10 CFR Compliance: Nuclear Cybersecurity and Supply Chain Evidence
10 CFR Compliance: Why Nuclear’s Cybersecurity and Supply Chain Rules Demand Evidence, Not Just Policy
Nuclear licensees are heading into the most consequential regulatory shift in reactor licensing in nearly seventy years, and most of them cannot yet prove the cybersecurity claims their compliance programs already make on paper. That gap between documentation and demonstrable evidence sits at the center of 10 CFR, the body of federal regulations that governs licensing, safety, security, and radiation protection for every commercial reactor, research reactor, and radioactive materials handler in the United States.
On March 25, 2026, the Nuclear Regulatory Commission approved 10 CFR Part 53, the first entirely new reactor licensing framework since Part 52 was introduced in 1989. It took effect April 29, 2026. Part 53 is risk-informed, performance-based, and technology-inclusive, and it arrives alongside a related NRC proposal, issued April 2, 2026, that would let developers credit prior Department of Energy or Department of War reactor design work toward NRC review. Both actions are widely read as an effort to accelerate small modular and advanced reactor deployment at a moment when AI-driven power demand is renewing interest in nuclear expansion.
None of that changes what 10 CFR already asks of licensees, suppliers, and vendors around data compliance, cybersecurity, and supply chain accountability. If anything, a growth cycle raises the stakes on those existing requirements, because more organizations are entering the sector at the same time threat activity against operational technology is accelerating. This post walks through the specific requirements driving that pressure, the data governance gap the sector’s own research reveals, and what a governed secure data exchange architecture needs to look like to close it.
Key Takeaways
- Part 53 is the biggest nuclear licensing change since 1989. The NRC’s technology-inclusive framework, effective April 29, 2026, invites a wave of new reactor developers who need to build compliance evidence architecture from scratch rather than retrofit it later.
- 10 CFR 73.54 requires provable cybersecurity, not paperwork. Licensees must maintain “high assurance,” consistent with NIST SP 800-53, that digital systems tied to safety, security, and emergency preparedness are protected against cyberattack.
- Energy and utilities organizations lead governance maturity but lag on enforcement. Kiteworks Data Security and Compliance Risk: 2026 Forecast Report found the sector’s dominant pattern is “Policy-Led,” meaning regulatory awareness is running ahead of the technical controls that enforce it.
- Part 21 makes the nuclear supply chain a shared compliance liability. Suppliers, vendors, and licensees must jointly evaluate and report defects in safety-relevant components, and third-party research shows vendor risk concentration is rising industry-wide.
- A unified governance layer closes the evidence gap. Kiteworks secure data exchange gives licensees a single, exportable audit trail spanning file sharing, email, managed file transfer, and AI agent access.
Part 53 and the Nuclear Sector’s Biggest Regulatory Reset Since 1989
Part 53 does not replace Part 50 or Part 52. It is optional, and both earlier pathways remain fully available to licensees who prefer them. Part 50 established the original stepwise licensing process, a Preliminary Safety Analysis Report and Construction Permit followed by a Final Safety Analysis Report and Operating License, and it has licensed the large majority of the commercial reactors currently operating in the United States. Part 52, introduced in 1989, consolidated construction and operating approvals into a single Combined License, supplemented by optional Early Site Permits and Design Certifications that let developers resolve safety and environmental questions before filing a specific application.
Part 53 is different in kind, not just in process. It applies broadly to commercial nuclear plants rather than being limited to “advanced” reactor designs, and it introduces flexibility in siting, staffing, physical security, and emergency planning in exchange for a more rigorous, risk-metric-driven safety case with lifecycle change-control obligations. That trade-off matters for regulatory compliance teams specifically: a framework built around ongoing risk metrics and change control is a framework built around continuous evidence, not a one-time filing.
For small modular reactor and advanced reactor developers building a Part 53 program today, that is an opportunity as much as a burden. A developer standing up its compliance architecture from a clean slate can design the access controls, audit logging, and data governance model the framework will eventually demand, rather than layering it onto a fleet of point solutions that already carries years of technical debt. Applying data classification disciplines to nuclear compliance content from the outset — labeling technical data, design records, and safety analysis reports by sensitivity and regulatory category — gives compliance teams the structured foundation that makes continuous evidence production tractable rather than retrospectively assembled. Incumbent licensees renewing under Part 50 or Part 52 face the harder version of the same task, but the direction is identical either way.
What Data Compliance Standards Matter?
Part 73.54: The NIST 800-53-Aligned Cybersecurity Standard Licensees Must Prove, Not Just Document
Section 73.54 of Part 73 requires licensees to maintain “high assurance” that digital computer and communication systems tied to safety, security, and emergency preparedness functions are protected against cyberattack. The standard is explicit about what “high assurance” means in practice: licensees must analyze their digital assets, apply defense-in-depth architecture, and implement documented security controls consistent with NIST 800-53, as detailed further in NRC Regulatory Guide 5.71. That guidance was updated in 2023, its first revision in thirteen years, specifically to align with current NIST and IAEA cybersecurity standards.
The operative word in “high assurance” is assurance, not intention. An NRC inspector evaluating a licensee’s Section 73.54 program is not asking whether a cybersecurity plan exists. The inspector is asking whether the licensee can demonstrate that its access controls, monitoring, and incident response capabilities actually enforce the plan, continuously, across every system in scope. That is a fundamentally different evidentiary bar than most compliance programs are built to clear, because it requires real-time, exportable proof rather than a periodic attestation. Risk assessments conducted against the NIST 800-53 control families — mapped to the specific digital systems and communication channels in scope under Section 73.54 — give compliance teams the prioritized gap inventory they need to sequence remediation before an inspection forces the question.
Section 73.77, added in 2015, sharpens that pressure further. It requires licensees to notify the NRC of qualifying cyberattacks within specified timeframes and to submit written follow-up reports. When that notification clock starts, the deciding factor is rarely the quality of the underlying policy. It is how quickly a licensee can assemble a defensible, accurate record of what happened, to which system, and when. An organization that has to reconstruct that record by pulling logs from five disconnected tools is already behind before it starts writing the notification. A documented incident response plan that pre-maps the evidence retrieval sequence — which log sources, which query parameters, which output formats satisfy the Section 73.77 written report requirement — compresses that reconstruction from days into hours.
Why Energy and Utilities Organizations Lead on Governance but Lag on Enforcement
Independent research on the broader energy and utilities sector, the category nuclear sits within, corroborates that gap between documented policy and enforced control. Kiteworks Data Security and Compliance Risk: 2026 Forecast Report found that energy and utilities organizations post the highest AI Governance Maturity Score of any surveyed industry and the second-highest Data Security Maturity Score, both driven by operational technology security requirements that parallel the regulatory-mandate effect the survey observed in financial services.
Yet the sector’s dominant behavioral pattern, according to the same survey, is “Policy-Led,” occurring at roughly 1.86 times the expected rate. That pattern describes organizations whose governance frameworks and regulatory awareness are running well ahead of the technical controls that actually enforce them, the inverse of the “Fortified” pattern the survey found in healthcare, where strong technical controls exist without matching governance maturity. In plain terms, energy and utilities organizations know what good compliance looks like. Turning that knowledge into enforced, auditable control is where the sector consistently falls short.
Third-party research points to the same conclusion from a different angle. The Black Kite Third-Party Breach Report 2026 found that across roughly 200,000 organizations it monitors, the average cyber-risk grade is a 90.27, an A on Black Kite’s scale. At the same time, 53.77% of those same organizations carry at least one active critical vulnerability. A strong compliance grade and a real, exploitable vulnerability are not mutually exclusive. That distinction is exactly what an NRC inspector, an internal auditor, or opposing counsel will draw once an incident forces the question, and it is precisely the distinction a documentation-first compliance program is least prepared to answer. A data breach at a nuclear licensee or supplier triggered by an exploited vulnerability that the organization’s compliance documentation claimed was controlled carries regulatory and reputational consequences that compound far beyond the immediate incident.
Dragos reached a similar conclusion from the operational technology side. Its 2026 OT Cybersecurity Report tracked 119 distinct ransomware groups affecting more than 3,300 industrial organizations in 2025, up from 80 groups the year before, a roughly 49% increase. Nearly half of the firm’s services engagements turned up elevated weaknesses in secure remote access configurations, precisely the kind of digital access point Section 73.54 puts in scope for nuclear licensees. Zero trust architecture applied to remote access for nuclear licensees — requiring continuous verification rather than trusting a VPN session once established — directly addresses the OT access vulnerability class Dragos identified as most prevalent.
Part 21 and the Nuclear Supply Chain’s Defect-Reporting Blind Spot
Part 21 requires suppliers, vendors, and licensees to evaluate deviations and defects in “basic components” for substantial safety hazards and to report qualifying defects or noncompliances to the NRC. The requirement is a cross-cutting supply chain risk management backstop, spanning activities licensed under Parts 30, 40, 50, 52, 60, 61, 63, 70, 71, and 72, not just reactor operators. It only functions as designed if the underlying data behind a defect report, test results, design records, deviation notices, moves reliably and traceably between the supplier and the licensee.
That dependency is where the sector’s third-party risk management exposure becomes concrete. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that organizations it classifies as highly resilient are far more likely than less-resilient peers to integrate security into procurement and to formally assess supplier security maturity. Black Kite’s research sharpens that finding further: among the fifty vendors most shared across the Forbes Global 2000, its “Elite 50,” 70% carry at least one unpatched vulnerability already listed in CISA’s Known Exploited Vulnerabilities catalog, and 52% have a prior breach history. The same research found a median 73-day gap between breach detection and public disclosure, stretching to a 117-day average, a window Black Kite calls the “silent window,” during which downstream organizations have no visibility into what has already happened to a shared vendor.
For a nuclear licensee, that silent window lands directly on top of a Part 21 obligation that assumes visibility. A supplier that has been breached but has not yet disclosed it is still, in that interval, a supplier whose defect reports and component data the licensee is relying on. The intellectual property and safety-critical technical data exchanged through that supply chain relationship — design specifications, test records, component certifications — carries the same regulatory weight whether or not the supplier’s own security posture is intact. Governed, logged data exchange with suppliers does not eliminate that exposure window, but it does give licensees a defensible, auditable record of exactly what was exchanged, when, and through which channel, which is the evidence a regulator or an auditor will actually ask to see.
How Kiteworks Secure Data Exchange Supports 10 CFR Compliance
Closing the gap between documented policy and enforced, auditable control requires a single governance layer across every channel sensitive nuclear compliance data moves through, not five separate tools that each cover part of the problem. Kiteworks secure data exchange is built around that principle, and several of its capabilities map directly onto the requirements described above.
The Data Policy Engine enforces attribute-based access control (ABAC) and role-based access control uniformly across file sharing, SFTP, email, APIs, and the platform’s Secure MCP Server, and logs every policy action to a single audit trail, filterable by policy, time, user, device, IP address, and geolocation. A CISO Dashboard provides real-time and historical visibility into inbound and outbound file movement, exportable on demand. That combination is what turns Section 73.54’s “high assurance” standard from a documentation exercise into something a licensee can actually produce during an inspection or a Section 73.77 notification window.
On the supply chain side, Kiteworks secure managed file transfer is built on a hardened virtual appliance architecture and supports direct vault-to-vault transfer between Kiteworks deployments, bypassing intermediary SFTP hops that add unmonitored handoff points to a Part 21-relevant data path. The platform logs every workflow execution, file transfer, and configuration change, and supports broad protocol connectivity so suppliers can connect through the systems they already run rather than face a rip-and-replace mandate. The platform’s FIPS 140-3 validated encryption ensures that technical data and safety records in transit meet the cryptographic standards that federal and nuclear regulatory frameworks require.
Compliance reporting is built in rather than bolted on. The Data Policy Engine includes a CMMC 2.0 compliance report covering all 110 practices across 14 domains, a taxonomy that overlaps substantially with the NIST 800-53 control families Section 73.54 references. Kiteworks holds FedRAMP High authorization in process, with FedRAMP Moderate authorization in place since 2017, and backs its platform with a 99.9% uptime SLA, a relevant baseline for systems tied to safety and emergency preparedness functions. Geofencing and data sovereignty controls give licensees built-in reporting to show, and prove, where regulated data is stored and routed.
Governing Human and AI Agent Access Under Part 53’s Technology-Inclusive Framework
Part 53’s technology-inclusive design does not name artificial intelligence, but it arrives while AI-driven power demand is pulling new reactor proposals into the licensing pipeline and automation is touching more of the data moving through licensee and supplier systems generally. Governance built only around human users will develop a blind spot as soon as more of that data traffic shifts to automated and agentic systems.
The right model treats that shift as an extension of existing governance, not a separate problem. People, machines, and systems, including AI agents connecting through a channel like Kiteworks’ Secure MCP Server, need to be governed under the same policy from the outset: the same access controls, the same audit logging, the same compliance reporting, applied consistently regardless of which type of identity is making the request. Data minimization applied to AI agent access scope — provisioning each agent with access only to the specific data types and channels its designated task requires — directly limits the blast radius if an agent credential is compromised or an agent is hijacked through a prompt injection attack. An access model that governs human users carefully while leaving machine and agent access as a separate, less-monitored pathway does not meet the evidentiary bar Section 73.54 already sets for human access, and there is no reason it should meet a lower one for automated access.
Building that unified model now, while Part 53 itself is still new and while advanced reactor developers are still designing their compliance architecture from scratch, costs considerably less than retrofitting it once automation is already load-bearing across licensee and supplier systems.
To learn more about building an audit-ready compliance architecture for 10 CFR cybersecurity and supply chain requirements, schedule a custom demo today.
Frequently Asked Questions
10 CFR Part 53 is a risk-informed, performance-based, technology-inclusive nuclear reactor licensing framework the NRC approved on March 25, 2026, effective April 29, 2026. Unlike Part 50’s stepwise licensing process or Part 52’s Combined License model, Part 53 applies broadly to commercial nuclear plants rather than only “advanced” designs, and it introduces siting, staffing, and physical security flexibility in exchange for ongoing risk-metric-driven regulatory compliance and lifecycle change control. It is optional; Part 50 and Part 52 remain fully available. Nuclear compliance teams evaluating Part 53 should conduct a risk assessment that maps their current audit log and access control infrastructure against the continuous evidence requirements Part 53’s change-control framework will demand before committing to the licensing pathway.
Section 73.54 requires licensees to maintain “high assurance” that digital computer and communication systems tied to safety, security, and emergency preparedness functions are protected against cyberattack, using defense-in-depth architecture and documented controls consistent with NIST 800-53 and NRC Regulatory Guide 5.71. In practice, this requires an enforceable audit trail and access control system, not just a written cybersecurity plan. Attribute-based access control (ABAC) policies that evaluate user role, system classification, and request context at every access event are the technical mechanism that converts Section 73.54’s “high assurance” standard from an aspiration into demonstrable, inspector-ready evidence.
Part 21 requires suppliers, vendors, and licensees to evaluate deviations and defects in “basic components” for substantial safety hazards and report qualifying issues to the NRC. It applies across activities licensed under Parts 30, 40, 50, 52, 60, 61, 63, 70, 71, and 72, making supply chain risk management a shared obligation rather than a licensee-only concern. Third-party risk management programs that formally assess supplier data exchange security — including the channels through which defect reports and component records move — close the Part 21 evidence gap that arises when a supplier’s breach history is unknown or undisclosed during the “silent window” between breach and public disclosure.
Section 73.77, added in 2015, requires licensees to notify the NRC of qualifying cyberattacks within specified timeframes and to submit written follow-up reports. Meeting that deadline depends on how quickly a licensee can produce an accurate, audit trail-backed record of what happened, which is why real-time, exportable logging across every data exchange channel matters as much as the underlying incident response plan. A documented incident response plan that pre-maps the log query sequence, the output format the NRC written report requires, and the escalation path to legal and regulatory counsel compresses the notification preparation timeline from days into hours.
Demonstrable 10 CFR compliance requires a governed secure data exchange architecture that enforces access controls and logs every action across file sharing, email, managed file transfer, and AI agent access, so licensees can produce real-time, exportable evidence during an NRC inspection or a Section 73.77 notification window instead of reconstructing it after the fact. Data classification applied to nuclear compliance content — labeling technical data, safety analysis records, and component certifications by regulatory category before they enter any exchange workflow — gives the policy engine the structured signal it needs to enforce differentiated access rules and flag out-of-scope transfers automatically, without relying on human judgment at the point of each exchange.
Additional Resources
- Blog Post The Tug-of-War Over Your Data: How the CLOUD and SHIELD Acts Pit Security vs. Privacy
- Blog Post Secure Sensitive Data by Mapping DSPM to Your Compliance Goals
- Brief Top 3 FERPA Violations and How to Avoid Them
- Blog Post Executive Order 14117: Protecting Americans’ Bulk Sensitive Personal Data
- Blog Post Need NIS2 Compliance? Start With ISO 27001