Modernizing Security Requirements
Federal RegisterJun 26, 2026
Ask Donna
What actually matters in this document.
Text
NUCLEAR REGULATORY COMMISSION
10 CFR Parts 26, 50, 52, 72, 73, and 95
[PRM-26-4; PRM-26-7; PRM-26-8; NRC-2012-0079; and NRC-2025-1303]
RIN 3150-AL53
Modernizing Security Requirements
AGENCY:
Nuclear Regulatory Commission.
ACTION:
Proposed rule and draft guidance; request for comment.
SUMMARY:
The U.S. Nuclear Regulatory Commission (NRC) is proposing to revise its regulations to modernize security and fitness-for-duty requirements to enhance efficiency, consistent with Executive Order 14300, “Ordering the Reform of the Nuclear Regulatory Commission.” The proposed revisions are intended to reduce regulatory burden, where appropriate, while continuing to provide reasonable assurance that safety and security will be adequately maintained at NRC-licensed facilities.
DATES:
Comments must be submitted electronically using
https://www.regulations.gov
by 11:59 p.m. eastern time on July 27, 2026.
ADDRESSES:
Submit your comments, identified by Docket ID NRC-2025-1303, at
https://www.regulations.gov.
If your material cannot be submitted using
https://www.regulations.gov,
call or email the individuals listed in the
FOR FURTHER INFORMATION CONTACT
section of this document for alternate instructions.
Do not include any personally identifiable information (such as name, address, or other contact information) or confidential business information that you do not want publicly disclosed. All comments are public records; they are publicly displayed exactly as received and will not be deleted, modified, or redacted. Comments may be submitted anonymously.
Follow the search instructions on
https://www.regulations.gov
to view public comments.
You can read a plain language description of this proposed rule at
https://www.regulations.gov/docket/NRC-2025-1303.
For additional direction on obtaining information and submitting comments, see “Obtaining Information and Submitting Comments” in the
SUPPLEMENTARY INFORMATION
section of this document.
FOR FURTHER INFORMATION CONTACT:
Nicole Fields, Office of Nuclear Material Safety and Safeguards, telephone: 630-829-9570, email:
Nicole.Fields@nrc.gov
and Shyrl Coker, Office of Nuclear Reactor Regulation, telephone: 301-287-3603, email:
Shyrl.Coker@nrc.gov.
Both are staff of the U.S. Nuclear Regulatory Commission, Washington, DC 20555-0001.
SUPPLEMENTARY INFORMATION:
Executive Summary
A. Need for the Regulatory Action
The U.S. Nuclear Regulatory Commission (NRC) is proposing to revise its regulations to modernize security and fitness-for-duty requirements to enhance efficiency, consistent with Executive Order 14300, “Ordering the Reform of the Nuclear Regulatory Commission.”
B. Major Provisions
Major provisions of this proposed rule, supported by accompanying draft guidance, include the following:
•
Fitness for Duty Programs.
The NRC is proposing effectiveness and efficiency improvements to the drug and alcohol testing requirements based on lessons learned from implementing title 10 of the
Code of Federal Regulations
(10 CFR) part 26, “Fitness for Duty Programs,” to align with select changes made by other Federal agency testing programs, and to address several petitions for rulemaking (PRMs). Changes include enabling the collection and drug testing of oral fluid specimens for all conditions for testing, a risk-informed reduction in the annual random testing rate for most licensee employees, enhancing blind performance testing requirements with additional program flexibilities and targeted sampling reductions, updating the refresher training interval, and eliminating the requirement for licensees to conduct annual audits of U.S. Department of Health and Human Services certified laboratories. The NRC also is proposing to extend the duration of applicability for the optional subpart K to 10 CFR part 26 fitness-for-duty programs for reactor construction, and to enable licensees and other entities to escort construction workers instead of subjecting those workers to a subpart K program. Under the fatigue management program requirements, the NRC is proposing to add a new exception from the work-hour controls for sequestration events, specifying alternative work hour controls and requirements that licensees may meet during such events. The NRC is also proposing to eliminate the annual reporting of fatigue management performance information to the NRC. These changes would reduce unnecessary regulatory burden.
•
Security Requirements for Independent Spent Fuel Storage Installations.
The proposed rule would revise security requirements for independent spent fuel storage installations (ISFSIs) to improve clarity and consistency between the requirements for general license ISFSIs and specific license ISFSIs. Major provisions would allow standalone ISFSIs located outside a power reactor's protected area to implement security programs appropriate for their risk profile. The rule would streamline the process for updating ISFSI security plans and reduce the frequency of required submissions to the NRC. These changes would be responsive to stakeholder feedback and Commission direction, reducing licensee burden and facilitating efficient transitions to decommissioning.
•
Physical Security Requirements.
The NRC is proposing to modernize and streamline physical security requirements for nuclear power reactors and materials by shifting from prescriptive rules to performance-based, risk-informed criteria. The amendments would provide increased flexibility for implementing security measures and allow for the use of technology-inclusive approaches and alternatives tailored to diverse reactor designs. The proposal addresses access authorization, cybersecurity, safeguards information handling, event notifications, and training, and resolves industry concerns from recent rulemakings. In revising performance objectives, the changes would support innovation, reduce unnecessary regulatory burden, and maintain protection against credible threats.
•
Facility Security Clearance and Safeguarding of National Security Information and Restricted Data.
The NRC is proposing to revise 10 CFR part 95, “Facility Security Clearance and Safeguarding of National Security Information and Restricted Data,” to remove requirements that are duplicative and to ensure alignment with 32 CFR part 117, “National Industrial Security Program Operating Manual (NISPOM).” These changes would provide references to the applicable provisions of 32 CFR part 117 for implementation of the National Industrial Security Program.
C. Costs and Benefits
The NRC prepared a draft regulatory analysis to determine the expected quantitative costs and benefits of this proposed rule and associated draft guidance as well as qualitative factors to be considered in the NRC's rulemaking decision. The conclusion from the analysis is that this proposed rule and associated draft guidance would result
in net cost savings to the industry and the NRC, over the next 30 years, ranging from $561 million using a 7 percent discount rate to $1.01 billion using a 3 percent discount rate. For the industry, the net cost savings are estimated at $557 million (7 percent discount rate) and $1.01 billion (3 percent discount rate). For the NRC, the net cost savings are estimated at $3.4 million (7 percent discount rate) and $6.7 million (3 percent discount rate). On an annualized basis, the net cost savings to the industry and the NRC would be about $45.2 million per year at a 7 percent discount rate and $51.8 million per year at a 3 percent discount rate.
The draft regulatory analysis also considers qualitative factors, such as regulatory efficiency. These benefits would result from clarifications, administrative changes, and streamlining of processes (such as notifications), along with aligning requirements with existing Federal regulations instead of maintaining separate but similar NRC requirements.
For more information, please see the draft regulatory analysis (available in the NRC's Agencywide Documents Access and Management System (ADAMS) Accession No. ML26113A051).
Table of Contents
I. Obtaining Information and Submitting Comments
A. Obtaining Information
B. Submitting Comments
II. Executive Order 14300: Ordering the Reform of the Nuclear Regulatory Commission
III. Background
IV. Discussion
A. Fitness for Duty Programs (Part 26)
B. Security Requirements for Independent Spent Fuel Storage Installations (ISFSIs) (Parts 72 and 73)
C. Physical Security Requirements (Part 73)
D. Facility Security Clearance and Safeguarding of National Security Information and Restricted Data (Part 95)
V. Specific Requests for Comments
VI. Regulatory Flexibility Certification
VII. Regulatory Analysis
VIII. Backfitting and Issue Finality
IX. Cumulative Effects of Regulation
X. Plain Writing
XI. National Environmental Policy Act
XII. Paperwork Reduction Act
XIII. Executive Orders
A. Executive Order 12866: Regulatory Planning and Review (as Amended by Executive Order 14215, Ensuring Accountability for All Agencies)
B. Executive Order 14154: Unleashing American Energy
C. Executive Order 14192: Unleashing Prosperity Through Deregulation
D. Executive Order 14267: Reducing Anti-Competitive Regulatory Barriers
E. Executive Order 14270: Zero-Based Regulatory Budgeting To Unleash American Energy
XIV. Voluntary Consensus Standards
XV. Availability of Guidance
XVI. Availability of Documents
I. Obtaining Information and Submitting Comments
A. Obtaining Information
Please refer to Docket ID NRC-2025-1303 when contacting the NRC about the availability of information for this action. You may obtain publicly available information related to this action by any of the following methods:
•
Federal Rulemaking Website:
Go to
https://www.regulations.gov
and search for Docket ID NRC-2025-1303.
•
NRC's Agencywide Documents Access and Management System (ADAMS):
You may obtain publicly available documents online in the ADAMS Public Documents collection at
https://www.nrc.gov/reading-rm/adams.html.
To begin the search, select “Begin ADAMS Public Search.” For problems with ADAMS, please contact the NRC's Public Document Room (PDR) reference staff at 1-800-397-4209, at 301-415-4737, or by email to
PDR.Resource@nrc.gov.
For the convenience of the reader, instructions about obtaining materials referenced in this document are provided in the “Availability of Documents” section.
•
NRC's PDR:
The PDR, where you may examine and order copies of publicly available documents, is open by appointment. To make an appointment to visit the PDR, please send an email to
PDR.Resource@nrc.gov
or call 1-800-397-4209 or 301-415-4737, between 8 a.m. and 4 p.m. eastern time, Monday through Friday, except Federal holidays.
•
Public Meeting:
The NRC will conduct a public meeting to describe the proposed amendments and answer questions from the public on the proposed rule. The NRC will publish a notice of the location, time, and agenda of the meeting on the NRC's public meeting website within 10 calendar days of the meeting. Stakeholders should monitor the NRC's public meeting website for information about the public meeting at:
https://www.nrc.gov/public-involve/public-meetings/index.cfm.
B. Submitting Comments
Comments must be submitted electronically using
https://www.regulations.gov
no later than 11:59 p.m. eastern time on July 27, 2026. Please include Docket ID NRC-2025-1303 in your comment submission.
The NRC cautions you not to include identifying or contact information that you do not want to be publicly disclosed in your comment submission. The NRC will post all comment submissions at
https://www.regulations.gov
as well as enter the comment submissions into ADAMS. The NRC does not routinely edit comment submissions to remove identifying or contact information.
If you are requesting or aggregating comments from other persons for submission to the NRC, then you should inform those persons not to include identifying or contact information that they do not want to be publicly disclosed in their comment submission. Your request should state that the NRC does not routinely edit comment submissions to remove such information before making the comment submissions available to the public or entering the comment into ADAMS.
II. Executive Order 14300: Ordering the Reform of the Nuclear Regulatory Commission
On May 23, 2025, President Donald J. Trump signed Executive Order (E.O.) 14300, “Ordering the Reform of the Nuclear Regulatory Commission.” Section 5, “Reforming and Modernizing the NRC's Regulations,” requires the NRC to undertake a review and wholesale revision of its regulations and guidance documents as guided by the policies set forth in section 2 of the E.O. This rulemaking addresses section 5(g), which directs the NRC to “[r]evise the Reactor Oversight Process and reactor security rules and requirements to reduce unnecessary burdens and be responsive to credible risks.”
III. Background
Over the decades, the NRC has developed a comprehensive regulatory framework to ensure that licensee programs at nuclear facilities provide reasonable assurance that public health and safety is adequately protected and are in accord with the common defense and security. This proposed rule seeks to modernize the NRC's regulatory framework for licensee security programs—reducing regulatory burden, where appropriate, while continuing to provide reasonable assurance of adequate safety and security. The principal regulations relevant to this
proposed rule are set forth in 10 CFR parts 26; 72, “Licensing Requirements for the Independent Storage of Spent Nuclear Fuel, High-Level Radioactive Waste, and Reactor-Related Greater Than Class C Waste”; 73, “Physical Protection of Plants and Materials”; and 95.
The regulations in 10 CFR part 26 govern fitness-for-duty (FFD) programs, including drug and alcohol testing and fatigue management, for personnel at nuclear power plants and certain other NRC-licensed facilities. The requirements are designed, in part, to provide reasonable assurance that individuals are trustworthy, reliable, and not under the influence of any substances, legal or illegal, or mentally or physically impaired from any cause that could adversely affect their ability to safely and competently perform their duties.
The regulations in 10 CFR part 72 set forth requirements for the licensing and operation of ISFSIs. These facilities are used to safely store spent nuclear fuel and certain other radioactive materials, both at power reactor sites and away from reactor sites. Part 72 includes both safety and security provisions, with physical protection requirements that vary depending on whether the ISFSI is operated under a general license or specific license.
The regulations in 10 CFR part 73 address the physical protection of plants and materials. Part 73 contains detailed requirements for physical security programs, access authorization, cybersecurity, and the protection of safeguards information. These requirements apply to commercial nuclear power reactors, fuel cycle facilities, and other licensees that possess special nuclear material (SNM). The regulation is structured to protect against the design basis threats of radiological sabotage and theft or diversion of SNM, and includes requirements for security organization, training, response strategies, and contingency planning.
The regulations in 10 CFR part 95 establish requirements for facility security clearances and the safeguarding of national security information and restricted data. These requirements are intended to ensure that NRC licensees and certificate holders who require access to classified information maintain appropriate security measures in accordance with the National Industrial Security Program.
The NRC recognizes the need to modernize and streamline its security and FFD regulations to reduce unnecessary regulatory burden, promote regulatory clarity, provide appropriate program flexibility, and support the deployment of innovative technologies, while also continuing to provide reasonable assurance that safety and security will be adequately maintained. This proposed rule aligns with national policy directives to facilitate the expansion of United States nuclear energy capacity, as articulated in recent Executive Orders and statutory mandates.
In addition to E.O. 14300, other recent E.O.s related to the expansion of United States nuclear energy capacity include E.O. 14156, “Declaring a National Energy Emergency” (90 FR 8433; January 29, 2025), which stressed the need for a reliable, diversified, and affordable supply of energy, and E.O. 14154, “Unleashing American Energy” (90 FR 8353; January 29, 2025), which stated that it is in the national interest to “unleash America's affordable and reliable energy and national resources.”
Recent statutory mandates related to nuclear energy capacity include the Nuclear Energy Innovation and Modernization Act (Pub. L. 115-439, 132 Stat. 5572) (NEIMA) and the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024 (Pub. L. 118-67, 138 Stat. 1448) (ADVANCE Act). In response to NEIMA, the NRC recently issued a final rule establishing 10 CFR part 53, “Risk-Informed, Technology-Inclusive Regulatory Framework for Commercial Nuclear Power Plants,” which sets forth a regulatory framework for licensing and regulating advanced reactors (91 FR 15696; March 30, 2026). Part 53 is designed to accommodate a wide range of reactor technologies and business models, providing performance-based requirements that enable the use of modern safety and security approaches. As discussed in Section IV of this document, proposed changes as a part of this proposed rule would apply to licensees and applicants under 10 CFR parts 50, “Domestic Licensing of Production and Utilization Facilities”; 52, “Licenses, Certifications, and Approvals for Nuclear Power Plants”; and 53. The proposed amendments are intended to provide enhanced regulatory flexibility for both current and future licensees, streamline administrative processes, and ensure that NRC requirements remain effective, efficient, and responsive to credible risks.
The NRC prepared an unofficial redline strikeout version of the proposed changes to regulatory text that is intended to help the reader identify the changes. The unofficial redline strikeout version of the proposed rule is publicly available and is listed in the “Availability of Documents” section. Comments on the rule text should refer to this proposed rule and not the unofficial redline strikeout version.
IV. Discussion
The discussion is organized by subject area because of the wide-ranging set of issues covered by this proposed rule. The proposed rule also includes minor editorial corrections.
A. Fitness for Duty Programs (Part 26)
The proposed rule would incorporate effectiveness and efficiency improvements into the NRC's FFD program requirements for drug and alcohol testing and fatigue management since the NRC's extensive amendments of part 26 in 2008 (73 FR 17176; March 31, 2008). These proposed effectiveness and efficiency changes would reduce unnecessary regulatory burden on licensees and other entities and address section 5(g) of E.O. 14300. This proposed rule focuses on three areas: (1) incorporating lessons learned from implementing part 26 since 2008; (2) aligning part 26 with select updates made to the U.S. Department of Health and Human Services (HHS) Mandatory Guidelines for Federal Workplace Drug Testing Programs (HHS Guidelines) and the U.S. Department of Transportation (DOT) drug testing requirements in 49 CFR part 40, “Procedures for Transportation Workplace Drug and Alcohol Testing Programs”; and (3) addressing three PRMs.
1
1
The PRMs (PRM-26-4, PRM-26-7, and PRM-26-8) are discussed in this section and in Section IV.A.(i)(s), “SAE credential—State-licensed or -certified marriage and family therapists,” and Section IV.A.(i)(t), “SAE credential—Certified Addiction Specialist by the American Academy of Health Care Providers in Addictive Medicine,” of this document.
Proposed changes to the drug and alcohol testing program requirements include the following: expanding the option to collect and drug test oral fluid specimens for all conditions for testing in § 26.31(c); implementing a risk-informed reduction to the annual random testing rate in § 26.31(d)(2)(vii) that applies to most licensee employees (
i.e.,
those that do not perform critical safety- or security-related functions); extending the duration of applicability for the optional FFD program for reactor construction under subpart K to 10 CFR part 26, “FFD Program for Construction”; enabling licensees and other entities to escort construction workers performing activities under § 26.4(f), as an alternative to those workers being subject to an FFD program; enhancing the § 26.168 blind performance testing requirements to
reduce unnecessary burden; eliminating annual audits of HHS-certified laboratories performed by licensees and other entities; updating the FFD program refresher training interval; and removing unused regulations (specifically, subpart F, “Licensee Testing Facilities”). Proposed changes to the fatigue management program requirements include alternative requirements that licensees can meet during a sequestration event and the elimination of the requirement to annually report fatigue management information to the NRC.
From 2010 through 2012, the NRC also received three PRMs (docketed by the NRC as PRM-26-4, PRM-26-7, and PRM-26-8), which the NRC determined to be appropriate for consideration in the rulemaking process; all three of the PRMs are being considered as part of this rulemaking. To address PRM-26-4, “California Association of Marriage and Family Therapists” (75 FR 51958; August 24, 2010), the NRC is proposing to add State-licensed or State-certified marriage and family therapists to the list of acceptable credentials in § 26.187(b) that qualify individuals to serve as substance abuse experts (SAEs). The NRC also considered the issues identified for rulemaking in PRM-26-7, “Certification of Substance Abuse Experts” (76 FR 61625; October 5, 2011), related to Certified Addiction Specialists. The NRC is not proposing to add the petitioner's requested Certified Addiction Specialist that has been certified by the American Academy of Health Care Providers in the Addictive Disorders to the list of acceptable credentials to serve as an SAE under § 26.187(b), and accordingly would deny PRM-26-7.
Finally, the NRC considered the issues identified for rulemaking in PRM-26-8, “Additional Synthetic Drug Testing” (78 FR 22209; April 15, 2013). The NRC determined that the 2022 part 26 final rule (87 FR 71422; November 22, 2022), in part, addressed the issues raised in this petition by expanding the drug testing panel to include additional semi-synthetic opioids (hydrocodone, hydromorphone, oxycodone, oxymorphone), methylenedioxy-methamphetamine (MDMA), and methylenedioxyamphetamine (MDA). Under § 26.31(d)(1)(i), licensees and other entities also have the ability to consult with local law enforcement, hospitals, and drug counseling services to determine if other drugs with abuse potential are being used in the geographic locale of facilities, and to expand the drug testing panels to include any controlled substance that is listed on Schedules I through V of section 202 of the Controlled Substances Act. In addition, under § 26.77(b), a licensee or other entity must take immediate action to prevent any individual from performing covered duties if they appear impaired, which provides reasonable assurance that impairment from any cause (including the use of both scheduled and unscheduled substances) can be addressed. Accordingly, the NRC is not proposing changes related to PRM-26-8 and would deny this petition.
HHS and DOT have also updated their drug testing program requirements since the 2008 and 2022 amendments to part 26. On October 12, 2023, HHS published final revisions to the HHS Guidelines for the testing of drugs in urine and oral fluid specimens (88 FR 70768 and 88 FR 70814, respectively). DOT published two final rules amending its drug and alcohol testing programs in 49 CFR part 40. One updated DOT's urine drug testing requirements (82 FR 52229; November 13, 2017), and the other enabled oral fluid drug testing (88 FR 27596; May 2, 2023). The HHS Guidelines govern Federal employee workplace drug testing programs at more than 100 Federal agencies and Federal agency drug testing programs (
e.g.,
DOT) that test civilians in safety- and security-sensitive positions similar to personnel tested under the NRC's FFD program in part 26. The NRC has historically relied on the HHS Guidelines to establish the technical requirements for the collection and testing of specimens for drugs and the review of test results. The NRC also relies on the DOT's drug and alcohol testing regulations in 49 CFR part 40 in certain situations for which HHS does not have guidelines; for example, the HHS Guidelines do not cover testing for alcohol or evaluating and returning individuals to covered duties following a positive drug or alcohol test result. The DOT-regulated entities also test millions of individuals each year, which provides valuable lessons learned from implementing a testing program covering a much larger worker population than exists in the U.S. nuclear industry. This proposed rule would incorporate select updates to the HHS Guidelines and DOT drug testing requirements into part 26.
(i) Drug and Alcohol Testing
(a) Program Implementation Milestone
The proposed rule includes a risk-informed change that would extend the implementation milestone for when a licensee or other entity must transition from the optional subpart K to an FFD program that meets all of the requirements of part 26, except subparts K and M, “Fitness for Duty Programs for Facilities Licensed under 10 CFR part 53.” The milestone would change from the receipt of special nuclear material in the form of fuel assemblies to before initial fuel load into the reactor.
The NRC has reassessed the risks presented during the construction of nuclear power reactors and has determined that implementation of § 26.3(a) and (c) and § 26.4(e)(1) is not commensurate with current risk insights. Section 26.3(a) currently requires, in part, that licensees authorized to operate a nuclear power reactor under part 50 and holders of a combined license (COL) under part 52 after the Commission has made the finding under § 52.103(g) shall implement the FFD program under the requirements of part 26, except for subparts K and M, before the receipt of SNM in the form of fuel assemblies. Under § 26.3(c), licensees and other entities constructing a nuclear power plant must implement their FFD program no later than receipt of SNM in the form of fuel assemblies. The risk associated with unirradiated fuel, however, does not increase when the fuel arrives onsite, because its engineered safety features, storage, and configuration have not changed since the fuel was in transit. For transit and receipt onsite, the same physical protection requirements (
i.e.,
§ 73.67, “Licensee fixed site and in-transit requirements for the physical protection of special nuclear material of moderate and low strategic significance”) are applied to protect the fuel. Safety and security risks associated with unirradiated nuclear fuel begin to increase once the process of loading fuel into its operating configuration begins. The operational milestone “before initial fuel load into the reactor” therefore corresponds more closely to the start of NRC-licensed activities that could result in consequences adverse to public health and safety or the common defense and security than does the current milestone of receipt of nuclear fuel onsite. Further, this proposed milestone change is based on recent operating experience from implementing subpart K FFD programs at power reactor construction sites. Specifically, the NRC issued an exemption to the licensee for Vogtle Electric Generating Plant Units 3 and 4 to delay implementing FFD programs, except those that applied for construction, until initial fuel load (86 FR 73809; December 28, 2021).
(b) Specimen Testing Options
The proposed rule would expand the option to collect and drug test oral fluid specimens for all conditions of testing specified under § 26.31(c). This proposed change would provide an effective method to thwart attempts to subvert the drug testing process because all oral fluid specimens would be collected under direct observation. Each year, approximately 25 to 30 percent of the drug testing violations under part 26 are identified subversion attempts. In most cases, a donor attempts to provide a specimen that did not come from their body (
e.g.,
synthetic urine). This action is possible because a donor typically provides a urine specimen inside a privacy enclosure. However, oral fluid testing is conducted in a manner that is directly observable without the privacy enclosure associated with collecting a urine sample, and therefore precludes potential subversion attempts that can be visually identified.
Currently, under § 26.83(b), licensees and other entities have the option to collect and drug test an oral fluid specimen instead of a urine specimen only when a directly observed collection is required (
i.e.,
when information suggests a donor may be attempting to subvert a urine drug test). Expanding the collection and drug testing of oral fluid specimens has the potential to significantly improve the deterrent capabilities of the drug testing process, which would improve public health and safety and common defense and security. This proposed rule would also reduce the financial and administrative burdens associated with actions taken in response to subversion attempts that licensees and other entities would no longer encounter.
(c) Blind Performance Testing Submissions
Blind performance test samples (BPTSs) are formulated to verify the accuracy and reliability of each drug and validity test performed by the HHS-certified laboratory that a licensee or other entity uses to perform testing under contract. In each calendar quarter, BPTSs must be submitted to the laboratory for each drug or drug metabolite that must be tested in donor specimens and for each validity test performed to identify subversion attempts. A licensee or other entity must prepare BPTSs to appear as donor specimens to the laboratory, and BPTSs must be submitted along with donor specimens throughout the calendar quarter to evaluate laboratory performance.
Each year, operating experience demonstrates that the BPTS program identifies unsatisfactory performance at HHS-certified laboratories. Given the consolidated use of testing laboratories by industry, an identified performance issue at one laboratory generally impacts numerous licensee and other entity FFD programs. Identified performance issues, for example, have pertained to false negative test results because of laboratory certified scientists failing to adhere to laboratory testing procedures, weaknesses in laboratory standard operating procedures, improperly formulated reagents used in testing, and testing equipment maintenance issues.
The proposed rule would incorporate three effectiveness and efficiency improvements for blind performance testing programs based on industry practice and lessons learned. These improvements would reduce unnecessary regulatory burden for licensees and other entities.
1. Testing During Initial 90 Days
The proposed rule would eliminate the increased number of BPTSs that must be submitted in the initial 90 days of a licensee or other entity initiating a contract with a new HHS-certified laboratory. Under the existing requirements in § 26.168(a), in this initial 90-day period, a minimum of 30 BPTSs must be submitted for testing, whereas in each subsequent calendar quarter, a minimum of 10 BPTSs must be submitted for testing. The increased number of BPTS submissions in the initial 90 days of testing is unnecessary. The NRC has found that the post-initial 90-day period BPTS submission number of 10 BPTSs per calendar quarter is sufficient to identify unsatisfactory laboratory performance. The blind testing program already requires that, if unsatisfactory performance is identified (
e.g.,
false negative test result for a BPTS formulated to test positive for marijuana), a licensee or other entity must take immediate action to investigate and implement corrective actions under §§ 26.719(c) and 26.167(f). Eliminating the increased number of BPTSs in the initial 90 days of testing would also reduce an unnecessary financial and administrative burden on a licensee or other entity considering changing to another HHS-certified testing laboratory.
2. Fleetwide BPTS Submissions
The proposed rule would revise § 26.168(a) to clarify how a licensee or other entity is to determine how many BPTSs it must submit for testing in each calendar quarter, after the initial 90-day period, to the HHS-certified laboratory that it maintains under contract to perform testing. The current BPTS submission requirements require a minimum of 10 BPTSs to be submitted per quarter, or 1 percent of the donor specimens up to a maximum of 100 BPTSs, whichever is greater. Generally, § 26.168(a) has been applied at the facility level (
e.g.,
a location with one or more nuclear power reactors), whereby the minimum BPTS submission requirement almost always applies. However, § 26.168(a) could also be interpreted to apply at the fleet level. That is, a utility could calculate the number of BPTSs to submit to its HHS-certified laboratory based on the total number of donor specimens submitted for testing from all its facilities each quarter. This application would result in a reduction in the number of BPTS submissions per quarter compared to treating each of the utility's facilities independently under § 26.168(a). Either application would adequately maintain safety and security because the testing capabilities of the laboratory used by the licensee would be effectively challenged throughout each testing quarter. Current industry practice demonstrates that a small number of HHS-certified laboratories are used by a large number of part 26-regulated entities (regardless of whether the number of BPTS submittals is calculated at the facility or the fleet level), which ensures that the HHS-certified laboratories undergo adequate testing, focusing on those program elements unique to the NRC's FFD framework.
3. Quarterly Drug Testing Submissions
The NRC is proposing to eliminate the BPTS submission requirements in § 26.168(b)(1) and (2) that require a licensee or other entity to submit at least two BPTSs positive for marijuana in each quarter and to replace the BPTS positive for PCP with an additional BPTS positive for cocaine in at least two quarters per year. These prescriptive requirements are unnecessarily restrictive to effectively challenge testing performed at HHS-certified laboratories (
e.g.,
changing drug use trends may warrant a licensee to adjust which substances it submits to the laboratory, once it meets the minimum required in a quarter). The NRC is also proposing clarifications to § 26.168(d) for false negative challenge BPTSs and § 26.168(f) for negative BPTSs, which require a minimum of 10 percent of BPTSs submitted each quarter to be false negative challenge BPTSs and negative BPTSs, respectively. To conform with § 26.168(e) for validity testing BPTSs, the NRC is proposing to
include a statement in each requirement to clarify that either a minimum of one BPTS, or 10 percent of BPTSs submitted each quarter, whichever is greater, must be submitted per quarter.
(d) Escorting Construction Workers
The proposed rule would amend part 26 to permit licensees and other entities to escort construction workers performing activities covered under § 26.4(f) instead of requiring these workers to be subject to an FFD program. This proposed change is based on recent operating experience from implementing subpart K FFD programs at the Vogtle Electric Generating Plant Units 3 and 4. Specifically, the NRC issued an exemption to the Vogtle licensee to permit the escorting of construction workers (84 FR 27364; June 12, 2019). To permit escorting, the proposed rule would amend § 26.5, “Definitions,” to define the word “Escort”; § 26.4(e) to include a new requirement that individuals that serve as an escort must be subject to an FFD program that meets all part 26 requirements, except subparts I, “Managing Fatigue,” K, and M; § 26.4(f) to state that individuals who are escorted and constructing or directing the construction of safety- or security-related structures, systems, and components (SSCs) need not be subject to the licensee's FFD program; § 26.27(c)(5) and § 26.606(b)(7) to require the licensee or other entity to establish, implement, and maintain written procedures for escorting; and § 26.403(a) and (b) to require the licensee or other entity implementing a subpart K FFD program to establish, carry out, and maintain a procedure for escorts and those individuals under escort. These proposed changes would improve regulatory flexibility and potentially reduce costs by enabling licensees and other entities the opportunity to better plan and carry out construction activities with individuals who may be onsite for only short periods of time.
(e) Fitness for Duty Program Refresher Training
The proposed rule would revise § 26.29(c)(2) to change the FFD program refresher training interval from a nominal 12-month frequency to a nominal 24-month frequency. This proposed change would align with the refresher training interval that would apply to future part 53 licensees and other entities that implement § 26.608(b) of subpart M. The proposed rule would maintain the requirement in existing §§ 26.29(c)(2) and 26.608(b) for refresher training to be performed more frequently than the specified interval if the need is indicated, such as when an individual fails to properly implement FFD program procedures, or because of the severity of problems discovered through licensee-performed FFD program audits. This proposed change would reduce unnecessary regulatory burden by providing licensees and other entities with more flexibility on when to perform FFD program refresher training.
(f) Random Testing Rates for Licensee Employees
The proposed rule would revise § 26.31(d)(2)(vii) to reduce the annual random testing rate from 50 percent to 25 percent for most licensee employees (
i.e.,
those that do not perform critical safety- or security-related activities). This risk-informed proposed change is based on an assessment of approximately 35 years of FFD program performance data annually reported to the NRC by licensees and other entities.
The licensee employee workforce has consistently tested positive at much lower rates on pre-access and random drug and alcohol testing than the contractor/vendor workforce. The data show two to three times higher positive rates for contractor/vendors than licensee employees. In addition, FFD program performance data has consistently demonstrated that the licensee employee worker population has very low subversion rates.
The existing 50 percent annual random testing rate would continue to apply to the small subset of licensee employees that perform critical safety and security-related functions (
i.e.,
individuals licensed under 10 CFR part 55, “Operators' Licenses,” to operate a power reactor, security personnel under § 26.4(a)(5), FFD program personnel under § 26.4(g), and any supervisory personnel directing the operation or maintenance of safety- or security-related SSCs or directing the performance of security duties under § 26.4(a)(5)).
(g) Random Testing—Use of Consortium/Third-Party Administrators
The proposed rule would amend § 26.31(d)(2)(vii) to incorporate a requirement—similar to that described in § 26.607(b)(2)(vi) of subpart M of 10 CFR part 26—that applies to FFD programs with small staff sizes where random testing cannot be implemented without predictability. Small staff sizes can contribute to increased predictability in random testing, due to the possibility for staff to make inferences based on patterns in testing frequency that are more easily recognizable when there is a smaller pool of employees to choose from. For FFD programs with small staff sizes, the proposed rule—under a new § 26.31(d)(2)(vii)(C)—would require the use of a consortium/third-party administrator (C/TPA) to include the workers from multiple licensees or other entities in a combined random testing pool, from which the C/TPA would make testing selections throughout the year. Use of a C/TPA would significantly improve the effectiveness of the random testing programs of potential future licensee sites that may have small worker populations, and would ensure that individuals at these facilities would not be able to predict whether random testing would be conducted in a given period of time. As discussed in the 2026 part 53 final rule, C/TPAs have been used for many years by other Federally-regulated testing programs implemented by the U.S. Department of Transportation, such as those covering independent owner-operator truck drivers. This proposed aligning change would ensure that effective random testing programs can be implemented at future nuclear power reactor sites under parts 50 and 52 that may be operated by a small number of individuals.
The proposed rule would also include a conforming revision to § 26.607(b)(2)(vi) to ensure that a C/TPA-managed random testing pool for a facility licensed under part 53 meets the same annual random testing rate as that required under § 26.607(b)(2)(v). Without this correction, a C/TPA pool would not have a specified random testing rate.
(h) Licensee Audits of HHS-Certified Laboratories
The proposed rule would eliminate the § 26.41(c)(2) requirement for licensees and other entities to annually audit the HHS-certified laboratories maintained under contract to perform testing. These audits are redundant because HHS's National Laboratory Certification Program (NLCP) uses highly trained technical experts to independently inspect each HHS-certified laboratory twice per year. The NLCP inspection process evaluates the majority of laboratory services and functions provided to licensees and other entities under part 26, and the § 26.168 performance-based blind performance testing program (
i.e.,
quarterly submission of BPTSs and implementing of corrective actions under §§ 26.719(c) and 26.167(f)) effectively monitors and addresses unsatisfactory performance issues associated with unique testing program attributes specific to NRC programs. As
a result of eliminating the annual auditing requirement, the proposed rule would also make conforming changes to § 26.41(a), (c)(1), (g), and (g)(4) and would remove § 26.41(g)(5). These proposed rule changes would reduce unnecessary regulatory burden on licensees and other entities and the HHS-certified laboratories that perform testing for part 26 regulated entities.
(i) HHS-Certified Laboratory Contract Provisions for Subpart M FFD Programs
The proposed rule would revise § 26.607(c)(4), in subpart M of 10 CFR part 26, to align with the requirements of § 26.153(f) that apply to existing licensees and other entities implementing FFD programs under part 26. Paragraph § 26.607(c)(4) requires, in part, that each licensee or other entity establish and maintain a contract with the HHS-certified laboratory relied upon for testing, and that the contract must stipulate that the laboratory is subject to inspection and auditing by the licensee or other entity, and that the laboratory must provide access to records and permit copying and removal of records, if necessary. However, § 26.607(c)(4), as published in the 2026 final rule that created subpart M, did not include other important contractual requirements in § 26.153(f). The proposed rule would address these differences between the commensurate requirements by creating a new § 26.607(c)(5) that would replace the last sentence currently in § 26.607(c)(4).
Specifically, the proposed rule would add the requirements equivalent to those in the existing requirements of § 26.153(f)(1) through (6). These requirements specify that laboratories must comply with applicable provisions of any State licensor; make qualified personnel available to testify at any administrative or disciplinary proceedings against an individual based on a laboratory's test results; and provide a donor with access, upon written request, to all laboratory records associated with testing of the individual's specimen and any relevant records on laboratory certification, review, or revocation-of-certification proceedings. These requirements also include individual privacy requirements pertaining to laboratory records; conflict of interest provisions applicable to a licensee's or other entity's medical review officer (MRO); and the requirement that the NRC and any licensee or other entity using the laboratory's services must be permitted to inspect the laboratory at any time, including unannounced inspections.
Maintaining uniform contractual requirements for HHS-certified laboratories that perform testing for any licensee or other entity FFD program under part 26 would be necessary because the NRC does not regulate HHS-certified laboratories. As such, contractual requirements would ensure that the NRC and its licensees and other entities have adequate access to each laboratory facility, its personnel, and its records, as necessary to conduct quality assurance reviews. Contractual requirements would also ensure that conflicts of interest do not exist between the laboratory and MROs who may review the laboratory's test results for a licensee or other entity.
(j) Maintaining Back-Up HHS-Certified Laboratories Under Contract for Subpart M FFD Programs
The proposed rule would remove the § 26.607(c)(4) requirement that a licensee or other entity maintain a contract with a back-up HHS-certified laboratory for each biological specimen tested. While a contract with a primary laboratory performing testing on all donor specimens for a licensee or other entity is necessary, imposing a requirement that a back-up laboratory also be maintained under contract is unnecessarily restrictive, inconsistent with industry practice, and is not required for current licensees and other entities implementing an FFD program under part 26.
A back-up HHS-certified laboratory typically conducts testing for a licensee or other entity only when a donor is determined to have violated the FFD policy based on a confirmed positive drug test result or a substituted or adulterated validity test result, and the donor requests retesting at a second laboratory to independently verify the accuracy of the initial laboratory's test result. Many current licensees and other entities implementing FFD programs under part 26 do not maintain a contractual relationship with a particular back-up laboratory and instead provide a donor with a list of all HHS-certified laboratories in the United States to choose from with respect to conducting additional testing on their specimen.
Given the limited use of back-up laboratories by existing licensees, the § 26.607(c)(4) contractual requirement would impose an unnecessary additional burden on future part 53 licensees and other entities that implement subpart M FFD programs and is inconsistent with the current HHS-certified laboratory contractual requirements that apply to part 50 and 52 licensees and other entities. The proposed change would reduce unnecessary regulatory burden and afford donors maximum flexibility in choosing the HHS-certified laboratory to perform additional testing on their specimens, in instances where follow-up testing is requested after an FFD policy violation has been determined.
(k) Licensee Testing Facilities
The proposed rule would eliminate subpart F, “Licensee Testing Facilities.” Under subpart F, part 26 currently enables licensees to conduct initial drug and initial validity testing on urine specimens at a licensee testing facility (LTF), typically located at the power reactor site. Any specimen tested by an LTF that does not test negative or has a validity testing issue must be forwarded to an HHS-certified laboratory for additional testing.
Historically, LTF testing was the preferred option for many FFD programs because of the quick turnaround time on negative drug test results, which enabled the timely in-processing of workers during outages. Use of LTFs, however, has steadily declined over time as HHS-certified laboratories have greatly improved the turnaround times for reporting negative test results, and no licensee FFD programs currently use an LTF. Operating experience also demonstrates that future use of LTFs is unlikely given high operating costs, the increasing technical complexity of urine testing (
e.g.,
drugs tested, cutoff levels used, validity tests performed), and the fact that LTFs can only test urine specimens.
Eliminating the option for LTFs would improve regulatory effectiveness and efficiency by more closely aligning the part 26 drug testing program with the HHS and DOT testing programs, both of which require testing to be performed at HHS-certified laboratories. Eliminating subpart F would also simplify other part 26 requirements beyond subpart F, because numerous sections reference the use of an LTF or describe LTF-specific processes. Eliminating subpart F would also reduce the administrative burden on the NRC to maintain training programs and inspection procedures that accommodate LTF use.
On December 3, 2025 (90 FR 55621), the NRC published a direct final rule to insert a conditional sunset provision into § 26.121, “Purpose,” and certain other regulations in response to E.O. 14270, “Zero-Based Regulatory Budgeting to Unleash American Energy” (90 FR 15643; April 15, 2025). The conditional sunset provision in § 26.121 provides that subpart F of part 26 will cease to have effect on January 8, 2027, unless the NRC, after considering public input on the costs and benefits of the
subpart, determines that the cessation deadline should be extended. The NRC is using this proposed rule to accelerate the sunsetting of subpart F by proposing to remove subpart F and make other conforming changes.
(l) Event Notification for Supervisor FFD Policy Violations
The proposed rule would risk-inform the 24-hour reporting requirement in § 26.719(b)(2) to notify the NRC of significant violations of a licensee's or other entity's FFD policy by supervisory personnel. Specifically, the proposed rule would focus this notification requirement on supervisors who direct the operation or maintenance of safety- or security-related SSCs or who direct the performance of security duties as specified in § 26.4(a)(5).
The timely reporting of information to the NRC is necessary to enable prompt regulatory action, if needed. Operating experience demonstrates that 24-hour notification of FFD policy violations for supervisors directing work activity that is not safety- or security-significant is unnecessary. These violations would continue to be captured in the existing annual FFD program performance reporting requirements under §§ 26.717, “Fitness-for-duty program performance data,” and 26.417(b)(2), which ensure that the NRC receives uniform and robust information on all FFD program violations. This risk-informed change would reduce unnecessary burden on licensees, other entities, and the NRC.
(m) Behavioral Observation Program
The proposed rule would apply the same behavioral observation program (BOP) requirement to SAEs that already applies to MROs and MRO staff under § 26.31(b)(1)(v). The change would make SAEs subject to BOP when onsite at a licensee or other entity's facility, removing the current distinction between MROs and MRO staff, who are subject to BOP when onsite, and SAEs, who are currently subject to BOP both onsite and offsite when they are providing services to an FFD program. SAE and MRO functions are typically, although not always, performed by the same medical professional. Under the current requirements, if a medical professional is both an MRO and an SAE for the same FFD program, that professional is not subject to BOP when performing services for the licensee from an offsite location. However, if that same professional only provided SAE services to a licensee, they would be subject to BOP at whatever location they provided services to that licensee's FFD program. This BOP distinction between MROs and SAEs poses an unnecessary burden on licensees and other entities that choose to use medical professionals that only provide SAE services. SAEs also typically provide services to FFD programs from locations other than a licensee's or other entity's facility, communicating with individuals by telephone or by video teleconference methods. Therefore, this change would reduce unnecessary regulatory burden on licensees and other entities that rely on SAEs that do not also provide services as MROs.
(n) Shy-Bladder Evaluation
A shy-bladder evaluation is required under current § 26.119, “Determining `shy' bladder,” if a donor is unable to provide a urine specimen of adequate quantity for drug testing within the 3 hours permitted for a urine collection. A shy-bladder evaluation must be completed within 5 business days of the unsuccessful attempt and performed by a licensed physician that is acceptable to the MRO and has expertise in the medical issues raised by the donor's inability to provide a specimen for testing. The proposed rule would revise § 26.119(a) to extend the deadline to complete a shy-bladder evaluation from 5 business days to 10 business days if a justification acceptable to the MRO is provided by the donor.
The purpose of a timely evaluation is to determine if a medical condition precluded the donor from providing a urine specimen for testing (
e.g.,
end stage renal failure). If a medical condition is identified, then the MRO could request the collection of an alternative specimen for drug testing. If no medical condition is identified, then the donor is determined to have subverted the testing process by refusing to provide a urine specimen for testing. Under the current requirements, if a donor is unable to obtain a medical evaluation within 5 business days, the licensee would make a subversion attempt determination for a refusal to provide a specimen for testing and the individual would be permanently denied authorization under § 26.75, “Sanctions.” The proposed rule would reduce unnecessary regulatory burden by providing additional flexibility to accommodate for potential challenges a donor may encounter in obtaining an appointment and completing the required shy-bladder evaluation by an appropriately qualified physician within 5 business days from the date of failing to provide a specimen for testing. Based on industry operating experience, the NRC anticipates that licensees would only exercise this flexibility on rare occasions, when necessary to address extenuating circumstances.
(o) Initial Drug Test Requirements
The proposed rule would revise paragraph (1) of § 26.167(d), “Quality control requirements for performing initial drug tests,” in three ways. It would remove “of urine” from the phrase “any initial drug test of urine performed by an HHS-certified laboratory,” to clarify that the initial drug testing requirements apply to any specimen that is tested by an HHS-certified laboratory (
i.e.,
urine or oral fluid under § 26.83(b)). It would also remove the requirement that HHS-certified laboratories use an immunoassay “that meets the requirements of the Food and Drug Administration for commercial distribution.” Instead, § 26.167(d)(1) would specify that the initial drug test may be an immunoassay or an alternate technology that is permitted for use in Federal workplace drug testing programs to align with changes to Section 11.10 of the HHS Guidelines (82 FR 7920; January 23, 2017). The proposed rule would also remove the prohibition that “non-instrumented immunoassay testing devices that are pending HHS/SAMHSA [Substance Abuse and Mental Health Services Administration] review and approval may not be used for initial drug testing under this part.” This prohibition is unnecessary because the requirements in § 26.167(d)(1) are specific to testing performed at HHS-certified laboratories, which adhere to the testing requirements in the current version of the HHS Guidelines for the specimen(s) to be tested, unless otherwise directed under part 26. Reducing the prescriptive nature of the initial drug testing requirement would reduce unnecessary regulatory burden and ensure that licensees and other entities can benefit from the best testing approaches available at HHS-certified laboratories to identify drugs and drug metabolites. The proposed rule would also make conforming changes to § 26.405(f) in subpart K.
(p) MRO Qualifications
Under paragraph (a) of § 26.183, “Medical review officer,” an MRO must be a physician holding either a Doctor of Medicine or Doctor of Osteopathy degree who is licensed to practice medicine by any State or Territory of the United States, the District of Columbia, or the Commonwealth of Puerto Rico. The proposed rule would revise § 26.183(a) to clarify that “an equivalent foreign degree” also would be acceptable. This clarification would ensure that physicians who have received their medical degrees from
medical schools outside the United States could still be considered qualified to serve as an MRO under part 26. This change would reduce unnecessary regulatory burden on licensees and other entities by allowing them to consider additional qualified physicians who may be able to provide services as an MRO.
(q) Review of Dilute Specimen Test Results
The proposed rule would address inconsistencies in the requirements that apply to the review of dilute test results to clearly define the activities that must be performed by MROs and that may be performed by MRO staff.
As currently written in § 26.183(c), one of the responsibilities of the MRO is to review and interpret dilute test results, and § 26.185(g)(2) and (4) specify how the MRO is to conduct the reviews of those results. For MRO staff, § 26.183(d)(2)(ii) limits the review of dilute test results to performing administrative functions (
e.g.,
reviewing custody and control forms for errors). However, under § 26.183(d)(2)(i), MRO staff under the direction of the MRO are permitted to “receive, review, and report negative test results to the licensee's or other entity's designated representative.” As currently written, the MRO must review all dilute test results (both positive and negative), which is inconsistent with the MRO review requirements for dilute test results under § 26.185(g)(2) and (4). Specifically, § 26.185(g)(2) states that MRO review is required for “positive and dilute” specimen test results, and § 26.185(g)(4) states that MRO review is not required for “negative and dilute” specimen test results. A “negative and dilute” test result is not an FFD policy violation and is therefore acceptable for review by MRO staff under § 26.183(d)(2)(i).
The proposed rule would make changes to § 26.183(c) and (c)(1), § 26.183(d)(2)(ii) through (iv), and § 26.185(b) by replacing “dilute” with “positive and dilute.” The proposed rule would also make the conforming change of adding the term “positive and dilute” to § 26.405(g). These changes would reduce unnecessary regulatory burden by addressing internal inconsistencies in the part 26 requirements regarding the review of dilute positive and dilute negative validity test results.
(r) Clinical Evidence of Abuse Before Verifying Positive Results for Using Another Person's Prescription Medication
The proposed rule would enable licensees to more efficiently address the misuse of controlled substances by individuals by allowing licensees to more readily address instances wherein an individual illegally uses a prescription medication that has not been prescribed to them.
Currently, under § 26.185(j)(3), if the MRO determines that a donor has used another individual's prescription medication and no clinical evidence of drug abuse is found during the required clinical examination, the MRO must report that the donor misused a prescription. However, under the current framework, this is not considered a positive test result. The MRO is to report an FFD policy violation for a confirmed positive test result only when clinical evidence of abuse also exists.
Requiring the MRO to confirm a positive test result only if clinical evidence of drug abuse exists, even when the donor admits to using another individual's prescription medication and lacks a legitimate medical explanation, is inconsistent with the HHS Guidelines and DOT requirements. Specifically, under those programs, the MRO is to report a confirmed positive drug test result if a donor admits to unauthorized use of a drug or does not provide a legitimate medical explanation for the test result (
i.e.,
a valid prescription, as specified in Section 13.5 of the HHS Guidelines for urine and oral fluid testing and in DOT's requirements in 49 CFR 40.137).
The use of another person's prescription medication is prohibited by Federal law and is described in the HHS “Medical Review Officer Manual for Federal Workplace Drug Testing Programs (effective February 1, 2024).” Specifically, the MRO Manual states that—
Under no circumstances can prescriptions be legally transferred from a different individual to a donor in the event the donor exhausts his or her own prescription medication, even if the other individual's medication is identical and prescribed for the same medical condition (Controlled Substances Act Revised 2010, Pharmacist's Manual, Section VIII—Dispensing Requirements—Required Information for Prescription Labels). Federal Food and Drug Administration regulations [found in 21 CFR 290.5] require that the label of any drug listed as a “controlled substance” in Schedules II, III, or IV of the [Controlled Substances Act] must, when dispensed to or for a patient, contain the following warning: “CAUTION: Federal law prohibits the transfer of this drug to any person other than the patient for whom it was prescribed.”
The proposed rule would eliminate the requirement in § 26.185(j)(3) to determine that clinical signs of abuse exist to report a positive test result as an FFD policy violation when a donor admits to using another individual's prescription medication. This proposed rule change would align with other Federal agency testing policies, would improve public health and safety and common defense and security by allowing licensees to more efficiently address known trustworthiness and reliability concerns, and would remove unnecessary regulatory burden, as a positive test result could be reported by an MRO after a discussion with the donor (
i.e.,
without the need to perform a clinical evaluation).
(s) SAE Credential—State-Licensed or -Certified Marriage and Family Therapists
The proposed rule would add a State-licensed or -certified marriage and family therapist (MFT) to the list of credentials that would qualify individuals to serve as an SAE under § 26.187(b). This action would address the PRM docketed as PRM-26-4.
To be a State-licensed or -certified MFT requires a master's or doctoral degree, supervised clinical experience, and successful completion of the national examination conducted by the American Association for Marriage and Family Therapy Regulatory Board. Many programs accredited by the Commission on Accreditation of Marriage and Family Therapists have “substance abuse” knowledge as part of their core curriculum requirements in their graduate studies. Potential candidates can sit for the examination only after their credentials have been examined and found to meet the education and experience requirements for licensure or certification in their respective States. In 2006, the DOT added State-licensed or -certified MFTs to its list of credentialed professionals eligible to serve as substance abuse professionals under 49 CFR 40.281(a) (71 FR 49382; August 23, 2006).
Updating the § 26.187(b) SAE credential list to include State-licensed or -certified MFTs would be consistent with the approach taken by the NRC when it established the SAE requirements in the 2008 part 26 final rule. In the 2008 part 26 final rule, the NRC stated that it had adapted many of the SAE provisions from the DOT requirements regarding substance abuse professionals under 49 CFR part 40, subpart O.
This proposed change would reduce unnecessary regulatory burden by allowing licensees and other entities to consider additional qualified individuals who may be able to provide SAE services.
(t) SAE Credential—Certified Addiction Specialist by the American Academy of Health Care Providers in Addictive Medicine
The proposed rule would address a PRM (PRM-26-7) that requested that the “Certified Addiction Specialist” (CAS) certification from the American Academy of Health Care Providers in the Addictive Disorders (the Academy) be added to the list of acceptable credentials to serve as an SAE under § 26.187(b)(5). In a supplement to its petition to the NRC dated August 3, 2011 (ML11256A020), the Academy stated that it was in the process of preparing a petition to request that the DOT add the CAS certification to the substance abuse professional credentials in 49 CFR 40.281(a). As of the issuance of this proposed rule, however, the CAS credential does not appear on the DOT's approved credentials list in 49 CFR 40.281(a), and the NRC has not received any additional information to support the Academy's petition. Furthermore, the NRC evaluated publicly available information regarding the CAS credentialling process and determined that, while the training and education requirements are similar to those in place for credentials currently accepted in accordance with NRC requirements, the Academy did not provide adequate information on the examination process associated with the CAS credential. Based on this evaluation, the NRC determined that there is insufficient information available to support adding the CAS certification to the list of acceptable credentials. The proposed rule, therefore, would not incorporate the CAS certification into § 26.187(b)(5).
(u) Face-to-Face for-Cause Determinations of Fitness
The proposed rule would remove the prohibition on the use of electronic means to perform face-to-face for-cause determinations of fitness under § 26.189(c), because video technology has advanced significantly since the creation of the § 26.189(c) requirement in the 2008 part 26 final rule.
Video teleconference technology is already being used by some clinicians to complete other NRC-required evaluations, such as performing psychological assessments under the personnel access authorization requirements in § 73.56(e)(4) or determinations of fitness performed under § 26.189(b) when potentially disqualifying FFD information is discovered about individuals subject to part 26.
The proposed rule would specify that if video teleconference technology is used by a professional to conduct a face-to-face determination of fitness for a for-cause drug and alcohol testing determination under § 26.31(c)(2) or a fatigue assessment performed for cause under § 26.211(a)(1), then the determination must be supported by an individual that is in the room with the person being evaluated. A supporting person would be necessary in these circumstances to ensure that the professional performing the determination of fitness is provided with contemporaneous information that can only be obtained in the location where the person is being assessed (
e.g.,
sensory information such as the smell of alcohol on an individual's breath or an aspect of the individual's physical condition that is not ascertainable by video teleconference). The proposed rule would specify that the supporting person must have received training on the FFD program under § 26.29, which includes the “ability to observe and detect performance degradation, indications of impairment, or behavioral changes.” All individuals subject to a licensee's or other entity's FFD program must complete this training.
Eliminating the prohibition on the use of electronic communications to perform face-to-face determinations of fitness would reduce unnecessary regulatory burden and could improve the speed at which these determinations are made.
(v) Post-Event Testing Terminology
The proposed rule would make a conforming change to terminology used in § 26.405(c)(3) that applies to FFD programs implemented under subpart K of part 26. Specifically, the proposed rule would replace “post-accident” with “post-event” and “accident” with “event.” The term “post-event” is used in FFD program requirements under subpart M of part 26. The term “post-event” is also used in NRC Forms 890, “Single Positive Test Form,” and 891, “Annual Reporting Form for Drug and Alcohol Tests,” which licensees and other entities have used to submit FFD program performance data to the NRC under § 26.417(b)(2).
(w) Clarification of Subpart K FFD Program Applicability to Individuals Directing the Construction of Safety- or Security-Related SSCs
The proposed rule would clarify the provisions of § 26.419, “Suitability and fitness evaluations,” for individuals who direct the construction of safety- or security-related SSCs in subpart K FFD programs to ensure that licensees are able to assign duties to those individuals in accordance with FFD program requirements.
Section 26.4(f) requires that individuals constructing or directing the construction of safety- or security-related SSCs be subject to a subpart K FFD program (or an FFD program that meets all the requirements of part 26, except for subparts I, K, and M). Furthermore, in the 2008 part 26 final rule, the Commission stated that § 26.419 “requires licensees and other entities who implement FFD programs under subpart K to develop, implement, and maintain procedures for evaluating whether to assign individuals to the duties specified in § 26.4(f).” However, the rule text of § 26.419 only includes provisions for assigning duties to “individuals to construct safety- and security-related SSCs,” but does not currently include such provisions for the individuals directing those activities. As such, the NRC is proposing to include in § 26.419 individuals directing the construction of safety- or security-related SSCs to provide clarity and maintain consistency with § 26.4(f) and the intent of the 2008 part 26 final rule.
(x) Terminology Clarification for Construction FFD Programs
The proposed rule would make a conforming change to the terminology used in § 26.401(b), revising the term “entities” to “licensees and other entities.” This administrative revision would provide consistency in the use of the terminology across part 26, subpart K.
(ii) Fatigue Management
(a) Temporary Relief From Work Hour Controls
The NRC is proposing to add a new exception from the work hour controls in § 26.205(c) and (d) during sequestration events as an alternative to licensees needing to grant waivers. This new exception in § 26.207(e) would address sequestration events during which licensee personnel remain on-site at the facility due to unavoidable external conditions (
e.g.,
a severe weather event, public health emergency, or failure of local infrastructure) that could affect safe and secure plant operation. Part 26 currently contains exceptions for plant emergencies and other limited circumstances but does not account for conditions in which personnel may be required to remain on
site due to unavoidable external circumstances.
Under the proposed rule, during such events, licensees would be able to implement alternative fatigue management controls for up to 60 days, consistent with those authorized by the NRC during the COVID-19 public health emergency (
e.g.,
NRC Letter, “Quad Cities Nuclear Power Station, Units 1 and 2—Exemption from Select Requirements of 10 CFR part 26 (EPID L-2020-LLE-0018 [COVID-19]),” dated April 8, 2020). If a licensee were to use this exception and need to extend the alternative controls beyond 60 days, the licensee would need to submit an exemption request. The addition of the sequestration exception would provide a less burdensome alternative to waivers or exemption requests during sequestration events.
(b) Annual Fatigue Reporting
The NRC is proposing to eliminate the requirement in § 26.203(e) and § 26.717(b)(9) for licensees to provide annual reports of waivers and fatigue management program information to the NRC. In addition, the NRC is also proposing to eliminate the same requirement for subpart M FFD programs in § 26.202(e). Annually, the FFD performance reports have included limited instances when waivers to the work hour controls were issued, with the trends decreasing in the years since the requirements were first implemented in 2009, demonstrating the successful implementation of the work hour controls to mitigate fatigue. While no longer submitted in an annual report, the associated records would continue to be maintained by licensees in accordance with § 26.203(d) and would be available for NRC inspection or review as needed. The elimination of the reports would reduce burden on licensees and would also save NRC resources associated with the receipt and maintenance of these records.
(c) Expanding the Applicability of Remote Assessments
The NRC is proposing changes to §§ 26.207(a)(1)(ii) and 26.211(b) to allow additional licensees to use electronic communications to perform face-to-face assessments to support the approval of work hour control waivers and to conduct fatigue assessments. Under the current provisions, only licensees and other entities under 10 CFR part 53, as specified in § 26.3(f), can use electronic communications for these purposes. The proposed changes would expand the option of using electronic communications to other types of NRC licensees specified in § 26.3(a), (c), and (d). The provisions would continue to indicate that supervisors may conduct such assessments from a remote location under appropriate circumstances, and that such remotely conducted assessments need to be supported by someone who is present in-person with the individual being assessed and who is trained in accordance with the requirements of either §§ 26.29 and 26.203(c), or §§ 26.608 and 26.202(c).
The reasoning for these changes and the associated need for in-person support to augment electronic communications is addressed further in the discussion of the proposed changes to § 26.189(c) in Section IV.A.(i)(u) of this document.
(iii) Changes to Definitions in Part 26
The proposed rule would add two new definitions, revise five definitions, and remove four definitions in § 26.5. The additions, revisions, and removals would improve the clarity, consistency, and accuracy of the requirements under part 26. Specifically, this proposed rule would add definitions for “Escort” and “Sequestration event.” In conjunction with another proposed rule change to remove subpart F, “Licensee Testing Facilities,” this proposed rule would revise definitions for “Analytical run,” “Cancelled test,” “Cutoff level,” “Positive result,” and “Rejected for testing”; and remove definitions for “Licensee testing facility,” “Questionable validity,” “Validity screening test,” and “Validity screening test lot.”
A definition for “Escort” would be added, defining the term to mean a person who is designated by the licensee or other entity to be responsible for directly observing an individual who has been assigned to perform duties and responsibilities or maintain the type of access described in § 26.4(f) but is not subject to the requirements in part 26.
A definition for “Sequestration event” would be added, defining the term to mean a situation in which personnel remain on-site at a nuclear power reactor due to unavoidable external conditions that pose a risk to the safe, secure, and continuous operation of the facility.
B. Security Requirements for Independent Spent Fuel Storage Installations (ISFSIs) (Parts 72 and 73)
An ISFSI is a complex designed for the safe storage of power reactor spent nuclear fuel and certain other radioactive materials. These installations use robust storage systems, such as dry casks, that securely contain and shield the radioactive material until it can be disposed of in the future, allowing licensees to store this material safely on site or at standalone storage locations. The security risk profile of an ISFSI is reduced from that of an operating nuclear power reactor due to the absence of a fueled reactor and the placement of all spent fuel into these robust storage systems. This configuration eliminates reactor-related target sets and significantly lowers the potential consequences of radiological sabotage.
There are two main types of ISFSIs regulated by the NRC: general license ISFSIs and specific license ISFSIs. A general license ISFSI is operated by a nuclear power plant licensee under a general license provided in NRC regulations. Section 72.210, “General license issued,” states that a general license for an ISFSI is issued to persons authorized to possess or operate nuclear power reactors under 10 CFR part 50, part 52, or part 53. A nuclear power plant licensee does not need to apply for a separate, stand-alone license for the ISFSI. In contrast, a specific license ISFSI is authorized through a separate, detailed licensing process that is independent from the nuclear power reactor license. Although both types of ISFSIs must meet NRC safety and security standards, there are differences in the licensing approach and in some of the security requirements that currently apply to each type.
The proposed requirements for ISFSI security would enhance consistency and regulatory clarity between general and specific license ISFSIs. Licensees operating general license ISFSIs that are not collocated with an operating reactor would have the option to provide physical protection under the same requirements that apply to specific license ISFSIs. These changes would provide consistency for similarly situated ISFSIs, while reducing the burden of submitting exemption and alternative measure requests.
Additionally, this proposed rule would extend the time associated with submitting ISFSI security plan changes to the NRC. The frequency required for the submission of security plan changes would be modified to reduce the licensee burden that is associated with security plan revisions.
(i) Security Requirements for ISFSIs Located Outside a Reactor's Protected Area
The proposed rule would include changes addressing security requirements for ISFSIs located either outside the protected area (PA) of an operating reactor or within the PA of a decommissioning reactor for which all
spent fuel at the site has been placed in dry storage.
Some ISFSIs are located within the same PA as an operating reactor. Other ISFSIs are located in a separate PA because either the reactor with which an ISFSI was originally collocated has gone into decommissioning or the ISFSI was constructed with a separate PA. The proposed changes to parts 72 and 73 of the NRC's regulations would allow licensees with ISFSIs in this latter category the option to implement security requirements that are designed specifically for ISFSIs. With regards to ISFSIs adjacent to decommissioning reactors, the proposed changes are consistent with those in SECY-24-0011, “Final Rule: Regulatory Improvements for Production and Utilization Facilities Transitioning to Decommissioning,” dated January 31, 2024, which is currently being considered by the Commission.
This proposed rule would revise § 72.212(b)(9) to allow general license ISFSIs the option to develop and implement their physical protection programs in accordance with § 73.51, “Requirements for the physical protection of stored spent nuclear fuel and high-level radioactive waste,” instead of § 73.55, “Requirements for physical protection of licensed activities in nuclear power reactors against radiological sabotage.” This change would align the physical protection requirements of general license ISFSIs and specific license ISFSIs for separate protected areas constructed outside the PA of an existing operating reactor, or during decommissioning, once all spent fuel at the site has been placed in dry storage. This change would be appropriate because the security requirements in § 73.51 are designed for and provide security appropriate to the reduced risk level of ISFSIs as compared to nuclear power plants, which are subject to § 73.55. This change would reduce the regulatory burden on current and future licensees by offering the increased flexibility provided under § 73.51. In particular, licensees that choose to transition to § 73.51 would no longer be required to implement protection measures against the design basis threat nor comply with the associated requirements outlined in § 73.55.
The proposed rule also includes conforming changes to §§ 72.13, “Applicability,” and 73.51 to clarify the applicability of the security requirements that are found in part 72, subpart H, “Physical Protection,” to general license ISFSIs. Currently, these licensees need to submit alternative measures or exemption requests from certain § 73.55 requirements to allow for the implementation of security requirements that are consistent with the risk profile for their facilities. The proposed change would eliminate the need to submit alternative measures or exemption requests. Licensees that elect to implement the new proposed regulatory requirements would provide a revised security plan through the process described in paragraph (p)(2) of § 50.54, “Conditions of licenses.”
ISFSIs that are within an operating reactor PA would still be required to implement § 73.55, consistent with the physical protection program for the reactor, with the specific exceptions in § 72.212(b)(9). Additionally, licensee physical protection programs would be required to continue to address the terms of any applicable security-related orders associated with either a general or specific license ISFSI.
(ii) Submittal of Security Plan Changes
The proposed rule would extend the time associated with the requirement to submit ISFSI security plan changes to the NRC under paragraph (e) of § 72.44, “License conditions,” and paragraph (b) of § 72.186, “Change to physical security and safeguards contingency plans.” Instead of submitting to the Commission a report containing a description of each change within two months after the change is made, licensees would have to submit the report within 12 months after the change is made. This revision would reduce the licensee burden that is associated with security plan revisions. The extension would also maintain safety and security because it would be limited to reports of changes that would not decrease the effectiveness of the plans.
C. Physical Security Requirements (Part 73)
Under this proposed rule, the security regulations for the physical protection of plants and materials under 10 CFR part 73, along with their associated guidance documents, would be revised to reduce unnecessary burdens and respond to credible risks—as directed in E.O. 14300, section 5(g)—to support efficiencies in licensing and oversight. Where possible, prescriptive requirements would be replaced with more performance-based requirements to streamline, clarify, and modernize the current regulations, thus increasing flexibility for current and future licensees and facilitating the increased deployment of new civilian nuclear reactor technologies, consistent with section 2(b) of E.O. 14300.
This proposal covers updates across various elements of part 73, including physical protection, security training, access authorization, and cybersecurity for power reactors; transmittal of safeguards information (SGI); special nuclear material security; records; and definitions. This proposal also incorporates changes to part 73 intended to address industry concerns from the 2023 Enhanced Weapons final rule, the consideration of law enforcement support to licensee security programs, and certain aspects of the draft final decommissioning rule in SECY-24-0011.
(i) Power Reactor Physical Protection Program
The proposed changes to § 73.55, as well as appendices B, “General Criteria for Security Personnel,” and C, “Licensee Safeguards Contingency Plans,” to part 73, would support the agency's mission to enable the safe and secure use and deployment of civilian nuclear energy technologies and would reduce unnecessary burden on current and future licensees.
This proposed rule would provide licensees with increased flexibility in implementing their physical protection programs by incorporating performance-based requirements and, where appropriate, allowing for specific alternatives. The proposed alternatives would most likely be available to non-light water reactor designs that incorporate security by design and engineered safety or security features.
For the existing light-water reactor fleet, the proposed revision of the security requirements would eliminate certain prescriptive requirements that are more appropriately addressed in regulatory guidance and in some instances are no longer necessary for the implementation of the physical protection program.
This proposed rule would establish a revised performance objective that applies a risk-informed approach that would continue to provide reasonable assurance that activities involving special nuclear material are not inimical to the common defense and security, and do not pose an unreasonable risk to public health and safety.
Existing licensees that are in compliance with § 73.55 as of the effective date of publication of the final rule, if this proposed change is made effective in a final rule, would also be in compliance with the proposed revisions to the regulations and would not be required to modify their current physical protection programs. However, existing licensees would be able to voluntarily adopt the proposed
alternative methods of compliance and take advantage of the increased flexibility in implementing the requirements of § 73.55.
This proposal builds on previous efforts to risk-inform physical security regulations by shifting from prescriptive to performance-based requirements to allow for the use of technology-neutral alternatives (
e.g.,
security and safety features) in the implementation of § 73.55. The core performance-based criteria for implementing licensees' physical protection programs would remain unchanged because these programs would continue to be required to detect, assess, interdict, and neutralize threats.
The proposed amendments would revise § 73.55 and appendices B and C to 10 CFR part 73 to enhance requirements for physical protection, power reactor security training, and contingency response. Specifically, the proposed revisions should provide increased flexibility in the implementation of security, training, and response measures. This would be accomplished by modifying the performance objective, the use of performance-based requirements, and the use of voluntary alternatives that allow for the use of technology and engineered design features.
The proposed requirements would adopt technology-inclusive approaches to provide the necessary regulatory flexibility for licensing and regulating multiple categories of nuclear reactor technologies and designs. A technology-inclusive approach to security requirements would provide greater flexibility in both the design and implementation of physical protection programs. Licensees and applicants using this approach could integrate security considerations into the safety design process, enabling the effective implementation of security measures through the use of both design-based and engineered security features. This approach could enable safety and security functions to work collaboratively in the implementation of the physical protection program. Additionally, the proposed technology-inclusive approach would allow for the increased use of technology by licensees to implement security measures for the protection of a facility, providing greater operational flexibility.
(a) High Assurance
The general performance objectives throughout part 73 would be revised to reflect the Commission's decision on the concept of “high assurance” as it relates to licensee physical protection programs. In SRM-SECY-16-0073, “Staff Requirements—SECY-16-0073—Options and Recommendations for the Force-on-Force Inspection Program in Response to SRM-SECY-14-0088,” dated October 5, 2016, the Commission determined that the concept of “high assurance” in security regulations is functionally equivalent to “reasonable assurance” used in safety contexts and that security regulations should not be applied using a “zero risk” mentality. Therefore, the proposed rule would revise the regulations in §§ 73.20(a), 73.22(f)(3), 73.51(b)(1), 73.54(a), 73.55(b)(1), and 73.56(c) to use the term “reasonable assurance” in place of “high assurance.”
(b) Significant Core Damage and Spent Fuel Sabotage
The performance objective in § 73.55(b)(3) would be revised from specifically protecting against significant core damage and spent fuel sabotage to a broader goal of preventing a release of radionuclides from any source that exceeds the dose reference values defined in § 50.34(a)(1)(ii)(D)(
1
) and (
2
), § 52.79(a)(1)(vi)(A) and (B), or § 53.210, as applicable. This shift would emphasize radiological sabotage in general, rather than focusing solely on core damage or spent fuel scenarios. The existing fleet of light-water reactors would be in compliance with this proposed performance objective by continuing to prevent significant core damage and spent fuel sabotage. The revised objective would be technology-inclusive, providing flexibility to accommodate multiple categories of nuclear reactor technologies and designs, including those that may not have conventional cores.
(c) Achievable Target Sets
This proposed rule would introduce a revised set of requirements in § 73.55(f), “Target sets,” that adopts a risk-informed, technology-inclusive, and graded approach through the identification of achievable target sets. Licensees that voluntarily elect to implement the revised performance objective would need to perform an analysis to identify the necessary plant equipment, operator actions, mitigative measures, detection capabilities, assessment processes, and armed response needed to identify the achievable target sets for the site's physical protection program, which must be designed to prevent a radionuclide release from exceeding the dose reference values specified in § 50.34(a)(1)(ii)(D)(
1
) and (
2
), § 52.79(a)(1)(vi)(A) and (B), or § 53.210, as applicable, to protect against the design basis threat of radiological sabotage as stated in § 73.1.
Achievable target sets would be identified through a site-specific analysis. Achievable target sets would include those that are within the capabilities of the design basis threat adversary to compromise, destroy, or render non-functional; cannot be mitigated after adversary interference is precluded and prior to a release of radionuclides exceeding the dose reference values defined in in § 50.34(a)(1)(ii)(D)(
1
) and (
2
), § 52.79(a)(1)(vi)(A) and (B), or § 53.210, as applicable; and, if defeated, result irreversibly in exceedance of the dose reference values defined in in § 50.34(a)(1)(ii)(D)(
1
) and (
2
), § 52.79(a)(1)(vi)(A) and (B), or § 53.210, as applicable.
Under this framework, licensees would determine the applicability of § 73.55 as follows:
• If a licensee could demonstrate that no achievable target sets exist, and would not credit any active measures (
e.g.,
operator action, mitigative action, detection, assessment, armed response), then the licensee would be exempt from the remaining requirements of § 73.55. The requirements of 10 CFR part 26; 10 CFR part 37, “Physical Protection of Category 1 and Category 2 Quantities of Radioactive Material”; and §§ 73.21, “Protection of Safeguards Information: Performance requirements,” 73.22, “Protection of Safeguards Information: Specific requirements,” 73.23, “Protection of Safeguards Information—Modified Handling: Specific requirements,” 73.54, “Protection of digital computer and communication systems and networks,” 73.56, “Personnel access authorization requirements for nuclear power plants,” and 73.67 would need to be implemented as applicable.
• If a licensee could demonstrate that no achievable target sets exist, and would credit active measures in making that demonstration, then the licensee would be required to implement the applicable requirements of § 73.55 through its physical security plan, training and qualification plan, safeguards contingency plan, and cybersecurity plan. Licensees that would rely on active measures could limit the scope of their physical protection program by ensuring that the credited active measures will be implemented when needed in response to threats.
• If a licensee could demonstrate that achievable target sets exist, then the licensee would be required to implement the requirements of § 73.55 through its physical security plan,
training and qualification plan, safeguards contingency plan, and cybersecurity plan.
(d) Prescriptive Requirements Revised to Performance-Based Requirements
The current physical security requirements use a combination of performance criteria (
e.g.,
protection against the design basis threat for radiological sabotage as stated in § 73.1) and numerous prescriptive requirements to implement a physical protection program to achieve the current performance objective. In this performance-based proposed rule, physical security would be implemented through performance criteria to meet the general performance objective, thus giving the licensee flexibility to determine how to meet the established performance criteria for an effective physical protection program. The proposed rule would remove a number of prescriptive requirements while preserving the effectiveness of the physical protection program framework. Power reactor physical protection programs would continue to address each of the programmatic functions of the overall physical protection program (
e.g.,
detection and assessment, delay barriers, armed response, etc.) to meet the performance objectives of 10 CFR 73.55 to protect against the design basis threat of radiological sabotage. For new applicants, the NRC would evaluate the measures an applicant proposes to use to meet the performance criteria and the general performance objective through the NRC's review and approval of the physical security plan. For existing licensees who make changes to their physical protection programs based on the revised performance criteria, the NRC would verify the adequacy of the licensee's measures through inspection.
1. Physical Barriers
Prescriptive physical barrier requirements in current § 73.55(e) would be revised to remove the details concerning the specific considerations and criteria for each barrier, including isolation zones. Isolation zones have been removed from the requirements to provide greater flexibility for licensee programs implementing detection measures. In certain conditions, these clear areas are not necessary to meet detection and assessment requirements due to site-specific configurations. Additionally, advancements in detection and assessment technologies have significantly reduced, or eliminated, the need for clear areas to identify unauthorized access into protected areas. The proposed rule would continue to require licensees to detect attempted or actual penetrations using detection and assessment equipment capable of meeting the performance objectives outlined in 10 CFR 73.55(b).
These specifics would be retained in guidance as voluntary considerations for licensee physical protection programs. Licensees would still be required by proposed § 73.55(e)(1) to ensure that physical barriers are sufficient to meet the performance criteria (
e.g.,
detect, delay, and deter) and performance objective for their intended function.
2. Access Control Measures
Access control measures in current § 73.55(g) would be revised to remove the prescriptive requirements regarding access to different areas of a facility. These specifics would be retained in guidance as voluntary considerations for licensee physical protection programs. Licensees would still be required by proposed § 73.55(g)(1) to ensure that their access control measures meet the performance criteria (
e.g.,
restricts unauthorized access and implements verification measures) and performance objective.
3. Search
The specific methods for how vehicles, materials, and personnel are searched in current § 73.55(h) would be revised with performance criteria applicable to searches conducted in various areas (
e.g.,
owner controlled and protected areas) of licensee facilities. Under proposed § 73.55(h), licensees would have the flexibility to determine the search method(s) used to meet the performance criteria for conducting searches.
4. Detection and Assessment
Prescriptive detection and assessment requirements in current § 73.55(i) would be revised to allow licensees the flexibility to use technology for surveillance and illumination to meet the performance criteria to detect and assess at all times. Advanced technology systems provide flexible capabilities to licensees offering superior detection range, accuracy, and reliability compared to human observation under 0.2 foot-candle illumination. Replacing a prescriptive lighting level with a technology-based detection strategy aligns with the performance-based approach. Because modern technologies provide detection and assessment capabilities that meet or exceed those enabled by the historical lighting and surveillance requirements, the overall security posture would continue to satisfy the standard of reasonable assurance of adequate protection against radiological sabotage. This proposed change would support the effective implementation of the licensee's protective strategy by allowing site-specific applications that align with the licensee's facility layout and operational needs.
5. Response Requirements
Current requirements in § 73.55(k) identify the minimum number of ten armed responders to implement a site's protective strategy to meet the performance objective to protect against the design basis threat of radiological sabotage. The proposed rule would remove this prescriptive number, allowing licensees flexibility to determine the minimum number of armed responders necessary to implement the site protective strategy and respond to the design basis threat of radiological sabotage. The proposed requirements would continue to allow licensees to use armed responders and armed security officers to form an armed response team to meet response requirements. The proposed rule would add an alternative in § 73.55(k)(5) for current and future licensees that voluntarily elect to rely partially or solely on law enforcement or other offsite armed response personnel to meet the response requirements for their facilities. Licensees that rely solely on law enforcement or offsite armed responders would be required to obtain prior Commission approval before using these entities to meet the site response requirements.
6. Safety/Security Interface
The NRC proposes to remove § 73.58, “Safety/security interface requirements for nuclear power reactors,” from part 73 to streamline requirements and to eliminate rule text that provides a level of detail more appropriate for guidance. A performance-based requirement for safety/security interface would be added to § 73.55(l)(1). The proposed safety/security interface requirement would require licensees to evaluate and manage changes to safety and security activities to prevent or mitigate potential adverse effects that could impact plant safety or security at power reactors.
The current requirements in § 73.55(l) regarding physical protection for reactor facilities using mixed-oxide (MOX) fuel would be removed. These provisions have never been applied to any applicant or licensee.
7. Security Program Reviews
The prescriptive requirements for conducting a security program review at a periodicity of every 24 months in
current § 73.55(m) would be revised to allow a licensee to conduct risk-based security reviews that are commensurate with the importance or significance to the safety of plant operations.
(e) Flexibility in Implementing an Acceptable Physical Protection Program
The proposed rule would revise § 73.55 to be more technology-inclusive. Designed-in features, structures, systems, and components, as well as engineered and administrative controls, could be used to provide flexibility in implementing an acceptable physical protection program for different reactor designs.
(f) Alternatives
In several areas of the proposed requirements, licensees would be provided with voluntary alternatives to existing regulations to achieve the required performance objectives. These alternatives would be technology neutral (
i.e.,
to address various approaches to plant SSCs, designs, and technology). The voluntary alternatives might not be suitable for a licensee to implement in all cases; therefore, in determining the use of the voluntary alternatives, licensees would be required to complete a site-specific analysis to determine if their plant design and physical protection program would meet the applicable proposed requirements and the overall performance objective of reasonable assurance of adequate protection against threats up to and including the design basis threat of radiological sabotage. The NRC has provided draft regulatory guidance that describes some acceptable methods to meet the proposed alternatives. Voluntary alternatives have been proposed for the security organization, bullet resistant barriers, Performance Evaluation Program, physical barriers, and response requirements. In addition to the alternatives specifically provided for in the regulations, licensees would be able to continue to propose alternative measures under the provisions of § 73.55(r), “Alternative measures.”
Licensees that retain their current physical protection program would be able to elect to change their security plans and implementing procedures to reference the new proposed regulatory requirements through the § 50.54(p) process.
(g) Appendix B to Part 73
The NRC proposes to revise the general criteria for security personnel in 10 CFR part 73, appendix B, to address the minimum age for employment, for the use of a qualified training instructor for the attestation of training documentation, and to provide flexibility for the use of a nationally recognized course of fire for all weapons identified in this appendix. For the security training that is outlined in appendix B, sections I through VI, the majority of prescriptive requirements would be removed. The requirements for suitability would be streamlined for all security personnel that are identified in appendix B to part 73. Also, the NRC proposes changes to the training for power reactor licensees in the implementation of licensee Performance Evaluation Programs. The proposed rule would reduce the required frequency of tactical response drills from four per year to two per year. In addition, the requirement for each member of each shift to participate in one force-on-force exercise annually would be modified to once every three years. The proposed modifications to the performance evaluation program reflect that licensees have mature, established training programs that have consistently demonstrated that licensee security forces maintain the knowledge, skills, and abilities for effective contingency response. Tactical response drills would continue to be based on target set scenarios and would provide a practical demonstration of defense against specific design basis threat attributes. The proposed adjustment to the frequency of participation in the licensee's full-scale force-on-force exercises recognizes that full-scale exercises are the most resource intensive to conduct. While valuable, this activity is only one component of a comprehensive performance evaluation program. This proposed change recognizes that the broader performance evaluation program is sufficiently robust without relying on annual force-on-force participation. On an annual basis, licensees would conduct at least one fully integrated force-on-force exercise to test the protective strategy as a whole. The licensee's performance evaluation program would continue to ensure that any degradation in security force member performance and potential protective strategy deficiencies would be identified and corrected through the corrective action program. Additionally, several prescriptive training requirements would be removed from appendix B to part 73 (
e.g.,
range activities periodicity, written exams, required courses of fire, and on-the-job training hours). Removing these prescriptive elements would not eliminate these training areas from the licensee's training and qualification program, rather it would provide licensees with increased flexibility to design and implement training that more directly supports their operational needs. In place of the prescribed range activity periodicity and courses of fire, the regulations would require licensees to ensure security officers have the appropriate types of weapons training at frequencies that ensure the proper handling of firearms with the accuracy that is necessary to implement the use of assigned weapons. This approach allows for flexibility in scheduling and allows the licensee to use performance data to determine the appropriate type of training and intervals, thus reducing administrative burden and providing for more efficient allocation of resources. With regard to written exams, such exams are only one method of evaluating security force knowledge. The proposed removal of required written exams would allow licensees the option to use other types of knowledge-based activities or performance-based evaluations to evaluate the knowledge, skills, and abilities of members of the security organization. These changes are being proposed to decrease the burden in implementation of licensee security training programs and allow for increased flexibility, while maintaining safety and security. The requirements that were retained or modified would continue to capture the programmatic areas that licensees must implement to provide the appropriate training for security personnel. Training methods that were previously described in requirements would generally be retained in guidance as one acceptable method of meeting the requirements. Licensees would be required to ensure that the personnel who implement the physical protection program have the appropriate knowledge, skills, and abilities to effectively perform their assigned duties and responsibilities to accomplish the performance objective of protecting public health and safety.
The removal of the prescriptive security equipment lists from appendix B to part 73 would allow licensees to select equipment that best meets their operational needs and integrate new technologies as appropriate. The removal would reduce the need for exemptions or license amendments.
The proposed rule would remove the prescriptive requirements for 40 hours of on-the-job training, and would instead use a performance-based approach that allows a licensee to determine the appropriate number of on-the-job training hours. Modern training methodologies, job-specific competencies, and improved
instructional systems design processes enable licensees to tailor training more precisely to the knowledge, skills, and abilities needed for each role. Allowing flexibility in determining the number of on-the-job training hours gives licensees the ability to align training with actual task complexity, prior experience, and demonstrated proficiency, rather than relying on a uniform time-based metric. The regulations would continue to require that on-the-job training is documented and attested by a qualified training instructor or a security supervisor. The licensee would verify that the implemented training approach provides personnel with the capability to effectively execute their responsibilities under the safeguards contingency plan
(h) Appendix C to Part 73
The changes proposed in appendix C to part 73 would remove the prescriptive periodicity associated with the review of safeguards contingency plans to provide licensee flexibility in these types of reviews.
(i) Expand Regulatory Flexibility
The proposed rule would expand the regulatory options for physical security for new applicants under parts 50 and 52. Specifically, applicants would be able to select the most appropriate physical security rule for their design and approach for licensing by complying with either § 73.55 or § 73.100, “Technology-inclusive requirements for physical protection of licensed activities at advanced nuclear plants against radiological sabotage,” which was developed for reactors licensed under part 53. The distinctions between § 73.55 and § 73.100 largely reflect the fact that the existing reactor fleet was built without accounting for security during the initial design phase. The proposed revisions to § 73.55 in this rule would address the current configuration of the operating fleet and, similar to § 73.100, provide increased flexibility to accommodate the wide range of current and future reactor technologies. Currently, applicants under part 53 have the option of complying with either § 73.55 or § 73.100 for physical security. Extending this flexibility to applicants under parts 50 and 52 would ensure that future applicants have appropriate physical security options for licensing when designing their physical protection programs under part 50, 52, or 53. This proposal would include revisions to §§ 50.34, 52.79, and 73.100 to reflect this expanded regulatory flexibility for future applicants.
(ii) Access Authorization
The NRC is proposing revisions to its access authorization requirements under §§ 73.55 and 73.56 to promote program efficiency by providing appropriate flexibilities to licensees and reducing unnecessary program burdens, while maintaining safety and security. The proposed revisions would also provide additional relief from requirements for those licensees and applicants who demonstrate that no achievable target sets exist in accordance with proposed § 73.55(f).
(a) Changes to the Milestone for Program Implementation
The proposed rule includes a risk-informed change that would extend the implementation milestone for when a licensee or other entity must transition from its construction-phase security measures (employed through appropriate site procedures for the control of personnel, access controls, and pre-employment screening during the construction phase) to an operational access authorization program that meets all of the applicable requirements of § 73.56.
Under the existing regulations, § 73.56(a)(3) requires licensees to implement the requirements of § 73.56 before fuel is allowed onsite (in the protected area). The proposed rule would change the milestone for implementation of an access authorization program from before fuel is allowed onsite (
i.e.,
into the protected area) to before initial fuel load into the reactor.
This proposed milestone change is based on recent operating experience from implementing phased subpart K FFD programs and pre-employment screening at power reactor construction sites. Specifically, the NRC issued an exemption to the licensee for Vogtle Electric Generating Plant, Units 3 and 4, to delay implementing the access authorization program requirements of § 73.56 until initial fuel load (86 FR 67734; November 29, 2021). The NRC has reassessed the risks presented during the construction of nuclear power reactors and has determined that the currently established milestone for transition to an operations-phase access authorization program is not commensurate with current risk insights. The risk associated with unirradiated fuel does not increase when the fuel arrives onsite, because its engineered safety features, storage, and configuration have not changed since the fuel was in transit. (For transit and receipt onsite, physical protection requirements under § 73.67 are applied to protect the fuel.) Safety and security risks associated with unirradiated nuclear fuel only begin to increase once the process of loading the fuel into its operating configuration begins. The operational milestone “before initial fuel load into the reactor” therefore corresponds more closely to the start of NRC-licensed activities that could result in consequences adverse to public health and safety or the common defense and security than does the current milestone of receipt of nuclear fuel onsite.
(b) Revisions To Reduce Unnecessary Burden and Prescriptiveness
The proposed changes to access authorization program requirements would revise and/or eliminate program elements that have been identified as being unnecessarily costly or burdensome and not adding commensurate value to site safety or security. Requirements in § 73.56 would be revised to reflect insights gained from operating experience in the years since the requirements were last revised in the Power Reactor Security Requirements final rule in 2009 (74 FR 13970; March 27, 2009). These changes would promote efficiency and effectiveness for commercial nuclear power plant licensees and applicants, while adequately maintaining safety and security.
Proposed revisions to § 73.56(d)(3) would remove prescriptive requirements for the verification of true identity. Some approved methods for verifying true identity (
e.g.,
validating a foreign national's claimed non-immigration status using independent sources of reliable information) would be maintained in applicable guidance contained in Regulatory Guide (RG) 5.66, “Access Authorization Program for Nuclear Power Plants.” This change would provide appropriate flexibilities to licensees in implementing identity verification requirements, and the NRC would maintain reasonable assurance regarding the trustworthiness and reliability of personnel unescorted through continued reporting of access authorization information to the Federal Bureau of Investigation (FBI) Threat Screening Center.
Proposed revisions to § 73.56(i)(1)(v) would remove the requirement to perform a credit history re-evaluation as part of the process for determining the continued trustworthiness and reliability of individuals. Operating experience has shown that, although conducting a credit history evaluation at the time that unescorted access is initially authorized is important towards making an initial determination
regarding an individual's trustworthiness and reliability, re-evaluations of credit history add little value. Potential concerns regarding continued trustworthiness and reliability are more effectively identified through the required criminal history update and through licensee behavioral observation programs.
(c) Adjustment to Annual Supervisory Review
The proposed rule would adjust the requirements in § 73.56(i)(1)(iv) regarding supervisory review for personnel who are maintaining unescorted access. As proposed by the NRC, if an individual's supervisor were to interact with that individual with a frequency that allows the supervisor to form an informed and reasonable opinion regarding the individual's behavior, trustworthiness, and reliability, then the supervisor would not be required to conduct an annual supervisory review. Otherwise, the individual would be subject to an annual (within 365 calendar days) supervisory review conducted in accordance with the requirements of the licensee's or applicant's behavioral observation program. This proposed adjustment would reduce the unnecessary redundancy of annual reviews for cases where an individual is already subject to regular review by their supervisor, while still ensuring that individuals would undergo supervisor review in instances where contact is less frequent, ensuring that the objectives of the behavior observation program would be met.
(d) Relaxations for Licensees Who Opt Into a U.S. Government Monitoring and Notification Program
The proposed rule would modernize program requirements by adjusting the frequency of certain requirements (
e.g.,
criminal history records checks and vital area access list authorization) in a manner that provides additional burden relief to those licensees who opt into a U.S. Government continuous monitoring and notification program—such as the FBI Record of Arrest and Prosecution Background (Rap Back) service—through a Memorandum of Understanding with the NRC.
The FBI Rap Back service is a subscription-based program that provides continuous, automated notifications of new criminal activity associated with individuals who have undergone a fingerprint-based background check. Enrolling in such a service can substantially reduce the need for a licensee to rely on repeated background checks to ensure the continued trustworthiness and reliability of personnel. The proposed rule would reflect these benefits by reducing the frequency of required checks for those licensees enrolled in such a program. This change would help enable licensees to modernize their programs and reduce unnecessary burden, while ensuring that security is adequately maintained through the use of appropriate alternative processes.
(e) Reductions to the Frequency of Audits and Record-Retention Periods
The proposed rule would reduce the frequency of audits required under § 73.56(n), “Audits and corrective action,” by extending audit intervals from 12 months to 24 months for contractors or vendors, and from 24 months to 36 months for licensee and applicant programs. The proposed audit interval for contractors or vendors would be shorter than the interval for licensee and applicant programs because contractor and vendor activities operate outside licensees' routine processes and are less easily observable by licensees. The proposed rule would also reduce the records retention period in § 73.56(o)(2) from 5 years to 3 years. These proposed changes would reduce costs and administrative burdens while enhancing overall efficiency. With these changes, there would still be reasonable assurance that security will continue to be adequately maintained because licensees would still be required to periodically review the effectiveness of their programs, and the NRC would maintain the ability to effectively oversee program effectiveness through its inspection and oversight of licensee performance.
(f) Alternative Requirements for Licensees Who Demonstrate No Achievable Target Sets Exist in Accordance With § 73.55(f)
The proposed rule would provide relief from certain human reliability requirements for licensees and applicants who could demonstrate no achievable target sets exist in accordance with proposed § 73.55(f) and who would not credit any active measures (
e.g.,
operator action, mitigative action, detection, assessment, armed response) in making that demonstration. Under the proposed rule, such licensees would implement a program that meets the alternative access authorization requirements of § 73.120, “Access authorization program for commercial nuclear plants,” which were originally developed to provide alternative requirements for facilities licensed under 10 CFR part 53 that meet the criteria outlined in § 73.100(a)(1)(i).
Under the requirements of § 73.120, eligible licensee facilities would be relieved from the requirements to perform psychological assessments and reassessments in § 73.56(e), “Psychological assessment,” and to establish a full training program for behavioral observation (
i.e.,
initial and refresher training including knowledge checks) in § 73.56(f), “Behavioral observation.” Such licensees would have the option to provide minimal guidance to personnel on reporting questionable behavior, similar to the Department of Homeland Security's “If you see something, say something” campaign or a commensurate corporate behavior awareness program. This relief would be commensurate with the lower security risk posed by potential human actions at these facilities.
(iii) Category I Physical Fitness and Performance Evaluation Programs
The proposed changes to § 73.46 would reduce burden on current and future licensees. The proposed changes for facilities licensed to possess or use a Category I quantity of SNM are in the areas of security training, specifically for drills, exercises, and physical fitness requirements. The proposed rule would reduce the required frequency of security training exercises from four to a maximum of three per year. On an annual basis, the licensee would need to ensure that each shift participates in at least two tactical response drills, one of which would test the security response using the response force and a mock adversary team. Additionally, the licensee would need to conduct at least one force-on-force exercise annually and ensure that each shift that implements the safeguards contingency plan protective strategy participates in one force-on-force exercise every three years. Licensees would continue to ensure the effectiveness of their security programs, as security officers would maintain the knowledge, skills, and abilities necessary for contingency response activities through annual recurring training.
The proposed changes for security drills and exercises captured in 10 CFR 73.46(b)(9) and the physical fitness test captured in 10 CFR 73.46(b)(10) would be revised to align with the approach taken for power reactors. These changes are being proposed to decrease the burden in the implementation of licensee security training programs and to allow for increased flexibility, while maintaining safety and security.
These revisions would streamline the current requirements for security drills, exercises, and the physical fitness test to eliminate certain prescriptive
requirements, which in some instances are no longer necessary for the implementation of the training program. Existing licensees that are in compliance with § 73.46 as of the effective date of the final rule, if this proposed change is made effective in a final rule, would also be in compliance with the proposed revisions to the regulations and would not be required to modify their current physical fitness and performance evaluation programs.
(iv) Category II and Category III Material Security
(a) Performance-Based Requirements
The NRC proposes to modify § 73.67(d) for physical protection for fixed site facilities for SNM of moderate strategic significance. This proposal would build on previous efforts to risk-inform physical security regulations by shifting from prescriptive to performance-based requirements that would increase flexibility for current and future licensees; reduce unnecessary burden on licensees; and, where appropriate, allow for alternatives. The proposed changes to § 73.67 would support the agency's mission to enable the deployment of nuclear energy technologies (
e.g.,
the use of high-assay low-enriched uranium fuel supporting new types of reactors).
This proposed rulemaking for Category II quantities of SNM would address regulatory gaps and create a standardized approach for physical security. This would provide a consistent set of requirements for new applicants that use this type of SNM. Additionally, these changes would support efficiencies in the NRC's licensing and oversight programs.
The existing security requirements for possession and use of Category II quantities of SNM were originally established in 1979. Since that time, the NRC and other governmental agencies completed several studies to evaluate the risk and consequences associated with the physical protection of SNM. These studies were performed following the terrorist events of September 11, 2001, in part to evaluate and address changes in the threat environment. These studies and changes in the threat environment identified new vulnerabilities and risks that were not addressed by the then-existing regulations.
Subsequently, the NRC issued orders containing additional security measures to fuel cycle facilities licensed to possess Categories I and III quantities of SNM. At the time these orders were issued, the only facilities licensed to possess a Category II quantity of SNM were non-power reactors. To address the threat at these non-power reactor facilities, in 2002 and 2003, the NRC issued confirmatory action letters documenting the implementation of compensatory measures. However, additional security measures specific to a Category II quantity of SNM were not developed.
The NRC proposes to modify requirements in § 73.67 for Category II quantities of SNM to be largely performance-based, only retaining the prescriptive requirements that would be expected for all licensees subject to the requirements of § 73.67(d). The proposed rule would allow greater flexibility for both material and potential reactor licensees who would utilize these requirements for physical protection. This would permit licensees to adjust their security to better correspond to what is needed to ensure adequate physical protection.
The performance objectives in § 73.67(d)(1)(ii) and (iii) would require licensees to provide prompt detection for Category II quantities of SNM, instead of the early detection standard used in § 73.67(a)(2)(i) and (ii). Additional measures contained in § 73.67(d)(1) would provide requirements to store material in a controlled access area, mitigate and delay the bulk theft of special nuclear material, analyze and identify site-specific conditions that affect the protective strategy, provide defense in depth, coordinate the physical security plan with other onsite plans to avoid conflicts, and manage the potential for adverse effects on safety, security, and material control. These proposed changes would allow licensees possessing Category II quantities of SNM at a fixed site to implement protective strategies that are commensurate to the attractiveness of the material.
Proposed § 73.67(d)(2) would include performance requirements for the physical protection capabilities of detection, assessment, response, communication, and access authorization. Proposed § 73.67(d)(2)(xiii) would add requirements for compensatory measures. This addition would specify performance objectives for compensatory actions that should be taken when an item relied on for security is in a degraded condition. This addition would ensure the effectiveness of the physical protection system under abnormal operating conditions such as inclement weather and equipment malfunctions.
The NRC proposes to remove the current § 73.67(d)(3) and replace it with a new proposed § 73.67(d)(3). The proposed replacement § 73.67(d)(3) would allow the Commission to adjust physical security requirements—either adding or removing measures—based on the specific risk posed by the individual facility and site conditions to ensure adequate protection. The NRC is issuing draft Regulatory Guide (DG)-5088, “Physical Protection of Special Nuclear Material of Moderate or Low Strategic Significance,” proposed Revision 2 to RG 5.59, for public comment with this proposed rule to support implementation of the proposed requirements.
Proposed § 73.67(d)(4), “Alternative measures,” as revised, would provide a regulatory method for licensees who may wish to use different protective measures that are demonstrated to meet the performance objectives and requirements in § 73.67(a) and (b)(1).
Existing licensees that are in compliance with § 73.67 as of the effective date of the final rule, if this proposed change is made effective in a final rule, would be in compliance with the proposed revisions to the regulation and would not be required to modify their current physical protection programs. However, existing licensees would be able to voluntarily adopt certain performance-based alternatives, which would allow for greater flexibility in implementing the requirements of § 73.67.
Licensees that would elect to implement the proposed revised performance objective would be required by proposed § 73.67(d)(1)(vi), (viii), (ix), and (x) to perform an analysis to identify the necessary plant equipment, mitigative measures, detection capabilities, assessment processes, and response needed to ensure the site's physical protection program would be designed to prevent theft and diversion of SNM.
Alternatively, licensees that would elect to retain their existing physical protection programs to protect against theft and diversion of special nuclear material would be in compliance with the proposed performance objectives. All current licensees approved to possess a Category II quantity of SNM have approved security plans that include site-specific, performance-based security requirements that meet the proposed performance objectives, so an analysis of the proposed performance objectives would not be required. These licensees would continue to meet and implement the current requirements as relates to site-specific analysis for their physical protection program.
Licensees that would retain their current physical protection program
would be able to elect to change their security plans and implementing procedures to reference the new proposed regulatory requirements using the existing § 70.32(e) process.
(b) Protection of Category II and Category III Special Nuclear Material
The proposed rule would address an identified regulatory gap in the security requirements in § 73.67 for the protection of Category II and Category III special nuclear material among power reactor license holders. Paragraphs 73.67(d) and (f) would be modified to include an exception for part 52 licensees who will use Category II quantities of SNM inside a protected area. This change would align with Commission direction in SRM-SECY-22-0052, “Staff Requirements—SECY-22-0052—Proposed Rule: Alignment of Licensing Processes and Lessons Learned from New Reactor Licensing (RIN 3150-AI66),” dated November 20, 2024, to make security requirements for Category II and Ill quantities of special nuclear material brought on site at nuclear power reactors for new and existing facilities licensed under part 50 consistent with those requirements for facilities licensed under part 52. Under the current regulations, a part 50 licensee is exempt from the regulations, but a part 52 licensee is not. By providing this exemption for part 52 licensees, the proposed rule eliminates the need for part 52 licensees to comply with both § 73.67 and the more stringent § 73.55 requirements when the material is located inside a protected area. The § 73.55 requirements are designed to protect irradiated fuel from sabotage events at nuclear power reactors. Given the relative risks of irradiated and unirradiated fuel, it is acceptable to protect unirradiated reactor fuel and other nonfuel SNM brought onsite at a nuclear power reactor in accordance with § 73.67 until that material is protected in accordance with § 73.55. The change in this proposed rulemaking would reduce unnecessary regulatory burden and provide consistency between parts 50 and 52 applicants by providing the same exception for part 52 licensees. This proposed change is discussed further in Section VIII, “Backfitting and Issue Finality,” in this document.
(v) Electronic Processing of Safeguards Information
Sections 73.22 and 73.23 currently restrict licensees to transmitting SGI using NRC-approved technology and storage on standalone computers, transmitting SGI for voice communications using only technology approved by the NRC, and processing documents only on a standalone computer. Historically, the NRC has expected SGI to be treated more like classified information. These current regulations are very restrictive and not consistent with the threat environment, SGI's status as sensitive unclassified information, and the design basis threat's focus on threats posed by non-state actors.
The NRC is proposing to revise its regulations for the protection of SGI in §§ 73.22 and 73.23 to expand the means through which SGI can be transmitted for voice communications and to provide an option through which SGI can be viewed on networked computer systems. Sections 73.22(f)(3) and 73.23(f)(3) would be revised to allow an individual to transmit SGI for voice communications using commercially available digital technology that uses encryption algorithms that are compliant with or validated against an active and approved version of Federal Information Processing Standard (FIPS) 140. Additionally, the proposed rule would expand the ability to process SGI on computer systems. Currently, SGI may be stored on only standalone computers. The proposed rule would provide an option in § 73.22(g)(2) to store and process SGI on computer systems that permit viewing of the information on networked computers, using a virtual desktop or thin client architecture, provided that the systems storing the SGI would implement security controls that ensure the information is protected against unauthorized disclosure.
(a) Voice Communications
The proposed rule would expand the means through which SGI could be transmitted for voice communications. The proposed changes in § 73.22(f)(3) would enable licensees to communicate SGI by voice using encryption algorithms that have been approved by the National Institute of Standards and Technology (NIST), rather than also requiring that they be submitted to the NRC for review and approval. Draft guidance changes would discuss appropriate measures to protect against spills (
e.g.,
disabling transcription and recording, use in an area where only SGI authorized personnel are present, etc.).
Current § 73.23(f)(3) requires that SGI be transmitted only by NRC-approved secure electronic devices, encrypted by a method (FIPS 140-2 or later) approved by the NRC. Under the proposed § 73.23(f)(3), SGI would be transmitted only using a commercially available encryption system compliant with an active, approved version of FIPS 140. This change would eliminate the requirement for entities to seek NRC approval prior to using an encryption system, as long as it meets the FIPS 140 standard.
(b) Viewing Safeguards Information on Networked Computer Systems
The proposed rule would provide an option through which SGI could be viewed on networked computer systems. Processing SGI on standalone computers creates a significant burden, particularly for new reactor vendors incorporating security by design principles. Additionally, the cybersecurity field has matured significantly since the SGI regulations were last modified. The proposed changes in § 73.22(g)(2) would give licensees the option to use networked systems that would implement security controls specified by NIST as being appropriate for controlled unclassified information (NIST SP 800-171) using a thin client or virtual desktop architecture that would protect SGI from unauthorized disclosure and from being transmitted or stored on unapproved computers.
(vi) Decommissioning
As discussed in Section IV.B.(i), “Security Requirements for ISFSIs Located Outside a Reactor's Protected Area,” of this document, this proposed rule would streamline and expedite the reduction of resources needed to implement the physical protection program as a site in decommissioning transitions from storing fuel in the spent fuel pool to dry storage. Those proposed changes are consistent with the draft amendments presented to the Commission in SECY-24-0011.
(vii) Addressing Issues Related to the 2023 Enhanced Weapons Final Rule
This proposed rule would revise part 73 definitions, physical security event notification requirements, and suspicious activity reporting requirements to resolve industry concerns and challenges from the 2023 Enhanced Weapons final rule (88 FR 15864; March 14, 2023).
The proposed amendments would modify requirements issued in the 2023 Enhanced Weapons final rule that posed concerns and challenges for industry to effectively and efficiently implement. Industry identified these concerns and challenges to the NRC and requested exemptions from these requirements (
e.g.,
definitions of specific terms, protocols for contacting local Federal Aviation Administration (FAA) control towers, and the timelines associated with certain notifications). The NRC
proposes to clarify or remove other provisions from the 2023 Enhanced Weapons final rule that were identified as imposing unnecessary burdens. The NRC was able to address many of the implementation issues by revising three RGs in 2024 (
i.e.,
RG 5.62, Revision 3, “Physical Security Event Notifications, Reports, and Records”; RG 5.86, Revision 1, “Preemption Authority, Enhanced Weapons Authority, and Firearms Background Checks”; and RG 5.87, Revision 1, “Suspicious Activity Reports Under 10 CFR part 73”). Other issues that could be resolved only by rulemaking were discussed in a public meeting on July 31, 2025 (“Summary of July 31, 2025, Meeting with External Stakeholders Discussing Perspectives on Recent Security Event Notifications,” dated December 18, 2025). The proposed changes to §§ 73.2, “Definitions,” 73.1200, “Notification of security events,” 73.1205, “Written follow-up reports of security events,” 73.1210, “Recordkeeping of security events,” and 73.1215, “Suspicious activity reports,” in this proposed rule would resolve these issues and are reflected in the proposed revisions to supporting guidance in DG-5089 and DG-5098.
Section 73.1200 would be revised in several locations to increase consistency between facility-based and transportation-based event notifications (
e.g.,
use of hostile action versus hostile threat, adding notification of thefts of spent nuclear fuel or high-level radioactive waste from facilities). The NRC proposes to clarify language on the elimination of duplication to reduce burden for a single event that had both a physical security component (under part 73) and an information security component (under part 95).
Sections 73.1205 and 73.1210 would be revised to correct unnecessary records retention requirements by replacing the phrase “whichever is later” (which implied an obligation after license termination) with “whichever is earlier.” Section 73.1205 would also be revised to remove the requirement for written follow-up reports subsequent to 15-minute and 8-hour event notifications to reduce industry burden. For events of high security significance requiring notification within 15 minutes (
i.e.,
actual or expected attacks on a facility or shipment), prompt onsite follow-up by the NRC would occur and would be documented sufficiently by the NRC and the licensee to obviate the need for a licensee's written follow-up report within 60 days. For events of low security significance requiring notification within 8 hours, documented follow-up can occur during the NRC's next routine security inspection.
The NRC would make conforming changes to NRC Form 366, “Licensee Event Reports,” to remove references to § 73.77, “Cybersecurity event notifications,” which would be revised by this rulemaking as discussed in Section IV.C.(x).
Section 73.1215 would be revised to use more generic language for suspicious activity reports to the FAA. Specifically, references to “aircraft” would be revised to “crewed/uncrewed aviation-related assets” and the term “local FAA control tower” would be revised to “applicable FAA facility.” The revised language would provide greater flexibility in implementing the reporting provisions and making these reports while meeting FAA operational (workload and airspace) considerations. The NRC proposes to add language on the elimination of duplication to address suspicious activity reports that would otherwise be required under both § 73.1215 and § 37.57, “Reporting of events” (
e.g.,
a licensee storing both spent fuel and greater than class C waste at an ISFSI).
(viii) Personnel Identification System
Section 73.70, “Records,” would be revised to add a conforming change to reflect the proposal in § 73.55(g)(6)(ii) to allow licensees to use a personnel identification system, rather than specifically requiring numbered badges. With this change, licensees would have an option for the method of compliance for logging individuals that have been issued identification to enter a protected area. This proposed change could also reduce the cost of providing access to individuals that have access to a protected area.
Under the current § 73.70, certain licensees are required to maintain records of the names, addresses, and badge numbers of all individuals authorized to have access to vital equipment or special nuclear material, and the vital areas and material access areas to which authorization is granted. This proposed change would require licensees who elect to use an alternative personnel identification system to retain the records for individuals enrolled in that system. By adding this option, power reactor licensees would have an option for complying that also reduces the cost of producing badges for personnel that have access to vital areas or special nuclear material.
(ix) Definitions
Section 73.2 would be updated to reflect various regulatory changes in 10 CFR part 73 that affect multiple categories of licensees by revising the definitions of “Physical barrier,” and “Contraband.” A new definition for “Target set” would be added. As it relates to the relevant sections, these proposed changes would enhance clarity and promote consistency.
The definition for “Physical barrier” would be revised to allow for increased flexibility in licensee methods for meeting part 73 requirements. This change would reduce the need for licensees to submit licensing actions to modify their physical barriers in ways that depart from the current, prescriptive requirements. Instead, licensees could adopt a performance-based approach based on the function of the barrier in the physical protection program.
The definition of “Contraband” would be revised to remove reference to “disease causing agents” because the ability to identify these agents would exceed the reasonable capabilities of a licensee's physical protection program. With the removal of “disease causing agents,” the term “dangerous materials” would be redundant to the existing terms in the definition of contraband and therefore would also be removed. Separately, language in the definition of contraband regarding electronic devices would be removed. The existing requirements in 10 CFR part 95, “Facility Security Clearance and Safeguarding National Security Information and Restricted Data,” and 32 CFR part 117, “National Industrial Security Program Operating Manual (NISPOM),” are sufficient to protect classified information from unauthorized electronic devices, which pose an information security concern rather than a physical security concern.
A definition for “Target set” would be added in § 73.2. This term was previously defined in regulatory guidance, including RG 5.81, Revision 1, “Target Set Identification and Development for Nuclear Power Reactors,”
2
and NUREG-2203, “Glossary of Security Terms for Nuclear Power Reactors.” The NRC proposes to revise that definition to reflect the dose consequence performance objective of proposed § 73.55.
2
Revision 1 to RG 5.81 contains Official Use Only—Security Related Information. Therefore, this RG is withheld from public disclosure but is available to those affected licensees, stakeholders who have established a need to know, and cleared stakeholders who have access authorization.
(x) Cybersecurity
(a) Regulatory Guidance Revisions
The existing regulatory framework for cybersecurity under § 73.54 is
performance based and provides reasonable assurance that digital computer and communication systems and networks associated with safety, security, and emergency preparedness (SSEP) functions are adequately protected against cyberattacks up to and including the design basis threat, as defined in § 73.1. Commercial nuclear power plant licensees can choose from approved guidance documents (
e.g.,
RG 5.71, “Cybersecurity Programs for Nuclear Power Reactors,” and NEI 08-09, “Cyber Security Plan for Nuclear Power Reactors”) for well-established standardized approaches to meet the cybersecurity requirements in § 73.54.
The NRC is proposing to update RG 5.71 to reflect lessons learned from operating experience while ensuring that licensees continue to maintain reasonable assurance of safety and security. The proposed RG 5.71 updates would effectively result in reducing regulatory burden by, for example, focusing on safety and security over general cybersecurity hygiene—cutting approximately 19 percent of controls—and allowing licensees to take credit for cybersecurity best practices already in use (beyond those specified in RG 5.71).
(b) Event Notifications
The requirements for commercial nuclear power plant licensees to notify the NRC of certain cybersecurity-related events that adversely impact or could have impacted SSEP functions are defined in § 73.77, with supporting guidance in RG 5.83, “Cybersecurity Event Notifications.” To date, no licensee has made a notification under these provisions. In lieu of reporting incidents in accordance with the requirements of § 73.77, licensees have used the existing notification processes under §§ 50.72 and 50.73 (for safety-related events) and § 73.1200 (for security-related events). This proposal would simplify the regulation in § 73.77 by eliminating specific event notifications and instead redirect licensees to the aforementioned notification processes (
i.e.,
a cybersecurity-related event notification would use these safety-related or security-related regulations, based upon the affected function). This approach would allow the NRC to withdraw RG 5.83 and incorporate cybersecurity-related events reporting into the broader, established notification processes under parts 50, 53, and 73.
(c) Expand Regulatory Flexibility
To support innovation and modernization of the existing cybersecurity regulatory framework, this proposed rule would expand the regulatory options for new applicants under parts 50 and 52. Specifically, applicants would be able to select the most appropriate cybersecurity rule for their design and risk profile by complying with either § 73.54 or § 73.110, “Technology-inclusive requirements for protection of digital computer and communication systems and networks,” which was developed for part 53. Differences between the § 73.54 requirements and those in § 73.110 are primarily based on the implementation of a consequence-based approach to cybersecurity in § 73.110 that provides flexibility to accommodate the wide range of reactor technologies to be assessed by the NRC. A graded approach based on consequences would account for the differing risk levels among reactor technologies.
This proposal would include revisions to §§ 73.54, 73.55, 73.77, and 73.110; the companion regulatory guidance for § 73.110, DG-5103 (proposed Revision 1 to RG 5.96), “Establishing Risk-Informed and Technology-Inclusive Cybersecurity Programs for Commercial Nuclear Plants”; and §§ 50.34 and 52.79 to reflect this expanded regulatory flexibility.
This proposal would eliminate the existing introductory paragraph of § 73.54. That statement was originally intended to require that operating nuclear power plants, at the time of rule implementation in 2009, establish, implement, and maintain a cybersecurity program. All currently operating nuclear power plants have fully implemented their cybersecurity plans and will continue to maintain their plans per the requirements of § 73.55 and § 73.54.
The NRC is also proposing revisions to § 73.54(g) as conforming changes to align with the expansion of regulatory options for new applicants. Specifically, the cybersecurity program review requirement would be independent of the physical security program.
(xi) Design Requirements
The NRC is proposing amendments to § 50.34(a)(3)(i) and § 52.79(a)(4)(i) to require that safety and security be considered together in the design process such that, where possible, security issues are effectively resolved through design and engineered security features. This approach, which is consistent with the requirement in § 53.440(f), ensures consideration is given to safety and security together throughout the plant's lifetime, including the design process and prior to implementing changes to plant configurations, to ensure risks are effectively managed. This evaluation helps determine whether enhancements to the design basis or physical protection system are warranted. Incorporating security strategies and design features early in the design process can be significantly more efficient and cost-effective than retrofitting these measures after the plant has been designed or constructed.
D. Facility Security Clearance and Safeguarding of National Security Information and Restricted Data (Part 95)
The proposed rule would revise 10 CFR part 95 to remove requirements that are duplicative and ensure alignment with 32 CFR part 117 by providing references to 32 CFR part 117 where appropriate. Furthermore, specific NRC prescriptive requirements would be eliminated to resolve any conflicting regulations.
Part 95 establishes requirements for licensees, applicants, and other entities that obtain a facility security clearance from the NRC, as well as the requirements for the protection of classified matter. These requirements are based on the National Industrial Security Program Operating Manual (NISPOM), which was codified in regulation in February 2021, at 32 CFR part 117. Part 95 ensures that entities that fall under NRC cognizance meet the requirements of the NISPOM.
The regulations in 32 CFR part 117 establish the NRC as the cognizant security agency for NRC-cleared entities that are issued facility security clearances. Currently, cleared entities under NRC cognizance are subject to both 10 CFR part 95 and 32 CFR part 117, which has resulted in the establishment of duplicative and inconsistent regulatory requirements for cleared entities.
Under this proposed rule, the NRC would revise 10 CFR part 95. The proposed changes would not affect any existing regulatory guidance, but inspection procedures related to part 95 would be updated. The NRC would remove requirements from 10 CFR part 95 that are duplicative or inconsistent with the requirements in 32 CFR part 117. Part 95 would retain only those requirements and processes that are unique to NRC-cleared entities.
Section 95.1, “Purpose,” would be revised to identify that the purpose of part 95 is to implement the National Industrial Security Program, as described in 32 CFR part 117.
Section 95.5 would be revised to remove unused definitions or those definitions that are duplicative to definitions in 32 CFR part 117.
Section 95.11, “Specific exemptions,” would be revised to change the section title to “Specific exemptions and waivers,” to include reference to the NRC's ability to issue waivers in accordance with 32 CFR part 117.
Section 95.17, “Processing facility clearance,” would be renamed “Facility clearance process” for clarity. Requirements unrelated to the facility clearance process that had previously been in § 95.17 were moved to other more relevant sections. Other revisions would clarify that the review referred to in § 95.17 is an operational readiness review (rather than a security review). The NRC would revise § 95.17 to use the definition of “key management personnel” found in 32 CFR part 117.
The NRC proposes to delete §§ 95.18, “Key personnel”; 95.25, “Protection of National Security Information and Restricted Data in storage”; 95.27, “Protection while in use”; 95.29, “Establishment of Restricted or Closed areas”; 95.31, “Protective personnel”; 95.35, “Access to matter classified as National Security Information and Restricted Data”; 95.45, “Changes in classification”; and 95.51, “Retrieval of classified matter following suspension or revocation of access authorization,” because they duplicate provisions in 32 CFR part 117.
Section 95.19, “Changes to security practices and procedures,” would be revised to remove the requirement to resubmit the Standard Practice Procedures Plan every 5 years. This change would result in a reduction in licensee burden.
The NRC proposes to add § 95.24, “Safeguarding National Security Information and Restricted Data,” which would be a new section. This section would retain existing requirements from 95.25, “Protection of National Security Information and Restricted Data in storage,” related to the maintenance of keys and padlocks used to protect classified information. There would be no additional licensee burden associated with this change.
Sections 95.33, “Security education,” 95.34, “Control of visitors,” 95.37, “Classification and preparation of documents,” 95.39, “External transmission of documents and material,” 95.43, “Authority to reproduce,” and 95.47, “Destruction of matter containing classified information,” would be modified to remove specific requirements and instead require that cleared entities conduct these activities in accordance with 32 CFR part 117.
Section 95.49, “Security of automatic data processing (ADP) systems,” would be renamed “Authorization to operate national security systems,” consistent with usage in 32 CFR part 117. Specific requirements would be deleted, and the revised section would require cleared entities to process classified information on information technology or operational technology systems in accordance with 32 CFR part 117.
The NRC would revise § 95.57, “Reports,” to establish reporting requirements consistent with the provisions in 32 CFR part 117 that state that the cognizant security agency (CSA) (in this case, the NRC) will provide guidance on reporting security events. The proposed revision would provide that all actual or suspected losses or compromises of classified information would be reported to the NRC Headquarters Operations Center within one hour of discovery, with a written follow-up submitted within 48 hours. If it is determined that no loss, compromise, or suspected compromise occurred, a written report documenting this determination would be submitted in accordance with § 95.9, “Communications,” within 48 hours of reaching that conclusion. If the NRC is not the CSA, the entity would first report to their applicable CSA and then to the NRC. This revision would also eliminate the previous requirement for monthly logs.
V. Specific Requests for Comments
The NRC is seeking advice and recommendations from the public on the proposed rule. The NRC is particularly interested in comments with supporting rationales from the public on the following questions. In addition to the general discussion in Section IV, additional context is provided for certain questions in order to help the public comment on these issues.
Requirements for Vital Areas
Part 73 establishes requirements for the physical protection of licensed activities and facilities, which includes nuclear power reactors and Category I facilities. Section 73.2 defines vital areas and vital area equipment. The vital area concept focuses protective measures and access controls on locations housing equipment and functions essential to preventing significant radiological consequences from malevolent acts.
The licensees and the NRC have gained additional experience implementing the requirements associated with vital areas. The current approach for power reactors to protect their facilities focuses on the use of target sets (plant equipment and operator actions) that may or may not involve vital equipment. Evolving plant design changes, digital modernization, and operational practices may warrant an assessment of whether the vital area concept remains optimally defined and implemented across 10 CFR part 73 are clear, efficient, and risk-informed.
Question 1:
The NRC seeks stakeholder input on whether to revise or remove the term “vital areas” for power reactor facilities. Please explain the basis for your response.
Performance Objective
Under current part 73, licensees subject to § 73.55 must meet the performance objective in § 73.55(b)(3) of protecting against significant core damage and spent fuel sabotage. The NRC is proposing to change the performance objective from protecting against significant core damage and spent fuel sabotage to a broader goal of preventing release of radionuclides from any source that exceeds the dose reference values defined in § 50.34(a)(1)(ii)(D)(
1
) and (
2
), § 52.79(a)(1)(vi)(A) and (B), or § 53.210, as applicable, given that the term “core damage” is not necessarily applicable for some reactor technologies and designs.
Question 2:
The NRC seeks stakeholder input on the following:
a. How would this change impact the security programs of current licensees?
b. Would changing the performance objective in § 73.55(b)(3) provide any benefit to future licensees given that § 73.100 already offers a flexible, technology-inclusive performance objective for new reactors?
Fitness-for-Duty Program Requirements
Part 26 establishes requirements for FFD programs at NRC-licensed facilities. These requirements have been developed over time to provide, in part, a level of detail needed to support licensee legal considerations (
e.g.,
related to donor protections, the accuracy and reliability of tests performed, and the defensibility of licensee decisions regarding sanctions imposed on individuals because of FFD program violations). The proposed rule includes several changes to 10 CFR part 26 intended to reduce regulatory burden while increasing program effectiveness, efficiency, and flexibility.
Question 3:
Are there additional changes that the NRC should consider to streamline or simplify FFD program requirements for NRC licensees? For example, are there specific requirements in 10 CFR part 26 or other related regulations that could be transitioned to regulatory guidance (
e.g.,
to reduce prescriptiveness and allow licensees
and applicants to propose alternate methodologies in their licensing applications)? Please explain the basis for yo
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.