The NRC Cybersecurity Rule (10 CFR 73.54): What Licensees Must Demonstrate
10 CFR 73.54 requires a documented cyber security plan protecting digital assets from a defined cyber threat. What examiners actually check, and where licensees fall short.
The business problem
Power reactor licensees operate under 10 CFR 73.54, which requires protecting digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions from a defined cyber threat. The rule itself is short. The expectation behind it — built out through Regulatory Guide 5.71 and each licensee's own NRC-approved Cyber Security Plan — is not.
Why it matters
An organization can have strong general IT security and still fail an NRC cyber inspection, because 73.54 isn't evaluated against generic best practice — it's evaluated against the specific plan the licensee itself submitted and the NRC approved. A gap between what the plan promises and what's actually implemented is the finding, regardless of how good the underlying control is in isolation.
“The inspector isn't grading your cybersecurity against an industry standard. They're grading it against the plan you told the NRC you'd follow — which means the first question is always whether anyone still knows what that plan actually commits you to.”
Signs the organization should pay attention now
- The facility's Cyber Security Plan hasn't been reviewed against current implementation in the last cycle
- Regulatory Guide 5.71's defense-in-depth categories aren't mapped to a current, complete digital asset inventory
- Digital assets have been added or changed since the plan was last updated, without a documented review of whether they fall in scope
- No one can point to the specific plan language governing a given control when asked directly
- Cyber Security Plan implementation is treated as purely an IT function, without documented executive oversight
What good looks like
The organization maintains a living crosswalk between its NRC-approved Cyber Security Plan and current implementation, reviews that crosswalk whenever the digital asset inventory changes, and can show inspectors specific evidence tied to specific plan commitments — not general security posture.
See where your program stands against 10 CFR 73.54 and RG 5.71.
Take the Nuclear Cybersecurity AssessmentPractical guidance
Pull the current Cyber Security Plan and confirm, item by item, that implementation still matches what's written. Treat any digital asset added since the last review as unclassified until someone has actually determined whether it's a Critical Digital Asset. And give a named executive ownership of keeping the plan and its implementation in sync — not just IT.
My CISO Partner's perspective
We treat the Cyber Security Plan as the actual audit standard it is, not a document filed once and left alone — our work centers on keeping the plan and the implementation honestly in sync, year over year.
Where to go from here
If no one can point to the specific line in your Cyber Security Plan that governs a given control, that gap — not the control itself — is what an inspector will find first.
Questions, answered directly.
73.54 as written applies specifically to power reactor licensees. Other NRC-regulated facility types carry their own applicable security requirements, so it's worth confirming which apply to your specific license type.
NRC guidance describing an acceptable method — built around defense-in-depth protective strategies — for complying with 73.54. Licensees generally build their Cyber Security Plans around it, though it is guidance rather than the rule itself.
NRC inspectors, following the agency's cyber security inspection procedures, evaluate the licensee against its own NRC-approved Cyber Security Plan.
A digital device or system that is itself in scope for protection because it performs, or is associated with, a safety, security, or emergency-preparedness function.
Talk to a CISO about your Cyber Security Plan.
30 minutes. No obligation. No sales pitch.