Nuclear Cybersecurity & Regulatory Readiness
Know where you stand across the NRC's security and licensing frameworks before an inspector, a licence milestone or a board asks. An advisory readiness assessment delivered by executive-level security leadership, with reporting your board can act on and remediation you can track.
This is an assessment and readiness service. An Assessment Readiness Score is an advisory measure prepared by My CISO Partner; it is not a Regulatory Compliance Determination, which only the cognizant regulator makes.
A structured readiness assessment against the regulations that govern your facility.
We take the NRC's security, personnel, material control, cybersecurity, information-protection, ownership and licensing requirements, express them as an assessable control library with their citations preserved, and work through every applicable control with your team: what the requirement asks, what you have in place, what evidences it, where the gaps are, how serious they are, and what closes them.
- One versioned framework across eight regulatory domains, so a regulatory update becomes a new edition and your historical results stay exactly as they were assessed.
- Every control keeps its regulatory reference. Requirement statements are plain-English summaries for audit planning; the regulations control.
- A readiness score that distinguishes compliance status, risk severity, regulatory importance, evidence sufficiency and remediation status — with the calculation shown, never a bare percentage.
- Safeguards Information stays in your approved handling process. The platform records that evidence exists and was examined; it never stores SGI.
Organisations that answer to the NRC — or will.
Operating licensees
Power reactors, research reactors and fuel cycle facilities preparing for inspection, a licence action or a periodic programme review.
Advanced reactor developers
Pre-application and applicant organisations building a security and cyber programme alongside a 10 CFR Part 53 or Part 50/52 path.
Organisations with FOCI obligations
Licensees, applicants and suppliers whose ownership or investment structure brings foreign ownership, control or influence questions.
Leadership and counsel
CEOs, boards, general counsel and chief compliance officers who need the position stated in plain language, with the basis for every statement.
The gaps that surface late are the expensive ones.
No single picture
Physical, personnel, cyber, MC&A and SGI obligations live with different owners and different binders. Nobody can say, on one page, where the programme stands.
Evidence that cannot be produced
A control is "implemented" until an inspector asks for the record. Every control here carries what an auditor examines, what was received, and when it expires.
Findings without owners
Gaps noted in a report and never closed. Every finding has a rating, an owner, a date, a remediation plan and a validation step, and closed findings cannot be quietly edited.
Emerging rules
Part 53 guidance is still moving. Emerging requirements are flagged as such in the framework so nobody relies on a citation that has changed.
Boards asking the wrong question
"Are we compliant?" is the regulator's determination to make. "Where are we not ready, and what are we doing about it?" is answerable, and it is what the executive dashboard answers.
Sensitive material in the wrong place
Detailed findings can constitute Safeguards Information. Text fields are capped, evidence is classified, and SGI is recorded as held externally — by design, not by policy alone.
Ten stages, one traceable chain.
From the first conversation to the executive report, every stage leaves a record you can follow back: framework → domain → requirement → control → evidence → assessment → finding → remediation.
- Scope is set from your licensing status, facilities, ownership position and SGI handling — domains that do not apply are recorded as out of scope with the reason, not silently dropped.
- Each control is recorded as Compliant, Partially Compliant, Non-Compliant, Not Applicable or Not Assessed — the assessor's vocabulary, not a verdict on the organisation — with evidence requested, received and rated for sufficiency.
- The readiness score weights each control by its regulatory significance, discounts it by evidence sufficiency, deducts for unresolved critical and high findings, and caps its band when coverage is low. The weighting is configuration, and every step is shown.
- Issued results are frozen. A final assessment cannot be edited or reopened; a changed position is a new assessment, so history is never rewritten.
Eight domains, with their governing references.
Physical Protection
Protection of the facility and special nuclear material — 10 CFR Part 73, including 73.55 and the physical security plan.
Personnel Security / Access Authorization
Access authorization, fitness for duty and insider mitigation — 10 CFR 73.56 and Part 26.
Material Control & Accounting
Control and accounting of special nuclear material — 10 CFR Part 74.
Cybersecurity
Protection of digital computer and communication systems — 10 CFR 73.54 and Regulatory Guide 5.71.
Safeguards Information
Identification, marking, handling and protection of SGI — 10 CFR 73.21–73.23.
Foreign Ownership, Control or Influence
Ownership and control restrictions and their mitigation — Atomic Energy Act §103d/§104d, 10 CFR 50.38, 32 CFR Part 117 (NISPOM).
FOCI Operational Controls
The day-to-day operation of FOCI mitigation, including export control touchpoints — 10 CFR Part 810, ITAR and EAR where they apply.
Advanced Reactor Licensing / Part 53 Readiness emerging
Readiness against the 10 CFR Part 53 framework and its evolving guidance. Flagged as emerging: citations are confirmed against current NRC guidance before reliance.
What you receive.
- A scoped, control-by-control assessment record with regulatory references preserved.
- An evidence register: every request, version, review decision, validity period and expiry, with an access ledger.
- A findings register with rating, priority, owner, due date, root cause, business and regulatory impact, and a remediation plan per finding.
- The Assessment Readiness Score with its domain breakdown and the full calculation.
- An executive report — purpose and basis, scope, score, readiness by domain, priority findings, evidence position, remediation plan, limitations — and board briefing content.
- A client portal that shows assessment status, the released findings and remediation plan, outstanding evidence, upcoming deadlines and delivered reports.
Written for the people who decide.
One dashboard for the CEO, the board, the CIO and CISO, general counsel and the compliance officer: overall readiness, critical and high findings, overdue remediation, evidence gaps, domains at risk and assessment completion — with drill-down from the headline to the control, the finding, the evidence and the action. Every number is a recorded fact; the summary says what it is built from.
Findings that get closed, not filed.
Each finding carries a remediation plan with actions, owners, dates, milestones and a validation step. Progress, overdue items and aging are visible to leadership; closure needs a reviewer and closure evidence; a closed finding can only be reopened with a stated, recorded reason.
Ownership after the assessment.
Readiness is not a one-time exercise. Our Fractional CISO service carries the programme forward: owning the remediation plan, keeping evidence current, preparing leadership for inspections and licence milestones, and re-assessing as the rules and your facilities change.
Questions, answered directly.
No. It is an advisory readiness assessment. The readiness score describes the state of preparation as observed by the assessors; only the cognizant regulator determines compliance. Nothing in the reports states that an organisation is, or is not, in compliance with any regulation, and the platform is built so that it cannot say so by accident.
It is not uploaded, stored or transmitted through the platform. Free-text fields on nuclear controls are capped so a findings narrative cannot accumulate, evidence is classified, and material that constitutes SGI is recorded as held in your approved handling process with a reviewer's attestation of what was examined. We agree the handling arrangement with you before any sensitive documentation is exchanged.
Only what determines scope: your licensing status, facilities, whether foreign ownership or SGI handling applies, the state of your cyber programme, the regulatory drivers you already know about, and your timeline. From those answers we propose which of the eight domains apply and whether the engagement is a readiness assessment or a pre-licensing baseline. A consultant confirms the scope with you before fieldwork.
Named, senior consultants perform the assessment and make every judgement. An AI assistant can be enabled per engagement, by an administrator with a stated basis, to help the assessor spot evidence gaps, inconsistent responses and possible duplicates; everything it produces is labelled AI GENERATED — HUMAN REVIEW REQUIRED, cites only records already in the assessment, and is accepted, modified or rejected by the assessor. It cannot change a status, close a finding or make any determination.
Start with the scope.
A short intake tells us which domains apply. A consultant confirms the scope with you, then the assessment begins.