

Nuclear Power Reactors,” Revision 1,

dated February 3, 2023. RG 5.73, “Fatigue Management for Nuclear ML083450028.

Power Plant Personnel,” dated March 20,

2009. SECY-18-0096, “Functional Containment ML18115A157.

Performance Criteria For Non-Light-Water-

Reactors,” dated September 28, 2018. SECY-19-0117, “Technology-Inclusive, Risk- ML18311A264 (package).

Informed, and Performance-Based

Methodology to Inform the Licensing Basis

and Content of Applications for Licenses,

Certifications, and Approvals for Non-

Light-Water Reactors,” dated December

2019. SECY-20-0032, “Rulemaking Plan on `Risk- ML19340A056.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors (RIN-3150-

AK31; NRC-2019-0062,' ” dated April 13,

2020. SECY-20-0070, “(Redacted) Technical ML20126G265 (package).

Evaluation of the Security Bounding Time

Concept for Operating Nuclear Power

Plants,” dated November 8, 2021. SECY-24-0049, “Proposed Rule: Reporting ML23318A479.

Requirements for Nonemergency Events at

Nuclear Power Plants (RIN 3150-AK71; NRC-

2020-0036),” dated June 10, 2024. SECY-93-092, “Issues Pertaining to the ML040210725.

Advanced Reactor (PRISM, MHTGR, and PIUS)

and CANDU 3 Designs and their Relationship

to Current Regulatory Requirements,”

dated April 8, 1993. SRM-SECY-10-0121, “Modifying the Risk- ML110610166.

Informed Regulatory Guidance for New

Reactors,” dated March 2, 2011. SRM-SECY-17-0100, “Security Baseline ML18283A072.

Inspection Program Assessment Results and

Recommendations for Program

Efficiencies,” dated October 8, 2018. SRM-SECY-20-0032, “Rulemaking Plan on ML20276A293.

`Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced Reactors

(RIN-3150-AK31; NRC-2019-0062),”' dated

October 2, 2020. SRM-SECY-20-0045, “Population Related ML22194A885.

Siting Considerations for Advanced

Reactors,” dated July 30, 2022. SRM-SECY-98-144, “Staff Requirements--SECY- ML003753593.

98-144--White Paper on Risk-Informed and

Performance-Based Regulations,” dated

February 24, 1999. SECY-23-0021, “Proposed Rule: Risk- ML21162A095.

Informed, Technology-Inclusive Regulatory

Framework for Advanced Reactors (RIN 3150-

AK31),” March 1, 2023. SECY-23-0021, Enclosure 1, “Draft Federal ML21162A102.

Register Notification”. SECY-23-0021, Enclosure 2, “Draft ML21162A104.

Environmental Assessment for the Proposed

Rule--Risk-Informed, Technology-Inclusive

Regulatory Framework for Advanced

Reactors”. SECY-23-0021, Enclosure 3, “Draft ML21165A112.

Regulatory Analysis for the Proposed Rule:

Risk-Informed, Technology[dash]Inclusive

Regulatory Framework for Advanced

Reactors”. SECY-23-0021, Enclosure 4, “Alternative ML22244A001.

Approaches Considered for Selected Topics

During the Development of 10 CFR Part 53”. SECY-23-0021, Enclosure 5, “Estimated ML22304A099 (non-public).

Resources for The Risk-Informed,

Technology-Inclusive Regulatory Framework

For Advanced Reactors Rulemaking”. Staff Requirements--SECY-23-0021, ML24064A047 (package).

“Proposed Rule: Risk-Informed, Technology-

Inclusive Regulatory Framework for

Advanced Reactors (RIN 3150-AK31),” March

4, 2024.

The NRC may post materials related to this document, including public comments, on the Federal rulemaking website at https://www.regulations.gov under Docket ID NRC-2019-0062. In addition, the Federal rulemaking website allows members of the public to receive alerts when changes or additions occur in a docket folder. To subscribe: (1) navigate to the docket folder (NRC-2019-0062); (2) click the “Subscribe” link; and (3) enter an email address and click on the “Subscribe” link.

← A. IntroductionContentsList of Subjects →

How to cite this
  1. The rule itself

    Nuclear Regulatory Commission, “Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors,” 91 FR 15696 (March 30, 2026). Effective April 29, 2026.
    https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors

  2. This page

    “Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors,” the text from “D. Changes to Part 26, Subpart N” to “XIX. Availability of Documents.” Read the Mandate, https://readthemandate.org/rules/rule-2026-06048/text-5/ (retrieved August 27, 2026).

Cite the document when the claim is about what the document says. Cite this page when the indexing, the wording or the record of what has happened is what is being relied on.

How This Rule Is Set Out

Federal Register documents are United States government works and are not under copyright, so the rule is here whole rather than cut to an excerpt. It is split at the headings the Register itself prints: the line it is filed under, the captioned fields on its face, the preamble where the agency says what it is doing and why, and the amendments to the Code of Federal Regulations. No passage is shortened.

Two things the Register prints are not reproduced: the running head it repeats at every page break, and the tables it sets as pictures rather than as words. Its own marker for one of those tables, [GRAPHIC] [TIFF OMITTED], is left standing where the table was, so a reader can see that something is there and follow the link to the page it is on.

Every heading in the rule is listed on the rule's own page, which says which of these pages each one is on.