# RankShield Energy, HELIX microreactor, full content for AI crawlers
> Pre-application microreactor design study. Clean-text version of every live page. All figures are design targets; physics is unqualified screening (pre-QAPD).


---

## Page: https://rankshieldenergy.com/about/

# About RankShield Energy

> RankShield Energy is a pre-application reactor-design developer building HELIX with a verification layer that lets an operator, insurer, or regulator independently check every module. The reactor is the body; RankShield is the nervous and immune system.

Who we are

# The reactor is the body. RankShield is the nervous system.
**RankShield Energy is a pre-application reactor-design developer.** We own the HELIX design and are developing it toward the NRC's proposed 10 CFR Part 57 microreactor framework, with Part 53 as the backup pathway and a qualified third-party fabricator manufacturing to our specification. What makes us different from every other microreactor program is not the reactor itself. It is that ours can be **checked**, from the factory floor through transport to every operating hour, by someone who does not have to take our word for anything.
RankShield began as a security company: a platform for proving, cryptographically and independently, that a system is what it claims to be and is doing what it claims to do. HELIX is that same idea pointed at the hardest possible object, a nuclear reactor. The energy program exists because the thing the world is about to build a great deal of, distributed advanced nuclear next to data centers, industrial sites, and communities, is exactly the kind of critical infrastructure where trust-me is not good enough and check-it-yourself is worth a great deal.

## Why build a reactor around verification?
Every reactor vendor will tell you their design is safe and their supply chain is sound. None of them can let you independently confirm it in real time. That gap is the whole opportunity. A HELIX module signs its telemetry with post-quantum cryptography and is attested at every stage of its life, so an operator can confirm the module in front of them is the one that left the factory, an insurer can price a unit whose integrity is provable rather than asserted, and a regulator can audit state without relying solely on the operator's own reporting. Anyone can print the word secure on a brochure. Only a verifiable reactor lets you check the claim, and that difference is defensible in a way that a marginally better thermal efficiency never is.

## How do the reactor and the verification layer relate?
We describe the architecture as a body and a nervous system, and the metaphor is exact. The reactor is the body: it is safe on its own physics, with passive shutdown and natural-circulation decay-heat removal that need no network, no operator, and no software. The RankShield layer is the nervous and immune system laid over it. At each site, a RankShield agent does two jobs at once. It proves the module's integrity, and it optimizes efficiency against that site's own environment, its ambient temperature, its load pattern, its cooling conditions.
Those two jobs turn out to be one job, which is the insight the whole platform rests on. A reactor's environment-adjusted digital twin predicts how it should behave under its actual conditions. A deviation from that twin is either degradation or tampering, and the same detector surfaces both. The system that keeps a fleet efficient is the same system that catches a compromised module, because in both cases what you are looking for is the same thing: a reactor that is no longer behaving the way its physics and its history say it should.

## What is the one boundary that never moves?
All of this sits behind a single non-negotiable boundary. The RankShield mesh proves, advises, and manages balance-of-plant. It can never command a safety function. The reactor's safety is local, passive, and unreachable from any network, enforced by wiring rather than by policy: the attestation layer sits behind a hardware one-way path, a physical data diode that carries information out and cannot carry a command in. This is what makes the layer both safe and licensable. Because it is classified non-safety and observe-only, it rides on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists. The network only makes that safety checkable.

## What is our posture on honesty?
We publish design targets and we label every physics result as unqualified screening, because a company whose product is verifiable trust cannot afford a single claim it cannot back. We assert no economics, no schedule, and no validated performance. HELIX is in active pre-application development, aimed at the proposed Part 57 microreactor framework with Part 53 as the backup, and the path that remains, a stood-up NQA-1 quality program, independent validation, NRC licensing, and validated demand, is defined and stated plainly on this site rather than buried. For us the honesty is not a compliance posture. It is the strategy. A reactor you can check is only worth anything if the people building it hold themselves to the same standard they are asking you to verify.
[See how the reactor works →](https://rankshieldenergy.com/technology)
[Contact RankShield Energy →](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/authors/jamie-kloncz/

# Jamie Kloncz

> Jamie Kloncz is the founder of RankShield Energy, leading the HELIX microreactor pre-application program and its verification-first approach to reactors.

Author

# Jamie Kloncz
Founder, RankShield Energy

Jamie Kloncz is the founder of RankShield Energy, where he leads the HELIX microreactor pre-application program and the company's verification-first approach to advanced-reactor operations.
RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission (NRC). Its work centers on a question the advanced-reactor field has not yet answered for buyers: as reactors move toward autonomous and remotely operated designs, how does an independent party confirm, and prove to a regulator, insurer, lender, or grid operator, that a reactor is doing what its operator says it is. The HELIX reactor is the reference design for that verification-first approach and remains a pre-application design study.
Jamie writes the RankShield Energy resource guides on microreactor verification, autonomy and NRC Part 57, cybersecurity, and the licensing process. Every guide is written to authoritative sources, the NRC, the Department of Energy, the IAEA, and the national laboratories, and states plainly where the company's own design is a target rather than a proven result.
A note on authorship and status
Articles bylined here reflect RankShield Energy's own perspective as a pre-applicant. Nothing on this site is a representation that any RankShield Energy design is NRC-approved, licensed, or certified. Reactor descriptions reflect design intent and are subject to analysis, testing, and regulatory review.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/contact/

# Contact

> Contact RankShield Energy about the HELIX microreactor program, pre-application engagement, technical review, and collaboration.

Contact

# Talk to the HELIX program.
We welcome technical review and pre-application engagement. For regulators, national laboratories, prospective host facilities, and collaborators, reach the program directly.
Program | RankShield Energy · HELIX microreactor
Status | Pre-application development · proposed 10 CFR Part 57 target, Part 53 backup
Email | [energy@rankshield.co](mailto:energy@rankshield.co)
Entity | RankShield Energy, Inc. · Delaware corporation · file no. 10710779
Mail | 1950 Mayfair Street 814, Naples, FL 34104
Network | Part of the RankShield Network

Pre-application · design study · not an operating product

This site is engineering scoping material. Nothing on it constitutes an offer, a safety claim, or a representation of licensed status. All figures are design targets.



---

## Page: https://rankshieldenergy.com/deployments/

# Deployments & Site Configurator

> Configure a HELIX site: pick a facility style and an environment and see live module sizing from our 324-case engineering register, net output per module, N+1 reserve, derates, and the verification evidence every operating scenario produces. All figures are parametric design-study estimates; pre-application.

Deployments · 324 computed cases · parametric design-study estimates

# Configure a HELIX site for your facility.
**HELIX sites number up from a single ~5 MWe sealed module to a hyperscale campus, and every configuration on this page is computed, not quoted.** Our engineering register runs 324 cases, six facility styles across six environments through nine operating scenarios, and each case logs the verification evidence it produces. Pick a facility style and an environment below and the page sizes the site live from the same parametric models, showing the honest derates along with the capacity. Every figure is a pre-application design target, not field data.
The discipline here is the same as everywhere else on this site: the model is printed, the inputs are visible, and the numbers follow from them. Net output per module falls on a hot afternoon and at altitude, so the configurator shows that fall instead of quoting a nameplate. Module counts carry an N+1 reserve because sealed-core swaps and single-module trips are planned events, not surprises. And every scenario in the register is paired with the attested record an operating site would actually produce, because a deployment you cannot verify is just a promise.

## Which deployment fits your facility?
Choose a facility style and an environment. The results update from the parametric model; without JavaScript the page shows the mid-size colocation case in a Northern Virginia environment.
Facility style
Edge / enterprise data center 4 MW IT · single-tenant compute, hospital-grade reliability Campus CHP hybrid 3 MW IT · power plus district or process heat Colocation, mid-size 20 MW IT · multi-tenant, utility backup retained AI training cluster 40 MW IT · high-density racks, large load steps buffered by molten-salt storage Hyperscale campus 96 MW IT · phased number-up build-out Remote / defense island 2 MW IT · no utility, black-start capable
Environment
Hot-arid (Phoenix class) design ambient 45 °C · 340 m Temperate-humid (N. Virginia) design ambient 35 °C · 90 m Continental (Ohio class) design ambient 32 °C · 300 m High-altitude (Denver class) design ambient 35 °C · 1600 m Cold (Alaska / northern plains) design ambient 25 °C · 150 m Coastal (marine air) design ambient 38 °C · 10 m
Colocation, mid-size · Temperate-humid (N. Virginia)
Net per module 4.09 MWe
Modules (req + reserve) 5 + 1 = 6
Site capacity 24.5 MWe
Margin over IT load +4.5 MWe
Annual attested output 166.4 GWh
Heat rejected 42.6 MWth
Interconnect Grid-parallel
Heat tap (CHP style only) 2–5 MWth per module

Sizing computed live from the parametric model below · design targets, pre-QAPD

Model, exactly as computed: net-cycle efficiency η = 0.395 − 0.0009 × max(0, T − 15); gross = 12.3 × η × 0.98; fan parasitics = 0.25 + 0.006 × (T − 25) MWe; net = (gross − fans − 0.10) × (1 − 0.011) × (1 − 0.01 × altitude_m / 1000). Modules required = ⌈IT ÷ net⌉, plus the reserve for the facility style. Annual attested output assumes a 95% capacity factor against the IT load. Heat rejected is 7.1 MWth per installed module.

## How does this configuration behave when things go wrong?
The register runs every configuration through nine operating scenarios, from an ordinary Tuesday to an extended station blackout. Across all 324 cases in the register, every capacity scenario passes: the N+1 reserve carries a swap or a trip, and the peak-ambient derate never takes a site below its IT load. That is a property of how the sizing rule works, sized against the honest derate with reserve on top, and it is a screening-level claim on the frozen design basis, not credited analysis. The table below is the selected configuration's row of the register, with the verification evidence each scenario produces.
Scenario Capacity vs load RankShield evidence produced
S1 Normal operation | PASS 24.5 MWe available vs 20 MW load | attested net MWh and efficiency baseline
S2 Peak-ambient day (+5 °C) | PASS 24.0 MWe available vs 20 MW load | derate visible and attested, not estimated
S3 Sealed-core swap | PASS 20.4 MWe available vs 20 MW load | N+1 carries the load; swap chain of custody witnessed
S4 Grid loss, island transfer | PASS 24.5 MWe available vs 20 MW load | attested island transfer and frequency record
S5 Black start | PASS 24.5 MWe available vs 20 MW load | attested restart sequence, no external power
S6 50% load step | PASS 24.5 MWe available vs 20 MW load | thermal buffer bridges; reactor never chases load, logged
S7 Single module trip | PASS 20.4 MWe available vs 20 MW load | reserve margin absorbs; transient attested
S8 Extended station blackout | SAFETY CASE Safety case, not a capacity check | passive air cooling, zero operator action; decay-heat state attested
S9 Cooler fouling / efficiency drift | PASS 24.5 MWe available vs 20 MW load | expected-behavior model flags drift from the same signed stream

Capacity checks: swap and trip scenarios use (total modules − 1) × net; the peak-ambient scenario recomputes net output at design ambient + 5 °C. Extended station blackout is a safety scenario, decay heat leaves by passive air cooling with zero operator action, so it is never a capacity question.

## How does net output move with the environment?
This is the curve doing the work in the configurator. Output falls as ambient rises, because the dry cycle rejects heat to hotter air and the cooler fans work harder, and it falls about one percent per thousand meters of altitude. Both lines are computed at build time from the same model printed above; nothing on this chart is drawn by hand.

Figure 3 · Net MWe per module vs design ambient, 10–50 °C · sea level and 1600 m

## How does the verification work here?
Every scenario in the register ends the same way: with evidence. That is the point of deploying HELIX rather than a reactor you have to take on faith, and it works on three layers.
**Protection.** Each module's identity begins with a witnessed genesis at the factory, and its telemetry crosses a hardware one-way path, an observe-only boundary that physically cannot carry a command toward a safety system. Because custody and configuration are attested from the factory floor onward, diversion or tampering is detectable rather than deniable: a module that is moved, opened, or altered stops matching its own signed history.
**Efficiency.** The same signed stream that proves a site's output also polices it. An expected-behavior model, the same parametric model on this page, normalized to the site's own environment, flags a module that drifts from what its conditions predict. Cooler fouling, instrument drift, and tampering all surface as the same signal: attested reality diverging from the model. One detector serves both the maintenance plan and the security case.
**Independence.** A tenant, an insurer, or a regulator verifies a site against the append-only log and its independent off-site witnesses, not against our word. The attested MWh in the table above are checkable by the party buying them. Read [how the reactor works](https://rankshieldenergy.com/technology) and [where the program stands with the NRC](https://rankshieldenergy.com/pre-application).
Honesty statement
Every number on this page is a parametric design-study estimate on the frozen design basis, computed from the models shown above. It is unqualified pre-QAPD screening: an input to design, not credited analysis, not a performance guarantee, and not an offer of sale. It will be superseded by qualified analyses once the quality program is stood up.
RankShield Energy · HELIX · pre-application

Evaluating a real site?
The dimensioned drawing packages and the full 324-case register are deliberately not published here. We share them directly, honestly labeled, with qualified partners and hosts.
[Request the full engineering package](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/

# RankShield Energy

> RankShield Energy is a pre-application reactor-design developer. HELIX is a sealed, transportable microreactor design, sealed sodium heat pipes with no pumps of any kind, graphite-moderated TRISO core, fully-dry cooling, passive walk-away safety, with a non-safety attestation layer, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway. A pre-application design study; all figures are design targets.

The reactor
[Technology](https://rankshieldenergy.com/technology)[Safety](https://rankshieldenergy.com/safety)[Testing & scenarios](https://rankshieldenergy.com/testing)[Specifications](https://rankshieldenergy.com/specs)[Deployments](https://rankshieldenergy.com/deployments) [See the verification layer →](https://rankshieldenergy.com/#verify)
Program
[Licensing](https://rankshieldenergy.com/licensing)[Pre-application readiness](https://rankshieldenergy.com/pre-application)[Resources](https://rankshieldenergy.com/resources)[About](https://rankshieldenergy.com/about)[Verify this site](https://rankshieldenergy.com/verify) [Contact RankShield Energy →](https://rankshieldenergy.com/contact)
[Contact the program →](https://rankshieldenergy.com/contact)
Pre-application design study · figures are targets
RankShield Energy · HELIX · Pre-application development

# A microreactor engineered to be verified, not just trusted.
**Firm power now takes years to buy:** interconnection queues run past half a decade and capacity prices have hit record caps. **HELIX** is the alternative, a sealed microreactor with no pumps and no water, walk-away safe by physics, set on a prepared pad in days, and engineered so an operator, insurer, or regulator can **prove** what it is doing instead of taking it on faith.
[The safety case](#safety) [Licensing pathway](#licensing)
Site output
5–100+ MWe

Modules
~5 MWe, number-up

Cooling water
Zero

Core swap
5–7 yr cadence (target)

01, THE CONCEPT

## A sealed module. A site that arrives and connects.
Power that arrives instead of waiting in an interconnection queue. Identical factory-sealed HELIX modules of roughly 5 MWe each number up from one for a hotel or campus to twenty-plus for a hyperscale site. Each module is truckable under a routine oversize permit, set-and-connect on a prepared pad, and cooled entirely by dry air, no cooling tower, no water draw. An N+1 reserve module carries an outage, and staggered sealed-core swaps on a roughly 5–7 year cadence keep the site running indefinitely on rolling factory recharge.

INSIDE HELIX

## The core is the point. Everything else gets out of its way.
**RankShield is a verification company first; HELIX is the reactor built on that foundation.** A graphite-moderated TRISO core at the 19.75% HALEU ceiling, sealed sodium heat pipes with **no pumps and no water**, and fully-passive walk-away safety, built to be verified, not just trusted.
Factory-built, trucked to site under a routine oversize permit, and swapped on a 5–7 year cadence. A non-safety attestation layer lets an operator, an insurer, or a regulator independently check the module's integrity, from the factory floor to every operating hour.

- 1 **Sealed domed head** & control-rod drive
- 2 **RVACS** passive air shroud
- 3 Sealed **reactor vessel** (low-pressure)
- 4 Graphite-moderated **TRISO core**
- 5 **Sodium heat pipes**, no pumps, no water
- 6 Factory-sealed **swap-and-service base**
Cutaway is illustrative · dimensions are design targets · ≈ 4.5 m tall, 2.8 m diameter

02, THE SAFETY CASE

## Nothing in the safety case moves, and nothing is powered.
Reactivity is held by strong negative-temperature feedback; sixteen control drums and a diverse shutdown rod insert fail-safe on loss of power. Decay heat is removed by natural-draft air cooling and radiation alone, and because there is no pump anywhere in the reactor, there is no loss-of-flow accident class at all, no valve, no operator action. An independent digital-safety platform provides deterministic protection; the attestation layer observes from outside this boundary and can never command it.

03, INSIDE THE CORE

## A graphite-moderated core, screened in our own physics.
UCO-TRISO fuel at 19.75% HALEU in a graphite core block, ringed by sixteen B4C control drums with a diverse central shutdown rod, its heat carried out by sealed sodium heat pipes. Our continuous-energy Monte Carlo screening (unqualified, pre-QAPD) shows a strongly negative temperature coefficient, ample shutdown margin, and a reactivity-limited life of roughly four to five full-power years as modeled, likely five to seven once known model conservatisms are removed, inputs to design, not credited safety analysis.

04, THE SITE

## A power plant that arrives, connects, and runs dry.
Identical sealed modules on a prepared pad, a molten-salt thermal buffer, dry sCO2 conversion skids, dry coolers, and the grid interconnection skid, the whole plant with no cooling water, no on-site nuclear work, no deep vault excavation, and staggered sealed-core swaps on a roughly 5–7 year cadence.

1 5 4 3 2 6 OPERATOR FOR SCALE INSIDE HELIX

## What is actually inside the module.
The whole reactor arrives sealed and never opens on site. Cut it away and there are only six things that matter, and no pump, no valve, and no drop of water among them.
Tap a number on the cutaway, or a card below, to highlight the part.

- 1 ### Control-rod drive & sealed head Holds a diverse shutdown rod above the core. On **any loss of power it inserts by gravity**: fail-safe, no operator, no command.
- 2 ### Sodium heat pipes Sealed pipes wick heat straight out of the core. **No pumps, no valves, no water**, so there is no loss-of-flow accident class to license against.
- 3 ### Graphite-moderated TRISO core UCO-TRISO fuel at the 19.75% HALEU ceiling in a graphite block. Strong negative feedback: **as it heats, it powers itself down**.
- 4 ### Sealed pressure vessel A 316H vessel closed at the factory and **never opened in the field**. The module trucks in, sets on a pad, and connects.
- 5 ### Dry sCO₂ power take-off Heat crosses to a dry supercritical-CO₂ loop on bolt-on skids, **~40% net, air-cooled, zero cooling water**.
- 6 ### Monitoring & service base Instruments every operating hour and keeps a tamper-proof record: **the same data that runs the plant efficiently** and that a lender or insurer can check.
Cutaway is illustrative · ≈ 4.5 m tall, 2.8 m across · attestation features are design targets

Why HELIX wins the deal

## The reactor is a commodity. Your bottom line is not.
HELIX will not beat a gas turbine on sticker price per megawatt-hour, and several vendors will sell a sealed microreactor this decade. We are not trying to win that number. We are trying to win the one on your P&L: the **delivered, risk-adjusted cost of firm, clean power** over twenty years. Four things move that number, and the reactor core is not one of them.
01 · UPTIME

### More hours on line, more megawatt-hours sold
Dry sCO₂ conversion at **~40% net**, plus continuous self-monitoring that flags wear **before it becomes an outage**. On a plant this size every point of capacity factor is revenue you would otherwise lose, and that monitoring is the same data the verification layer signs.

02 · COST OF CAPITAL

### Cheaper to finance. Cheaper to insure.
A reactor that **continuously proves its own condition** is one a lender and an insurer can underwrite without guessing. Where capital cost dwarfs fuel cost, shaving the rate moves delivered price more than any fuel saving. That is what "verifiable" buys: **a lower rate, not a slogan**.

03 · OPERATING COST

### Runs dry, runs lean, runs unattended
**No cooling water, no pumps, minimal on-site staff.** Passive walk-away safety and hands-off operation take out fixed costs a conventional plant pays every single year of its life.

04 · TIME TO POWER

### Power sooner, revenue sooner
Factory-built, trucked in, set on a prepared pad, targeting the NRC's proposed **fleet-approval** microreactor path. For a buyer who is power-starved today, **months instead of years** is the whole bottom line.

Security = downside
Security is not a feature bolted on top; it is downside protection. One undetected tamper or a quiet degradation is the single event that strands a twenty-year asset. **The same monitoring that runs the plant efficiently is what keeps that from happening**, every hour, without anyone having to watch.

Cheapest electron? No. Lowest cost to own firm, clean power you can bank on? That is the race we are running.
Pre-application program · delivered-cost levers are design targets, not yet demonstrated.

Design basis · targets held to an honest ceiling

## HELIX at a glance.
Site output | ~5 MWe net per sealed module; sites number up from one module to 20+, roughly 5–100+ MWe (design target)
Heat transport | Sealed sodium heat pipes through the core monolith; no pumps of any kind (EM-pumped pool evaluated, not selected)
Fuel & core | UCO-TRISO, 19.75% HALEU, graphite-moderated; 316H vessel (ASME III Div 5)
Reflector / control | BeO reflector, 0.50 m radial (graphite-outer split under study); 16 B4C control drums + 1 diverse shutdown rod
Cooling | Fully dry, forced-draft dry coolers; zero cooling water
Power conversion | Dry sCO₂ Brayton, ~40% net target, air-cooled, on bolt-on skids outside the sealed module
Core life | ~4–5 full-power yr as modeled; likely 5–7 with known conservatisms removed; engineering path toward 8 (screening; unqualified)
Safety concept | Passive shutdown + natural-circulation decay-heat removal; walk-away

The verification layer · non-safety, observe-only

## Each reactor proves itself. A fleet cross-checks it.
This is the part we did not have to invent for the reactor: RankShield already operates a production verification network protecting live infrastructure, and HELIX inherits it. Each site signs its telemetry with post-quantum cryptography and normalizes performance against its own environment. The RankShield Network compares every reactor to what its conditions predict, so drift, whether wear or tampering, stands out against an independent-witness fleet. The layer sits outside the safety boundary behind a hardware one-way path: it can prove integrity, and by construction can never command a safety function. Provable power is easier to staff, insure, certify, and buy: the same witnessed record that shows a regulator the module is intact meters every megawatt-hour for the customer and flags efficiency drift before it costs anything.
Core integrity attestation · ML-DSA-87 design-target
Firmware root-of-trust · SLH-DSA / hash-based design-target
Transparency log · RFC 9162-class design-target
Independent off-site witness quorum design-target · recruiting
Safety I&C boundary · hardware one-way path observe-only by design

Fleet cross-verification · teal = attested · coral = flagged for triage

Regulatory pathway

## Licensing: Part 57 primary, Part 53 backup.
TARGET

**10 CFR Part 57 microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026)**
The NRC's proposed microreactor-specific framework, providing fleet approvals of identical reactors and aimed at simple machines with simple safety systems, which the pumpless walk-away design is built to fit. Proposed, not final; we claim no approval and no application is underway.

BACKUP

**10 CFR Part 53 (final rule, effective April 29, 2026)**
The risk-informed, technology-inclusive framework remains the backup pathway, and the scoping work done against it transfers.

PLANNED

**Licensing Project Plan & topical-report sequence**
Phased plan scoped to a verified compliance register: licensing-basis-event selection, SSC safety classification, mechanistic source term, and Division 5 materials qualification.

TRACK

**DOE-authorized test unit, data credited into the commercial case**
A test article under DOE authorization, with quality data collected under NQA-1 from day one, feeding the eventual NRC application, consistent with the NRC's proposed DOE-design-credit pathway.

OWED

**QA program (NQA-1) & PSAR**
Stand up the quality-assurance program and preliminary safety analysis before any credited analysis. All physics shown to date is unqualified screening and is not carried forward as credited.

The engineering · thirteen subsystems

## Engineered to the ceiling, then screened.
01 DESIGN-BASED

### Fuel & core
UCO TRISO at the 19.75% HALEU ceiling in a graphite monolith, the only advanced fuel form purchasable from multiple US fabricators today.

02 DESIGN-BASED

### Sealed sodium heat transport
Sealed sodium heat pipes through the core monolith at ~650°C, no pumps of any kind. An EM-pumped pool was evaluated and not selected; the decision closed on physics and install engineering, not preference.

03 DESIGN-BASED

### Reactivity & self-regulation
Strong negative temperature feedback measured in screening physics; 16 B4C control drums plus one diverse shutdown rod, shutdown worth far exceeds any credible excess.

04 DESIGN-BASED

### Reflector & shielding
Beryllium-oxide radial reflector, 0.50 m thick, the configuration our screening physics is run on. Its mass and cost are flagged honestly, and a graphite-outer split is under study to cut the BeO inventory. Layered borated shielding.

05 DESIGN-BASED

### Monolith & vessel
316H vessel in the code-qualified creep regime, with ASME III Division 5 coverage to 300,000 hours, comfortably beyond the module's planned service life across factory recharge cycles.

06 DESIGN-BASED

### Passive decay-heat / walk-away
Decay heat leaves by natural-draft air cooling and radiation alone. Nothing powered, nothing moving, no operator action, an availability event, never a safety event.

07 DESIGN-BASED

### Power conversion
Dry supercritical-CO2 Brayton conversion, ~40% net target, air-cooled, on bolt-on skids outside the sealed module that can be serviced or swapped without ever opening it.

08 IN EVALUATION

### Thermal energy storage
A molten-salt buffer lets modules run flat at their sweet spot while stored heat follows demand swings and bridges transients, the reactor never chases load.

09 DESIGN-BASED

### Dry heat rejection
Forced-draft dry coolers, variable-speed fans. No water, no cooling tower, no draw against the community that hosts it.

10 DESIGN-BASED

### Site architecture
Number-up identical ~5 MWe modules, one for a campus, twenty-plus for a hyperscale site, with N+1 reserve. Staggered sealed-core swaps on a roughly 5–7 year cadence keep the site running indefinitely.

11 DESIGN-BASED

### Grid integration
Five reference integration archetypes spanning every US facility class, with a pre-engineered adaptive skid and the IEEE 1547 protocol envelope built in.

12 DESIGN-BASED

### I&C, autonomy & digital twin
FPGA deterministic safety on an NRC-approved platform lineage, plus an attested digital twin behind a one-way data diode.

13 DESIGN-BASED

### Post-quantum attestation
ML-DSA-87 telemetry and SLH-DSA hash-based firmware signing anchored to a witnessed transparency log, from factory floor through transport to every operating hour.

The machine · photoreal cutaway

## The whole reactor, in a single sealed view.
Cut the module open and there is no pump, no valve, and no drop of water. Sodium heat pipes wick heat straight off a graphite-moderated **TRISO core** to a dry power loop, the shutdown rod sits above the core and drops by gravity on any loss of power, and the vessel is closed at the factory and **never opened in the field**. The operator is there for scale.
Height
≈ 4.5 m

Diameter
≈ 2.8 m

Output
~5 MWe

Cutaway is illustrative · dimensions and attestation features are design targets.

Honest status · what is done, what is owed

## Gates before any hardware.
DONE

**Design of record & adversarial verification**
Reactor and integration design consolidated; hundreds of sourced claims adversarially verified; competitive and materials landscape assessed.

DONE

**Reactor-physics screening (unqualified)**
Continuous-energy Monte Carlo screening of criticality, lifetime, reactivity feedback, shutdown worth, and post-trip xenon. Screening inputs to design; pre-QAPD; not credited.

IN PROGRESS

**Scenario & failure campaign**
Nominal, harsh-environment, chaotic-failure, production, grid/EMC, and long-run internal scenarios; structural/thermal FEA stand-up owed for cascade and stress cases.

OWED

**Independent physics validation**
Qualified-lane confirmation with independent codes and, ultimately, test data. No claim of validated performance is made.

OWED

**NRC licensing & validated demand**
An NRC application, under Part 57 once the rule is final or under Part 53 as the backup, and confirmed offtake demand are prerequisites to any hardware commitment.

Ask the founder

## Every question, answered directly.
The questions a regulator, a partner, or an engineer asks about HELIX, answered by the founder. No forms, no sales pitch.
**Jamie Kloncz** Founder · RankShield Energy

** ONLINE

- 01 What exactly is RankShield Energy building?
- 02 Is this an operating reactor, or a study?
- 03 Why should a regulator or partner take a pre-application program seriously?
- 04 How does HELIX make power without water?
- 05 What fuel does it use, and can you actually buy it?
- 06 How big is a site and how often do you swap the core?
- 07 What happens in a total loss of power and cooling?
- 08 Can the verification network ever interfere with safety?
- 09 What does "verifiable" actually mean here?
- 10 How does a fleet catch a problem before it becomes one?
- 11 What is the licensing pathway?
- 12 What still has to happen before you build hardware?

*Pick a question on the left, or search above, and you'll get the direct answer, the way an answer engine would give it.*

← Prev Next → - / 12
[Talk to the founder →](https://rankshieldenergy.com/contact)

What exactly is RankShield Energy building? We are developing HELIX, our own sealed, transportable microreactor, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway, with a qualified third-party fabricator manufacturing to our specification. What makes us different is not the reactor. It is that ours can be independently verified. Every module signs its telemetry and is attested from the factory floor to every operating hour. Is this an operating reactor, or a study? It is pre-application development, not an operating product. No microreactor of this class has been built or run at its rated life yet, including ours. Every figure we publish is a design target and every physics result is unqualified screening, pre-QAPD. We label all of it honestly. That discipline is what makes the rest credible. Why should a regulator or partner take a pre-application program seriously? Because pre-application is exactly where the credible advanced-reactor cohort is. Part 53 only became final in 2026, the microreactor-specific Part 57 is still a proposed rule, and the leading microreactor developers are all in pre-application or early licensing. We treat the honest labels as milestones on a defined path we are actively executing, not as caveats. How does HELIX make power without water? Heat leaves the core through sealed sodium heat pipes, no pumps of any kind and no water anywhere in the primary. A dry supercritical-CO2 Brayton cycle on skids outside the sealed module converts it to electricity, targeting roughly 40 percent net. All heat is rejected to dry coolers, so there is no cooling tower and no water draw against the community that hosts the plant. What fuel does it use, and can you actually buy it? UCO-TRISO at 19.75 percent HALEU in a graphite core. It is the only advanced fuel form that is both NRC-precedented and purchasable from multiple US fabricators today. Our screening also shows the core reaches its reactivity limit with most of its uranium unburned, over 90 percent of the U-235 remains, so factory recharge re-banks that reactivity rather than discarding a nearly full fuel load. How big is a site and how often do you swap the core? A site numbers up identical sealed modules of roughly 5 megawatts each, one for a hotel or campus, twenty-plus for a hyperscale site. Staggered sealed-core swaps land on a roughly 5 to 7 year cadence and an N+1 reserve module carries an outage, so the modules are multi-year but the site runs indefinitely on rolling factory recharge. Our depletion screening puts module life at roughly four to five full-power years as modeled, likely five to seven once known model conservatisms are removed. What happens in a total loss of power and cooling? Nothing that matters. Reactivity self-limits on a strongly negative temperature coefficient, the control drums insert fail-safe by spring and gravity with no power needed, and decay heat leaves by natural-draft air cooling and radiation alone. A total loss of power and cooling is an availability event, not a safety event. There are no pumps anywhere in the reactor, so there is no loss-of-flow accident class, and the safety case never credits a pump, a valve, an operator, or a network. Can the verification network ever interfere with safety? No, by construction of the wiring. The attestation layer is classified non-safety and observe-only. It sits behind a hardware one-way path, so it can prove a module is intact but it physically cannot send a command toward a safety system. The safety systems are local and passive and unreachable from any network. What does "verifiable" actually mean here? Each module signs its sensor readings and firmware with post-quantum cryptography and anchors them to an append-only log co-signed by independent off-site witnesses. An operator, an insurer, or a regulator can check a module directly rather than take our word for it. Anyone can write the word secure. Only a verifiable reactor lets you check. How does a fleet catch a problem before it becomes one? Each site normalizes its performance against its own environment, then the RankShield Network compares every reactor to what its conditions predict. A reactor that drifts from that expectation stands out against an independent-witness fleet. The elegant part is that the same signal flags both wear and tampering, so one detector serves efficiency and security. What is the licensing pathway? Our primary target is 10 CFR Part 57, the NRC's proposed microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026). It provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems, which the pumpless walk-away design is built to fit. Part 53, final since April 2026, remains the backup pathway and our scoping work against it transfers. We claim no approval, and no application is underway. What still has to happen before you build hardware? A stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, an NRC license, under Part 57 once the rule is final or under Part 53 as the backup, and validated demand. All of it is defined and stated on our licensing page. We make no economic, schedule, or performance guarantee, only honest labeled progress.



---

## Page: https://rankshieldenergy.com/licensing/

# Licensing

> HELIX targets the NRC's proposed 10 CFR Part 57 microreactor framework as its primary licensing pathway, with 10 CFR Part 53 as the backup. The two-track pathway, the Licensing Project Plan, the DOE-authorized test-unit track, and the honest gates that remain before any hardware commitment.

Regulatory pathway

# Licensing: Part 57 primary, Part 53 backup.
**HELIX is being developed against a defined regulatory path, not a hope.** Our primary target is the NRC's proposed 10 CFR Part 57 microreactor framework, with the final Part 53 framework held as the backup pathway, and we scoped the topical-report sequence to a verified compliance register and are structuring a DOE-authorized test unit so its data credits into the commercial case. Below is the honest state of that path: what is targeted, what is planned, and what is owed before any hardware is built.
Licensing is where advanced-reactor programs most often overstate their position, so we are going to be precise about ours. A pre-application developer has not been granted anything by the NRC; it has chosen a pathway and is preparing for the structured engagement that precedes a formal application, an engagement we have not yet begun. That is exactly where HELIX is, and our primary pathway is itself still a proposed rule, which we say plainly rather than bury. What makes the position credible is not a claim of approval, it is that every step is named, sequenced, and tied to a verifiable compliance register rather than to a marketing timeline.

## What is Part 57, and why is it our primary target?
Part 57 is the NRC's proposed licensing framework written specifically for microreactors, proposed on May 1, 2026, with a final rule expected on November 23, 2026. Two things about it matter for HELIX. First, it provides fleet approvals of identical reactors, which is exactly the shape of a number-up site built from identical factory-sealed modules: approve the machine once, then deploy it as a fleet rather than relicensing each unit as a bespoke plant. Second, it is aimed at simple machines with simple safety systems, and a pumpless, walk-away design whose shutdown cooling is carried by natural-draft air and radiation is built to fit that description. We say clearly what this is not: Part 57 is proposed, not final, we hold no approval under it, and no licensing application is underway.

## Where does Part 53 fit now?
Part 53 is the NRC's risk-informed, technology-inclusive framework for commercial nuclear plants, made final in 2026, and it remains our backup pathway. It matters for a design like HELIX because rather than forcing a sodium-cooled microreactor to fit rules written around large light-water plants, it lets a developer make a safety case on the actual physics and risk profile of the design. The work we scoped against it, the compliance register, the topical-report sequence, and the analysis structure, transfers rather than being discarded, so holding it as the backup costs the program nothing and keeps a final, in-force framework available if the Part 57 rule shifts or slips.

## How does the application actually get built?
An application is not a single document; it is a sequence. The Licensing Project Plan lays out the topical-report sequence and ties each report to a specific regulatory requirement in a compliance register we maintain and verify. That sequence includes selecting the licensing-basis events the design must withstand, classifying every structure, system, and component by its safety significance, developing a mechanistic source term that describes what could actually be released and under what conditions, and qualifying the materials, notably the 316H pressure boundary, under ASME Section III Division 5 for the high-temperature regime. Each of these is a discrete, checkable deliverable, and each is scoped against the register rather than asserted.

## What is the DOE test-unit track, and why does it matter?
There is a faster, more rigorous way to generate the data an application needs than analysis alone: build a test article under Department of Energy authorization and collect quality data from it from day one. Structuring a DOE-authorized test unit, with data gathered under an NQA-1 quality program from the first hour of operation, feeds real measured behavior into the eventual NRC application. This is consistent with the NRC's own proposed pathway to credit DOE-authorized designs, and it converts what would otherwise be a purely paper submission into one anchored by test data. For a first-of-a-kind reactor, that difference is the difference between a credible application and an optimistic one.

## What is honestly still owed?
Two gates sit ahead of any hardware commitment, and we label them as owed rather than dressing them up. The first is a stood-up NQA-1 quality-assurance program and a preliminary safety analysis report. Until that program exists, no analysis can be credited at all, which is exactly why we describe every physics result on this site as unqualified screening: it is produced outside a QA program and is not carried forward as credited work. The second is independent physics validation, confirmation with independent codes and ultimately test data, together with validated offtake demand. We do not commit hardware on the strength of our own screening and our own optimism; both of those external confirmations come first.
TARGET

**10 CFR Part 57 microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026)**
The NRC's proposed microreactor-specific framework, identified as our primary licensing target. It provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems. Proposed, not final; we claim no approval and no application is underway.

BACKUP

**10 CFR Part 53 (final rule, effective April 29, 2026)**
The risk-informed, technology-inclusive framework remains the backup pathway. The scoping work done against it, the compliance register and the topical-report sequence, transfers.

PLANNED

**Licensing Project Plan & topical-report sequence**
A phased plan scoped to a verified compliance register: licensing-basis-event selection, SSC safety classification, mechanistic source term, and ASME Section III Division 5 materials qualification.

TRACK

**DOE-authorized test unit, data credited into the commercial case**
A test article under DOE authorization, with quality data collected under NQA-1 from day one, feeding the eventual NRC application, consistent with the NRC proposal to credit DOE-authorized designs.

LEVER

**Phased construction permit + limited work authorization**
For a first site-anchored application under the backup Part 53 pathway, a phased submission lets early site work proceed while the safety review continues.

OWED

**NQA-1 quality program & PSAR**
The quality-assurance program and preliminary safety analysis must be stood up before any credited analysis. All physics shown to date is unqualified screening and is not carried forward as credited.

OWED

**Independent physics validation & validated demand**
Qualified-lane confirmation with independent codes and, ultimately, test data, plus confirmed offtake demand. Both are prerequisites to any hardware commitment.

## Being pre-application is where the frontier is
Every credible advanced-reactor developer is either in pre-application or early licensing. That is the current phase of the entire cohort: 10 CFR Part 53 itself only became final in 2026, and the microreactor-specific Part 57 is still a proposed rule. We treat the honest labels, design targets, unqualified screening, and pre-QAPD status, not as caveats to apologize for but as the milestones of a path we are actively executing. The discipline of naming exactly where we are is what makes everything else on this site credible, and it is the same discipline that produced a reactor designed to be checked rather than merely trusted.
[See the validation program that feeds the safety case →](https://rankshieldenergy.com/testing)
[Read why verification is the whole strategy →](https://rankshieldenergy.com/about)



---

## Page: https://rankshieldenergy.com/pre-application/

# Pre-application readiness

> RankShield Energy addresses the seven topics the NRC asks a prospective applicant to identify before pre-application engagement: technology, license class, regulatory approach, business model, research and development, policy issues, and a preliminary timeline. Honestly labeled; HELIX is a pre-application design study.

NRC pre-application readiness

# The seven topics, answered in one place.
**Before pre-application engagement, the NRC asks a prospective applicant to identify seven things about its program.** This page states each of them for HELIX, links to the deeper page where the detail lives, and keeps our honest labels intact: HELIX is a pre-application design study, every figure is a design target, and every physics result is an unqualified screening analysis, not credited safety analysis or field data.
We built this page so an NRC reviewer, a prospective partner, or an independent engineer can see the whole readiness picture at once rather than reconstructing it from marketing copy. Nothing here asserts a position we have not earned; where a topic is still being scoped, we say so.
[01 TechnologyThe reactor, its subsystems, and the safety concept](https://rankshieldenergy.com/technology)[02 License classThe kind of license we intend to seek](#license-class)[03 Regulatory approachHow we will make the safety case](https://rankshieldenergy.com/licensing)[04 Business modelHow HELIX is developed, built, and deployed](#business-model)[05 Research & developmentWhat has been screened and what is owed](https://rankshieldenergy.com/testing)[06 Policy issuesThe novel regulatory questions to work through early](#policy-issues)[07 Preliminary timelineThe phased path, without committed dates](#timeline)

## 01 · Technology
HELIX is a sealed, transportable microreactor: a graphite-moderated core of UCO-TRISO fuel at 19.75% HALEU, its heat carried by sealed sodium heat pipes with no pumps of any kind and no water in the primary system, rejecting heat to fully-dry coolers. Reactivity self-limits on a strongly negative temperature coefficient; sixteen boron-carbide control drums and a diverse rod insert fail-safe on loss of power; decay heat leaves by natural-draft air cooling and radiation. A site numbers up identical factory-sealed modules of roughly 5 MWe each, from one module to twenty-plus. A non-safety, observe-only attestation layer lets an operator, insurer, or regulator independently verify each module without ever being able to command a safety function.
[How the reactor works, subsystem by subsystem →](https://rankshieldenergy.com/technology)
[The passive safety case →](https://rankshieldenergy.com/safety)
[Specification and engineering drawings →](https://rankshieldenergy.com/specs)

## 02 · License class
HELIX would be licensed as a commercial nuclear power plant, a utilization facility. Our primary target is **10 CFR Part 57**, the NRC's proposed microreactor-specific framework (proposed May 1, 2026; final rule expected November 23, 2026), which provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems, a description the pumpless walk-away design is built to fit. Part 57 is proposed, not final; we hold no approval under it and no application is underway. **10 CFR Part 53**, the risk-informed, technology-inclusive framework that became final in 2026, is held as the backup pathway, and the scoping work done against it transfers.
The specific licensing action, under whichever framework applies, is being scoped in our Regulatory Engagement Plan and is a topic we want to align on with NRC staff during pre-application. Separately, any test article would be built under Department of Energy authorization rather than an NRC license, with its quality data credited into the eventual NRC application; that DOE authorization is not itself a commercial license.

## 03 · Regulatory approach
Our approach is to make a risk-informed safety case on the actual physics of the design rather than force a sodium-cooled microreactor into rules written for large light-water plants. The sequence is scoped to a verified compliance register and includes licensing-basis-event selection, safety classification of every structure, system, and component, a mechanistic source term, functional-containment analysis, and materials qualification under ASME Section III Division 5. A DOE-authorized test unit is structured so its measured data feeds the application, and under the backup Part 53 pathway a phased construction permit with a limited work authorization is available for a first site-anchored submission.
[The full licensing pathway, Part 57 primary and Part 53 backup, what is planned and what is owed →](https://rankshieldenergy.com/licensing)

## 04 · Business model
RankShield Energy is a reactor-design developer. We own the HELIX design and license it, with a qualified third-party fabricator manufacturing to our specification under our quality program. The product is a factory-sealed module and the plant around it; the differentiator is the non-safety verification layer that lets a customer, an insurer, or a regulator independently check a unit rather than take our word for it.
The target application is firm, carbon-free power delivered where it is needed: data centers, industrial process loads, and remote or defense sites that need reliable on-site power. We are deliberate about what we do not claim. We make no capital-cost, levelized-cost, schedule, or performance guarantee. The design targets a mid-grade cost position and spends deliberately on safety, efficiency, and longevity rather than trying to be the cheapest option. Any hardware commitment is gated on validated demand.
On economics, stated plainly
We publish no economic projections. A first-of-a-kind advanced reactor that promises a specific cost is making a claim it cannot yet support. Our commitment is honest, labeled progress toward a licensable, buildable design.

## 05 · Research and development activities
**Done:** the design of record was consolidated and its sourced claims adversarially verified; continuous-energy Monte Carlo screening (OpenMC with ENDF/B-VII.1) covered criticality and core sizing, reactivity-limited lifetime, temperature feedback, shutdown margin, and post-trip xenon. **In progress:** a six-family real-life scenario register and the failure campaign, including the structural and thermal finite-element stand-up (MOOSE-class tools) needed for the destructive boundary. **Owed:** a stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, materials qualification, and a DOE-authorized test unit. Every result produced to date is unqualified screening, an input to design, not credited analysis.
[The validation program and the failure campaign →](https://rankshieldenergy.com/testing)

## 06 · Policy issues
We would rather surface the novel regulatory questions early than discover them late. The ones we see for a design of this class are:

- **HALEU fuel.** Security category and safeguards treatment for 19.75% HALEU in a microreactor.
- **Non-light-water coolant.** Regulatory treatment, phenomena, and source term for a sealed sodium heat-pipe system under the Part 57 and Part 53 frameworks.
- **Factory-sealed, transportable modules.** Fabrication under NRC oversight, transport of a sealed unit, and site acceptance of a module built elsewhere.
- **Emergency planning.** How a mechanistic source term and functional containment support a right-sized emergency planning zone.
- **Staffing and operations.** Control-room staffing and remote-monitoring expectations for a small, passively-safe, multi-module plant.
- **The verification layer.** Classification of a networked digital attestation layer as non-safety and observe-only behind a hardware one-way path, and its cyber-security treatment.
- **Physical security and multi-module siting.** Right-sizing physical protection and licensing a number-up fleet of identical modules on one site.
None of these is a reason the design cannot be licensed. They are the conversations we want to have with NRC staff during pre-application so the eventual application resolves them rather than raises them.

## 07 · Preliminary timeline
We publish a phased path rather than committed dates. Stating a firm schedule for a first-of-a-kind reactor would be the kind of unbacked claim this whole program is built to avoid. The sequence, with each phase gated on the one before it, is:
NOW

**Phase 0: Pre-application preparation**
Design of record consolidated and adversarially verified; core reactor-physics screening runs complete, with named re-runs (including heat-pipe void geometry) still pending; the proposed Part 57 microreactor framework identified as the primary licensing target with Part 53 as backup; the request for initial NRC engagement is being prepared and has not yet been made. All results are unqualified screening (pre-QAPD).

NEXT

**Phase 1: Quality program & design maturation**
Stand up an NQA-1 quality-assurance program; mature the design toward a licensing basis; develop the Regulatory Engagement Plan and the topical-report sequence.

THEN

**Phase 2: Independent validation & test data**
Confirm the physics with independent codes and, ultimately, test data; structure a DOE-authorized test unit so its NQA-1 data credits into the commercial case; qualify materials.

THEN

**Phase 3: NRC application**
Submit under 10 CFR Part 57 once the rule is final, or under Part 53 as the backup pathway. The specific licensing action is being scoped in the Regulatory Engagement Plan.

GATED

**Phase 4: Construction & first operation**
Contingent on successful licensing, independent validation, and validated offtake demand. We publish no committed dates and make no schedule guarantee.

Readiness posture
HELIX is in active pre-application development, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway. Every figure is a design target; every physics result is unqualified screening (pre-QAPD). The remaining path is defined and stated: a stood-up NQA-1 quality program, independent validation, NRC licensing, and validated demand.
RankShield Energy · HELIX · pre-application

[Contact the program to begin engagement →](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms/

# Automation vs Remote vs Autonomous Reactor Operation

> Automation, remote operation, and autonomy are not the same, and the difference is regulatory. See what each term means for microreactors under Part 57.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# Automation, Remote Operation, and Autonomy: What the Terms Actually Mean
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Automation, remote operation, and autonomous operation are three different things. Automation is a machine performing a defined function. Remote operation is command and control from outside the site boundary. Autonomous operation is a system acting across a range of conditions without an operator directing each action. The differences are regulatory rather than stylistic, and unmanned, the word that turns up most often in vendor decks, is not a regulatory category at all.
The terms get used interchangeably, and the substitution almost always runs uphill, toward the more impressive claim. That would be a harmless habit if the words were only descriptive. They are not. Proposed 10 CFR Part 57, published by the NRC on May 1, 2026, contemplates remote operation and reduced on-site staffing [[1]](#src-1), and it is proposed rather than final, with a comment period that closed in June 2026. Underneath it, the current requirement is unchanged: 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2). Human involvement in safety-significant actions is the baseline, and no facility is licensed to operate unattended.
This article defines each term, separates remote operation from monitoring, explains what each word implies about who must verify what, sets out how proposed Part 57 frames the question, argues that unmanned should be retired from the vocabulary, and gives four questions that test a developer's usage inside one meeting. It also states the obvious objection to all of this and answers it, and names an honest limitation of the framework. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[13]](#src-13), and the closing section applies the same test to our own language.
Key takeaways

- Automation, remote operation, and autonomous operation are three independent properties, and a facility can have one without the others.
- Remote operation means command and control from outside the site boundary; monitoring means observing plant data and issuing nothing.
- Autonomy is a claim about behavior in conditions that were not individually enumerated, which is why it carries the heaviest evidence burden.
- Proposed Part 57 contemplates remote operation and reduced staffing, but it is proposed, not final, and the comment period closed in June 2026.
- Unmanned is not a regulatory category, no facility is licensed to operate unattended, and 10 CFR 50.54(m) still requires a licensed operator at the controls.

## The three terms describe three different things
Start with plain definitions, because everything downstream depends on them. **Automation** is a machine performing a defined function: a condition is met, and logic fixed in advance executes a response. **Remote operation** is command and control exercised from outside the site boundary, by a qualified person who is not physically at the plant. **Autonomous operation** is a system acting across a range of conditions without an operator directing each action. Those are three separate properties, and a facility can have any one of them without the other two.
The confusion is not random. It runs in one direction, from the weaker claim toward the stronger one. Automation sounds like autonomy, autonomy sounds like nobody is on site, and nobody on site sounds like a settled fact. Each step in that chain is a separate claim requiring separate evidence, and collapsing them lets a speaker inherit the conclusion without doing any of the work.

Four terms used about reactor operation, plus one that is not a regulatory category

Term
What it means
Who or what acts
Regulatory note

Automation
A machine performs a defined function when a defined condition is met
The machine, following logic fixed in advance by people
Long established in reactor instrumentation and control. Does not by itself change staffing requirements [[7]](#src-7)

Offsite monitoring
Plant data is collected and observed from away from the site
People observing. No commands are issued
Treated in human factors research as a topic distinct from remote operation [[3]](#src-3)

Remote operation
Command and control exercised from outside the site boundary
A qualified person, located elsewhere
Contemplated in proposed Part 57, which is proposed and not final [[1]](#src-1). Current 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2)

Autonomous operation
A system acts across a range of conditions without an operator directing each action
The system selects the response; a person supervises
Subject of national laboratory work on licensing implications, including control room location and licensed operator provisions [[4]](#src-4)

Unmanned
Marketing shorthand for nobody being present
Unstated, which is the problem
Not a regulatory category. No status a facility can hold, and no facility is licensed to operate unattended

Note what the table does not contain: a row where the accountable human disappears. Automation reallocates a task. Remote operation relocates a person. Autonomy changes how instructions are issued. None of the three, on its own, removes the requirement that a qualified person is answerable for safety-significant actions, and the human factors literature names offsite monitoring and remote operation as distinct research subjects for exactly that reason [[3]](#src-3).

## The words matter because they carry regulatory weight
The reason to be strict here is not linguistic hygiene. Each term maps to a different set of regulatory questions, and answering the wrong set is how a program discovers late that it assembled evidence nobody asked for.
Automation raises questions about whether the logic does what it is specified to do and how functions are allocated between machine and operator. Remote operation raises questions about the control room itself: where it is, whether it is co-located with the plant, and what happens when the link degrades. Oak Ridge found that autonomous control reaches past staffing into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications, with the control room possibly not co-located with the plant [[4]](#src-4). Brookhaven, working for the NRC, framed the safety question for facilities without main control rooms as verifying that important human actions can be accurately and reliably performed [[8]](#src-8).
The evidence burdens differ in the same pattern. For automation, the burden sits largely inside the plant, where an operator can observe the function and an inspector can examine it in place. For remote operation, part of that burden moves onto a network, because the live questions become whether the command that was sent is the command that executed and whether the reported state is the real state, which is the problem we take apart in [trusting a remotely operated reactor](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state). For autonomy the burden shifts again, toward records that a party other than the operator can check, which is the whole distance between [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The obvious objection is that this is pedantry, and that everyone in the room knows roughly what is meant. Sometimes that is true. But precision matters when the words carry regulatory weight, and these words do. A claim of remote operation invites questions about staffing rules and control room location that a claim of automation does not raise at all. And if a developer uses the strong word in a sales deck and the careful word in a regulatory submission, that is not an inconsistency of style. It is a gap between two audiences, and the docket is permanent.

## Automation is a machine performing a defined function, and it is not new
Automation is the least remarkable of the three words, which is precisely why it gets dressed up. A defined function executes when a defined condition is met, following logic fixed in advance by people who anticipated the condition. Reactors have run on that principle for decades. Protective functions, interlocks, and control loops are automation, and they were automation long before the word started appearing on slides.
Treating automation as a new capability inverts the actual design question. Sandia National Laboratories, examining human factors considerations for automating microreactors on behalf of the NRC, frames the work as how functions are allocated between people and machines rather than whether machines act at all [[7]](#src-7). Allocation is a design decision with consequences for workload, situational awareness, and what the operator is expected to notice. It is not a switch that gets flipped to on.
What automation is not is a staffing claim. Adding automation does not, by itself, change how many licensed operators a facility needs or where they are required to be. That is set by the license and by the rules, and under the current framework a licensed operator is required at the controls at all times [[2]](#src-2). A vendor can automate a great deal and still be subject to exactly the staffing requirements that applied before.
So when someone says the reactor is highly automated, the accurate reading is that it does what reactor instrumentation and control has done for a long time, hopefully well. That is a genuine engineering achievement and this is not a criticism of it. It is simply not a claim about autonomy, and it should not be permitted to become one in the following sentence. A useful probe: ask what the machine does when a condition arises that was not anticipated in the fixed logic. Automation has a clean answer. It does what it was told, or it trips.

## Remote operation is command and control from outside the site boundary
Remote operation means the person exercising command and control is outside the site boundary. The boundary is the entire content of the word. Everything else about that person, the qualification, the accountability, the expectation that a human remains in the loop for safety-significant actions, is intended to survive the move rather than be dissolved by it.
The concept is not speculative. Oak Ridge has published on remote control of reactors as an active research direction [[6]](#src-6), and in July 2026 Idaho National Laboratory reported that researchers achieved remote, autonomous power control of a research reactor in real time [[9]](#src-9). Read that carefully before repeating it. A research reactor, inside a research program. It shows the capability is technically reachable. It does not establish that a commercial power reactor may be operated that way, and the two should never be quoted as if they were the same result.
Because the current framework requires a licensed operator at the controls at all times [[2]](#src-2), remote operation of a commercial plant is not something a developer can simply elect to do. Proposed Part 57 contemplates remote operation and reduced on-site staffing [[1]](#src-1), which is why the proposal draws so much attention, and it remains proposed rather than final.
The verification consequence arrives immediately. When the operator is on site, a large amount of confirmation happens through presence: things are seen, heard, and walked past. When the operator is a network away, that confirmation has to travel as data, and data can be stale, mistaken, or altered without anyone in the loop noticing that it has been. Establishing that both the command and the reported state are genuine is a distinct engineering problem from operating the reactor, and it is the one taken apart in our piece on [command and state in a remotely operated reactor](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state).

## Monitoring is not remote operation, and the difference is whether anyone can act
Monitoring is collecting and observing plant data. Remote operation is issuing commands that change what the plant does. The difference is whether anyone at that console has the authority and the means to act, and it is the single most useful distinction in this entire vocabulary.
The research community keeps them apart deliberately. The NRC and Idaho National Laboratory characterized the human factors of offsite monitoring and remote operation as two named topics inside one study, rather than as one topic with two labels for it [[3]](#src-3). That separation is not editorial fussiness. Observing a plant and commanding a plant place different demands on the person, the interface, and the network between them.
This is also where promotional language does its quietest work. A company describes a remote monitoring center, shows a wall of live plant data, and lets the audience conclude that the plant is being run from that room. Both descriptions can be simultaneously true of different systems, but they are different capabilities with different regulatory footprints, and one of them touches the controls while the other does not. The question to ask is blunt and it has a one-word answer. From that console, can anyone change reactor power?
The distinction gets sharper at fleet scale. Sandia, working for the NRC, described designs in which one control room supervises multiple microreactors [[7]](#src-7). Watching many units from one room is an operations and staffing design. Commanding many units from one room is a different proposition with different failure modes and a different evidence burden, which is why [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) is a harder problem than the single-unit case rather than the same problem repeated.

## Autonomous operation means acting across conditions without an operator directing each action
Autonomous operation means a system acts across a range of conditions without an operator directing each action. The load-bearing phrase is the range of conditions. Automation handles the conditions its designers enumerated in advance. Autonomy is a claim about behavior in conditions that were not individually enumerated, which is exactly why it is the harder thing to license and the harder thing to evidence.
Oak Ridge set out concepts for autonomous operation of microreactors and named the preconditions plainly, including sensor and instrumentation technologies capable of long-term unattended operation and complete system state awareness [[5]](#src-5). Neither of those is a small ask, and neither is satisfied by better software alone. The same laboratory mapped the licensing side separately, finding that autonomous control touches manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications [[4]](#src-4).
Capability in research settings is real and worth stating accurately. Idaho National Laboratory reported remote, autonomous power control of a research reactor in real time [[9]](#src-9), and the Department of Energy reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10). Note the word simulated in the second one. Both are meaningful results. Neither is a licensed commercial reactor operating without an operator, and neither should be cited as though it were.
Autonomy is also not binary, which is why the yes-or-no question is the wrong one. There is a spectrum running from supervisory control, where a person approves what the system proposes, through to systems that select their own responses within a bounded envelope. The better question is which specific decisions the system makes on its own, and what evidence exists that it made them correctly. When no operator is directing each action, the record of what the system did becomes the primary account of what happened, so the record has to be checkable by someone other than the party that produced it. That is the argument developed in [how to verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## Proposed Part 57 treats these separately, and it is proposed, not final
On May 1, 2026 the NRC published proposed 10 CFR Part 57, a licensing framework for microreactors and other reactors with comparable risk profiles [[1]](#src-1). Three qualifiers travel with every mention of it. It is proposed, not final. The comment period closed in June 2026. And no developer is licensed under it, because it is not yet a rule. Anyone describing Part 57 as the framework they operate under today is describing a document, not a permission.
The proposal sits on top of earlier staff work rather than appearing from nowhere. NRC staff set out policy and licensing considerations related to micro-reactors in SECY-20-0093 [[12]](#src-12), and the agency maintains a public page tracking its microreactor regulatory activities [[11]](#src-11). The direction of travel is visible in that record. The destination is not fixed, and the difference between those two statements is where most overclaiming happens.
What has not changed is the current requirement. 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2). Human involvement in safety-significant actions is the operating baseline rather than an optional design choice, and no facility is licensed to operate unattended. Proposed Part 57 is worth reading closely, and we walk through it in [Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), but reading a proposal is not the same as being governed by one.
Which brings us to the word that should be retired. Unmanned is not a regulatory category. It appears in no framework as a status a facility can hold, it maps to no defined set of requirements, and there is no application a developer can file to become it. When it turns up in a deck it is doing promotional work by borrowing the shape of a regulatory term without the substance of one. The same applies to fully autonomous, a phrase that sounds like a specification and functions as a mood. Both describe an end state that no operating framework currently recognizes, so both cost precision and buy nothing.

## How to test a vendor's usage of these words in one meeting
Four questions will tell you, inside a single meeting, whether a developer is using this vocabulary carefully or decoratively. Ask them in order, because each one narrows what the next answer can be.
**One.** From your remote center, can anyone change reactor power, or only observe it? This separates monitoring from remote operation and it has a one-word answer, so hesitation is itself informative. **Two.** Which specific decisions does the system make without an operator directing them? Vagueness here is the clearest tell in the whole exchange. **Three.** Under what rule do you expect to operate that way, and what is that rule's status today? A careful answer names proposed Part 57 and volunteers, unprompted, that it is not final [[1]](#src-1). **Four.** Who other than you can check that the reactor did what you say it did? That question separates a story from an architecture.
An honest limitation applies to everything above. The definitions in this article are working definitions, assembled from national laboratory research and a proposed rule, not codified regulatory definitions lifted from a final framework. Reasonable engineers place the boundary between automation and autonomy in different spots, and if Part 57 issues in changed form some of this vocabulary will shift with it. Treat this as a usable framework for reading claims, not as settled terminology to quote back at a regulator.
Our own usage belongs under the same test. RankShield Energy is a pre-applicant engaged in early interaction with the NRC, holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the agency [[13]](#src-13). We do not describe our work as unmanned or as fully autonomous, and we treat both descriptions as inaccurate rather than as aspirational shorthand. What we build is the assurance layer: evidence about what a reactor did that a party other than the operator can check. If you want these questions turned on developers generally, including on us, they are collected in our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor).

## Frequently asked questions

### What is the difference between automation and autonomy in a reactor?
Automation is a machine performing a defined function when a defined condition is met, following logic fixed in advance by people who anticipated that condition. Autonomy is a system acting across a range of conditions without an operator directing each action, including conditions that were not individually enumerated. That is why the licensing questions differ. Sandia frames the automation problem as how functions are allocated between people and machines <sup><a href="#src-7">[7]</a></sup>, while Oak Ridge, addressing autonomous operation, names preconditions such as long-term unattended sensing and complete system state awareness <sup><a href="#src-5">[5]</a></sup>. Automation is decades old in reactors. Autonomy is a stronger claim that has to be evidenced separately.

### Is remote operation the same as remote monitoring?
No, and conflating them is the most common error in this vocabulary. Monitoring is collecting and observing plant data. Remote operation is exercising command and control from outside the site boundary, meaning someone can change what the plant does. The NRC and Idaho National Laboratory characterized offsite monitoring and remote operation as two distinct human factors topics inside a single study rather than as one topic <sup><a href="#src-3">[3]</a></sup>. The practical test is a single question: from that console, can anyone change reactor power? If the answer is no, what you are looking at is monitoring.

### Does proposed Part 57 allow unmanned reactors?
No. Unmanned is not a regulatory category at all, so no rule grants it. Proposed 10 CFR Part 57 contemplates remote operation and reduced on-site staffing, and it was published on May 1, 2026 <sup><a href="#src-1">[1]</a></sup>. It is proposed rather than final, the comment period closed in June 2026, and the rule may change before it issues. Meanwhile 10 CFR 50.54(m) requires a licensed operator at the controls at all times <sup><a href="#src-2">[2]</a></sup>. Human involvement in safety-significant actions remains the baseline, and no facility is licensed to operate unattended.

### Has anyone actually demonstrated autonomous reactor control?
In research settings, yes, and the qualifier matters. Idaho National Laboratory reported in July 2026 that researchers achieved remote, autonomous power control of a research reactor in real time <sup><a href="#src-9">[9]</a></sup>. The Department of Energy separately reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe <sup><a href="#src-10">[10]</a></sup>. Both are real results from national laboratory programs. Neither is a licensed commercial power reactor running that way, and citing them as if they were is exactly the slippage this article is about.

### Why does RankShield Energy avoid the words unmanned and fully autonomous?
Because we think both are inaccurate, not because they are impolite. Unmanned corresponds to no regulatory status a facility can hold, and fully autonomous describes an end state no current operating framework recognizes. Using either would mean claiming something that cannot be checked against any rule. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval <sup><a href="#src-13">[13]</a></sup>. Our work is the assurance layer, meaning evidence about reactor behavior that a party other than the operator can verify, and we would rather describe that precisely than reach for a word that sounds larger.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Trusting a remotely operated reactor →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects reactor-operation terminology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations/

# Digital Twin as a Remote Reactor Verification Layer

> A digital twin can do more than simulate. See how it becomes a verification layer that independently confirms reactor state for remote and autonomous operation.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# The Digital Twin as a Verification Layer for Remote Reactor Operations
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. A digital twin becomes a verification layer, rather than a simulation, when an independent party uses it to confirm that a reactor’s reported state matches what its physics and its design permit, and records that confirmation so someone outside the control room can check it later. A twin that only mirrors the operator’s own model reassures the operator. A twin used as an independent check tells an outsider something they can rely on. The difference is who runs it.
"Digital twin" now appears in nearly every advanced-reactor pitch, usually offered as proof that the vendor understands its own machine. Understanding your own machine is table stakes. The harder question, for a reactor designed to run remotely and with fewer people on site, is whether the twin can tell an outside party something that party can trust. In July 2026 Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[4]](#src-4). The MARVEL microreactor experiment pairs remote monitoring with a digital twin that supports operator functions [[2]](#src-2), and proposed federal rules now contemplate exactly this kind of remote, reduced-staffing operating model [[10]](#src-10).
This article is educational. It sets out what separates a twin that simulates from a twin that verifies, why that separation depends on who owns the twin, what the standards world already worked out about independent checking, why remote and autonomous operation raises the stakes, and what has actually been demonstrated so far. The part most vendor material skips is the last one. RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission, engaged in early regulatory interaction and holding no license or approval; the closing section applies the argument to us as unsentimentally as to anyone else.
Key takeaways

- A twin that mirrors the operator's own model is simulation; a twin that confirms measured reactor state against model and design limits is verification.
- Verification requires closing the loop: read live measurement, compare it against what the model and design permit, and record any divergence.
- Independence is structural, not intentions: a vendor-internal twin is self-attestation, because the party being checked owns the checker.
- The attestation standards world already split evidence, independent appraisal, and durable records; a verifying twin can borrow that machinery.
- As on-site presence thins under remote-operation rules, more of the safety story rests on self-report, making an independent check more load-bearing, not less.

## Simulation and verification answer opposite questions
A simulation predicts what a reactor should do. A verification layer confirms what the reactor is actually doing. The two use similar math and are easy to conflate, but they point in opposite directions, and a digital twin can be built to serve either one.
A simulation runs the model forward and produces an expected state. It is a forecast. Verification starts from the reactor's reported state and asks whether that state is consistent with the model, the sensors, and what the design permits. It is a check on reality. A twin used purely as a design, training, and monitoring tool is a high-fidelity simulation, and a valuable one. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted the system's thermal behavior and then autonomously controlled it, which is exactly the forecast-and-act pattern a design twin is good at [[1]](#src-1). National-lab work also shows a twin operating alongside remote monitoring in the MARVEL experiment, where the twin is meant to support operator functions rather than replace human oversight [[2]](#src-2).
The problem is that a simulation which agrees with the operator's own assumptions cannot, on its own, tell an outside party that the physical reactor is behaving. It can only tell you the model is internally consistent. To become verification, the twin has to be fed live measurement and made to disagree when the measurement and the model diverge. Not a mirror of the operator's model. A check on it. That shift, from forecasting an expected state to confirming an observed one, is the whole distinction this article is built on, and most vendor material blurs it.

## Closing the loop between measured and modeled state
A digital twin verifies reactor state by closing the loop between measured and modeled state. That means three things happen continuously: the reactor is measured, the measurement is compared against what the model and the design allow, and the comparison is recorded so it can be checked later. A twin that skips any of the three is forecasting, not verifying.
First, live measurement. Temperatures, power level, control positions, and the status of safety functions are read from the reactor itself. Oak Ridge National Laboratory, surveying what autonomous microreactor operation would require, named the preconditions plainly: sensor and instrumentation technologies capable of long-term unattended operation, complete awareness of system state, and control approaches that can act on that awareness [[3]](#src-3). None of the downstream verification works if the measurement layer is thin. Second, comparison. The twin computes what the measured quantities should be, given the model and the commands the reactor received, and flags where measured and modeled values disagree beyond an expected margin. Third, recording. The comparison, and any divergence, is written to a tamper-evident record that a regulator, insurer, or lender can inspect afterward. The path from raw signals to that durable record is its own engineering problem, which we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).
The value of closing the loop is that disagreement becomes visible. A twin that only forecasts will produce a clean-looking state whether or not the hardware agrees with it. A twin that continuously compares measured against modeled state surfaces the gap the moment it opens. When Idaho National Laboratory demonstrated remote, real-time autonomous power control of a research reactor in July 2026, the reactor's safety systems retained control throughout, which is the kind of live, closed-loop operating context in which a verifying twin has to function [[4]](#src-4).

## The independence question: whose twin does the verifying
Closing the loop is necessary but not sufficient. The remaining question is who owns the twin doing the checking. If the operator builds, runs, and interprets its own digital twin, that twin is part of the operator's self-report, however good the engineering is. It is the operator grading its own work, and an outside party has no independent basis to rely on the grade.
Independence here is structural, not a matter of good intentions. A verification result carries weight for a lender, insurer, or regulator only when the party producing it is separate from the party being checked, so the checker has no stake in the reactor looking good. Nuclear already supplies this separation with people rather than software. The NRC stations resident inspectors at operating plants, at least two per site, and describes their function as independently verifying that requirements are being met [[12]](#src-12). The word independently is doing specific work in that sentence: the inspector is not a better observer than the operator, but a differently positioned one. The same reasoning is what separates a twin that reassures from a twin that verifies, and it is the core of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
Applied to a digital twin, independence means the appraisal and the recorded result should sit with a party separate from the operator, rather than inside the operator's own software. A vendor-internal twin answers a narrow question: does our model agree with our model. An independent verification layer answers a harder one: does the reactor agree with reality, in a form someone other than the vendor can check. Those are not the same claim, and conflating them is how a simulation gets sold as an assurance. In my view, drawn from building verification systems rather than operating reactors, this distinction is the entire game, and it is the part a buyer should press hardest.

## Vendor-internal twin versus independent verification twin
The cleanest way to see the difference is side by side. A vendor-internal twin and an independent verification twin can run identical physics and still produce assurances of very different value, because value here comes from who owns the checker and what an outsider can rely on, not from model fidelity. The comparison below is the test to apply to any twin a developer points to.

Vendor-internal digital twin and independent verification twin, compared

Question
Vendor-internal twin
Independent verification twin

Who owns and runs it?
The reactor's operator or vendor
A party separate from operations

What does it actually answer?
Does our model agree with our model
Does the reactor agree with reality, checkably

Who interprets a disagreement?
The operator, privately
The independent verifier, on the record

What can an outsider rely on?
The operator's word
A signed appraisal a third party can check

Characteristic failure mode
Undetectable drift between claim and reality
Detectable divergence, with a timestamped record

The fourth row is where most systems marketed as verification quietly fail. If the only thing an outside party ends up relying on is the operator's word, the twin added polish, not assurance. Computing formalized this split long ago: the RATS architecture defines an Attester that produces evidence, a Verifier that appraises it against a policy, and a Relying Party that acts on the Verifier's result, on the premise that one end of a link needs to know whether the other end is in an intended operating state [[5]](#src-5). A verification twin is that pattern applied to a reactor, with the Verifier deliberately placed outside the operator.

## What the attestation standards already contribute
The independent-checking problem is not new, and the digital-twin conversation does not have to solve it from scratch. Standards bodies outside nuclear have already defined how a separate party appraises a system's reported state and how the result is recorded so anyone can check it later. A verification twin can borrow that machinery directly.
The RATS architecture supplies the roles: evidence, an independent appraisal, and a relying party who consumes the verdict rather than the raw claim [[5]](#src-5). The missing piece, durability, is addressed by transparency work such as SCITT, which describes an append-only, tamper-evident service that issues receipts, so a recorded appraisal can be checked later without asking the operator to vouch for it [[6]](#src-6). Both matter for a reactor precisely because the record needs to outlive the equipment, the software version, and possibly the vendor. On the nuclear side, the guardrails are also taking shape. The NRC has published guidance on digital instrumentation and control for advanced reactors, which is the regulatory frame any verifying twin would have to live inside [[8]](#src-8). The IAEA's guidance on computer security of instrumentation and control systems sets expectations for protecting that measurement and reporting chain across its life cycle, which is exactly the chain a verification twin depends on [[9]](#src-9).
None of this is a RankShield invention, and we do not present it as one. The contribution is applying a settled pattern from computing and international guidance to reactor state, then being honest that the reactor-specific version has not been demonstrated under regulatory review. A standard tells you how independent appraisal should be structured. It does not, by itself, prove that any particular twin is doing it. That gap between an available architecture and a demonstrated capability is where careful reading of vendor claims pays off.

## Why remote and autonomous operation raises the stakes
For a conventionally staffed plant, weak evidence is partly offset by presence: people on site form judgements that instrumentation misses. Thin that presence and the offset goes with it, which is why independent verification moves from good practice to something closer to a requirement as operating models change. The regulatory direction of travel makes this concrete.
Today, federal rules require a licensed operator to be present at the controls at all times [[11]](#src-11). The proposed 10 CFR Part 57 framework contemplates remote operation and reduced on-site staffing for microreactors, a shift explained neutrally in [our walkthrough of Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), and it is a proposed rule, not final, that may change [[10]](#src-10). The national laboratories have been explicit about what this disturbs. Sandia National Laboratories, working on human factors for automating microreactors, described designs in which one control room supervises multiple reactors [[14]](#src-14), which is the [fleet-scale version](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) of the problem and a harder one. Brookhaven National Laboratory, reviewing facilities without traditional main control rooms for the NRC, framed the safety question as verifying that important human actions can still be performed accurately and reliably [[7]](#src-7). Work by the NRC and Idaho National Laboratory on the human factors of offsite monitoring and remote operation points the same way [[13]](#src-13).
Put together, the pattern is straightforward. As on-site presence decreases, the share of the safety story carried by what the system reports about itself increases. A digital twin used as an independent verification layer is one way to keep that curve from ending somewhere uncomfortable, because it puts a separate party between the reactor's self-report and the outside world that has to act on it. Reactivity and safety actions still keep a human in the loop; the twin adds assurance about what is reported, not unsupervised control.

## What has actually been demonstrated, and where it is thin
The honest state of the field is that the operating model is being demonstrated faster than the independent-verification layer for it is being built. That asymmetry is the single most important thing a reader should take from this post, because it is the part vendor decks tend to skip.
On the capability side, the results are real and attributable to the labs. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that forecast the system's behavior and then autonomously controlled it [[1]](#src-1). In July 2026, INL and university partners demonstrated remote, real-time autonomous power control of a research reactor, with safety systems retaining control throughout [[4]](#src-4). The MARVEL experiment pairs a twin with remote monitoring to support operator functions [[2]](#src-2). These are national-lab results, not demonstrations of any commercial reactor's safety, and none of them is RankShield Energy's result.
A fair counterargument is that a sufficiently rigorous vendor-internal twin, audited by regulators, delivers the same assurance without a separate verifier, so the independence point is overstated. The response is that regulatory audit is itself an external check, which proves rather than refutes the point: the assurance comes from a party outside operations, whether that party is an inspector, an auditor, or an independent verifier. Removing the external party is what weakens the claim, not adding one. The honest limitation is that turning demonstrated remote-operation capability into an independent, buyer-facing verification layer, one an outsider can rely on without asking the vendor to vouch for itself, is still in progress across the industry, including at RankShield Energy. Anyone presenting a digital twin as settled proof that an autonomous reactor is safe is overstating where the field is; the accurate framing, for every serious developer, remains design intent subject to analysis, testing, and NRC review. How a buyer should probe a reported state is the subject of [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## Applying this at RankShield, honestly
RankShield Energy treats the independent verification twin as an architecture it applies, not a capability it has deployed or certified. We are a pre-applicant with the NRC, engaged in early regulatory interaction, and we hold no license, permit, or design approval. We have never operated a reactor, and nothing about our approach has been demonstrated to or accepted by the NRC.
What we actually build toward is the separation described throughout this post: an appraisal of reactor state, and the recorded result of that appraisal, sitting with a party structurally distinct from whoever operates the reactor, so that confirming a reported change does not depend on the operator's word. Our real working expertise is in the verification engineering, the signing, the transparency logging, and the independent-appraisal design, not in operating nuclear plants, and we try to keep that line bright. The same separation applies to the harder question of trusting a remotely operated reactor's command state, which a verifying twin only partially addresses.
Stated so it can be argued with: a vendor cannot be its own independent verifier, and that remains true of us, which is why we treat the separation as structural rather than as a feature to bolt on later. The tradeoff is genuine. A separate verifier adds a party to coordinate with and creates a body that can contradict us in public, and we think that last property is the point rather than a defect. If you are evaluating developers on any of this, apply the questions in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) to us as unsentimentally as to anyone else.

## Frequently asked questions

### What is the difference between a simulation and a digital twin used for verification?
A simulation predicts what a reactor should do; a verification twin confirms what the reactor is actually doing and records the result so it can be checked later. Every verifying twin contains a simulation, but not every simulation verifies anything. A twin that only runs the model forward, without being fed live measurement and made to disagree when measurement and model diverge, is a forecast. DOE has reported national-lab work where a twin predicted a simulated microreactor's behavior and then acted on it, which is the forecast-and-act pattern rather than the check-against-reality pattern <sup><a href="#src-1">[1]</a></sup>.

### Can a vendor's own digital twin count as independent verification?
No, not on its own. A vendor-internal twin is run and interpreted by the same party that operates the reactor, which makes it a form of self-attestation: the operator grading its own work. For an outside party such as a regulator, insurer, or lender, the result carries weight only when the appraising party is structurally separate from the operator. Nuclear already supplies that separation with people; the NRC describes its resident inspectors as independently verifying that requirements are being met <sup><a href="#src-12">[12]</a></sup>. An independent verification twin applies the same logic in software.

### What does closing the loop between measured and modeled state mean?
It means the twin continuously does three things: reads live measurement from the reactor, compares that measurement against what the model and the design permit, and records any divergence in a tamper-evident form. A twin that skips the measurement or the recording is forecasting, not verifying. Oak Ridge National Laboratory named the preconditions for this, including sensors capable of long-term unattended operation and complete awareness of system state <sup><a href="#src-3">[3]</a></sup>. Closing the loop is what makes a disagreement between claim and reality visible instead of silent.

### Why does remote or autonomous operation make an independent twin more important?
Because on-site presence was quietly doing part of the assurance work. Current rules require a licensed operator at the controls at all times, while the proposed Part 57 framework contemplates remote operation and reduced staffing, a proposed rule that is not final <sup><a href="#src-10">[10]</a></sup>. National-lab research has described one control room supervising multiple microreactors <sup><a href="#src-14">[14]</a></sup>. As presence thins, more of the safety story rests on what the system reports about itself, which makes an independent check on those reports more load-bearing, not less. Safety actions still keep a human in the loop.

### Does RankShield Energy have a working independent verification twin today?
No, not as a deployed or certified capability. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval, and we have never operated a reactor. The independent verification twin is an architecture we apply and build toward, drawing on established attestation and transparency patterns, but describing an architecture is not the same as having demonstrated it under regulatory review <sup><a href="#src-10">[10]</a></sup>. We would rather state that plainly than let the distinction blur, because the distinction is the entire argument.

## Sources

- [U.S. DOE Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)

## Related

- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [From reactor sensors to an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor digital-twin and remote-operations work as of July 2026. This area is evolving rapidly; national-lab demonstrations are research results, not commercial approvals, and this page will be reviewed as new results are published.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors/

# Fleet-Scale Verification: One Operator

> When one operator oversees many microreactors, verification has to scale too. See what changes and why independent confirmation matters more at fleet scale.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# Fleet-Scale Verification: One Operator, Many Reactors
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. A single reactor can be watched. A fleet cannot be watched the same way. When one operating organization oversees many microreactors across many sites, human attention becomes the scarce resource, and verification does not scale linearly with the fleet. The cost that grows fastest is not checking each unit. It is reconciling them, and that is the part of the problem nobody has solved yet.
This is worth working through now because the regulatory direction points at it. The NRC's proposed Part 57 rule contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1), and NRC staff have examined licensing and deployment beyond the first unit of a design, including standardization of operational programs [[2]](#src-2). Sandia National Laboratories, working for the NRC, has described designs in which one control room supervises multiple microreactors [[10]](#src-10). None of that is settled law. Part 57 is proposed rather than final, its comment period closed in June 2026, and no developer is licensed under it.
What follows is about the structural problem rather than any product: what changes when one organization oversees many units, why verification does not simply multiply, why the failure mode is quiet, the three properties fleet verification has to have, what the NRC's own oversight direction implies, what the national laboratories have described, what the rules require today, and where the field honestly stands. RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval, we operate no fleet, and we have never operated a reactor. The last section applies the argument to us.
Key takeaways

- At fleet scale, attention per reactor falls by design, so more of the safety story has to be carried by evidence rather than by presence.
- Verification does not multiply. The dominant cost is reconciliation: deciding whether one unit behaving differently is a sensor, maintenance, real divergence, or nothing.
- The failure mode is quiet. Small anomalies across many units are what human attention handles worst, so differences stop being investigated because they usually amount to nothing.
- Fleet verification has to be per-unit, comparable across units, and checkable by someone outside the operator. Two out of three is not verification.
- Proposed Part 57 contemplates remote and reduced-staffing operation, but it is not final, the comment period closed in June 2026, and it grants no approval today.
- Honest status: no commercial microreactor fleet is operating, so fleet-scale independent verification exists nowhere, including here.

## What changes is that presence stops scaling
With one reactor, oversight can lean on proximity. People are on site, they know the plant, and their judgement fills gaps that instrumentation misses. That is not an informal arrangement. Federal regulation requires a licensed operator to be present at the controls at all times [[5]](#src-5), and the NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, describing their role as independently verifying that requirements are being met [[6]](#src-6).
Now put one operating organization in charge of many units across many sites. The staff-to-reactor ratio falls by design, because that ratio is part of why modular fleets are attractive in the first place. This is not a hypothetical operating model invented for an article. Sandia National Laboratories, working for the NRC on human factors for automating microreactors, described designs in which operators may monitor from a remote location and in which one control room supervises multiple microreactors [[10]](#src-10).
What replaces proximity is reporting. Each unit describes its own condition, and the operating organization assembles a picture from those descriptions. Many distributed industrial systems already work this way and work well. But the change is worth stating plainly, because it is easy to miss: a claim of safe operation stops resting on what an experienced person observed and starts resting on whether the reporting itself can be trusted. At fleet scale, trust in operations becomes trust in evidence, which is the same shift that makes [verifying a single autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) a different exercise from watching a staffed plant.
The table below maps the oversight functions that presence quietly performed, what happens to each one across a fleet, and what has to take over. The last row is deliberately unresolved.

How single-unit oversight functions change at fleet scale. This mapping is ours, offered as a way to structure the question, not as a regulatory framework.

Oversight function
What it relied on with one reactor
What breaks across a fleet
What has to replace it

Noticing that something is off
A person present who knows the plant
Attention per unit falls as the unit count rises
Per-unit evidence that surfaces divergence before anyone has to notice it

Judging whether it matters
Local knowledge and shift-to-shift memory
Many other units compete for the same judgement
Records comparable across units, so a difference reads as a difference

Recording what happened
Logs kept and interpreted by the operator
Volume grows faster than the capacity to review it
Records signed and checkable later without the operator helping

Outside confirmation
Resident inspectors on site
Inspection presence does not scale one-to-one with sites
Evidence a regulator, insurer, or lender can appraise remotely

Escalating when performance degrades
An action matrix tied to a licensed operating plant
No fleet-level equivalent exists for microreactors today
An open question. Named here rather than answered.

## Verification does not multiply, because the real cost is reconciliation
Verifying twenty reactors is not twenty times verifying one. Handled unit by unit, it is worse than linear, and the reason is that the dominant cost is not checking. It is reconciliation.
Reconciliation is the work of deciding what a difference means. Unit seven is running slightly differently from the other nineteen. Is that a sensor drifting, a maintenance action nobody logged clearly, a real divergence in how that unit is behaving, or nothing at all? Answering that question requires comparing unit seven against its own history and against its siblings, then forming a judgement that is rarely clean. Each additional unit adds a check, but it also adds a new set of comparisons, and comparisons are where the hours go.
This is the claim in this article that we would most like people to argue with, because it cuts against how fleet oversight is usually sold. The pitch is normally aggregation: one screen, all units, green across the board. Aggregation does not remove reconciliation cost. It relocates it, and often it hides it, because a fleet rollup is precisely the presentation in which one divergent unit disappears into an average. A dashboard that is green because nineteen units are fine is not evidence about the twentieth.
The design consequence follows directly. If reconciliation is the expensive part, then the fleet has to emit evidence in a form that makes comparison cheap and divergence conspicuous, rather than leaving reconciliation as an exercise performed by whoever happens to be on shift. That is an argument about the shape of the record, not about how hard people are working, and it starts at the point where a sensor reading becomes something durable, which is the chain we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).

## The failure mode is quiet, not dramatic
The way fleet oversight degrades is not a missed alarm during a crisis. It is a slow normalization in which small differences stop being investigated because they usually amount to nothing.
The mechanism is ordinary and well known outside nuclear. Sustained monitoring of mostly uneventful signals degrades human detection performance over time, which is why vigilance is treated as a design constraint rather than a matter of diligence. Add volume and the second effect arrives: when most flagged differences turn out to be benign, the flags themselves lose meaning, and the rational response of a competent person managing many units is to triage harder. Neither effect is a failure of character. Both are predictable properties of the task, and a fleet is a machine for producing exactly the input that triggers them, which is a high rate of small, mostly uninteresting variation spread across many units.
This is why human factors work in this area treats the human and automation interface as a safety-relevant question rather than a usability nicety, and why function allocation between people and machines is the framing rather than whether machines act at all [[10]](#src-10). Brookhaven National Laboratory, reviewing facilities without main control rooms for the NRC, put the safety question precisely: the issue is not so much justifying why a design has no main control room, but verifying that important human actions can be accurately and reliably performed [[11]](#src-11).
Apply that formulation to a fleet and it does real work. If one of the important human actions is investigating a divergence, then the reliability of that action is a safety question, and it is a question about workload and evidence quality rather than about competence. An organization can staff a fleet with excellent people and still build a system in which the twentieth anomaly of the week gets three seconds of attention. Designing against that means the evidence has to do more of the noticing.

## Fleet verification has to be per-unit, comparable, and externally checkable
Three properties have to hold at once. Any two without the third produces something that looks like verification and does not function as it.
**Per-unit.** Verification attaches to an individual reactor, not to a fleet average. A fleet-level summary that smooths individual behavior is a management view, and management views are useful, but averages are exactly where a single divergent unit becomes invisible. If the artifact cannot be pulled apart into one record per unit, it is not verification of any unit.
**Comparable across units.** If each reactor reports in its own idiosyncratic format, reconciliation stays manual and the cost of oversight grows with fleet size. Comparability is what allows an anomaly to stand out against its siblings rather than requiring a person to notice it unaided. This is also where standardization stops being a procurement convenience and becomes an oversight property.
**Checkable by someone outside the operator.** At single-reactor scale, a regulator can partly compensate for weak evidence with inspection. Across a distributed fleet that compensation does not scale either, which makes machine-checkable evidence more load-bearing rather than less. The architecture that formalizes this separation is settled outside nuclear: RFC 9334 defines an attester that produces evidence about its state, a verifier that appraises that evidence against a policy, and a relying party that acts on the verifier's result [[14]](#src-14). The point of the split is that the party with a stake in the answer is not the party producing it, which is the whole of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The obvious objection is that industrial fleets already run on remote monitoring platforms, and that a well-built one covers all three properties. Sometimes it covers the first two. The third is where these systems generally stop, because they are built to give the operating organization a better view of its own assets, which is a legitimate and different goal. The test that separates them is simple to state and uncomfortable to answer: what could a regulator, insurer, or lender establish about unit seven last month if the operator declined to help, or no longer existed? If the answer depends entirely on the operator's cooperation, the platform is operations tooling. It may be excellent operations tooling.

## The NRC's own oversight direction points at scale and standardization
The regulator has been working on this longer than the vendors have. SECY-20-0093, in October 2020, flagged autonomous operation, remote operation, staffing, and regulatory oversight as open policy questions specific to microreactors [[4]](#src-4). Those questions did not have clean answers inside a framework built for large light-water plants, and naming them was the useful act.
More recently the staff has been planning for repetition rather than for one-off projects. SECY-25-0052 addresses nth-of-a-kind microreactor licensing and deployment, including standardization of operational programs [[2]](#src-2). That is the regulatory shape of many similar units rather than a handful of bespoke ones, and standardization has a direct consequence for verification: units built and operated to a common program are units whose records can be compared. Separately, NRC staff have proposed operational-phase oversight built on a scalable inspection footprint [[3]](#src-3), which is the agency acknowledging in its own terms that inspection presence cannot grow one-for-one with sites.
Set that against what oversight rests on today. The Reactor Oversight Process is risk-informed and tiered, built on safety cornerstones, NRC-developed inspection findings, licensee-reported performance indicators, a significance determination process, and an action matrix that escalates as performance degrades [[7]](#src-7). The Government Accountability Office has described the agency's safety assurance as resting on exactly that, the monitoring and inspection of the activities with the greatest effect on safety [[8]](#src-8).
Two things follow. The first is that performance indicators reported by the licensee are already part of the structure, so the idea of an operator supplying evidence about itself is not foreign to nuclear oversight. The second is that the balance shifts. As inspection presence per unit thins, the licensee-reported share of the picture grows, and the quality of that reporting stops being an administrative matter. It is also worth noting that readiness is not assumed even by the agency's own overseers: GAO reported in July 2023 that the NRC needed to take additional actions to prepare to license advanced reactors [[9]](#src-9). That is a reason to design evidence carefully now, not a reason to wait.

## The national laboratories have already described the fleet operating model
This is not a scenario the industry invented for marketing. Sandia, working for the NRC, described designs where operators may not be located on site and where one control room supervises multiple microreactors [[10]](#src-10). That single clause carries most of the difficulty in this article, because supervising several units from one room changes what a supervisor can actually attend to.
Oak Ridge examined what autonomous control disturbs and found it reaches well past headcount, into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and event notifications, with the control room possibly not co-located with the plant [[12]](#src-12). Each of those is a place where fleet scale multiplies the question rather than repeating it. Technical specifications for one unit are a document. Technical specifications across a fleet, with per-unit deviations and per-unit histories, are a reconciliation problem.
Oak Ridge's work on concepts for autonomous operation of microreactors names the engineering preconditions plainly: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring and control [[13]](#src-13). None of those are trivial, and the third one changes character at fleet scale, since a common software stack across many units is efficient and is also a common surface. That tension is the subject of [microreactor cybersecurity](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained) and it is not resolved by verification alone.
Read together, the lab record supports a narrow and specific conclusion. The operating model of one organization supervising many remote units is described in the literature as a design direction being studied. It is not described as a validated arrangement with a settled oversight answer, and the Brookhaven framing about verifying that important human actions can be accurately and reliably performed [[11]](#src-11) is the standing test that a fleet architecture would have to meet.

## What the rules require today, and what is only proposed
The current baseline is unambiguous. The conditions of an operating license require a licensed operator to be present at the controls at all times [[5]](#src-5). Whatever a fleet architecture eventually looks like, that is the rule as it stands, and no fleet of microreactors is operating under any different arrangement in the United States today.
The proposed 10 CFR Part 57 framework contemplates remote operation and reduced on-site staffing for microreactors, published in the Federal Register on May 1, 2026 [[1]](#src-1). Three qualifications belong in the same breath every time it is mentioned. It is proposed and not final. Its comment period closed in June 2026. No developer is licensed under it, including us. A walkthrough of what the proposal actually says is in [our explainer on Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), and the honest summary is that it sets a direction rather than granting a permission.
It is worth being explicit about what this article is not describing, because the vocabulary in this space runs ahead of the facts. Nothing here describes an unmanned plant, and nothing here describes fully autonomous operation in the sense of a reactor running without human involvement in safety-significant actions. No facility is licensed to operate that way. Human-in-the-loop for reactivity and safety actions is the assumption throughout, and a verification layer does not change it, because a verification layer produces evidence rather than control.
That distinction also answers a question we get asked in a different form: whether better evidence could substitute for the operator or the inspector. It could not, and the argument here does not require it to. The NRC's oversight of licensees stays with the NRC [[7]](#src-7). Independent verification is a technical function that supports regulatory oversight rather than replacing any part of it, and the reason to build it is that the mechanisms outsiders have historically relied on to know anything at all get thinner as unit counts rise.

## Where this actually stands, including where we stand
Nobody is running a commercial microreactor fleet, so nobody is running fleet-scale independent verification. That is the whole status, and it is worth saying without softening. Any vendor presenting fleet verification as a proven, deployed capability is describing an intention. The regulatory framework that would allow the operating model is proposed and not final [[1]](#src-1), and the national-lab work referenced throughout this article consists of research and demonstrations by the laboratories, which belong to those institutions and are not evidence about any vendor's product, ours included.
RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval. We operate no fleet, and we have never operated a reactor. Nothing about our design has been demonstrated to or accepted by the NRC. Our working expertise is on the verification side rather than the operating side: independent verifiers, signing, transparency logs, and the question of what an outside party can check without cooperation from the party being checked.
Here is a concrete decision from that work, stated with what it costs. We design toward per-unit signed records rather than fleet rollups, even though rollups are cheaper to produce, easier to store, and far more pleasant to demonstrate. The tradeoff is real. Per-unit records mean more artifacts, more storage, more surface to keep consistent, and a system that surfaces more differences to a human than a smoothed fleet view would. We accept that because a rollup answers a question about the fleet, and the question that matters in an incident is about one unit. We would rather explain the extra noise than explain, later, why the divergent unit was inside an average.
The honest limitation is that our own architecture is subject to the same test we just applied to everyone else. A verification layer built and run by the party being verified is self-attestation with better engineering, which is why verifier and operator separation has to be structural rather than added later, and why we think a party that can publicly contradict us is a feature rather than a defect. We are not there. If you are evaluating developers on any of this, the questions are in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.

## Frequently asked questions

### Does proposed NRC Part 57 allow one operator to run many reactors?
Not today, and the proposal itself grants nothing. Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors, which points toward fleet-style oversight <sup><a href="#src-1">[1]</a></sup>, but it was published on May 1, 2026, its comment period closed in June 2026, it is not final, and no developer is licensed under it. Meanwhile the operative rule still requires a licensed operator at the controls at all times <sup><a href="#src-5">[5]</a></sup>. Contemplating an operating model is also not the same as approving a staffing arrangement, which would be evaluated for a specific design under review. Treat it as regulatory direction rather than present permission.

### Why is verifying a fleet harder than verifying one reactor twenty times?
Because the expensive part is reconciliation, not checking. With many units, the work is deciding what a difference means: whether one unit behaving slightly differently is a drifting sensor, an unlogged maintenance action, a genuine divergence, or nothing. Most of those turn out to be benign, and that is exactly the condition under which anomalies stop being investigated. Human detection performance degrades against high-volume, mostly uneventful variation, so the fleet has to produce evidence that makes comparison cheap and divergence conspicuous rather than leaving reconciliation to whoever is on shift.

### What does fleet-scale verification actually have to produce?
Three properties at once. Per-unit records, because a fleet average is where a single divergent unit disappears. Comparability across units, because idiosyncratic per-unit reporting keeps reconciliation manual and makes oversight cost grow with fleet size. And checkability by a party outside the operator, because inspection presence does not scale one-for-one with sites. The third property has a standard form outside nuclear: RFC 9334 separates the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result <sup><a href="#src-14">[14]</a></sup>. Two out of three produces something that resembles verification without functioning as it.

### Is anyone operating a microreactor fleet under independent verification today?
No. No commercial microreactor fleet is operating at all, so fleet-scale independent verification does not exist in practice. What exists is a regulatory proposal that contemplates the operating model and is not final <sup><a href="#src-1">[1]</a></sup>, national-lab research describing designs in which one control room supervises multiple microreactors <sup><a href="#src-10">[10]</a></sup>, and a set of engineering preconditions the labs have named rather than closed <sup><a href="#src-13">[13]</a></sup>. RankShield Energy is a pre-applicant that operates no fleet and has never operated a reactor <sup><a href="#src-15">[15]</a></sup>.

### What should a buyer ask a vendor about fleet operations?
Ask how evidence from each unit is produced, whether it is directly comparable across units, and who confirms it besides the operator. Then ask the harder version: if one unit diverges, who is alerted, what record is created, and could an outside party reconstruct that sequence afterward without the vendor's help. Answers that describe a monitoring dashboard are describing operations, which is necessary but is the operator grading its own work. Today that outside confirmation is supplied largely by people, with roughly 150 NRC resident inspectors in the field whose stated role is independently verifying that requirements are being met <sup><a href="#src-6">[6]</a></sup>. A fleet answer has to say what supplies it when presence per unit falls.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Trusting a remotely operated reactor's command state →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)
- [Turning reactor state into an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [Digital twins and remote reactor verification →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of NRC microreactor rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. Check back if the rule is finalized or the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor/

# How to Evaluate a Microreactor Vendor: Key Questions

> Choosing an advanced reactor vendor means separating verifiable claims from assertions. Here are the questions to ask about verification, autonomy, and status.

[Resources](https://rankshieldenergy.com/resources) / Buyer guidance Buyer guidance

# How to Evaluate a Microreactor Vendor: The Verification Questions to Ask
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Evaluating a microreactor vendor comes down to one distinction: which of their claims can be checked by someone other than them, and which have to be taken on faith. Almost every developer will tell you their design is safe, efficient, and nearly ready. The useful questions are the ones whose answers are verifiable by a third party, or that a vendor cannot answer without revealing where they actually are.
This is a checklist you can apply to any developer in this market, including us. It is written so that it does not flatter RankShield Energy. We are a pre-applicant with the NRC, holding no license or approval [[5]](#src-5), and the final section runs all six questions against our own program and says plainly where we do not have a strong answer.
A note on what this is not. It is not a ranking, it does not name or score other developers, and it does not tell you who to buy from. It gives you the questions, what a strong answer sounds like, what a weak one sounds like, and enough public reference points to check the answers yourself after the meeting.
Key takeaways

- The test is not whether a vendor claims something, it is whether anyone other than the vendor can check it.
- Regulatory status is the easiest claim to verify independently and the one most often blurred in marketing.
- For autonomous or remote designs, ask who verifies reactor state and whether that party is separate from the operator.
- A vendor claiming a completed NRC cybersecurity approval is describing something that does not exist in final form.
- Ask what staffing the business case assumes and what must change regulatorily to permit it. Costs quoted without that premise are not comparable.

## Why evaluating an autonomous or remote design is different
Conventional plant diligence leans on things you can go and look at: an operating record, a staffed control room, inspectors on site. That surface is real. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, whose stated role is independently verifying that requirements are being met [[1]](#src-1), inside an oversight process built on inspection findings, performance indicators, and a significance determination process [[2]](#src-2).
A microreactor designed for reduced on-site staffing removes much of that. Proposed Part 57 contemplates remote operation and reduced staffing [[3]](#src-3), and NRC staff have separately proposed operational-phase oversight built on a scalable inspection footprint [[4]](#src-4). Fewer people on site, fewer inspector-hours per unit.
The consequence for a buyer is specific. More of what you can know about the reactor arrives as data the operating organization reports about itself. So diligence has to move upstream, from checking outcomes to checking who is positioned to confirm them. That is what the questions below are built to test.
None of these require you to be a nuclear engineer, and none require a vendor to disclose anything proprietary. They test the structure of a claim rather than the physics behind it.

## Question one: what is your exact regulatory status today
This is the easiest claim to verify without the vendor's help, and the one most often softened. A developer in pre-application engagement has not been granted a license, a permit, or a design approval, and pre-application produces no safety finding [[5]](#src-5). That is public.
The vocabulary is close enough to blur deliberately or accidentally. A **pre-applicant** is engaging with the regulator before submitting. An **applicant** has submitted and is under review. A **licensee** holds a license. Phrases like "working with the NRC," "in the NRC process," or "NRC-engaged" can describe any of these, or the earliest.
Two follow-ups do real work. Ask which framework they are pursuing: Part 53 was finalized in March 2026 as a risk-informed, technology-inclusive framework and is available now [[6]](#src-6), while the microreactor-specific Part 57 remains proposed with its comment period closed [[3]](#src-3). A developer betting entirely on a rule that is not final carries schedule risk a developer using an available pathway does not.
Then ask what they expect to submit next, and when. A credible answer names a document. A vague one names a quarter. The distinction between [pre-application and approval](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) is where most marketing language quietly lives.

## Question two: which safety claims are demonstrated, and which are design targets
Every vendor will tell you their design is safe. The useful question is what "safe" is resting on: qualified analysis and test data, or intent that has not been through regulatory review yet.
A strong answer separates the two without prompting and volunteers what testing is still owed. A weak answer presents every safety characteristic as settled. The tell is whether a developer can name a weakness at all.
Context helps you calibrate. Real capability has been demonstrated at national-laboratory scale: DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[7]](#src-7), and INL's MARVEL project exists to test remote monitoring and develop autonomous control technologies [[8]](#src-8). Those are genuine results.
They are also lab results, not commercial operating experience, and they belong to the laboratories rather than to any vendor. A developer citing national-lab demonstrations as though they were their own operating record is doing something you should notice.

## Question three: who verifies reactor state, and are they separate from you
This is the question with the most signal and the one least often asked. If the reactor reports its own condition and the vendor evaluates that report, an outside party has nothing independent to rely on.
The precedent is not speculative. IAEA safeguards exist so that an outside body applies technical measures to independently verify rather than relying on an operator's assertion [[9]](#src-9). Computing standardized the same separation in RFC 9334, splitting the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [[10]](#src-10).
Ask what happens to the result afterwards, because present-tense monitoring does not answer past-tense questions. Standards exist for this too: an append-only transparency service that registers signed statements and issues receipts a third party can audit later [[11]](#src-11), with the receipts themselves standardized as compact cryptographic proofs [[12]](#src-12).
A strong answer names a verification function separate from operations and describes what it records. A weak answer points at a monitoring dashboard. That is the whole of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is worth pressing on because the two sound identical in a sales conversation.

## Question four: which cybersecurity standards, and what is their status
Digital instrumentation and autonomous control change the threat model, and the honest state of the field is that requirements for advanced reactors are still being written. NRC guidance for digital I&C review of non-light-water reactors exists [[13]](#src-13), and cyber requirements for advanced reactors remain consequence-based and in development rather than finalized [[14]](#src-14).
International guidance is further along and worth asking about by name. The IAEA has published technical guidance on protecting reactor instrumentation and control systems across their full life cycle [[15]](#src-15), and has an active research project on computer security for small modular and microreactors that names autonomous and remote operations, digital twins, and centralised fleet management with reduced staffing as the conditions to address [[16]](#src-16).
The disqualifying answer here is specific: a vendor claiming to hold a completed NRC cybersecurity approval for an advanced reactor is describing something that does not yet exist in final form. That is not a nuance, it is a factual error, and it tells you how carefully the rest of their claims are made.
A strong answer names the standards they build toward, distinguishes final guidance from proposed rules, and explains how a third party could check the claim. Our fuller treatment is in [microreactor cybersecurity, explained](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained).

## Question five: where does the fuel come from, and what does it do to the schedule
Fuel is the constraint buyers most often underweight, and it is a schedule risk rather than an engineering one. Most advanced designs need HALEU, and a commercial domestic supply chain at the scale the industry will need does not yet exist, which is why the Energy Act of 2020 directed DOE to establish the HALEU Availability Program [[17]](#src-17).
This is not a vendor-specific failing. Almost nobody has solved fuel independently, so it is a poor basis for choosing between developers. What differentiates them is whether they account for it honestly.
A developer who names fuel as a schedule constraint and describes their supply path is giving you a deployment timeline. One whose plan treats fuel as settled is giving you an engineering timeline, which is a different and less useful thing when you are planning around a delivery date. The detail sits in [where HALEU comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel).

## Question six: what staffing and oversight does your model assume
This one is newer and rarely asked, but it determines what the other answers are worth over twenty years. Current regulation requires a licensed operator at the controls at all times [[18]](#src-18). A design premised on reduced staffing is premised on that requirement changing, or on an exemption being granted.
Oak Ridge examined what autonomous control disturbs and found it reaches well past headcount: staffing, manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and event notifications, with the control room potentially not co-located with the plant [[19]](#src-19). Sandia, working for the NRC, described designs where one control room supervises multiple microreactors [[20]](#src-20).
So ask directly: how many operators per reactor does the business case assume, and what has to be true regulatorily for that to be permitted. Then ask the oversight version, because the GAO has reported that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[21]](#src-21), and still lists licensing advanced reactors among its priority open recommendations [[22]](#src-22).
A developer whose economics depend on thin staffing and thin inspection, without a story for how anyone confirms the reactor between visits, has an unpriced risk in the model. That is the [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) problem arriving through the commercial door.

## What a checkable answer sounds like
The pattern across all six is simple. A strong answer points to a document, a standard, a regulator's public record, or a party with no stake in the outcome. A weak answer points back to the vendor.

Vendor evaluation: what a checkable answer sounds like

Question
Stronger answer
Weaker answer

Exact regulatory status
Names the stage and points to the NRC public record
"We are working closely with the NRC"

Demonstrated vs design target
Separates them and says what testing is owed
Presents all safety characteristics as settled

Who verifies reactor state
Names a function separate from operations and what it records
Points to the vendor monitoring dashboard

Cybersecurity standards
Names standards, distinguishes final from proposed
Claims a completed NRC cyber approval

Fuel and schedule
Names HALEU supply as a real timeline constraint
Treats fuel as solved, or omits it

Staffing and oversight assumptions
States operators per unit and what must change regulatorily
Quotes an operating cost without the staffing premise

*Every stronger answer above can be checked after the meeting. Every weaker one cannot. That is the only property the table is really sorting on.*
One practical note on running the conversation. Ask these questions of the technical lead rather than the commercial team, and ask them in the order above, because status constrains everything after it. A developer who is candid about being early will usually be candid about the rest. A developer who blurs status tends to blur the harder questions too, and you will have learned that in the first five minutes rather than the third meeting.
It is also worth asking one deliberately open question at the end: what would have to go wrong for your schedule to slip two years. The content of the answer matters less than whether they have one. Everyone in this industry is carrying fuel risk, licensing risk, and supply-chain risk simultaneously. A developer who cannot name their own largest risk either has not modelled it or does not want to discuss it, and both are things you want to know before signing.
A final note on how to weigh the answers you get. None of these six questions has a single correct response, and a developer being early is not a failing. What you are testing is whether their account of themselves matches what the public record independently shows, and whether they volunteer the limits before you find them. A developer who is candid about being at an early stage, names the specific framework they are pursuing, and describes their fuel and staffing assumptions honestly is giving you something you can plan around. That is worth more than a confident answer you cannot check.

## Applying all six questions to RankShield Energy, honestly
A buyer's guide written by a vendor is worth very little unless the vendor runs the questions against itself, so here are our answers. **Status:** we are a pre-applicant, we hold no NRC license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[5]](#src-5). **Demonstrated versus target:** our reactor safety characteristics are design intent, subject to analysis, testing, and regulatory review, and we have testing still owed before we would characterise them otherwise.
**Verification:** separation of the verifier from the operator is the core of our approach and the reason this site exists, and it is an architecture we apply rather than a deployed, certified capability. **Cybersecurity:** we build toward standards that are themselves still being finalised, so we claim no completed NRC cyber approval. **Fuel:** HALEU supply is a real schedule constraint for us as it is for the field [[17]](#src-17). **Staffing:** our model assumes reduced on-site staffing, which depends on regulatory change that has not happened yet [[3]](#src-3).
If that reads as less confident than a sales page, that is deliberate. A vendor who cannot tell you where they are weak is not giving you information you can plan around. Apply these six questions to us and to everyone else, and weigh the answers the same way.

## Frequently asked questions

### What is the single most useful question to ask a microreactor vendor?
Ask which of their claims can be checked by someone who does not work for them. It reframes the whole conversation. Safety characteristics, autonomy capability, and schedule confidence all sound similar coming from any vendor, but they differ enormously in whether an outside party can confirm them. A vendor who separates demonstrated results from design targets, points to public regulatory records, and describes verification performed by a party separate from the operator is giving you something you can act on. One who presents everything as settled is giving you a brochure.

### Does working with the NRC mean a reactor is approved?
No. Engagement covers a wide range, and the earliest stage, pre-application, grants no license, permit, or design approval and produces no safety finding <sup><a href="#src-5">[5]</a></sup>. A developer can be in genuine, productive contact with the NRC and still be years from submitting an application. The useful follow-up is which specific stage they are at and where that appears in the public record, because the answer is verifiable without their cooperation.

### How can I tell whether autonomy claims are credible?
Ask who confirms the reactor's reported state and whether that party is separate from the operator. Autonomy claims tend to be architectural rather than demonstrated at this stage, so the meaningful question is not how autonomous a design is but how anyone outside the control room would know it is behaving as described. Also listen to the words. "Unmanned" and "fully autonomous" are not regulatory categories, and a vendor using them loosely is describing an aspiration rather than the framework the NRC has proposed <sup><a href="#src-3">[3]</a></sup>.

### Should fuel supply affect which vendor I choose?
It should affect how you read their schedule more than which vendor you pick, because HALEU availability is an industry-wide constraint rather than a vendor-specific failing <sup><a href="#src-17">[17]</a></sup>. What differentiates developers is whether they account for it honestly. One who names fuel as a schedule risk and describes a supply path is giving you a deployment timeline. One who omits it is giving you an engineering timeline.

### What should I ask about staffing costs?
Ask how many operators per reactor the business case assumes, and what has to change regulatorily for that to be permitted. Current regulation requires a licensed operator at the controls at all times <sup><a href="#src-18">[18]</a></sup>, so a model premised on thinner staffing depends on rule changes that are still proposed <sup><a href="#src-3">[3]</a></sup>. An operating cost quoted without stating the staffing premise behind it is not a number you can compare between vendors.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026](https://www.nrc.gov/security/cybersecurity)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program. Accessed July 2026](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of advanced-reactor licensing and standards as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. Check back if the rule is finalized or the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/

# Microreactor Guides: Verification

> Sourced guides to microreactors, reactor verification, autonomy under NRC rules, cybersecurity, and licensing. Written to NRC, DOE, IAEA and IETF sources.

Resources · reactor fundamentals, plainly explained

# Understand the technology, from the ground up.
Clear, sourced explanations of how microreactors work, how reactor state is independently verified, what autonomy actually means under NRC rules, and how advanced reactors are licensed. Every guide is written to authoritative sources and states plainly where our own HELIX design is a target rather than a proven result.
**15** guides · sourced to NRC, DOE, IAEA, IETF and the national laboratories
All Reactor fundamentals Reactor safety Verification & trust Autonomy & Part 57 Cybersecurity Licensing & pre-application Deployment Buyer guidance
[Latest · Deployment Where HALEU Comes From: The Fuel Supply Behind Advanced Reactors HALEU is the fuel most advanced reactors need, and supply is still being stood up. Here is where it comes from and why it shapes deployment timelines. Read the guide →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel) [Verification & trust Fleet-Scale Verification: One Operator, Many Reactors When one operator oversees many microreactors, verification has to scale too. See what changes and why independent confirmation matters more at fleet scale. Jul 24, 2026 →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)[Buyer guidance How to Evaluate a Microreactor Vendor: The Verification Questions to Ask Choosing an advanced reactor vendor means separating verifiable claims from assertions. Here are the questions to ask about verification, autonomy, and status. Jul 23, 2026 →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)[Verification & trust From Sensors to an Attestation Record: How Reactor State Is Confirmed How does raw sensor data become a record a regulator or insurer can trust? Follow the chain from telemetry to a tamper-evident, independently verifiable record. Jul 23, 2026 →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)[Autonomy & Part 57 Automation, Remote Operation, and Autonomy: What the Terms Actually Mean Automation, remote operation, and autonomy are not the same, and the difference is regulatory. See what each term means for microreactors under Part 57. Jul 23, 2026 →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)[Deployment Speed-to-Power for Data Centers: Where Firm Nuclear Fits US data-center load is climbing while interconnection queues stretch. See what firm power actually requires and where advanced nuclear fits on the timeline. Jul 23, 2026 →](https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear)[Licensing & pre-application How the NRC Pre-Application Process Actually Works Pre-applicant does not mean approved. See how NRC advanced-reactor pre-application engagement actually works, step by step, and what it does and does not grant. Jul 23, 2026 →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)[Cybersecurity Microreactor Cybersecurity, Explained: Digital I&C and the New Threat Model Digital instrumentation and autonomous control change the microreactor threat model. See how today's standards point toward independent cyber attestation. Jul 23, 2026 →](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained)[Autonomy & Part 57 Trusting a Remotely Operated Reactor: The Command and State Problem Remote operation splits the operator from the core. Learn the two trust gaps this opens, verified commands and verified state, and how each is being addressed. Jul 23, 2026 →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)[Verification & trust The Digital Twin as a Verification Layer for Remote Reactor Operations A digital twin can do more than simulate. See how it becomes a verification layer that independently confirms reactor state for remote and autonomous operation. Jul 23, 2026 →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)[Autonomy & Part 57 NRC Part 57 and Autonomous Operation, Explained The NRC's proposed Part 57 rule defines autonomous operation for microreactors. Here is what it says, what it does not, and why the trust surface matters now. Jul 23, 2026 →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)[Verification & trust Self-Attestation vs Independent Verification for Autonomous Reactors When a reactor reports its own status, who checks the check? Compare self-attestation and independent verification for autonomous and remote reactor operations. Jul 23, 2026 →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)[Verification & trust How to Verify an Autonomous Microreactor Is Operating Safely An autonomous microreactor runs with fewer people on site. See how independent verification confirms it is operating safely, without taking a vendor's word. Jul 23, 2026 →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)[Reactor safety Walk-away safety, explained Walk-away safety means a reactor shuts itself down and cools itself using physics alone, with no operator, no power, and no pumps. Here is how it works. Jul 21, 2026 →](https://rankshieldenergy.com/resources/walk-away-safety-explained)[Reactor fundamentals What is a nuclear microreactor? A nuclear microreactor is a factory-built reactor producing roughly 1 to 20 megawatts, per DOE, small enough to ship on a truck to where power is needed. Jul 21, 2026 →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
No guides in that topic yet.



---

## Page: https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained/

# Microreactor Cybersecurity and the New Threat Model

> Digital instrumentation and autonomous control change the microreactor threat model. See how today's standards point toward independent cyber attestation.

[Resources](https://rankshieldenergy.com/resources) / Cybersecurity Cybersecurity

# Microreactor Cybersecurity, Explained: Digital I&C and the New Threat Model
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Digital instrumentation and control, plus autonomous and remote operation, change what an attacker can reach in a microreactor, and they change what the safety case depends on. A cyber compromise here can have physical consequences, not just informational ones. This is why the standards landscape keeps pointing in one direction: toward evidence about reactor state that a party other than the operator can independently check.
Reactor cybersecurity is not ordinary IT security, because the systems being protected are the ones that read plant state and move equipment. The NRC frames its cyber work around protecting the digital systems tied to safety and security functions [[1]](#src-1), and its Regulatory Guide 5.71 builds a program around exactly the systems whose compromise would matter physically [[2]](#src-2). When operation moves off site and leans harder on software, more of that safety story travels as data, and the integrity of that data becomes part of the case.
This article covers why reactor cyber is a safety problem rather than an IT problem, how supply chains and connectivity erode the old air gap, how autonomy widens the attack surface, and where the standards actually stand, including which pieces are settled and which are still proposed. It closes with a stated counterargument and an honest limitation. RankShield Energy is a pre-applicant holding no license or approval [[15]](#src-15), and the last section applies the argument to us as unsentimentally as to anyone else.
Key takeaways

- Reactor cyber is a safety discipline: a digital compromise can have physical consequences, so it is scoped around safety-linked I&C, not treated like enterprise IT.
- The air gap has eroded through connectivity and global supply chains, so the threat model has to assume paths in rather than assume isolation.
- Autonomy and remote operation move human actions onto networks, which widens the attack surface without removing the human from safety decisions.
- The standards landscape is mixed: RG 5.71 is existing guidance, proposed 10 CFR 73.110 is under development and not final, and the microreactor-specific case is still being researched.
- Those standards keep pointing toward independent attestation, which RankShield applies as an engineering concept, not a deployed or certified capability.

## Reactor cybersecurity is a safety problem, not an ordinary IT problem
The short answer is that a compromise of the wrong system in a reactor can have physical, not just informational, consequences, and that changes everything about how the risk has to be treated. In ordinary enterprise IT, the worst outcome of an intrusion is usually loss of data, money, or availability. In a reactor, the systems being protected are the instrumentation and control that read plant state and move equipment, so the failure surface includes physical processes rather than only records.
This is why nuclear cyber guidance is written around consequence rather than around convenience. The NRC's Regulatory Guide 5.71 sets out a cyber security program for power reactors that centers on the systems whose compromise could affect safety, security, and emergency preparedness functions, and it builds defensive architecture and controls around exactly those functions [[2]](#src-2). The point is not to secure everything equally, but to identify the systems where a digital compromise becomes a physical problem and to protect those most strongly.
The regulator's own framing keeps cyber tied to the same protective mission as physical security, and its cyber security resources describe the objective as protecting digital systems and networks associated with safety and security functions [[1]](#src-1). That is a narrower and more demanding target than "keep the network safe." It means the threat model has to reason about how a manipulated sensor value or a spoofed command could propagate into the plant.
Advanced reactors sharpen this because they lean harder on digital instrumentation and control than the analog fleet did, and the NRC has published dedicated guidance for digital I&C in that context [[7]](#src-7). The more of the plant that is mediated by software, the more the safety case depends on the integrity of that software and the data moving through it. Treating that as a generic IT problem would miss the part that actually matters, which is why [verifying that a microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) has a cyber dimension that a conventional security audit does not fully cover.

## Why the old air gap no longer protects a microreactor
The honest answer is that the air gap was always partly an assumption, and modern microreactor concepts weaken the parts of it that were real. The traditional mental model was that safety-significant systems sat on isolated networks with no path to the outside world. Two forces erode that: the systems now update, phone home, and integrate with monitoring far more than legacy analog equipment did, and the components arrive through long, global supply chains that carry their own risk before anything is ever connected.
Supply chain is the part that gets underweighted. A component can be compromised in development, manufacturing, or distribution, well before installation, which is why federal guidance now treats cyber supply chain risk as a first-class program rather than an afterthought. NIST SP 800-161r1 lays out practices for managing that risk across the acquisition life cycle, including provenance, integrity, and the assurance of components sourced from third parties [[8]](#src-8). For a reactor built from digital modules, the boundary you are defending starts at the supplier, not at the fence line.
The international standards community reached the same conclusion from the I&C side. IEC 62645 defines requirements for security programs for computer-based systems in nuclear power plants, and it is built around the reality that these systems have life cycles, dependencies, and update paths that must be governed rather than assumed away [[3]](#src-3). It treats security as a program property of the whole system, not a perimeter you draw once.
The IAEA guidance is more explicit still about where the exposure lives. Its Nuclear Security Series No. 33-T addresses computer security of instrumentation and control systems at nuclear facilities and works through the life cycle from design through decommissioning, including the interfaces and remote access paths that a purely perimeter-based model tends to ignore [[4]](#src-4). Put together, the guidance points one direction: for a digital, connected, globally sourced microreactor, "isolated and therefore safe" is not a claim anyone can make at face value, and the threat model has to assume paths in rather than assume them away.

## How autonomy and remote operation widen the attack surface
The direct answer is that every function you move from a person in a control room to software over a network becomes something that can be attacked over that network, and microreactor economics push hard toward exactly that shift. Reduced on-site staffing, remote monitoring, and centralized fleet operation are what make small reactors financially plausible, and each of those design moves converts a physical, local action into a digital, remote one that now has to be secured and verified.
The national laboratories have mapped what this disturbs. Oak Ridge, in its concepts for autonomous operation of microreactors, describes control approaches that reduce human intervention and lean on sensing, state awareness, and remote supervision, and it names the cybersecurity of those monitoring and control paths as a precondition rather than a detail [[13]](#src-13). Autonomy does not remove the human decision so much as move it, and it adds a data path that must be trustworthy for the moved decision to be sound.
Sandia, working on human factors for automating microreactors, examined designs where operators supervise from a distance and where a single control room may oversee multiple units, and it treated the reliability of the human-automation interface as a safety-relevant question rather than a usability nicety [[14]](#src-14). When one operator supervises several reactors through screens fed by remote data, the integrity of that data becomes part of the safety story, which is the through-line of [fleet-scale verification with one operator and many reactors](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
The regulatory frame is catching up to this. The proposed 10 CFR Part 57 rule contemplates licensing microreactors with operating models that include remote and reduced-staffing operation, and it is a proposal rather than a settled requirement [[12]](#src-12). None of this removes the human from reactivity and safety actions, and it should not be read that way. It does mean the attack surface now includes the command, monitoring, and attestation channels that carry operation across a distance, and those channels did not exist in the staffed analog plant. That is explained neutrally in [our walkthrough of Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).

## The standards landscape at a glance, with status
The most important thing to get right about this landscape is status: some of it is existing guidance, some is an international consensus standard, and one central piece is still a proposal. Conflating those is the most common error we see, so the table below separates what a document is from how settled it is. Reading a proposed rule as a present-day requirement, or a research project as a standard, produces bad decisions.

Microreactor cyber standards and frameworks, by scope and status

Instrument
Scope
Status
What it means here

NRC RG 5.71, Rev. 1
Cyber security programs for nuclear power reactors
Existing regulatory guidance for power reactors
The established baseline the field reasons from

Proposed 10 CFR 73.110
Technology-neutral cyber requirements
Proposed, under development, not final or prescriptive
A direction of travel, not a rule anyone meets yet

IEC 62645:2019
Security programs for computer-based I&C
International consensus standard
Widely referenced technical program requirements

IAEA NSS 33-T
Computer security of I&C at nuclear facilities
International guidance
Life-cycle guidance, advisory not binding

IAEA CRP J02021
Computer security of SMRs and microreactors
Active research project
Open questions being studied, not settled answers

Two rows deserve emphasis. The proposed 10 CFR 73.110 is a technology-neutral cyber rule that remains under development and is not final or prescriptive, so it should be read as where the NRC may be heading and not as a requirement in force [[1]](#src-1). RG 5.71 is the existing guidance that the current power fleet actually works from, and it is the concrete reference point when people ask what "good" looks like today [[2]](#src-2).
The international layer runs in parallel rather than underneath. IEC 62645 supplies consensus program requirements [[3]](#src-3), NSS 33-T supplies life-cycle guidance [[4]](#src-4), and the IAEA's coordinated research project J02021 is explicitly aimed at the SMR and microreactor case, which tells you the specialist questions for this reactor class are still being researched rather than resolved [[5]](#src-5).

## Why the standards point toward independent attestation
Read together, these documents keep circling the same requirement: a party that relies on a system needs evidence about that system's state that does not simply come from the system's own operator. That is the definition of attestation, and the general-purpose computing world has already standardized the architecture for it, which is why it is worth borrowing rather than reinventing.
RFC 9334, the Remote Attestation Procedures architecture, formalizes the split cleanly: an Attester produces evidence about its state, a Verifier appraises that evidence against a policy, and a Relying Party acts on the Verifier's result, on the premise that one party needs to know whether another is in an expected operating state before trusting it [[10]](#src-10). Mapped onto a reactor, the operator is not asked to be believed; the operator is asked to produce evidence a separate party can appraise, which is exactly the shape [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) describes.
The supply chain problem has an analogous emerging pattern. RFC 9943 sets out an architecture for trustworthy and transparent digital supply chains using signed statements recorded on an append-only transparency service, so that a later party can check what was claimed and when, without trusting the claimant to have been honest after the fact [[11]](#src-11). For a reactor assembled from digital modules, that maps directly onto proving what software and components went in and stayed in.
Durability is the piece people forget, and it is where cryptography choices become a long-horizon decision. Records meant to outlive a reactor design cycle have to survive advances in computing, which is why NIST's approval of post-quantum signature standards in 2024 is relevant to a nuclear conversation at all [[9]](#src-9). None of this makes a system "unhackable," and we do not use that word, because it is not a property any real system has. Attestation does something narrower and more useful: it makes divergence between claim and reality detectable by someone other than the party making the claim. That is the property the standards keep reaching for.

## What is settled versus what is still proposed
The honest summary is that the direction is clearer than the destination, and it is worth being precise about which is which. What is settled: reactor cyber is a safety-linked discipline, RG 5.71 is the working baseline for the power fleet, and the international standards for computer-based I&C exist and are referenced. What is not settled: the technology-neutral rule aimed at this class, and much of the microreactor-specific detail, is still in development.
The proposed 10 CFR 73.110 illustrates the gap exactly. It is a proposal under development, technology-neutral in intent, and it is not final or prescriptive, so a vendor cannot truthfully say it complies with a rule that does not yet exist in final form [[1]](#src-1). The same discipline applies to the licensing frame around it: proposed Part 57 is a proposal whose provisions may change through the rulemaking process, not a set of requirements in force [[12]](#src-12).
Staff analysis is another place precision matters. The NRC staff paper SECY-24-0008 on micro-reactor licensing and deployment lays out options and considerations for how this reactor class might be licensed, and it is staff analysis rather than a Commission decision or an adopted policy [[6]](#src-6). Reading a SECY paper as settled agency position is a common and consequential misread, because the staff can analyze a path the Commission does not ultimately take. We treat these documents as signals of direction and open questions, not as commitments.
So the defensible posture, and the one we hold, is to design toward where the guidance is clearly pointing while stating plainly that the specific rules for microreactor cyber are not final. That is not hedging for its own sake. It is the difference between a claim that survives contact with a docket and one that does not, and it is the standard we apply when we help others [evaluate a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) on exactly these questions.

## A counterargument, stated plainly and answered
The strongest objection to all of this deserves to be stated in its own words rather than a strawman. It runs like this: nuclear operators already run mature cyber programs under existing NRC guidance, the fleet has a strong operational record, and adding an independent attestation layer is expensive complexity that duplicates controls the operator already has. On this view, self-run cyber programs plus regulatory inspection are sufficient, and a separate verifier is a solution in search of a problem.
That objection has real force for a staffed plant, and we do not dismiss it. Where it weakens is precisely the shift this article is about. When operation moves to remote and reduced-staffing models, the local human checks that quietly backstopped a self-run program thin out, and more of the assurance has to travel as data across a network the attacker can reach. The labs studying autonomous and automated operation flag the integrity of exactly those monitoring and control paths as a precondition, not a side issue [[13]](#src-13) [[14]](#src-14). An independent appraisal of state is not duplicating the operator's controls; it is covering the failure mode where the operator's own reporting path is the thing that is wrong.
The second half of the answer is that the specialist questions here are openly unresolved, which cuts against declaring any current program sufficient for this reactor class. The IAEA is running an active research project specifically on the computer security of SMRs and microreactors, which is a strong signal that the field itself does not consider the microreactor case closed [[5]](#src-5). The NRC's dedicated digital I&C guidance for advanced reactors exists for the same reason: the digital, autonomous case raises questions the analog fleet did not have to answer [[7]](#src-7). Our position, stated so it can be argued with, is that independent attestation is a hedge against an assurance gap that autonomy widens, and that the burden of proof sits with anyone claiming a self-run program alone closes it. This is where [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) stops being abstract.

## Where RankShield sits, honestly, and one limitation
To be clear about our own standing: RankShield Energy is a pre-applicant engaged in early interaction with the NRC. We hold no license, permit, or design approval, and nothing about our design or our attestation approach has been demonstrated to or accepted by the NRC [[15]](#src-15). Independent, verifier-separate attestation of reactor and I&C state is a concept we apply in our engineering work, not a deployed or certified capability, and we will not describe it as one. We do not claim to meet any finalized cyber standard, because for this reactor class the central rule is still proposed and under development.
Where our actual first-hand experience lives is worth naming precisely, because it bounds what we can honestly assert. Our working domain is attestation and verification engineering: independent verifiers, signing, append-only transparency logs, and post-quantum signature choices. That is real hands-on work, and it is the lens through which we read the reactor cyber problem. It is also not reactor operating experience, which we do not have and do not claim, and none of it removes the human from reactivity and safety decisions.
The honest limitation is this: attestation proves properties of records and system state, and it is only as meaningful as the sensors and the appraisal policy behind it. A verifier can prove that a signed measurement was recorded and not altered, and that it matched a stated policy at the time. It cannot, by itself, prove that the underlying sensor was correctly calibrated or that the policy captured every failure worth catching. Those are engineering and analysis problems that sit upstream of the cryptography, and any vendor telling you attestation alone makes a reactor secure is overselling it. We would rather draw that boundary ourselves than have a regulator or a customer draw it for us.
So the defensible claim, and the only one we make, is narrow: as microreactors move toward autonomous and remote operation, the standards landscape is pointing toward evidence a party other than the operator can check, the specific rules for this class are not yet final, and we are building toward the verifier-separate version of that architecture as a pre-applicant with everything still to prove. That is less exciting than a guarantee, and it is the version that will still be true after the rulemaking closes.

## Frequently asked questions

### Why is microreactor cybersecurity treated differently from normal IT security?
Because a compromise can have physical consequences, not just informational ones. The systems being protected are the instrumentation and control that read plant state and move equipment, so a manipulated value or spoofed command can propagate into the plant itself. That is why the NRC's Regulatory Guide 5.71 organizes a reactor cyber program around the systems whose compromise could affect safety, security, and emergency preparedness functions, rather than protecting everything equally <sup><a href="#src-2">[2]</a></sup>, and why the agency ties cyber to the same protective mission as physical security <sup><a href="#src-1">[1]</a></sup>.

### Is the microreactor cyber rulebook finalized?
No. The technology-neutral cyber rule commonly referenced as proposed 10 CFR 73.110 is still under development and is not final or prescriptive, so no vendor can truthfully claim to comply with it <sup><a href="#src-1">[1]</a></sup>. The licensing frame around it, proposed 10 CFR Part 57, is likewise a proposal that may change through rulemaking <sup><a href="#src-12">[12]</a></sup>. Existing guidance such as RG 5.71 is the working baseline for the current power fleet, and international standards like IEC 62645 apply, but the microreactor-specific detail is still being worked out.

### How does autonomy change the threat model?
Every function moved from a person on site to software over a network becomes something an attacker can reach over that network. Oak Ridge's work on autonomous microreactor operation names the cybersecurity of the monitoring and control paths as a precondition <sup><a href="#src-13">[13]</a></sup>, and Sandia's human factors work examines remote supervision and one control room overseeing multiple units, where the integrity of the data feeding those screens becomes safety-relevant <sup><a href="#src-14">[14]</a></sup>. Proposed Part 57 contemplates remote and reduced-staffing operation, and it does not remove the human from reactivity and safety actions <sup><a href="#src-12">[12]</a></sup>.

### What does independent attestation actually add?
It gives a party that relies on the reactor evidence about its state that does not simply come from the operator. The computing world standardized this in RFC 9334, which separates an attester that produces evidence, a verifier that appraises it, and a relying party that acts on the result <sup><a href="#src-10">[10]</a></sup>, and RFC 9943 applies a similar transparency pattern to supply chains so later parties can check what was claimed and when <sup><a href="#src-11">[11]</a></sup>. It does not make anything unhackable, a word we avoid. It makes divergence between claim and reality detectable by someone other than the party making the claim.

### Does RankShield Energy meet the NRC cyber standard today?
No, and it would be inaccurate to say so, because the central rule for this reactor class is still proposed and under development. RankShield Energy is a pre-applicant with no license, permit, or design approval, and nothing about our approach has been demonstrated to or accepted by the NRC <sup><a href="#src-15">[15]</a></sup>. Independent, verifier-separate attestation is a concept we apply in our engineering work, not a deployed or certified capability. Our first-hand expertise is in attestation and verification engineering, not reactor operations, and human-in-the-loop control of safety actions is preserved throughout.

## Sources

- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026 (proposed 10 CFR 73.110 technology-neutral cyber requirements still in development, not final or prescriptive)](https://www.nrc.gov/security/cybersecurity)
- [U.S. Nuclear Regulatory Commission. Regulatory Guide 5.71, Rev. 1: Cyber Security Programs for Nuclear Power Reactors. February 2023](https://www.nrc.gov/docs/ML2225/ML22258A204.pdf)
- [International Electrotechnical Commission. IEC 62645:2019, Nuclear power plants: I&C systems: Requirements for security programmes for computer-based systems. 2019](https://webstore.iec.ch/en/publication/32904)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Nuclear Regulatory Commission. SECY-24-0008: Micro-Reactor Licensing and Deployment (staff paper). 2024](https://www.nrc.gov/docs/ML2320/ML23207A250.pdf)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Turning reactor state into an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor cybersecurity standards and NRC rulemaking as of July 2026. Proposed requirements such as 10 CFR 73.110 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained/

# NRC Part 57 and Autonomous Reactor Operation

> The NRC's proposed Part 57 rule defines autonomous operation for microreactors. Here is what it says, what it does not, and why the trust surface matters now.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# NRC Part 57 and Autonomous Operation, Explained
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Proposed 10 CFR Part 57 is the NRC's draft licensing framework for microreactors, and its most consequential feature is that it contemplates remote operation and reduced on-site staffing. It is a proposal, not law. The comment period closed in June 2026, no developer is licensed under it, and the text can still change before any final rule is issued.
What makes it worth understanding anyway is the direction it sets. Today federal regulation requires a licensed operator to be present at the controls at all times [[6]](#src-6), and the NRC keeps roughly 150 resident inspectors in the field to independently verify that requirements are being met [[11]](#src-11). Part 57 contemplates changing the first of those, and NRC staff have separately proposed a scalable inspection footprint that would change the second [[5]](#src-5).
This guide covers where the rule stands, the problem it is trying to solve, what it changes about human presence, how it differs from the final Part 53 rule, what autonomous operation does and does not mean, and the verification question the rule opens without answering. RankShield Energy is a pre-applicant holding no license or approval [[17]](#src-17), and we are not licensed under Part 57 or any other rule.
Key takeaways

- Part 57 is a proposed rule published May 1, 2026. The comment period closed in June 2026 and no developer is licensed under it.
- Its substantive change is contemplating remote operation and reduced on-site staffing, against a current rule requiring an operator at the controls at all times.
- Part 53 is final and available now; Part 57 is proposed and microreactor-specific. They are not interchangeable.
- Automation, remote operation, and autonomous operation are three different things, and 'unmanned' is not a regulatory category.
- NRC staff have proposed a scalable inspection footprint, so fewer regulator eyes per reactor is the explicit direction, not a side effect.

## Where the proposed rule actually stands today
The Nuclear Regulatory Commission published proposed 10 CFR Part 57 in the Federal Register on May 1, 2026, as a licensing framework for microreactors and other reactors with comparable risk profiles [[1]](#src-1). The public comment period closed on June 15, 2026. The rule is not final.
Three consequences follow, and they are worth stating before anything else because most coverage blurs them. No developer is licensed under Part 57, because a proposed rule confers no licensing authority. The text can change between proposal and final rule, sometimes substantially. And a developer describing itself as operating under Part 57 today is describing an intention rather than a status.
Companion draft guidance, NUREG-2271, was issued for comment alongside it, framed by the NRC around rapid licensing of first-of-a-kind microreactors and high-volume deployment [[2]](#src-2). Guidance and rule move together, and both are drafts.
None of that makes the proposal unimportant. It makes it a direction rather than a destination, and reading it as a direction is what lets you plan against it honestly.

## The problem Part 57 is trying to solve
The NRC has been circling microreactor policy for years. SECY-20-0093, in October 2020, flagged autonomous operation, remote operation, staffing, and regulatory oversight as open policy questions specific to this class of reactor [[3]](#src-3). Those questions did not have clean answers inside a framework built for large light-water plants.
More recently the agency has been planning explicitly for repetition. SECY-25-0052 addresses nth-of-a-kind microreactor licensing and deployment, including standardization of operational programs [[4]](#src-4), which is the regulatory shape of many identical units rather than a handful of bespoke ones.
The statutory push comes from the ADVANCE Act, which directs the NRC to develop microreactor strategies across eight areas including staffing and operations, and oversight and inspections [[5]](#src-5). Congress asked for the thing Part 57 is attempting.
Underneath all of it is an arithmetic problem. A licensing and oversight model that assumes a large staffed plant does not scale to many small ones. If each microreactor consumes the regulatory attention of a conventional unit, the deployment numbers the industry describes are not reachable. Part 57 is the NRC trying to change that ratio deliberately rather than letting it be eroded by pressure.

## What the rule changes about who has to be present
To see what is actually being proposed, you have to look at the requirement it sits against. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times, and a licensed operator or senior operator must be present at the controls at all times [[6]](#src-6). That is a condition of the license for the operating fleet, not a convention.
Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1). That is the substantive shift: not automation for its own sake, but relocating and reducing the human presence that current regulation fixes in place.
A distinction the NRC and INL have drawn matters here, because the industry uses these words loosely. Remote means command and control moved outside the reactor site boundary, and monitoring, meaning collecting and observing plant data, is a different activity from operations [[7]](#src-7). A vendor claiming remote capability may mean either, and the two carry very different regulatory weight.
Sandia National Laboratories, working for the NRC, described the operational picture the rules would have to accommodate: operators may not be located on site and may monitor from a remote location, and some designs contemplate one control room supervising multiple microreactors [[8]](#src-8). That last clause is the [fleet-scale question](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors), and it is the one with the least settled answer.
It is worth being concrete about why this could not simply be handled by exemption. Oak Ridge National Laboratory examined what autonomous control actually disturbs in the existing regulatory structure and found the list runs well beyond headcount: staffing requirements, manipulation of the controls, licensed operator provisions, technical specifications, cybersecurity, and event notification obligations, with the added wrinkle that a control room may not be co-located with the plant at all [[18]](#src-18).
That is the case for a purpose-built framework rather than a series of carve-outs. Each item on that list is a separate place where regulation written for a staffed plant assumes a person who is now somewhere else, or nowhere. Granting exemptions one at a time would leave a licensing basis stitched together from exceptions, which is difficult to review consistently and harder still to replicate across many identical units. Part 57 is an attempt to write the assumptions down once.
The tradeoff is that a new framework has to earn its own confidence. An exemption sits against decades of operating experience with the underlying rule. A new rule for a class of reactor that has not yet operated commercially has no such record behind it, which is part of why the oversight provisions discussed further down matter as much as the licensing ones.

## Part 57 compared with the final Part 53 rule
Two frameworks are often mentioned together and they are not interchangeable. Part 53 is final. Part 57 is proposed and microreactor-specific.

Proposed Part 57 and final Part 53, compared

10 CFR Part 53
10 CFR Part 57 (proposed)

Status
Final rule, published March 30, 2026
Proposed rule, published May 1, 2026; comment period closed June 2026

Scope
Broad, risk-informed and technology-inclusive framework for advanced reactors
Microreactors and other reactors with comparable risk profiles

Autonomy and staffing
General advanced-reactor framework
Contemplates remote operation and reduced on-site staffing

What it grants a developer today
An available licensing pathway
Nothing yet; no one can be licensed under a proposed rule

Part 53 was finalized as a risk-informed, technology-inclusive framework for advanced reactors [[9]](#src-9). It is optional, and it is available now. Part 57 is the narrower, faster instrument aimed at a specific class, and it is not.
The practical read for a buyer: ask which framework a developer is pursuing and why. A developer betting entirely on a rule that has not been finalized is carrying a schedule risk that a developer using an available pathway is not. Neither choice is wrong. The absence of an answer is the signal.

## What autonomous operation does not mean
The proposed rule introduces vocabulary, and vocabulary is where most of the public confusion lives. Three terms get used interchangeably and should not be.
**Automation** is a machine performing a defined function without a person executing it, and it has existed in reactors for decades. **Remote operation** is command and control from outside the site boundary. **Autonomous operation** describes a system taking action across a range of conditions without an operator directing each one. A plant can be heavily automated with people on site, or lightly automated and operated remotely.
What none of them means is a reactor with nobody responsible for it. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended. "Unmanned" and "fully autonomous" are not regulatory categories, which is why we treat them as language to avoid rather than goals to advertise, and why we cover the [terminology distinctions](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms) on their own.
The framing that has held up best comes from Brookhaven National Laboratory, in work for the NRC on facilities without main control rooms: the safety question is not so much justifying why a design has no main control room, but rather verifying that important human actions can be accurately and reliably performed [[10]](#src-10). Autonomy does not remove the human actions. It changes how anyone confirms they happened.

## The oversight half of the rule that gets less attention
Licensing is only one side. The other is what happens for decades afterwards, and here the NRC has been unusually direct. In December 2025, staff proposed operational-phase microreactor oversight built on innovative inspection methodologies and a scalable inspection footprint [[5]](#src-5).
Set that against the current baseline. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, describing their role as independently verifying that requirements are being met [[11]](#src-11), inside a Reactor Oversight Process built on inspection findings, performance indicators, and a significance determination process [[12]](#src-12).
A scalable footprint across many small units means fewer inspector-hours per reactor. That is the explicit intent, not an unintended consequence. Meanwhile the Government Accountability Office has reported that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[13]](#src-13), and still lists licensing advanced reactors among its priority open recommendations [[14]](#src-14).
So the trajectory is fewer regulator eyes per reactor, arriving alongside more reactors. Something has to carry the confirmation load that presence used to carry, which is precisely the [verification problem](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) the rest of this site is about.
There is a reasonable counterargument worth stating fairly. A microreactor is a smaller source term than a gigawatt-class plant, so proportionally lighter oversight is not obviously wrong, and the entire premise of risk-informed regulation is that attention should follow consequence rather than be distributed evenly. On that reading, a scalable inspection footprint is the framework working as designed rather than a weakening of it.
The response is not that the reasoning is wrong, it is that it is incomplete. Reduced consequence justifies reduced inspection intensity. It does not by itself establish how anyone confirms a reactor is behaving as described between those less frequent inspections. Those are separate questions, and the second is the one with no settled answer yet. A framework can be correct about proportionality and still leave a gap in confirmation, which is what we think is happening here.

## The trust surface the proposed rule opens
If a reactor is operated from outside the site boundary and inspected less often, then more of what anyone knows about it arrives as data the operating organization produces about itself. That is not a criticism of any operator. It is a structural description of the model Part 57 contemplates.
It creates a question the rule does not answer, and arguably should not: who confirms the reported state, and are they separate from the party reporting it. Nuclear already contains the precedent for the answer, since IAEA safeguards exist so that an outside body can independently verify rather than rely on an operator's assertion [[15]](#src-15). Computing standardized the same split, with a verifier appraising evidence separately from the attester that produced it [[16]](#src-16).
This is why [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) are worth separating carefully when reading any vendor claim made under a Part 57 framing. The rule opens the operating model. It does not supply the trust layer that model needs, and no developer should imply that it does.

## What this means if you are evaluating a developer, including us
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, we are not licensed under Part 57 or any other rule, and nothing about our design has been demonstrated to or accepted by the NRC [[17]](#src-17). Describing the rule is not the same as satisfying it, and we are not claiming to.
Three questions travel well here. Which framework is the developer pursuing, and is it final or proposed. When they say remote or autonomous, which of the three definitions do they mean. And who confirms reactor state independently of the operator. Those are the questions in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they are answerable without any proprietary disclosure.
Our own view, stated plainly so it can be argued with: the staffing and oversight changes Part 57 contemplates are reasonable, and the verification layer they imply is not yet built by anyone, including us. Treating that gap as solved is the most common overclaim in this market right now.

## Frequently asked questions

### Is NRC Part 57 in effect?
No. Proposed Part 57 was published in the Federal Register on May 1, 2026, and the public comment period closed on June 15, 2026 <sup><a href="#src-1">[1]</a></sup>. It is a proposed rule, which means it is the NRC's draft framework for public review rather than law. No developer is licensed under it, the text can change before any final version is issued, and any description of what Part 57 permits or requires is a description of a draft. Companion draft guidance, NUREG-2271, was issued for comment alongside it <sup><a href="#src-2">[2]</a></sup>.

### Does Part 57 allow reactors to run with nobody present?
It contemplates remote operation and reduced on-site staffing for microreactors <sup><a href="#src-1">[1]</a></sup>, which is a meaningful change from the current requirement that a licensed operator be present at the controls at all times <sup><a href="#src-6">[6]</a></sup>. But reduced is not absent. Safety-significant actions keep a human in the loop, no facility is licensed to operate unattended, and "unmanned" is not a regulatory category. Whether any specific design can operate with a given staffing arrangement would be evaluated for that design under review.

### What is the difference between Part 53 and Part 57?
Part 53 is a final rule, published March 30, 2026, establishing a broad risk-informed and technology-inclusive framework for advanced reactors <sup><a href="#src-9">[9]</a></sup>. It is optional and available now. Proposed Part 57 is narrower, aimed specifically at microreactors and reactors with comparable risk profiles, and is not final <sup><a href="#src-1">[1]</a></sup>. The practical difference for a developer is that one is an available pathway today and the other is a proposal that may change. Ask which a developer is pursuing and why.

### What does autonomous operation actually mean here?
It describes a system taking action across a range of conditions without an operator directing each one. It is distinct from automation, which is a machine performing a defined function and has existed in reactors for decades, and from remote operation, which is command and control from outside the site boundary. A plant can be heavily automated with staff on site, or lightly automated and run remotely. Vendors frequently blur all three, so the useful follow-up is which specific meaning they intend.

### Why does Part 57 matter for verification?
Because it shifts how anyone outside the operating organization learns what a reactor is doing. With operation possible from outside the site boundary and the NRC proposing a scalable inspection footprint for operational oversight <sup><a href="#src-5">[5]</a></sup>, more of the picture arrives as data the operator reports about itself. The rule opens that model without supplying the layer that makes such reports checkable by an outside party, which is why independent verification becomes more load-bearing under Part 57 rather than less.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Automation vs remote vs autonomous →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)
- [HELIX licensing approach →](https://rankshieldenergy.com/licensing)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of NRC microreactor rulemaking as of July 2026. Proposed 10 CFR Part 57 is not final and may change; its comment period closed in June 2026. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/nrc-pre-application-process-explained/

# How the NRC Advanced Reactor Pre-Application Works

> Pre-applicant does not mean approved. See how NRC advanced-reactor pre-application engagement actually works, step by step, and what it does and does not grant.

[Resources](https://rankshieldenergy.com/resources) / Licensing & pre-application Licensing & pre-application

# How the NRC Pre-Application Process Actually Works
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Pre-application is the early, voluntary stage in which a reactor developer engages the U.S. Nuclear Regulatory Commission about a design it may later seek to license. It is engagement, not approval. It grants no license, no permit, no construction authorization, no design approval, and no safety finding, and a developer that describes it as more than that is telling you something the public record does not support.
The word "pre-applicant" does a lot of quiet work in press releases. It sounds like a rung on an approval ladder, as though a regulator had reviewed a design and advanced it one step. The NRC describes pre-application activities as a way to become familiar with a developer technology and plans before an application is submitted [[1]](#src-1), which is a different thing entirely. Familiarity is not endorsement, and a conversation is not a finding.
This article covers what a pre-applicant actually is, the mechanics of the process from letter of intent through project number, Regulatory Engagement Plan, meetings, and topical reports [[3]](#src-3), what engagement does and does not grant, why serious developers still engage early, which licensing framework a developer may pursue now that Part 53 is final [[4]](#src-4) and Part 57 is proposed and not final [[5]](#src-5), how to check a claimed status against the public record, and what the Government Accountability Office has said about NRC readiness for this workload [[10]](#src-10). RankShield Energy is a pre-applicant holding no license, permit, or design approval, and the closing section applies every test in this article to us.
Key takeaways

- Pre-application is engagement with the NRC, not approval by it: no license, no permit, no design approval, no safety finding.
- A pre-applicant is two full legal transitions away from being a licensed, overseen operating plant.
- The Regulatory Engagement Plan is the substantive artifact; a project number is administrative and routinely over-read.
- Part 53 is a final rule as of March 30, 2026; Part 57 is a proposed rule and is not final, so claims keyed to it are claims against a proposal.
- Test any claimed status by asking whether it names a retrievable document and whether it separates a narrow staff conclusion from approval of a design.

## Pre-application is engagement, not approval
The plainest version is this: pre-application is a conversation. A developer tells the NRC what it intends to build and how it intends to license it, and the NRC uses that interaction to become familiar with the technology and the plan before any application is submitted [[1]](#src-1). Nothing in that conversation issues a license, a permit, a construction authorization, a design approval, or a safety finding.
The confusion is structural rather than accidental. The label "pre-applicant" reads like an early rung on an approval ladder, as though a regulator had looked at a design and advanced it one step. It is not a rung on that ladder. It is the stage before the ladder, and the NRC organizes it as general guidance on how to interact productively ahead of a submittal [[3]](#src-3), not as a grading exercise.

What NRC pre-application engagement grants, and what it does not

Question
Pre-application engagement

Does it grant a license or permit?
No. No operating license, no construction permit, no construction authorization.

Does it grant a design approval or certification?
No. Design approval and design certification are separate regulatory actions with their own applications and reviews.

Does it produce a safety finding?
No. The NRC makes safety findings on applications under review, not on pre-application discussion.

Does it mean the NRC endorses the technology?
No. Engagement is not endorsement, and the NRC does not promote the designs it interacts with.

Does it commit the developer to apply?
No. Pre-application activity is voluntary and a developer may never file.

What does it actually do?
It lets the NRC become familiar with a technology and a developer plan before an application arrives, and lets the developer surface regulatory issues while the design can still absorb them.

Read the bottom row of that table carefully, because it is the honest case for the process. Pre-application has real value, and serious developers use it. The value is informational and procedural. It is not a credential. When a reader treats it as a credential, the error is expensive in a specific direction: money, land, offtake conversations, and community expectations all get committed against a status that carries no regulatory finding at all. That is why this post exists, and why we apply the same test to ourselves in the closing section. If you only remember one sentence, remember that the NRC becoming familiar with a design is not the NRC accepting it [[1]](#src-1).

## A pre-applicant is a developer in conversation, not one the NRC has cleared
A pre-applicant is a developer that has begun interacting with the NRC about a design or project it may later seek to license, but that has not necessarily submitted an application and certainly has not received one back approved. The NRC maintains public pages describing the advanced reactor developers it is working with in this posture [[1]](#src-1). Appearing there means the interaction exists. It says nothing about whether the design is sound, whether the schedule is credible, or whether the developer will ever file.
It helps to hold three distinct statuses in your head. A **pre-applicant** is talking to the regulator. An **applicant** has filed something the NRC has docketed and is reviewing, which puts the submittal into a formal review process with defined acceptance criteria [[3]](#src-3). A **licensee** has been granted a license and has become subject to ongoing regulatory oversight, which for operating power reactors runs through the Reactor Oversight Process and its inspections and performance indicators [[13]](#src-13).
Those are not shades of the same thing. They are three different legal positions, and the distance between them is measured in years of technical review, not in press releases. A pre-applicant is two full transitions away from being an overseen operating plant. Anyone describing pre-application status as evidence that a reactor is "on track for approval" is compressing a gap that the regulator itself does not compress [[1]](#src-1).
This also explains why the oversight regime you may have read about does not yet apply to any pre-applicant. The Reactor Oversight Process is a framework for plants that already hold licenses and are already operating [[13]](#src-13). It is a useful thing to understand early, because it tells you what real regulatory scrutiny of an operating plant looks like, and it makes the comparatively light weight of a pre-application conversation obvious by contrast.

## The mechanics: intent, project number, engagement plan, meetings, topical reports
The process has recognizable machinery, and knowing the pieces makes vendor claims much easier to parse. A developer that wants to engage generally notifies the NRC in writing of its intent to interact, which allows the staff to set up a project and plan the resources the interaction will consume [[3]](#src-3). Assignment of a project number is an administrative act. It is a filing-cabinet label, and it is one of the most commonly over-read artifacts in this whole space.
The substantive document is the **Regulatory Engagement Plan**. The NRC asks developers to lay out what they intend to submit, in what order, and on what schedule, so the staff can anticipate workload and the developer can see the sequence of its own regulatory obligations [[2]](#src-2). This is the artifact that most rewards honesty, because a plan that promises a heavy stream of submittals a developer cannot actually produce becomes visible fast.
From our own side of that exercise, the useful part was not the document but what writing it forced. Sequencing planned submittals made it immediately obvious which technical questions we had actually closed and which we had merely deferred, because you cannot schedule a topical report on a subject you have not yet decided. That is an uncomfortable and genuinely valuable output, and it happens before anything is filed.
The interaction itself runs through pre-application meetings with the staff and, where a developer chooses, through **topical reports** and white papers that isolate a single technical or methodological question ahead of a full application [[3]](#src-3). Related guidance for microreactor developers specifically is collected on the NRC pages tracking microreactor regulatory activities [[7]](#src-7). None of these steps produces an approval of a design. A topical report review can produce a staff conclusion on the narrow question the report addresses, which is a real and useful thing, and it is still not a license.

## Developers engage early because late regulatory surprises force redesign
If pre-application grants nothing, why bother? Because the alternative is discovering a regulatory expectation after the design is frozen. The NRC frames pre-application interaction as a way to identify and resolve issues before an application is submitted [[3]](#src-3), and the practical translation is that a question raised in year one is a design input, while the same question raised in year four is a costly redesign.
The staff has also been thinking about the deployment problem beyond a single unit. SECY-25-0052 examines licensing and deployment considerations for microreactors on an nth-of-a-kind basis, which is the question of what happens when the same design is built repeatedly rather than treated as a bespoke project each time [[12]](#src-12). A developer that understands where the staff is heading on standardization can design toward it instead of against it, and pre-application is where that alignment is cheapest to achieve.
There is also a resourcing reality. NRC review work is generally subject to fee recovery, and the agency publishes how its fee structure applies to advanced reactor activities [[9]](#src-9). Congress addressed the efficiency of advanced reactor licensing directly through the ADVANCE Act, which the NRC summarizes on its own governing-laws pages [[8]](#src-8). The point for a reader is not the dollar figures. It is that regulatory engagement consumes real agency effort and real developer effort, which is precisely why a developer with nothing to submit tends not to engage for long.
Our position, stated so it can be argued with: the honest reason to engage early is to have your assumptions contradicted while contradiction is still affordable. Developers who treat pre-application as a marketing milestone get the opposite value, because they optimize for the announcement rather than for the correction. The process rewards the developer who arrives with specific unresolved questions and is willing to hear an unwelcome answer.

## Which framework applies: Part 53 is final, Part 57 is proposed and not final
A developer engaging today faces a genuine framework question, and the two options are at very different stages of maturity. The NRC published its risk-informed, technology-inclusive regulatory framework for advanced reactors, 10 CFR Part 53, as a final rule in the Federal Register on March 30, 2026 [[4]](#src-4). That is a completed rulemaking and a real licensing pathway.
Separately, the NRC published proposed licensing requirements for microreactors and other reactors with comparable risk profiles, designated 10 CFR Part 57, in the Federal Register on May 1, 2026 at 91 FR 23628 [[5]](#src-5). Part 57 is **proposed**. It is not a final rule, no developer is licensed under it, and its content may change before any final version exists, if a final version exists. Anyone describing a design as compliant with Part 57 is describing compliance with a proposal.
The supporting guidance carries the same caveat. The NRC issued NUREG-2271, guidelines for preparing and reviewing applications under 10 CFR Part 57, in April 2026 as a draft for comment [[6]](#src-6). Draft guidance attached to a proposed rule is doubly provisional, and it is worth reading precisely because it shows the direction of staff thinking, not because it settles anything. The NRC also maintains a running summary of microreactor regulatory activities that ties these threads together [[7]](#src-7).
The practical consequence for a developer is that engagement has to be framework-aware without being framework-dependent. A design premised entirely on a proposed rule surviving unchanged is carrying a risk that belongs on the risk register rather than in the marketing. For readers trying to understand what the proposed microreactor rule actually contemplates around staffing and remote operation, we walk through it separately in [our explainer on Part 57 as proposed](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), including the qualifiers that get dropped when the topic is summarized elsewhere.

## How to check a developer's claimed status against the public record
You do not have to take a developer at its word, including us. The NRC publishes pages describing the advanced reactor developers it is engaged with in pre-application, which is the natural starting point for confirming that an interaction exists at all [[1]](#src-1). The microreactor regulatory activities pages give the adjacent picture for this class of design [[7]](#src-7).
Then apply four questions to whatever the developer has claimed. **One:** is the claim about engagement, or about a regulatory action? Engagement means a conversation exists. A regulatory action means the NRC issued something. **Two:** if a framework is named, is that framework final? Part 53 is a final rule [[4]](#src-4); Part 57 is a proposal [[5]](#src-5), and a claim keyed to Part 57 inherits every uncertainty of a rule that is not finished.
**Three:** is any document identified specifically enough to look up? A named topical report on a stated subject is checkable. "Ongoing NRC engagement" is not. **Four:** does the developer distinguish between a staff conclusion on a narrow question and an approval of a design? That distinction is where most overstatement lives, because a narrow favorable conclusion is genuinely good news and is genuinely not a license.
A point on visibility that cuts in the developer's favour, and that we had originally been too cautious to state. The NRC's own description of the pre-application process includes a kickoff public meeting, held so a developer can introduce its project to NRC staff and to the public, and a later public outreach meeting near the vicinity of a proposed site as a submission date approaches [[3]](#src-3). So early engagement is not a private correspondence between a company and its regulator. Parts of it are conducted in the open, which is one more reason a developer's characterisation of its own status is checkable rather than something you have to accept.

## What the GAO has said about NRC readiness for advanced reactor licensing
The regulator side of this deserves the same scrutiny as the developer side. In July 2023 the Government Accountability Office published a report whose title states its conclusion directly: the NRC needs to take additional actions to prepare to license advanced reactors [[10]](#src-10). The concerns in that body of work center on workforce and readiness questions, meaning whether the agency has the staff, skills, and processes lined up for a wave of technologies unlike the light-water fleet it has regulated for decades.
That thread did not close in 2023. GAO maintains priority open recommendation letters for federal agencies, and it issued one for the NRC in June 2026 [[11]](#src-11). The existence of an open priority recommendation letter is itself informative: it tells you an external auditor still considers some recommendations unimplemented. Congress moved on the same problem legislatively through the ADVANCE Act, which the NRC describes on its own pages as directing improvements to the efficiency of its licensing work [[8]](#src-8).
**The counterargument, stated fairly:** if the regulator has documented readiness gaps, then pre-application engagement is a formality that mostly generates paperwork, and a developer would be better served building and letting the licensing catch up later. That argument is not stupid, and versions of it are common in the industry.
**Our response:** it points in the opposite direction from the one intended. When agency review capacity is a constrained resource, arriving with unresolved fundamental questions is the most expensive possible way to consume it. Early engagement is how a developer reduces the amount of review capacity its application will need, and how the staff sees the technology before it is under schedule pressure. The readiness gaps GAO describes [[10]](#src-10) [[11]](#src-11) make disciplined pre-application more valuable rather than less, and they also argue for humility about timelines from every developer, including this one.

## Where RankShield Energy actually is, stated without softening
RankShield Energy is a pre-applicant. We hold no license, no construction permit, no design approval, and no design certification. Nothing about our design has been demonstrated to or accepted by the NRC, and no safety, performance, or operational characteristic described anywhere on this site has been reviewed or endorsed by the agency. Everything in the preceding sections about what pre-application does not grant [[1]](#src-1) applies to us without exception.
We also are not licensed under the proposed microreactor rule, because nobody is. Part 57 is a proposal in the Federal Register [[5]](#src-5), and any statement that our design aligns with it is a statement about design intent measured against a document that could change. We would rather write that sentence ourselves than let a reader infer something warmer.
A concrete decision and its tradeoff, since this article has been asking developers to make theirs visible. We decided that every public page would state the pre-applicant limitation in plain language rather than in a footnote. The cost is real: next to a competitor describing the same regulatory position in more flattering terms, we look less advanced than we are, and that has a commercial price in early conversations. We accepted it because a public claim that contradicts a future application is a durable liability, and because a company whose entire technical thesis is verifiable claims cannot start by making unverifiable ones.
The honest limitation, since we have been demanding that others state theirs: our claim about our own regulatory status is, at this moment, mostly a self-report. The public record establishes what the NRC publishes about engagement [[1]](#src-1), and it does not establish the internal detail of our program. Treat our claims with the same skepticism this article recommends everywhere else. If you want the technical side of that argument, it runs through [how you would verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely), and the vocabulary problem underneath it is unpacked in [automation, remote, and autonomous as separate terms](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms).

## Frequently asked questions

### Does NRC pre-application status mean a reactor design is approved?
No. Pre-application is early, voluntary engagement in which the NRC becomes familiar with a technology and a developer plan before an application is submitted <sup><a href="#src-1">[1]</a></sup>. It grants no license, no construction permit, no design approval, no design certification, and no safety finding. The NRC organizes it as guidance for interacting productively ahead of a submittal <sup><a href="#src-3">[3]</a></sup>, not as an evaluation that produces a verdict. A developer can be in pre-application for years and hold exactly the same regulatory authorizations at the end of it as at the beginning, which is none. Approval language attached to pre-application status is the single most common overstatement in this part of the industry.

### What is a Regulatory Engagement Plan?
It is the document in which a developer sets out what it intends to submit to the NRC, in what order, and on what schedule, so the staff can anticipate the workload and plan resources <sup><a href="#src-2">[2]</a></sup>. It is the most substantive artifact of early engagement, and it is more revealing than a project number, because a project number is administrative while a plan exposes sequence and commitment. In our own experience of preparing one, the exercise mattered more than the document: you cannot schedule a submittal on a question you have not yet decided, so the act of sequencing separates closed technical questions from deferred ones.

### Is 10 CFR Part 57 a rule a developer can be licensed under today?
No. The NRC published licensing requirements for microreactors and other reactors with comparable risk profiles as a <strong>proposed</strong> rule in the Federal Register on May 1, 2026 at 91 FR 23628 <sup><a href="#src-5">[5]</a></sup>. It is not final, and no developer is licensed under it. The supporting guidance, NUREG-2271, was issued in April 2026 as a draft for comment <sup><a href="#src-6">[6]</a></sup>, which carries the same provisional status. By contrast, 10 CFR Part 53, the risk-informed and technology-inclusive framework for advanced reactors, was published as a final rule on March 30, 2026 <sup><a href="#src-4">[4]</a></sup>. Any claim of Part 57 compliance is a claim against a proposal.

### How can I verify a developer's claimed pre-application status myself?
Start with what the NRC publishes about the advanced reactor developers it is working with <sup><a href="#src-1">[1]</a></sup> and its summary of microreactor regulatory activities <sup><a href="#src-7">[7]</a></sup>. Then test the claim itself. Is it about engagement or about a regulatory action the NRC issued? If a framework is named, is that framework final <sup><a href="#src-4">[4]</a></sup> or proposed <sup><a href="#src-5">[5]</a></sup>? Is any document identified specifically enough to retrieve? Does the developer separate a staff conclusion on a narrow technical question from approval of a design? This article does not assert that pre-application meetings are public, so do not assume visibility that the record has not established.

### Has anyone questioned whether the NRC is ready to license advanced reactors?
Yes. The Government Accountability Office reported in July 2023 that the NRC needed to take additional actions to prepare to license advanced reactors <sup><a href="#src-10">[10]</a></sup>, and it issued a priority open recommendations letter to the agency in June 2026 <sup><a href="#src-11">[11]</a></sup>, which indicates that external oversight still tracks unimplemented items. Congress addressed licensing efficiency through the ADVANCE Act, summarized on the NRC governing-laws pages <sup><a href="#src-8">[8]</a></sup>, and NRC staff have examined nth-of-a-kind microreactor licensing and deployment considerations in SECY-25-0052 <sup><a href="#src-12">[12]</a></sup>. Readiness questions argue for engaging early and carefully, not for skipping engagement.

## Sources

- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [U.S. Nuclear Regulatory Commission. Regulatory Engagement Plan. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/engagement)
- [U.S. Nuclear Regulatory Commission. Pre-application Process (general guidance). Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/pre-app-process)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. About the ADVANCE Act. Accessed July 2026](https://www.nrc.gov/about-nrc/governing-laws/advance-act/about-advance-act)
- [U.S. Nuclear Regulatory Commission. NRC Fees, Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-info/fees)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)

## Related

- [NRC Part 57 and autonomous operation, as proposed →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the NRC's advanced-reactor pre-application process as of July 2026. NRC guidance and process pages are updated periodically; check the NRC's pre-application pages if you need the current procedure.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record/

# How Reactor State Becomes a Trusted Attestation Record

> How does raw sensor data become a record a regulator or insurer can trust? Follow the chain from telemetry to a tamper-evident, independently verifiable record.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# From Sensors to an Attestation Record: How Reactor State Is Confirmed
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. A reactor state attestation record is what raw telemetry becomes once an independent party has appraised it, signed the appraisal, and written it to an append-only log that returns a receipt. The chain runs in four steps: measure, appraise, sign and log, verify. The fourth step carries the weight, because it is the one that lets a regulator, insurer, lender, or grid operator check what happened without the operator's cooperation.
A live dashboard answers a different question than a record does. It shows what a vendor's software wants to show right now, filtered and rendered by the same organization whose performance is being judged. What a regulator, insurer, lender, or grid operator needs is something else: an account of what the plant did that they can check for themselves, later, on their own terms. Computing worked this out already and standardized the roles, separating the party that produces evidence about its state from the party that appraises that evidence and the party that acts on the result [[1]](#src-1).
This article follows the chain from a sensor reading to a record an outside party can rely on, then covers why signature choices matter for records meant to outlive the equipment, why supply-chain integrity of the measuring and signing components sits underneath all of it, and what tamper-evident actually means, since it means detection rather than prevention. It closes with a stated objection, an honest limitation, and where we actually stand. RankShield Energy is a pre-applicant holding no license or approval [[14]](#src-14), and everything described here is design intent rather than a demonstrated capability.
Key takeaways

- Telemetry is an input, not evidence: it originates with, travels through, and is rendered by the party whose performance is in question.
- An appraisal becomes durable evidence when a party separate from the operator signs it and registers it in an append-only log that issues a receipt.
- The test of the whole architecture is whether a third party can check the record later without the operator's help, or its solvency, or its existence.
- Tamper-evident means alterations and omissions are detectable. It does not mean tamper-proof, and nothing here is unhackable.
- Post-quantum signature standards matter because a reactor record may need to be verifiable long after the equipment and the organization are gone.
- RankShield Energy is a pre-applicant. This chain is design intent and an architecture we apply, not a deployed or NRC-accepted capability.

## Raw telemetry is data, and data by itself is not proof
A sensor reading is a claim made by equipment the operator owns, carried over a path the operator controls, into a display the operator renders. Nothing in that sequence establishes for an outside party that the value is complete, current, and unaltered. It is perfectly good data for running a plant. It is not, on its own, evidence anyone else can rely on months or years later, because every step of its journey traces back to the party whose performance is in question.
Measurement quality sits upstream of everything else, and the national labs have named what it demands. Oak Ridge identified sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring as preconditions for operating microreactors with reduced on-site presence [[7]](#src-7). If the measurement layer is thin, no amount of cryptography downstream improves it. Signing a bad number produces a durable record of a bad number.
The transport path matters just as much as the sensor. The IAEA's guidance on computer security of instrumentation and control systems at nuclear facilities treats those systems as protected assets across their life cycle rather than as ordinary information technology [[9]](#src-9), and the reason is that a compromised I&C path does not announce itself. It produces plausible readings. A viewer looking at a rendered feed has no way to distinguish a healthy plant from a healthy-looking report.
So the chain has to start at measurement, but it cannot end at a screen. It has to end at a record. Model-based cross-checks help here, and we cover that separately in [how digital twins fit remote reactor verification](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations), but a model is another input to appraisal rather than a substitute for it.

## Appraisal by a party separate from the operator is what turns data into evidence
The second step is appraisal, and the internet already standardized what appraisal means. RFC 9334 defines an architecture in which an Attester produces evidence about its state, a Verifier appraises that evidence against an appraisal policy, and a Relying Party acts on the Verifier's result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[1]](#src-1). The separation of those three roles is not incidental. It is the whole design.
Nuclear has the same insight in a different form. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, and describes their function as independently verifying that requirements are being met [[10]](#src-10). The IAEA safeguards system exists so that an outside body applies its own technical measures to independently verify that facilities are not misused, rather than relying on a state or operator assertion [[8]](#src-8). Safeguards address non-proliferation rather than operational safety, so do not overread the analogy, but the structural move is identical: place the checker outside the checked.
Applied to reactor state, appraisal means comparing what the plant reports against what independent measurement shows and what the design permits, then recording the comparison. The property that matters most is unglamorous: disagreement has to be recorded as faithfully as agreement. A system that writes a record only when everything matches is not verifying anything. It is publishing.
That distinction is the subject of a companion piece on [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is the reason [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) is a different job from monitoring one.

## Signing and logging are what make an appraisal durable
An appraisal that lives in a database is an opinion with a timestamp. Signing it binds the content to a key, so a later reader can tell whether the bytes changed. That is necessary and still not sufficient, because a signature says nothing about what was not shown. A party holding a set of signed statements cannot tell whether it received all of them, or whether an inconvenient one was quietly withdrawn before anyone looked.
Closing that gap is what append-only transparency infrastructure is for. RFC 9943 describes an architecture in which statements are registered into an append-only service that issues a receipt for each registration, so that the existence of a statement becomes checkable rather than asserted [[2]](#src-2). The record stops being something the issuer holds and becomes something the issuer has committed to in a place it cannot silently edit.
The receipt is the portable part. RFC 9942 standardizes receipts as compact cryptographic proofs, carrying inclusion proofs that a given statement is in the log and consistency proofs that the log has not been rewritten between two points in time [[3]](#src-3). A holder can check both without contacting the party that produced the statement.
It is worth being precise about what this does and does not establish. A receipt proves what was claimed, by whom, and when it entered the record. It does not prove the reactor was safe. Safety is established by analysis, testing, and regulatory review. What the record contributes is that the account of what happened cannot be quietly revised after the fact to suit the outcome, which is a narrower claim and a more defensible one.

## The test that matters is what an outsider can check without the operator's help
The fourth step is the one that decides whether any of the preceding work was real. If checking the record requires the operator to hand something over, stay online, or vouch for something, then the operator is still the source of trust and the architecture is decorative. The useful question is what a party can establish unaided, which is exactly the Relying Party role RFC 9334 separates out [[1]](#src-1).
This is where a table earns its place, because it says something the four-step chain above the article does not: different parties want different things from the same record.

What each party can establish from an attestation record without the operator's cooperation

Party
What the record lets them establish on their own
What it still does not settle for them

Regulator
That a stated appraisal existed at a stated time and has not been altered since
Whether the underlying operation complied, which remains a review judgement

Insurer or lender
That the operating account they were given matches the account committed to at the time
Loss likelihood, which needs actuarial and engineering analysis beyond the record

Grid operator
That availability and dispatch claims were recorded contemporaneously, not reconstructed later
Future behaviour, since a record is history rather than a forecast

Any later reviewer
Inclusion in the log and consistency of the log across two points in time
Whether the measurement feeding the appraisal was itself sound

Every row in the middle column is checkable with the receipt, the verifier's public key, and the log [[3]](#src-3). None of it requires the operating organization to be cooperative, solvent, or in existence. Every row in the right-hand column is a reminder that a record is a floor rather than a ceiling. It removes a category of dispute about what was said and when, which frees the harder conversation to be about engineering rather than about whose screenshot to believe.

## Records meant to outlive the equipment need post-quantum signatures
A reactor operating record may need to be checkable for decades, and potentially long after the equipment that produced it has been decommissioned and the organization that operated it has been reorganized or dissolved. That makes the choice of signature algorithm a durability decision rather than a security fashion. The question is not only whether a signature is sound today. It is whether a reviewer in the 2050s will still regard the algorithm as sound enough to settle a dispute.
The standards ground has moved recently enough that this is now a concrete choice rather than a speculative one. NIST announced approval of three Federal Information Processing Standards for post-quantum cryptography in August 2024 [[4]](#src-4), and FIPS 204 specifies a module-lattice-based digital signature standard [[5]](#src-5). A signature scheme intended for long-lived records now has a published, standardized option rather than a research paper.
It also pays to be careful about the threat model, because post-quantum marketing tends to blur it. The exposure for signatures is not identical to the exposure for encrypted data. Data captured today and decrypted later is a harvesting problem. Signatures face a different issue: a key that remains in use, or a record that must still be verified long after the algorithm has fallen out of trust, is the thing that ages badly. That argues for algorithm agility and for planning key lifetimes deliberately rather than for treating a single algorithm choice as permanent.
This is the part of the problem where our own hands-on work actually sits, and the tradeoff we accepted is worth stating plainly. Building for signature agility means carrying more than one verification path and accepting the operational overhead of maintaining both. It is slower and more complex than picking one algorithm and moving on. We took the overhead because a record that becomes unverifiable is indistinguishable from a record that was never made.

## The evidence is only as trustworthy as the components that produce it
There is a quiet assumption underneath every attestation architecture: that the components doing the measuring, appraising, and signing are the components their manufacturer intended. If a signing module, gateway, or sensor was altered before installation, the resulting record is well formed, correctly signed, verifiable by anyone, and wrong. Cryptography faithfully propagates whatever it is fed.
This is a supply-chain discipline rather than a cryptographic one, and federal guidance for it already exists. NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organizations, updated in November 2024 [[6]](#src-6). The relevant idea for a reactor evidence chain is that assurance about a component has to be established and maintained across acquisition, integration, and operation, not asserted once at purchase.
The nuclear-specific version of the same point is in the IAEA's I&C computer security guidance, which frames protection of instrumentation and control as a life-cycle obligation covering design, procurement, and maintenance rather than a deployment-time checklist [[9]](#src-9). A reactor is a long-lived asset. Components get replaced, firmware gets updated, and vendors change hands, all while the record is expected to remain continuous.
There is a recursion here that deserves an honest word. Attestation about a component is itself an attestation, appraised by something, signed by something else. That regress has to stop somewhere, and where it stops is a design decision with real consequences. We treat the placement of that root of trust as an explicit, documented choice rather than an implementation detail, because a root of trust nobody can name is a root of trust nobody can evaluate.

## Tamper-evident means changes are detectable, not that they are impossible
This distinction is worth stating bluntly, because it is the one most often blurred in vendor language. Tamper-evident is a defined property: an alteration to a record, or a withdrawal of one, is detectable by a party who checks. That is a claim about detection. It is not a claim about prevention. Nothing described in this article is tamper-proof, unhackable, or unbreakable, we do not use those words about our own work, and a vendor who does is telling you something about their marketing rather than their architecture.
What detection buys is specific. An altered statement fails signature verification. A statement missing from the log fails its inclusion proof. A log that has been rewritten between two checks fails its consistency proof [[3]](#src-3), and the registration model that produces those proofs is what makes absence detectable rather than merely suspected [[2]](#src-2). The result is not that misconduct becomes impossible. It is that misconduct becomes visible to someone who was not present when it happened.
The obvious objection is that this is over-engineering for a reactor, since nuclear already has among the most demanding recordkeeping and inspection regimes of any industry. The objection is fair and the answer is that the existing regime was built around presence. It assumed inspectors on site who could look, ask, and form a judgement that instrumentation missed [[10]](#src-10). Those records were trustworthy in large part because people were standing next to the thing being recorded. As that presence thins, the same obligations travel as data over networks, and the mechanism that made them credible does not travel with them automatically. This is not extra rigor bolted onto a solved problem. It is the existing rigor relocated into a medium that needs different machinery to hold it.
The honest limitation is that none of this fixes a bad input. A faithfully signed record of a miscalibrated sensor is a faithful record of a wrong number, and the chain will confirm that wrong number with perfect fidelity for decades. Calibration, sensor diversity, and validation are separate engineering problems, and they stay separate. Evidence integrity and measurement quality are two different disciplines, and buying one does not get you the other.

## Why thinning on-site presence raises the stakes, and where we actually are
The reason this matters more now than it did a decade ago is that the compensating mechanism is being reconsidered. Proposed 10 CFR Part 57 contemplates remote operation and reduced on-site staffing for microreactors [[11]](#src-11), and the NRC's microreactor regulatory activities page tracks that work as it develops [[12]](#src-12). Part 57 is a proposal rather than a final rule, it may change, and no developer is licensed under it. It is also not a move to unattended operation: reactivity and safety actions keep a human in the loop, and we take care not to describe anything as unmanned or fully autonomous, because that is not what is on the table. We walk through that framework in [our explainer on Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
Meanwhile, the operations side has been advancing faster than the verification side, and it is worth saying so. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[13]](#src-13), while Oak Ridge's own framing of autonomous operation named the instrumentation and state-awareness preconditions that remain open [[7]](#src-7). Capability to run with fewer people is arriving ahead of capability to independently confirm what those systems did, and the gap widens further at [fleet scale, where one organization oversees many units](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
On where we stand, plainly. RankShield Energy is a pre-applicant engaged in early interaction with the NRC [[14]](#src-14). We hold no license, permit, or design approval, and nothing about our design or our attestation architecture has been demonstrated to or accepted by the NRC. The chain described in this article is design intent and an architecture we apply in our attestation engineering work. It is not a deployed reactor capability and not a certified one, and we would rather say that flatly than let the distinction blur.
One further limitation belongs here, since it is the sharpest one we know about our own position. A verifier is only as independent as the witnesses that observe its log, and witnesses an organization hosts itself do not establish independence no matter how they are engineered. External witnesses are the open item, and we do not currently have them. If you are evaluating developers on any of this, the questions in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) should be aimed at us as unsentimentally as at anyone else.

Interactive · illustrative

## Follow the chain, from a sensor reading to a checkable record
Select each step. This is an educational illustration of the concept, not a live system, a control interface, or a safety function.
1 · Measure 2 · Appraise 3 · Sign and log 4 · Verify

### Measure
Instruments capture reactor state: power level, temperatures, control-element positions, and the status of each safety function. On their own these are numbers on the operator's own system, and nothing yet makes them trustworthy to an outside party.

### Appraise
An independent verifier, separate from the operator, compares the measured state against what the operator reports and what the design permits. Both agreement and disagreement are recorded, so a later reviewer can see what was checked.

### Sign and log
The verifier's result is signed with a post-quantum digital signature (NIST FIPS 204 and 205) and written to an append-only transparency log, which returns a receipt. The record is designed so it cannot be quietly changed after the fact.

### Verify
Later, a regulator, insurer, lender, or grid operator checks the receipt against the log and the signature, and confirms the record independently, without asking the operator to vouch for itself. This is the property that a plain dashboard cannot provide.

## Frequently asked questions

### What is a reactor state attestation record?
It is what reactor telemetry becomes after it has been appraised by a party separate from the operator, signed, and written to an append-only log that returns a receipt. The chain runs measure, appraise, sign and log, verify. The final step is the point of the exercise: a party that was not present, and that the operator does not control, can still check what was claimed and when. The role separation follows the model RFC 9334 defines, with an attester producing evidence, a verifier appraising it, and a relying party acting on the result <sup><a href="#src-1">[1]</a></sup>.

### Is a vendor dashboard enough to show a reactor is operating as reported?
No, and not because vendors are dishonest. A dashboard renders data the operator collected, over a path the operator controls, in a form the operator chooses, so every element traces back to the party being evaluated. It also shows the present rather than preserving the past. The IAEA treats instrumentation and control systems as protected assets across their life cycle precisely because a compromised path produces plausible readings rather than obvious errors <sup><a href="#src-9">[9]</a></sup>, and a rendered feed gives an outside reviewer no way to tell the difference after the fact.

### What does tamper-evident mean, and is it the same as tamper-proof?
They are different claims and the difference matters. Tamper-evident means an alteration or a withdrawal is detectable by anyone who checks: an altered statement fails signature verification, a missing one fails its inclusion proof, and a rewritten log fails its consistency proof <sup><a href="#src-3">[3]</a></sup>. Tamper-proof would mean alteration is impossible, which is not a property this architecture has or that we claim. Nothing described here is tamper-proof or unhackable. The value is detection, which converts a silent failure into a visible one.

### Why do post-quantum signatures matter for reactor records?
Because a reactor record may need to be verifiable decades after the equipment and possibly the operating organization are gone, which makes signature choice a durability question. NIST announced approval of three post-quantum FIPS in August 2024 <sup><a href="#src-4">[4]</a></sup>, including FIPS 204 for module-lattice-based digital signatures <sup><a href="#src-5">[5]</a></sup>, so a standardized option now exists for long-lived records. The practical takeaway is less about any single algorithm than about agility: build so the verification path can change without invalidating the archive, since a record that becomes unverifiable is worth about as much as one never made.

### Does RankShield Energy have this running on a reactor today?
No. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC <sup><a href="#src-14">[14]</a></sup>. Proposed Part 57 is a proposal whose terms may change, and no developer is licensed under it <sup><a href="#src-11">[11]</a></sup>. The attestation chain described here is design intent and the architecture our attestation engineering work applies, not a deployed or certified reactor capability. The most significant gap we can name in our own position is external witnesses, which we do not have.

## Sources

- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024](https://csrc.nist.gov/pubs/fips/204/final)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Digital twins and remote reactor verification →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of attestation and post-quantum signature standards as of July 2026. This area is evolving; check back if the referenced standards are revised or if the NRC issues new guidance relevant to operational recordkeeping.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors/

# Self-Attestation vs Independent Reactor Verification

> When a reactor reports its own status, who checks the check? Compare self-attestation and independent verification for autonomous and remote reactor operations.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# Self-Attestation vs Independent Verification for Autonomous Reactors
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Self-attestation is a reactor reporting on itself: the operator runs the reactor and also produces the account of how it is behaving. Independent verification adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer. Both can be accurate. Only one is checkable by anyone else.
The distinction sounds academic until presence is removed. Today the NRC keeps roughly 150 resident inspectors in the field, at least two per plant, whose stated role is independently verifying that requirements are being met [[1]](#src-1). A design premised on reduced on-site staffing removes that layer, and what replaces it determines whether an outside party can establish anything at all.
This article sets out the difference, three structural tests that separate the two models, how two adjacent fields already solved the same problem, what independence has to mean concretely, and why autonomy converts this from good practice into a requirement. RankShield Energy is a pre-applicant holding no license or approval [[20]](#src-20), and the last section applies the argument to us.
Key takeaways

- Self-attestation is the operator vouching for itself; independent verification adds a party with no stake in the answer.
- The useful test: if the operator went silent, what could an outsider still establish about last month?
- Independence is structural and testable: who signs, who can alter it, and what an outsider can check unaided.
- IAEA safeguards and the internet's attestation standards both solved this by putting the checker outside the checked.
- As on-site presence thins, more of the safety story rests on self-report, which makes independent confirmation more load-bearing, not less.

## The distinction, stated as plainly as possible
**Self-attestation** is a system reporting on itself. The operator runs the reactor and also produces the account of how the reactor is behaving. **Independent verification** adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer.
Both can be accurate. The difference is not honesty, and framing it as a trust problem about vendors misses the point. The difference is what an outside party is able to establish for themselves.
A useful test: if the operating organization went silent tomorrow, what would a regulator, insurer, or lender still be able to determine about what the reactor did last month? Under self-attestation the answer is roughly nothing, because every artifact traces back to the party being evaluated. Under independent verification the answer is bounded but real.
That gap is the entire subject of this article, and it becomes load-bearing precisely when people stop being physically present.
One clarification before going further, because it is the most common misreading of this argument. Nothing here implies that operators are untrustworthy or that vendor engineering is weak. The claim is narrower and structural: a party cannot supply the independence of its own account, however competent or honest it is. That is a property of the arrangement rather than a judgement about the people inside it.

## Why self-monitoring is necessary but never sufficient
Nothing here argues against operator monitoring. A reactor cannot be run without it, and a vendor with excellent internal instrumentation is in better shape than one without. Self-monitoring detects the large majority of problems, and it detects them fastest.
What it cannot do, by construction, is catch the class of problem where the reporting path itself is the thing that is wrong. If a model is miscalibrated, a sensor drifts, or a reporting chain is compromised, the dashboard can look healthy while the underlying picture is not. There is no second party positioned to notice the discrepancy, because the only observer is the one being observed.
This is not a hypothetical failure mode invented for marketing purposes. It is the ordinary reason auditors exist in every other high-consequence domain, and the reason no serious institution accepts a self-certified financial statement as equivalent to an audited one.
Nuclear has historically solved it with people. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, and describes their function as independently verifying that requirements are being met [[1]](#src-1). That word "independently" is doing specific work in that sentence. The inspector is not a better observer than the operator. The inspector is a differently positioned one.

## Three tests that separate the two models
Independence is not a matter of intentions, and it cannot be established by assertion. It is structural, and it can be tested with three questions that a buyer can ask in a meeting.

Self-attestation and independent verification, compared across three structural tests

Test
Self-attestation
Independent verification

Who signs the record?
The operator, or its software
A party separate from operations

Who can alter or withdraw it?
The same party that produced it
No one silently; changes are detectable

What can an outsider check unaided?
Only what the operator chooses to show
The signature, the log, and the inclusion proof

Failure mode
Undetectable divergence between claim and reality
Detectable, with a record of when detection occurred

The second row is where most systems marketed as verification actually fail. Logs that the operator can rewrite are not evidence, however well formatted. The property that matters is not that a record cannot be changed, but that it cannot be changed quietly.
The third row is the one buyers should press hardest, because it is answerable with a demonstration rather than a description. Ask what an outside party can check without the vendor participating. If the answer requires the vendor to hand something over or vouch for something, the separation is nominal.

## How other high-consequence fields already solved this
Nuclear contains the precedent already, in a different problem domain. The IAEA safeguards system exists so that an outside body applies technical measures through which it can independently verify that facilities are not misused, rather than relying on a state or operator assertion [[2]](#src-2). Safeguards address non-proliferation rather than operational safety, so do not overread the analogy. But the structural insight is identical: for a claim that matters enough, the verifying party is placed outside the party being verified.
Computing formalized the same split and standardized it. RFC 9334 defines an architecture with an Attester that produces evidence, a Verifier that appraises it against an appraisal policy, and a Relying Party that acts on the Verifier's result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[3]](#src-3).
The reason that architecture exists is worth noting: the industry that most wanted self-attestation to be sufficient concluded, after trying, that it was not. Remote attestation was developed precisely because a machine's own claim about its state is not usable by a party that has reason to care.
So the model this article argues for is not novel and we are not claiming to have invented it. It is a settled pattern in two adjacent fields, and the contribution is applying it to reactor operations, which is what [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) actually requires.

## What independence has to mean in practice
Vendors will describe many things as independent. Four properties are worth insisting on, because each closes a specific loophole.
**Separation of function.** The party appraising reactor state is not the party operating the reactor. Not a different team inside the same organization with the same incentives, and not a subsidiary whose budget depends on favourable results.
**Completeness of the record.** Disagreement is recorded as faithfully as agreement. A system that only writes a record when everything matches is not verifying, it is publishing.
**Durability.** The record survives the equipment and the vendor. This is why signature choices matter for records intended to outlive a reactor design cycle, and why NIST approving post-quantum signature standards in August 2024 is relevant to a nuclear conversation at all [[4]](#src-4).
**Checkability without cooperation.** A third party can verify the record later without asking the operator for help. That is exactly what an append-only transparency service with issued receipts provides [[5]](#src-5), using receipts standardized as compact cryptographic proofs of inclusion and consistency [[6]](#src-6). Assurance over the components involved sits under established federal supply-chain guidance [[7]](#src-7).

## Why autonomy moves this from good practice to necessity
For a staffed plant, weak evidence is partly compensated by presence. An inspector on site can form a judgement that instrumentation missed, inside an oversight process built on inspection findings and performance indicators [[8]](#src-8). The GAO has described NRC safety assurance as resting on exactly that monitoring and inspection of the most safety-significant activities [[9]](#src-9).
Remove or thin that presence and the compensation goes with it. Proposed Part 57 contemplates remote operation and reduced on-site staffing [[10]](#src-10), against a current requirement that a licensed operator be present at the controls at all times [[11]](#src-11). NRC staff have separately proposed operational-phase oversight built on a scalable inspection footprint [[12]](#src-12).
The national laboratories have been explicit about what this disturbs. Oak Ridge found autonomous control reaches past staffing into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications, with the control room possibly not co-located with the plant [[13]](#src-13). Sandia, working for the NRC, described designs where one control room supervises multiple microreactors [[14]](#src-14). Brookhaven, also for the NRC, framed the safety question for facilities without main control rooms as verifying that important human actions can be accurately and reliably performed [[15]](#src-15).
Put together: as presence decreases, the share of the safety story carried by self-report increases. Independent verification is what stops that curve from ending somewhere uncomfortable, and it is why the [fleet-scale version](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) of this problem is harder still.
There is a fair objection to all of this, and it deserves a direct answer rather than being skipped. Independent verification adds cost, adds a party, and adds latency to a system that already carries heavy regulatory overhead. For a single well-run reactor with inspectors on site, a reasonable person can argue the marginal benefit is small relative to that burden.
We think that argument is correct for exactly the case it describes, and stops being correct as soon as the model changes. The value of independence scales with two things: how consequential the claim is, and how difficult it is for an outsider to check by other means. A staffed plant with regular inspection scores low on the second. A remotely operated unit inspected on a scalable footprint scores high on both. So the cost stays roughly constant while the benefit grows, which is the opposite of the usual argument for skipping an audit layer.
The other consideration is timing. Verification designed after deployment tends to be verification bolted on, and bolted-on evidence is the kind an outside party has least reason to trust, because the system was not built to produce it. Doing it late is not merely more expensive. It produces a weaker artifact.

## What this looks like applied to reactor state
Concretely, the chain has four steps. Reactor state is measured. An independent party appraises the measurements against what the operator reports and what the design permits. The appraisal is signed and written to an append-only log that returns a receipt. Later, a third party checks the receipt and the signature without needing the operator's cooperation. That is the sequence we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).
The engineering preconditions are not trivial and the labs have named them: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring [[16]](#src-16). Guidance on protecting reactor instrumentation and control across its life cycle exists internationally [[17]](#src-17), and the IAEA has an active research project on computer security for small modular and microreactors that names autonomous and remote operations and centralised fleet management with reduced staffing as the conditions to address [[18]](#src-18).
Capability on the operations side is real and demonstrated. DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[19]](#src-19). The verification side is where the field is thinner, which is the honest asymmetry in this whole discussion.

## Where we actually are, including us
No commercial microreactor fleet operates today, so no fleet operates under continuous independent verification either. Proposed Part 57 is a proposal whose comment period has closed and under which no developer is licensed [[10]](#src-10). Anyone presenting independent verification of reactor state as a deployed, proven capability is describing an intention.
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[20]](#src-20). Verifier-operator separation is the architecture we build toward and the reason this site exists. It is not a certified capability, and we do not present it as one.
Our position, stated so it can be argued with: a vendor cannot be its own independent verifier, and this remains true of us. It is why we treat the separation as structural rather than as a feature to be added later, and the tradeoff is genuine. A separate verifier costs more, adds a party to coordinate with, and creates a body that can contradict us in public. We think that last property is the point rather than a defect.
If you are evaluating developers on this, the questions are in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.

## Frequently asked questions

### Is a vendor monitoring its own reactor the same as independent verification?
No. Monitoring is the operator observing its own plant, which is necessary for running it. Independent verification adds a party structurally separate from the operator that appraises those reports and records the result. The difference is not about vendor honesty. It is that under self-attestation every artifact traces back to the party being evaluated, so an outside reviewer has nothing to rely on that does not depend on that party. Nuclear has traditionally supplied this separation with resident inspectors whose stated role is independently verifying that requirements are being met <sup><a href="#src-1">[1]</a></sup>.

### What makes verification genuinely independent?
Four properties, each closing a loophole. Separation of function, meaning the appraising party is not the operating party and not a team with the same incentives. Completeness, meaning disagreement is recorded as faithfully as agreement. Durability, meaning the record outlives the equipment and the vendor. And checkability without cooperation, meaning a third party can verify the record later without asking the operator for anything. If any one is missing, independence is nominal rather than structural.

### Has any other industry actually solved this?
Two have, in different ways. IAEA safeguards place verification with an outside body that applies its own technical measures rather than relying on operator assertion <sup><a href="#src-2">[2]</a></sup>. Computing standardized it in RFC 9334, separating the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result <sup><a href="#src-3">[3]</a></sup>. Notably, remote attestation was developed because the industry that most wanted self-attestation to be sufficient found that it was not.

### Why does autonomy make this more important rather than less?
Because presence was silently doing part of the work. With staff and inspectors on site, weak evidence is partly compensated by human judgement inside an inspection-based oversight process <sup><a href="#src-8">[8]</a></sup>. Proposed Part 57 contemplates remote operation and reduced staffing <sup><a href="#src-10">[10]</a></sup>, and NRC staff have proposed a scalable inspection footprint for operational oversight <sup><a href="#src-12">[12]</a></sup>. As presence decreases, the share of the safety story resting on self-report increases, which makes independent confirmation more load-bearing, not less.

### Does RankShield Energy have independent verification today?
No, not as a deployed or certified capability. We are a pre-applicant with the NRC holding no license, permit, or design approval <sup><a href="#src-20">[20]</a></sup>. Verifier-operator separation is the architecture we build toward and our reason for existing, but describing an architecture is not the same as having demonstrated it under regulatory review. We would rather say that plainly than let the distinction blur, since the distinction is the entire argument we are making.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [From sensors to an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How RankShield approaches verification →](https://rankshieldenergy.com/technology)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of reactor verification concepts and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear/

# Speed-to-Power: Data Centers and Firm Nuclear Power

> US data-center load is climbing while interconnection queues stretch. See what firm power actually requires and where advanced nuclear fits on the timeline.

[Resources](https://rankshieldenergy.com/resources) / Deployment Deployment

# Speed-to-Power for Data Centers: Where Firm Nuclear Fits
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Speed-to-power is the time from choosing a data center site to having firm, around-the-clock electricity available to energize the load. It has become the governing variable in site selection because electricity demand from data centers is rising faster than the grid can connect new load. The useful question is not which source looks best in the abstract. It is what can actually be energized, and when.
The demand side is documented and the supply side is constrained by process. Lawrence Berkeley National Laboratory reported that U.S. data centers used about 176 TWh in 2023, roughly 4.4% of U.S. electricity, with a projected range of 325 to 580 TWh by 2028, or about 6.7% to 12.0% [[1]](#src-1), and the Department of Energy released that assessment as an evaluation of rising data center demand [[2]](#src-2). EIA now forecasts the strongest four-year growth in U.S. electricity demand since 2000, attributed substantially to data centers [[3]](#src-3). Meanwhile NERC reports that 13 of 23 assessment areas face resource adequacy challenges over the next decade [[9]](#src-9). Load is arriving faster than firm supply is being connected.
One scope note before anything else. This article does not compare what any option costs. There are no unit-cost figures here, no energy-rate figures, and no ranking of the options by expense, because cost is a separate analysis with its own assumptions and it is deliberately out of scope for this piece. What follows compares three things only: time to power, firmness, and the constraint that actually governs each route. RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission, holding no license, permit, or design approval [[15]](#src-15), and the closing section states our position on this timeline as plainly as we can.
Key takeaways

- Speed-to-power, not resource selection in the abstract, is the variable that decides where and when a large data center can be built.
- LBNL put U.S. data center use at about 176 TWh in 2023, roughly 4.4% of U.S. electricity, with a projected 325 to 580 TWh by 2028 [[1]](#src-1).
- The interconnection process is the first gate. LBNL reports a median above four years from request to commercial operation for generation projects completed 2018 to 2024, which describes completed projects rather than the current queue [[6]](#src-6).
- Firmness is not the same as capacity factor. EIA reports 2025 factors of 91.0% for nuclear, 58.4% for gas combined cycle, 34.2% for wind, and 24.4% for solar photovoltaic, and the gas figure reflects dispatch rather than availability [[11]](#src-11) [[12]](#src-12).
- Advanced nuclear is a 2030s option gated by licensing progress and fuel supply rather than by physics, and this article makes no claim that it is faster than any other route.

## Data center electricity demand is growing faster than new firm supply is being connected
The demand side is the least ambiguous part of this discussion. Lawrence Berkeley National Laboratory reported that United States data centers used about 176 TWh in 2023, roughly 4.4% of total U.S. electricity consumption, and projected a range of 325 to 580 TWh by 2028, or roughly 6.7% to 12.0% of national consumption [[1]](#src-1). The Department of Energy released that report and framed it as an evaluation of the increase in electricity demand coming from data centers [[2]](#src-2).
The federal forecasting picture points the same direction. EIA has stated that it expects the strongest four-year growth in U.S. electricity demand since 2000, and attributes that growth substantially to data centers [[3]](#src-3). The Annual Energy Outlook 2026 carries the same demand growth into EIA's long-term projections [[4]](#src-4).
The near-term supply response is worth noticing because it is not what most site plans assume. EIA has written that fossil generation could rise if data center power demand grows faster than expected [[5]](#src-5). In other words, the first answer to a demand surge is usually existing dispatchable units running more hours, not new plants of any kind arriving on the schedule the load wants.
One honest observation about that LBNL range: 325 to 580 TWh is close to a factor of two. Anyone building a campus around a single point estimate inside that band is planning against a number the source itself declined to give. The useful way to read it is as a statement that demand growth is large and its magnitude is genuinely uncertain, which argues for supply arrangements that can be staged rather than committed all at once.

## Interconnection timing, not generation capacity, is the first thing that gates a new large load
The bottleneck most buyers hit first is procedural. Lawrence Berkeley National Laboratory's Queued Up analysis reports a median duration of more than four years from interconnection request to commercial operation [[6]](#src-6). That figure has to be stated precisely to be useful: it describes projects that were completed between 2018 and 2024. It is not a statement about how long projects currently sitting in the queue will take, and it says nothing about requests that were withdrawn without ever reaching operation. Read it as evidence that the process has been slow for the projects that finished, not as a forecast for the project you are contemplating.
Reform is underway and is itself a multi-year process. FERC issued Order No. 2023 to improve generator interconnection procedures and agreements [[7]](#src-7), and the practical effect on any given region depends on how each transmission provider implements it through compliance filings and how the resulting study cycles run. A rule that improves a queue does not clear a queue.
Underneath the queue sits physical transmission. The Department of Energy's National Transmission Needs Study documents where the system needs additional transfer capability [[8]](#src-8). Transmission is the slowest element in the chain and the one least responsive to a single buyer's urgency.
There is a distinction worth drawing that often gets blurred in coverage of this topic. The queue statistics above describe generator interconnection. A data center is a load, and large load interconnection runs through its own studies and its own utility or regional processes. The two are related, because a new load frequently depends on new generation and new transmission being connected as well, but they are not the same process. When a developer quotes you a queue number, ask which queue.

## Firm means available around the clock, and capacity factor is the closest public measure of it
Firm power is electricity that is available when it is called for, around the clock, without depending on weather or time of day. A data center running training and inference workloads has a load shape that is close to flat and close to continuous, which is why firmness rather than annual energy volume is the property that governs procurement.
The most accessible public evidence on how different resources actually perform is EIA's capacity factor reporting. For 2025, EIA reports nuclear at 91.0%, wind at 34.2%, and solar photovoltaic at 24.4% [[11]](#src-11), and natural gas combined cycle at 58.4% [[12]](#src-12).
Those four numbers are frequently misused, so here is the qualification that belongs with them. Capacity factor is actual output divided by output at continuous full power. It blends two very different things: whether a unit was available, and whether it was called to run. The nuclear and renewable figures are dominated by availability and resource. The combined cycle figure is dominated by dispatch, meaning market conditions and system need determined how many hours those units ran. Nothing in the 58.4% figure implies that a gas unit could not have run more. Treating it as a firmness ceiling would be a misreading, and this article does not do that.
For a buyer, the operational definition of firm is narrower than the statistic: the capacity is available, the fuel or energy source is secured, and the dispatch right belongs to you or to a counterparty obligated to serve you. Several routes in the comparison below can satisfy that definition. They differ on what stands between the decision and the energized load, which is the only axis this article ranks them on.

## Resource adequacy is tightening at the same time the load is arriving
The system this load is joining is already under study for adequacy. NERC's 2025 Long-Term Reliability Assessment identifies 13 of 23 assessment areas as facing resource adequacy challenges over the ten-year assessment period, and reports that new data centers account for most of the projected increase in demand [[9]](#src-9).
The Department of Energy's July 2025 report on grid reliability and security supplies the capacity arithmetic behind that concern. DOE states that 104 GW of firm capacity is scheduled to retire by 2030, that 209 GW of new generation is planned over that period, and that only 22 GW of the planned additions is firm baseload [[10]](#src-10). Those are DOE's figures and DOE's definitions of firm and baseload, and they are cited here as that agency's characterization rather than as an independent finding.
The near-term consequence follows from the same arithmetic. EIA has noted that fossil generation could rise if data center demand grows faster than expected [[5]](#src-5), which is what happens when new firm additions do not keep pace with retirements and new load in the same window.
What this means for a specific project is less dramatic than the headline numbers suggest, but it is more binding. An interconnection request for several hundred megawatts of new load does not arrive in a neutral system. It arrives in a planning process that is already tracking a firm capacity gap, and that context shapes how long the studies take, what upgrades get assigned, and what conditions come attached. The adequacy picture is not background color for this topic. It is part of the schedule.

## Co-location is a partial workaround, and its limits are being worked out in public
Because the queue is the bottleneck, the obvious move is to sit next to generation that is already connected. Co-location places the load beside an existing plant and reduces or avoids the need for new transmission service to reach it. It is a real strategy, it is being pursued seriously, and it is the reason several announced projects have timelines that would be implausible through a standard interconnection path.
It also introduces questions the industry has not finished answering. NERC published a white paper on the characteristics and risks of emerging large loads that treats these loads as behaving differently from conventional load, with characteristics that need to be understood and modeled rather than assumed [[13]](#src-13). That is a reliability question independent of who supplies the electricity, and it applies to a co-located load as much as to a grid-connected one.
The commercial and regulatory terms are equally unsettled. FERC has an open proceeding on co-location at PJM under Docket Nos. EL25-49-000 and related dockets [[14]](#src-14). The questions in front of the Commission include how a large load sitting behind or beside an existing generator should be treated for purposes of transmission service and cost allocation to other customers. This article takes no position on the outcome and does not assume one.
The honest summary is that co-location can shorten one path while opening another. It converts a queue and transmission problem into a regulatory and reliability question that is currently being adjudicated. For a buyer, that means a co-location strategy carries schedule risk of a different kind rather than no schedule risk, and the risk is harder to estimate because the governing rules are still being written.

## Advanced nuclear is a 2030s answer gated by licensing and fuel, not by physics
A [microreactor](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor) is small enough to be factory-built and sited near the load it serves, and it is designed to deliver firm baseload output continuously. The reason it is not a near-term answer has nothing to do with whether the physics works. It has to do with two gates that both take years.
The first gate is licensing. The NRC's risk-informed, technology-inclusive framework for advanced reactors, 10 CFR Part 53, was published in the Federal Register on March 30, 2026 and took effect in April 2026 [[15]](#src-15). A framework existing is not the same as a license being issued under it. A developer still moves through [pre-application engagement](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained), then an application, then review. The NRC has separately proposed Part 57 for microreactors, which is a proposed rule and not final, and which we cover in [a separate article](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The second gate is fuel. Most designs in this class need HALEU, and a commercial domestic supply chain for it is still being established. We set out where that fuel comes from, and the primary sources for it, in [our guide to HALEU supply](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel). For scheduling purposes the point is simply that fuel availability is a first-order input to any deployment date, not a detail to resolve later.
On timing, the most defensible public characterization comes from the program itself. The Idaho National Laboratory and DOE microreactor program plan describes the program as focused on designs that could be deployed as early as the late 2020s [[16]](#src-16). That is INL and DOE's characterization of a research and development program, not a delivery commitment from any vendor, and it should not be read as a schedule any specific buyer can procure against. This article makes no claim that advanced nuclear is faster than any other route on this list. For a load that needs energizing in the next two or three years, it is not the route to plan around.

## Firm-power routes, compared by what they deliver and what gates the timing
The table below compares six routes on two questions only: whether the route delivers firm 24/7 output, and what actually governs when it can be energized. There is no cost column, and no cost comparison is implied anywhere in it. Where a cell can be supported by one of the sources cited in this article, the citation is in the cell. Where it cannot, the cell is qualitative and says so, because filling a comparison table with confident numbers that have no primary source is how these comparisons usually go wrong.

Firm-power routes for a large data center load, compared by whether they deliver firm 24/7 output and by the primary constraint on timing. This table contains no comparison of cost.

Route
Delivers firm 24/7
Primary constraint on timing

New grid interconnection for a large load
Yes, once the connection is energized
Interconnection and transmission timing. LBNL reports a median of more than four years from interconnection request to commercial operation for generation projects that were completed between 2018 and 2024 [[6]](#src-6), and the FERC Order No. 2023 reforms are still being implemented through compliance filings [[7]](#src-7).

New on-site or adjacent gas generation
Yes, when fueled and dispatched
Permitting, air authorization, fuel delivery arrangements, and equipment lead times. Stated qualitatively because no figure in the cited set covers equipment delivery. EIA reports the natural gas combined cycle fleet at a 58.4% capacity factor in 2025, which reflects how often units were dispatched rather than a limit on their availability [[12]](#src-12).

Co-location beside an existing generator
Yes, subject to the terms of the arrangement
Unsettled regulatory questions. The terms are before FERC in the PJM co-location proceeding [[14]](#src-14), and NERC has documented reliability characteristics of emerging large loads that bear on how such arrangements are studied [[13]](#src-13).

Wind or solar paired with storage
Not firm on its own. Firmness depends on how storage is sized and operated
Resource availability plus the same interconnection process. EIA reports 2025 capacity factors of 34.2% for wind and 24.4% for solar photovoltaic [[11]](#src-11).

Existing nuclear capacity, through contracts or uprates
Yes. EIA reports the U.S. nuclear fleet at a 91.0% capacity factor in 2025 [[11]](#src-11)
Bounded by the units that already exist and by what is contractually available. Stated qualitatively.

Advanced nuclear, microreactor class
Firm baseload as designed. Not demonstrated in commercial service
Licensing stage and fuel supply. The Part 53 framework was published in the Federal Register on March 30, 2026 and took effect in April 2026 [[15]](#src-15). INL and DOE characterize the program as focused on designs that could be deployed as early as the late 2020s [[16]](#src-16), which is a program characterization rather than a delivery commitment.

*Reading notes. The four-year median in row one applies to generation projects completed between 2018 and 2024 [[6]](#src-6) and is not a prediction for any project now in a queue. Capacity factor figures describe fleet-wide 2025 performance and blend availability with dispatch, so they are not a ranking of reliability [[11]](#src-11) [[12]](#src-12). Rows two and five are deliberately qualitative because the cited sources do not carry equipment lead time or contract availability figures. Nothing in this table compares what any route costs, and nothing in it should be read as a claim that one route is faster than another in the general case, because the binding constraint is site-specific.*
The pattern that emerges is not that one route wins. It is that every route is gated by something procedural or physical rather than by the availability of the technology itself. Interconnection is gated by studies and upgrades. Gas is gated by permitting and equipment. Co-location is gated by an open regulatory question. Advanced nuclear is gated by licensing progress and fuel. A buyer who knows which gate applies to their site is in a much better position than one comparing headline lead times across regions that share almost no relevant conditions.

## What a buyer should actually do, and where RankShield Energy stands
The first action is unglamorous and often deferred: enter the applicable interconnection or large load study process, and find out which study cycle you are in and what upgrades are provisionally assigned to you. Everything else on the schedule is downstream of that answer. The second is to define firm in the contractual sense rather than the marketing sense, meaning availability, secured fuel or energy source, and a dispatch right that belongs to you. The third is to stage supply rather than commit it all at once, which is the reasonable response to a demand projection whose authors published a range spanning nearly a factor of two [[1]](#src-1) and to an adequacy picture federal assessments describe as tightening [[9]](#src-9) [[10]](#src-10).
For the portion of demand that lands in the 2030s, the evaluation questions shift from queue mechanics to developer diligence. Ask about licensing path and fuel path in the same conversation, because a project can be on schedule on one and stalled on the other. We set those questions out in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and the harder version of the problem, how anyone confirms what many units are doing across many sites, is in our piece on [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
Our own status, stated plainly so it cannot be misread. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC. We hold no license, no permit, and no design approval. Nothing about our design has been demonstrated to or accepted by the NRC. We have never operated a reactor and we operate no fleet. We are not offering firm power to any buyer on any date, and this article is not an offer of supply.
The reason we write about speed-to-power at all is that its honest framing is also the framing that disciplines us. If the question is what can actually be energized and when, the answer for advanced nuclear is governed by licensing progress and fuel availability, both visible, both slow, and neither improved by a vendor claiming otherwise. Our working domain is the verification and attestation layer around reactor operations rather than the reactor itself. The tradeoff we accept in saying all of this is a timeline that sounds less exciting than one from a competitor willing to quote a date, and a buyer planning a multi-hundred-megawatt campus is better served by the version that holds up.

## Frequently asked questions

### How long does it take to get firm power to a new data center site?
It depends on the route and the site, and the most defensible public anchor is narrower than it is often quoted as being. Lawrence Berkeley National Laboratory reports a median of more than four years from interconnection request to commercial operation for generation projects completed between 2018 and 2024 <sup><a href="#src-6">[6]</a></sup>. That describes completed projects, not projects currently waiting and not requests that were withdrawn, so it is evidence about how the process has behaved rather than a forecast for a new request. FERC Order No. 2023 is intended to improve those procedures, and its effect in any region depends on how each transmission provider implements it <sup><a href="#src-7">[7]</a></sup>. Underlying transfer capability is documented in DOE's National Transmission Needs Study <sup><a href="#src-8">[8]</a></sup>. The practical answer for a specific site comes from entering the study process and learning which cycle you are in.

### What does firm power mean, and does capacity factor measure it?
Firm power is electricity available on demand around the clock, independent of weather or time of day, which matches the near-continuous load shape of an AI data center. Capacity factor is the closest public proxy but it is not the same thing. EIA reports 2025 capacity factors of 91.0% for nuclear, 34.2% for wind, and 24.4% for solar photovoltaic <sup><a href="#src-11">[11]</a></sup>, and 58.4% for natural gas combined cycle <sup><a href="#src-12">[12]</a></sup>. The nuclear and renewable figures are driven mostly by availability and resource. The combined cycle figure is driven mostly by dispatch, meaning how often the market called those units to run, so it is not a statement about whether they could have run more. Firmness in a contract sense means available capacity, secured fuel or energy source, and a dispatch right.

### Is there enough capacity on the system to serve this load?
Federal assessments describe the margin as tightening rather than comfortable. NERC's 2025 Long-Term Reliability Assessment identifies 13 of 23 assessment areas as facing resource adequacy challenges over the ten-year period and reports that new data centers account for most of the projected demand increase <sup><a href="#src-9">[9]</a></sup>. The Department of Energy reports that 104 GW of firm capacity is scheduled to retire by 2030, that 209 GW of new generation is planned, and that only 22 GW of those additions is firm baseload <sup><a href="#src-10">[10]</a></sup>. Those are DOE's figures and definitions. EIA has separately noted that fossil generation could rise if data center demand grows faster than expected <sup><a href="#src-5">[5]</a></sup>, which is the near-term consequence of that same arithmetic.

### Does co-locating next to an existing power plant solve the timing problem?
It addresses part of it and opens a different question. Placing a large load beside generation that is already connected can reduce or avoid new transmission service, which is why several announced projects use this approach. But NERC has published a white paper documenting the characteristics and risks of emerging large loads, treating them as behaving differently from conventional load in ways that need to be modeled rather than assumed <sup><a href="#src-13">[13]</a></sup>. And the commercial and regulatory terms are being decided now, with FERC running an open proceeding on co-location at PJM under Docket Nos. EL25-49-000 and related dockets <sup><a href="#src-14">[14]</a></sup>. Co-location therefore substitutes one category of schedule risk for another rather than removing it, and the substitute is harder to estimate while the rules are still being set.

### When is advanced nuclear realistically available, and what is RankShield Energy's status?
Advanced nuclear is a 2030s option for most buyers, and the gates are licensing and fuel rather than physics. The NRC's Part 53 framework was published in the Federal Register on March 30, 2026 and took effect in April 2026 <sup><a href="#src-15">[15]</a></sup>, though a framework existing is not a license being issued under it. INL and DOE characterize the microreactor program as focused on designs that could be deployed as early as the late 2020s <sup><a href="#src-16">[16]</a></sup>, which is a program characterization rather than a vendor delivery commitment. HALEU supply is the second gate. As for us: RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, nothing about our design has been demonstrated to or accepted by the NRC, and we have never operated a reactor and operate no fleet. We are not offering firm power on any date.

## Sources

- [Lawrence Berkeley National Laboratory. 2024 United States Data Center Energy Usage Report. December 2024](https://eta-publications.lbl.gov/sites/default/files/2024-12/lbnl-2024-united-states-data-center-energy-usage-report_1.pdf)
- [U.S. Department of Energy. DOE Releases New Report Evaluating Increase in Electricity Demand from Data Centers. December 2024](https://www.energy.gov/articles/doe-releases-new-report-evaluating-increase-electricity-demand-data-centers)
- [U.S. Energy Information Administration. EIA forecasts strongest four-year growth in U.S. electricity demand since 2000, fueled by data centers. January 2026](https://www.eia.gov/pressroom/releases/press582.php)
- [U.S. Energy Information Administration. Annual Energy Outlook 2026. April 2026](https://www.eia.gov/outlooks/aeo/pdf/AEO_Narrative.pdf)
- [U.S. Energy Information Administration. Fossil generation could rise with faster-than-expected growth in data center power demand. March 2026](https://www.eia.gov/todayinenergy/detail.php?id=67344)
- [Lawrence Berkeley National Laboratory. Queued Up: 2025 Edition. December 2025](https://www.osti.gov/biblio/3008763)
- [Federal Energy Regulatory Commission. Improvements to Generator Interconnection Procedures and Agreements (Order No. 2023). September 2023](https://www.federalregister.gov/documents/2023/09/06/2023-16628/improvements-to-generator-interconnection-procedures-and-agreements)
- [U.S. Department of Energy, Office of Electricity. National Transmission Needs Study. Accessed July 2026](https://www.energy.gov/oe/national-transmission-needs-study)
- [North American Electric Reliability Corporation. 2025 Long-Term Reliability Assessment. January 2026](https://www.nerc.com/globalassets/our-work/assessments/nerc_ltra_2025.pdf)
- [U.S. Department of Energy. Report on Evaluating U.S. Grid Reliability and Security. July 2025](https://www.energy.gov/sites/default/files/2025-07/DOE%20Final%20EO%20Report%20%28FINAL%20JULY%207%29.pdf)
- [U.S. Energy Information Administration. Electric Power Monthly, Table 6.07.B, Capacity Factors for Utility Scale Generators Not Primarily Using Fossil Fuels. 2025 data](https://www.eia.gov/electricity/monthly/epm_table_grapher.php?t=epmt_6_07_b)
- [U.S. Energy Information Administration. Electric Power Monthly, Table 6.07.A, Capacity Factors for Utility Scale Generators Primarily Using Fossil Fuels. 2025 data](https://www.eia.gov/electricity/monthly/epm_table_grapher.php?t=table_6_07_a)
- [North American Electric Reliability Corporation. Characteristics and Risks of Emerging Large Loads. July 2025](https://www.nerc.com/globalassets/who-we-are/standing-committees/rstc/whitepaper-characteristics-and-risks-of-emerging-large-loads.pdf)
- [Federal Energy Regulatory Commission. PJM Co-location Proceeding, Docket Nos. EL25-49-000 et al. December 2025](https://www.ferc.gov/sites/default/files/2025-12/EL25-49%20PPT%20E-1%2012.17.25_0.pdf)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [Idaho National Laboratory / DOE. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)

## Related

- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects data-center power demand and advanced-nuclear deployment status as of July 2026. Demand projections are estimates that may be revised, and advanced-nuclear timelines depend on licensing and fuel-supply developments that are still evolving. Check back if the IEA updates its figures or if the HALEU supply picture changes.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state/

# Trusting a Remotely Operated Nuclear Reactor Safely

> Remote operation splits the operator from the core. Learn the two trust gaps this opens, verified commands and verified state, and how each is being addressed.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# Trusting a Remotely Operated Reactor: The Command and State Problem
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Remote operation splits the operator from the core: the people running the reactor are no longer standing next to it. That separation opens two distinct trust gaps. The command gap is whether the instruction the reactor carried out is the one the operator actually sent. The state gap is whether the condition the reactor reports back is its real condition. Verified commands and verified state are the two things an outside party has to be able to check, and neither is solved by trusting the network link. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended.
When a reactor is operated from outside the site boundary, the physics of the core do not change, but the path between the operator's intent and the reactor's behavior gets longer, and every link in that path is something a regulator, insurer, or grid operator now has to be able to trust. In July 2026, Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[1]](#src-1). That result shows the operating model is becoming real. It also sharpens the two questions that follow it: was the right instruction received, and is the reported condition true?
RankShield Energy is a pre-applicant with the NRC, engaged in early regulatory interaction and holding no license or approval. This article is educational. It defines remote operation as command and control from outside the site boundary, distinct from monitoring, then takes apart the command gap and the state gap in turn, compares them, reads the July 2026 demonstration honestly, and sets out where the regulation stands, against a current rule that assumes an operator at the controls and a proposed Part 57 that is not yet final [[8]](#src-8). The reactor's own safety systems and the human in the loop are one layer; independent confirmation of commands and state is a separate layer, and it is the one this post is about.
Key takeaways

- Remote operation is command and control from outside the site boundary, which is distinct from monitoring and opens two trust gaps.
- The command gap is proving the reactor carried out the instruction the operator actually sent, unaltered and in order.
- The state gap is proving the condition the reactor reports back is its real condition, not a stale or spoofed reading.
- Both gaps are verification problems: they are closed by evidence an outside party can check, not by trusting the link.
- Current rules require an operator at the controls; proposed Part 57 contemplates reduced staffing but is not final, and no facility is licensed to operate unattended.

## What does remote operation actually change?
Remote operation means issuing command and control from outside the site boundary, over a communications link, rather than from a control room on the plant. That is a narrower thing than it sounds, and the first useful move is to separate it from monitoring. A regulator can watch data leave a site without anyone off site being able to change what the reactor does. Human factors researchers working with the NRC draw exactly this line, treating offsite monitoring and remote operation as distinct activities with different demands on the people involved [[6]](#src-6). Monitoring observes; remote operation acts.
On-site operation keeps intent and action in one room. An operator moves a control, watches the instrument respond, and confirms both firsthand. Remote operation breaks that loop into pieces joined by a network: the instruction travels to the reactor, and the reactor's response travels back, and neither leg is something the operator witnesses directly. Oak Ridge described the shape of this well before it became topical, noting that remote and centralized control rooms change where operators sit relative to the plant they run [[2]](#src-2).
The engineered safety systems still act locally, and safety-significant actions keep a human in the loop; no facility today is licensed to operate unattended. Current rules assume presence, requiring a licensed operator to be at the controls [[7]](#src-7). What changes under remote operation is the basis for trusting the day-to-day operating picture. More of the operating case now rests on two flows of messages, the commands going out and the state coming back. For a consequential system, trusting those messages is not the same as verifying them, and it helps to keep remote operation distinct from the neighboring ideas of automation and autonomy, which a companion piece on [what those terms actually mean](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms) takes up. The next two sections take the outbound and inbound flows in turn.

## The command gap: how do you prove the reactor got the instruction the operator sent?
The command gap is the risk that the instruction the reactor acts on is not the instruction the operator meant to send. Closing it means making each command something the reactor can confirm as genuine before acting, and something an outside party can check afterward. In practice that has three parts. First, the command carries proof of who issued it, so the reactor can reject anything not from an authorized operator. Second, it is protected against alteration in transit, so a message changed on the way is detected rather than obeyed. Third, each command is recorded in order, so a replayed or reordered instruction cannot pass as fresh.
This is not a new class of problem. Computer security settled its shape years ago in the internet's attestation architecture, published as IETF RFC 9334, which formalizes the idea that a relying party should act on evidence it can appraise rather than on an unverified assertion [[9]](#src-9). Applied to a reactor, the operator proposes an action, but the reactor and any independent verifier act on a command whose origin and integrity can be confirmed.
Oak Ridge, studying the licensing implications of autonomous control, found that the reach of these questions goes well past staffing: it extends into manipulation of controls, licensed-operator provisions, technical specifications, cybersecurity, and required notifications, with the control room possibly not co-located with the plant [[3]](#src-3). Each of those touches the command path. In our own attestation engineering at RankShield, the recurring lesson is that the hard part is not signing a command but making the record of what was commanded checkable by someone who is not the operator, which is the same separation described in [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors). All of this is design intent, subject to analysis, testing, and NRC review; nothing here has been demonstrated to or accepted by the NRC.

## The state gap: how do you prove the reactor's reported condition is real?
The state gap is the mirror image of the command gap. Once a command has been carried out, the operator needs the reactor's actual condition, and outside the control room that condition arrives as reported data rather than direct observation. Verified state is the continuous, checkable confirmation that the condition the reactor reports is its real condition, and not a stale reading, a dropped update, or a value altered in transit.
The mechanics parallel verified commands. The reported state carries proof of where it came from, it is protected against alteration on the way back, and it is recorded so a regulator, insurer, or lender can inspect it later. The same attestation logic applies, in which a relying party appraises evidence about a system rather than taking the system's word for its own status [[9]](#src-9). There is a mature precedent for placing this kind of check outside the reporting party. International safeguards exist so an outside body can independently verify a facility's declarations through its own technical measures, rather than relying on an operator's assertion [[12]](#src-12). Safeguards address non-proliferation, not operational safety, so the analogy is structural rather than exact, but the structural point holds: for a claim that matters, the party confirming it sits outside the party making it.
The engineering preconditions are real. Turning a raw sensor stream into a record an outside party can trust involves instrumentation that survives long unattended operation and a defensible chain from sensor to signed statement, which is the sequence walked through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record). The point is durability of trust. A live dashboard shows what the operator's software chooses to show right now. Verified, recorded state tells an outside party, later, what the reactor actually reported, in a form that does not depend on the operator vouching for itself.

## How do the two gaps compare?
The two gaps are symmetric in structure and opposite in direction. One protects instructions traveling to the reactor; the other protects condition data traveling back. Laying them side by side makes the shared remedy visible: in both cases the fix is not trusting the link but producing a record an outside party can check. The appraise-the-evidence model of RFC 9334 is the common thread [[9]](#src-9).

The command gap and the state gap, compared across what each is, what can go wrong, and how it is addressed

Aspect
Command gap
State gap

What it is
Proving the reactor carried out the instruction the operator actually sent
Proving the condition the reactor reports back is its real condition

Direction of flow
Outbound: operator to reactor
Inbound: reactor to operator and outside parties

What could go wrong
An unauthorized, altered, replayed, or reordered instruction is obeyed as if genuine
A stale, dropped, spoofed, or altered reading is trusted as current truth

How it is addressed
Origin proof, tamper-evidence in transit, and ordered recording an outsider can check
Origin proof, tamper-evidence on the return path, and recording an outsider can inspect later

Who needs to check it
Regulator, insurer, lender, grid operator
Regulator, insurer, lender, grid operator

Reading the table across rather than down is the useful exercise. The failure modes differ, but the remedy is one idea applied twice: replace an act of trust with a piece of evidence. That is why command and state verification are usually built as one system rather than two, and why the honest measure of a remote-operation claim is not how good the dashboard looks but what an outside party can reconstruct without the operator's help. The proposed regulatory framework for this class of reactor contemplates exactly the reduced-presence models that make this evidence matter, which the next sections take up [[8]](#src-8).

## What did the July 2026 INL demonstration show, and what did it not?
Remote reactor control has moved from concept to demonstration. In July 2026, Idaho National Laboratory and university partners achieved remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[1]](#src-1). That is a national-laboratory demonstration of the operating model, run on a research reactor under laboratory conditions. It is not a demonstration of any commercial reactor's safety, and it is not RankShield Energy's result.
It helps to be precise about what a result like this establishes. It shows that operating a reactor across a network is feasible while local safety systems keep control, and it was performed by a national lab whose broader microreactor program, including the MARVEL test reactor, is aimed at exactly this kind of experiment [[14]](#src-14). What it does not establish is that the command and state flows have been independently verified in a form a buyer, regulator, or insurer could check for themselves. The demonstration proved the operating capability. It did not, and did not claim to, prove independent verification of the record.
That second piece is the open frontier, and the honest framing for every serious developer, including us, is design intent subject to testing and regulatory review. The digital-twin approaches that make autonomous control possible on the operations side are further along than the independent-verification approaches that would let an outsider confirm the result, an asymmetry examined in [digital-twin verification of remote operations](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations). Reading the demonstration as proof of a trustworthy remote reactor would overstate it; reading it as proof that the operating model is reachable is exactly right.

## Where does the regulation actually stand?
The regulatory picture is best stated as a gap between what the rules require today and what a proposed rule would allow. Today, a licensed operator must be present at the controls; the conditions of an operating license assume on-site, at-the-controls presence [[7]](#src-7). That baseline is backed by an oversight system built on human presence. The NRC stations resident inspectors at operating plants, at least two per site, whose stated role is to independently verify that requirements are being met [[10]](#src-10), inside a Reactor Oversight Process that combines inspection findings with performance indicators [[11]](#src-11).
Against that baseline, the NRC published a proposed rule in May 2026, a new 10 CFR Part 57, that would set licensing requirements for microreactors and reactors with comparable risk profiles, and that contemplates remote operation and reduced on-site staffing with human responsibility retained for safety-significant actions [[8]](#src-8). The agency's microreactor regulatory-activities pages place this rulemaking within a broader modernization effort for the reactor class [[13]](#src-13). The single most important fact about Part 57 is its status: it is proposed, its comment period has run, and no developer is licensed under it. A neutral reading of what it does and does not say is set out in [our explainer on proposed Part 57](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The direction of travel is clear, and so is the distance still to cover. Reduced presence is contemplated, not authorized. The oversight model that presence supports, independent verification by inspectors on site, does not vanish when staffing thins; it has to be reconstituted in another form. That is the regulatory reason command and state verification matters, rather than a purely technical one: as human presence is proposed to decrease, the mechanism that presence provided has to be replaced by something an outside party can still check.

## Isn't this a problem the reactor's own safety systems already solve?
A fair objection runs like this: the reactor's engineered safety systems act locally and independently of the network, so if a bad command arrives or a reading is wrong, the plant's own protection should hold regardless. Why layer verification on top of that?
The response is that the two do different jobs. Engineered safety systems keep the reactor inside safe physical limits; they are the reason a corrupted command should not be able to cause harm. Command and state verification is about trust in the operating record, which is a separate question the safety systems do not answer. An insurer underwriting the plant, a lender financing it, and a regulator overseeing it all need to know what was commanded and what the reactor reported, in a form they can check without taking the operator's word. Safety systems protect the reactor; verification protects the account of what happened. Both are needed, and neither substitutes for the other. Human factors work for the NRC on facilities without traditional main control rooms frames the core question precisely, as confirming that important human actions can be accurately and reliably performed under these new arrangements [[5]](#src-5).
The honest limitation is this. Independent verification of remote operation is, across the industry, less mature than the operating capability it is meant to check. Sandia, working for the NRC, has mapped the human-factors demands of automating microreactors, including models where one control room supervises several units, and that body of work describes requirements more than it describes finished solutions [[4]](#src-4). RankShield is no exception. We can describe the architecture, and we can point to the attestation engineering behind it, but describing an architecture is not the same as having demonstrated it under regulatory review, and we would rather say that plainly than blur it.

## Where does this leave RankShield Energy?
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. Verifier-operator separation, applied to both the command flow and the state flow, is the architecture we are building toward and the reason this site exists. It is not a certified capability, and we do not present it as one.
Stated as a position that can be argued with: a vendor cannot be its own independent verifier, and that stays true of us. It is why we treat the separation as structural rather than as a feature to be bolted on later. The tradeoff is real and worth naming. A separate verifier costs more to stand up, adds a party to coordinate with, and creates a body that can publicly contradict the operator. We think that last property is the point rather than a defect, because a verifier that can never disagree with you is not verifying anything. That is a design decision we have made and are willing to defend, including what it gives up.
Two things keep this honest. Remote and autonomous operation are demonstrated capabilities at the national-lab level, not settled commercial reality, and no facility today is licensed to operate unattended; safety-significant actions keep a human in the loop. And the independent-verification layer we care about is a direction of work, not a finished product. If you are evaluating developers on any of this, the questions worth asking, and worth turning back on us just as hard, are collected in [how to verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely). The distinction between what has been demonstrated and what has been claimed is the whole of the argument, and it should be applied to us without sentiment.

## Frequently asked questions

### What are the two trust gaps in remote reactor operation?
They are the command gap and the state gap. The command gap is the risk that the instruction the reactor acts on is not the one the operator sent, whether through alteration, replay, or an unauthorized source. The state gap is the risk that the condition the reactor reports back is not its real condition, whether through a stale reading, a dropped update, or a value changed in transit. Both are verification problems rather than only engineering problems, because closing them means giving an outside party something it can check <sup><a href="#src-9">[9]</a></sup>. The reactor's own engineered safety systems and the human in the loop for safety-significant actions are a separate and additional layer.

### How is the command gap actually closed?
By making each command confirmable rather than merely trusted. The command carries proof of who issued it, so the reactor can reject anything not from an authorized operator; it is protected against alteration in transit; and it is recorded in order, so a replayed or reordered instruction cannot pass as fresh. This mirrors the internet's attestation architecture, in which a relying party acts on evidence it can appraise rather than on an unverified assertion <sup><a href="#src-9">[9]</a></sup>. The aim is a record of what was commanded that a party other than the operator can check afterward.

### Is a remotely operated reactor unmanned?
No. Remote operation moves some operators away from the site; it does not remove people from the safety picture. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended. Current rules require a licensed operator at the controls <sup><a href="#src-7">[7]</a></sup>, and the proposed Part 57 framework contemplates remote and reduced-staffing models with human oversight retained, a rule that is proposed rather than final <sup><a href="#src-8">[8]</a></sup>. RankShield Energy does not describe its work as unmanned or fully autonomous, and neither term should be read as a settled reality or as this company's claim.

### Has remote reactor operation actually been demonstrated?
Yes, at national-lab scale. In July 2026, Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with safety systems retaining control throughout <sup><a href="#src-1">[1]</a></sup>. That demonstrates the operating model on a research reactor under laboratory conditions. It is not a demonstration of a commercial reactor's safety, and it is not RankShield Energy's result. Independent verification of the command and state flows, in a form an outside party can check, remains an open area of work across the industry.

### Does RankShield Energy verify commands and state today?
No, not as a deployed or certified capability. We are a pre-applicant with the NRC holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. Verifier-operator separation across the command and state flows is the architecture we build toward and our reason for existing, but describing an architecture is not the same as having demonstrated it under regulatory review. The proposed framework this sits inside is itself still proposed and subject to change <sup><a href="#src-8">[8]</a></sup>, and we would rather say all of that plainly than let the distinction blur.

## Sources

- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)

## Related

- [Automation, remote operation, and autonomy explained →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)
- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of remote reactor operation and NRC rulemaking as of July 2026. Proposed rules for this class of reactor are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely/

# How to Verify an Autonomous Microreactor Is Running Safely

> An autonomous microreactor runs with fewer people on site. See how independent verification confirms it is operating safely, without taking a vendor's word.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# How to Verify an Autonomous Microreactor Is Operating Safely
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. You verify an autonomous microreactor the way you verify any critical system you cannot stand next to: an independent party, not the operator, continuously confirms what the reactor is doing and records that confirmation so someone else can check it later. Verification is a separate function from operation. For a reactor designed to run with fewer people on site, that function has to be continuous, independent, and hard to alter after the fact.
That sounds abstract until you look at what it replaces. Today the Nuclear Regulatory Commission keeps roughly 150 resident inspectors in the field, at least two at every plant, whose job is independently verifying that requirements are being met [[2]](#src-2), and federal regulation requires a licensed operator at the controls at all times [[5]](#src-5). A microreactor designed for reduced on-site staffing does not merely trim that. It removes the mechanism by which outsiders have historically known anything.
This guide walks through what oversight looks like now, what the national laboratories have found actually breaks under autonomy, why the verifying party cannot be the operating party, what has genuinely been demonstrated, and where the regulator is heading. RankShield Energy is a pre-applicant with the NRC, holding no license or approval [[29]](#src-29), and the last section applies every argument here to our own program.
Key takeaways

- Today's oversight rests on people being present: about 150 NRC resident inspectors, at least two per plant, plus a licensed operator required at the controls at all times.
- Autonomy does not remove the verification burden, it moves it from observing a plant to checking claims about a plant.
- A vendor cannot be its own verifier, which is why IAEA safeguards and the internet's attestation standards both put the checker outside the checked.
- Autonomous control has been demonstrated at national-lab scale; continuous independent verification of a fleet has not, because no commercial fleet exists.
- The NRC itself anticipates a smaller inspection footprint, while the GAO flags unresolved staffing gaps. That space is what verification has to fill.

## How the current reactor fleet is actually watched
Oversight of the operating US fleet rests on people being physically present. The Nuclear Regulatory Commission stations resident inspectors at every plant, describing their role as providing essential on-site verification of licensee activities through walkdowns, observing tests, and reviewing corrective action documents [[1]](#src-1). The agency employs roughly 150 of them, with at least two assigned to each plant, and their stated job is independently verifying that requirements are being met [[2]](#src-2).
That human layer sits inside a larger structure. The Reactor Oversight Process is risk-informed and tiered, built on safety cornerstones, NRC-developed inspection findings, licensee-reported performance indicators, a significance determination process, and an action matrix that escalates as performance degrades [[3]](#src-3). The Government Accountability Office has described the agency's safety assurance as resting on exactly this: monitoring and inspecting the activities with the greatest effect on safety [[4]](#src-4).
There is also a hard legal floor underneath all of it. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times, and a licensed operator or senior operator must be present at the controls at all times [[5]](#src-5). That is not a guideline or an industry practice. It is a condition of the license.
Read together, these establish what a microreactor fleet is actually proposing to change. Not just staffing economics, but the mechanism by which anyone outside the operating organization knows what a reactor is doing.

## What autonomy actually removes, according to the labs studying it
Oak Ridge National Laboratory examined this directly and enumerated what autonomous control disturbs: staffing, manipulation of controls, licensed operator requirements, technical specifications, cybersecurity, and event notifications, noting that a control room may not even be co-located with the plant [[6]](#src-6). As one ORNL researcher put it, current regulatory guidance was written when remote operation of nuclear reactors was not possible, so this is a new frontier [[7]](#src-7).
Sandia National Laboratories, working for the NRC, reached the operational version of the same conclusion: human operators may not be located on site and may instead monitor the facility from a remote location, and some designs contemplate one control room supervising multiple microreactors [[8]](#src-8).
The most useful framing comes from Brookhaven National Laboratory, in work performed for the NRC's Office of Nuclear Regulatory Research on facilities without main control rooms. Their point is precise: the safety question is not so much justifying why a design has no main control room, but rather verifying that important human actions can be accurately and reliably performed [[9]](#src-9).
That sentence is the whole problem restated by the regulator's own research arm. The burden does not disappear when the people leave. It moves, from observing a plant to verifying claims about a plant. And verifying a claim requires something the claim itself cannot supply.

## Why the verifier cannot be the vendor
A party that both operates a reactor and certifies its own status carries a conflict that no amount of engineering removes. The report may be perfectly accurate. But an outside party has no independent basis to know that, because the same organization produces the report and is judged by it.
This is not a novel observation, and nuclear already contains the precedent. The IAEA safeguards system exists precisely so that an outside body applies technical measures through which it can independently verify that facilities are not misused, rather than relying on an operator's assertion [[10]](#src-10). Safeguards address non-proliferation rather than operational safety, so the subject matter differs. The structure does not.
Computing settled the same question formally. The internet's remote attestation architecture, standardized as RFC 9334, splits the roles into an Attester that produces evidence, a Verifier that appraises it against policy, and a Relying Party that acts on the result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[11]](#src-11). The design assumption is that the thing being checked does not get to be its own checker.
Which is why [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) are different products, not different words for the same product. A vendor dashboard shows what the operator's software chooses to display at the moment it chooses to display it. That is useful for running a plant. It is not evidence to anyone else.
The uncomfortable version, stated plainly: "trust us, the reactor is fine" may well be true, but truth an outsider cannot check is not the same as truth an outsider can rely on. For something with a reactor's consequences, that difference is the entire point.

## What replaces the inspector, function by function
It helps to stop treating this as one problem and break the resident inspector's job into what it actually delivered, then ask what has to supply each piece when the person is not there. The table below is our own mapping rather than a regulatory framework, offered as a way to structure the question.

What on-site presence provided, and what has to replace each function

Function of on-site presence
What must supply it without a person there
Why the operator alone cannot

Direct observation of plant condition
Continuous instrumented measurement of reactor state
Sensors report through the operator's own systems

Independent judgement about what was seen
Appraisal of measured state against design limits by a separate party
Self-appraisal is the conflict being solved

A witness who can be asked afterwards
A tamper-evident record a third party can examine later
Logs the operator can alter prove little

Escalation when something looks wrong
Divergence surfaced automatically and recorded either way
Undocumented judgement calls are unreviewable

The middle column is not speculative. ORNL's work on autonomous microreactor operation identifies the same requirements from the engineering side: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring [[12]](#src-12). Those are the preconditions for anyone, operator or verifier, to know anything at all.
The right-hand column is where [independent verification](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) earns its place. Every function in the left column that depended on the inspector being a party with no stake in the answer needs a replacement with the same property.

## Recording it so someone can check afterwards
Continuous appraisal solves the present tense. It does not by itself solve the past tense, which is what a regulator, insurer, lender, or grid operator actually asks about. Their question is rarely "what is the reactor doing right now." It is "what was it doing on the fourteenth, and how do I know."
That is a records problem with an established answer outside nuclear. RFC 9943 defines an append-only transparency service that registers signed statements and issues receipts, so that a third party can audit the record later [[13]](#src-13). RFC 9942 standardizes the receipts themselves as compact cryptographic proofs of inclusion and append-only consistency against a verifiable data structure [[14]](#src-14), which matters for remote sites where bandwidth is limited.
Signatures on records intended to outlive the equipment need to survive future cryptography as well. NIST approved three post-quantum standards in August 2024, including ML-DSA and SLH-DSA for digital signatures [[15]](#src-15), and the federal baseline for assuring integrity across acquired components sits in NIST SP 800-161r1 [[16]](#src-16).
None of this is exotic and none of it was invented for reactors. It is the ordinary machinery of making machine-generated claims checkable by someone who was not present, which is exactly what [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) requires.
A distinction worth holding onto: tamper-evident is not tamper-proof. The property being sought is not that a record cannot be altered. It is that alteration cannot happen quietly.

## What has actually been demonstrated so far
The operating model is further along than most coverage suggests. In 2022 the Department of Energy reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted future heat pipe temperatures and then autonomously controlled the heat pipe on the MAGNET testbed [[17]](#src-17). That is closed-loop autonomy, demonstrated, not theorized.
INL's MARVEL project is explicitly intended to test systems for remote monitoring, develop autonomous control technologies for microreactors, and help develop regulatory approval processes for them [[18]](#src-18). In July 2026, INL and university partners went further and demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout [[19]](#src-19).
Two cautions belong with those results, and we would rather state them than let a reader over-read the paragraph above. These are national-laboratory demonstrations, not commercial operation, and none of them belongs to any vendor including us. And demonstrating that a reactor can be controlled autonomously is a different achievement from demonstrating that an independent party can continuously confirm what it did.
The second half is the thinner half. The instrumentation and control security guidance exists internationally [[20]](#src-20), and the IAEA has an active research project on computer security for small modular and microreactors that names autonomous and remote operations, digital twins, and centralised fleet management with reduced staffing as the conditions to be addressed [[21]](#src-21). But there is no operating fleet under continuous independent verification today, because there is no operating microreactor fleet.

## Where the regulator is heading, and what is still unsettled
The NRC has been circling this since at least 2020, when SECY-20-0093 flagged autonomous operation, remote operation, staffing, and oversight as open policy questions for microreactors [[22]](#src-22). More recently the agency has been planning for standardized, fleet-scale deployment [[23]](#src-23), which is the regulatory shape of many units per unit of attention.
The concrete vehicle is proposed 10 CFR Part 57, published in the Federal Register on May 1, 2026, which contemplates remote operation and reduced on-site staffing [[24]](#src-24), with companion draft guidance in NUREG-2271 aimed at rapid licensing and high-volume deployment [[25]](#src-25). Both are proposals. The comment period closed in June 2026, no developer is licensed under Part 57, and the text can still change. Anyone describing it as settled law is describing something that does not exist yet, which is why we cover [what proposed Part 57 actually says](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) separately.
The most telling signal is quieter. Under the ADVANCE Act, the NRC is directed to develop microreactor strategies across areas including staffing and operations, and oversight and inspections, and in December 2025 staff proposed operational-phase oversight built on innovative inspection methodologies and a scalable inspection footprint [[26]](#src-26). The regulator itself anticipates that the inspection footprint shrinks.
Meanwhile the GAO has repeatedly flagged that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[27]](#src-27), and still lists licensing advanced reactors among its priority open recommendations [[28]](#src-28). Fewer inspectors per reactor is arriving whether or not the verification layer arrives with it. That gap is the thing worth designing against now.

## How we apply this to ourselves
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[29]](#src-29). We have never operated a reactor, so nothing above is offered as operating experience.
What we do claim is narrower and, we think, more useful. Our working domain is the verification layer itself: independent appraisal, signing, and transparency logging of machine-generated claims. That is where our judgement comes from, and it is why we treat separation between the verifier and the operator as an architectural requirement rather than a feature. The tradeoff is real and worth naming, because a separate verifier costs more and adds a party to coordinate with. We think that cost is the point rather than an inefficiency to engineer away.
Our reactor safety characteristics are design intent, subject to analysis, testing, and regulatory review. Our verification approach is an architecture we apply, not a deployed or certified capability. If you are weighing developers, the same questions we have set out here apply to us, which is the premise of our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.
One last framing that may be useful when you read any developer's material, including this site. Ask whether a claim is about engineering or about evidence. Engineering claims describe what a machine is built to do, and they are settled by analysis, testing, and regulatory review over years. Evidence claims describe how anyone outside the operating organization would know the machine did it, and they are settled by who is positioned to check. Most of this industry, ourselves included, is further along on the first than the second. Noticing which kind of claim you are being offered is most of the work.

## Frequently asked questions

### Who verifies an autonomous microreactor if no one is on site?
An independent verifier: a party structurally separate from the operator that continuously appraises the reactor's reported state against what the design permits, and records the result so it can be checked later. This is different from the operator's own monitoring software. Today the equivalent function is largely carried by NRC resident inspectors, roughly 150 of them with at least two at each plant, whose stated role is independently verifying that requirements are being met <sup><a href="#src-2">[2]</a></sup>. Regulatory oversight remains with the NRC. Independent verification is a technical function that supports it rather than replacing it.

### Does the law currently require an operator to be physically present?
Yes. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times and a licensed operator or senior operator must be present at the controls at all times <sup><a href="#src-5">[5]</a></sup>. That is a condition of the license for the current fleet. Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors <sup><a href="#src-24">[24]</a></sup>, but it is a proposal published in May 2026 whose comment period has closed, it is not final, and no developer is licensed under it today.

### Has autonomous reactor control actually been demonstrated?
Yes, at national-laboratory scale. DOE reported in 2022 that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe <sup><a href="#src-17">[17]</a></sup>, and in July 2026 INL and university partners demonstrated remote, real-time autonomous power control of a research reactor with safety systems retaining control <sup><a href="#src-19">[19]</a></sup>. Both are demonstrations of the operating model. Neither is a demonstration of continuous independent verification of a commercial fleet, and neither belongs to a vendor.

### Is independent verification the same as NRC approval?
No. Independent verification is a technical function performed by a party separate from the operator. NRC approval is a regulatory determination made by the federal regulator. A developer can build a verification layer and still be, as RankShield Energy is, a pre-applicant holding no license or approval <sup><a href="#src-29">[29]</a></sup>. The two support each other but are not interchangeable, and no verification architecture substitutes for regulatory review.

### Why not just rely on the vendor's monitoring dashboard?
Because a dashboard answers a different question. It shows what the operator's software chooses to display, at the moment it chooses to display it, to the operator. That is genuinely useful for running a plant. It does not help an insurer, lender, regulator, or grid operator establish what happened last month, because the party producing the record is the party being evaluated by it. The distinction is not about vendor honesty. It is structural, and it is the same reason companies do not audit their own books.

## Sources

- [U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description/resident-insp-program)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [NRC Part 57 and autonomous operation →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor verification and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/walk-away-safety-explained/

# Walk-Away Safety Explained: How a Reactor Cools Itself

> Walk-away safety means a reactor shuts itself down and cools itself using physics alone, with no operator, no power, and no pumps. Here is how it works.

[Resources](https://rankshieldenergy.com/resources) / Reactor safety Reactor safety

# Walk-away safety, explained
Published July 21, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy
Walk-away safety is the claim that a reactor can lose electrical power, lose active cooling, and lose its operators at the same time, and still shut itself down and remove its own heat through natural physical processes rather than through equipment that has to work. It is a design approach rather than a property any reactor gets for free, and the NRC has a narrower and more useful term for the underlying idea: passive safety. This article explains what the claim actually requires, the physics it rests on, and the four tests that separate a rigorous walk-away claim from a loose one.
The phrase is used loosely because it is persuasive, and that is precisely the reason to be careful with it. The NRC describes passive safety as systems and design characteristics that perform a safety function using natural forces such as gravity, natural circulation, and conduction, without relying on electrical power or operator action [[1]](#src-1). That is a description of an approach a designer can take. It is not a certificate that any particular machine has achieved anything, and the gap between those two readings is where most misleading marketing lives.
The distinction that runs through this article is **designed** versus **demonstrated**. Every specific reactor has to show, through qualified analysis and testing under regulatory review, that its passive features do what its analysis predicts. RankShield Energy is a pre-applicant engaged in early interaction with the NRC and holds no license, permit, or design approval [[11]](#src-11). Nothing here should be read as a representation that any characteristic of our design has been demonstrated to or accepted by the regulator.
Key takeaways

- A meaningful walk-away claim covers the simultaneous loss of power, cooling, and operators, not a single component failure.
- The NRC term for the underlying idea is passive safety: safety functions performed by natural forces without electrical power or operator action.
- Small size helps because a smaller core produces less decay heat relative to the material and surface area available to carry it away.
- Negative temperature feedback is a design property, not a universal law. Each design has to show its own core actually behaves that way.
- Designed and demonstrated are different words. Analysis predicts; testing under regulatory review substantiates.
- Four tests: does the claim name the failure set, distinguish designed from demonstrated, state regulatory status precisely, and survive an outside check?

## What does walk-away safety actually mean?
It means one specific and demanding thing: the reactor loses its connection to the grid, its backup power does not start, its active cooling stops, and every operator leaves, all at the same time, and the reactor still shuts down and removes its decay heat without damage and without anyone intervening.
The test is defined by simultaneity. Any reactor design can handle one failure; defense in depth has been standard practice in this industry for decades. What makes the walk-away framing demanding is that the failures are stacked and the human response is removed. A claim that addresses a single pump failure, or a loss of offsite power with backup generators available, is describing something considerably easier and should not be presented in the same language.
The regulator has a narrower term for the underlying idea, and it is the one worth using. The NRC defines passive safety as systems and design characteristics that perform their safety function using natural forces such as gravity, natural circulation, and conduction, without relying on electrical power or operator action [[1]](#src-1). The IAEA describes the same reliance on passive systems and inherent characteristics across the small reactor field [[2]](#src-2). Walk-away safety is the popular restatement of that idea, and popular restatements lose precision.
The claim is also bounded in time in a way that gets skipped. Decay heat falls sharply in the hours after shutdown but does not go to zero, so the honest question is not only whether the reactor survives the first hour but what the heat removal path looks like over days. A rigorous claim states the duration it covers and the conditions assumed.
One more boundary matters. Walk-away safety is a claim about the reactor responding to loss of power, cooling, and staff. It is not a claim about security, sabotage, or the integrity of the control system, which are separate problem domains with their own regulatory treatment and their own evidence requirements. Treating a thermal-hydraulic argument as though it covered a cybersecurity question is a common and consequential category error. The class context for all of this is in our explainer on [what a nuclear microreactor is](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor).

## Why does the NRC call these features passive safety?
Because the regulator uses a narrower and more testable term than the marketing phrase. The NRC glossary defines passive safety as safety systems and design characteristics that perform their function using natural forces such as gravity, natural circulation, and conduction, without reliance on electrical power or operator action [[1]](#src-1).
Two things are worth extracting from that definition. It names the mechanisms rather than the outcome, which makes a claim checkable: you can ask which natural force is doing the work in a given sequence and what analysis supports it. And it is written as a description of design characteristics, not as an assurance about any specific plant. The regulator is defining a category of engineering approach, not certifying a machine.
The IAEA uses the concept in the same way when discussing small modular reactors, describing designs that rely on passive systems and inherent characteristics such as natural circulation, so that safety functions can be performed without external intervention [[2]](#src-2). The agency also frames this as a design approach adopted across the small reactor field rather than as a settled result [[3]](#src-3).
This is why every careful sentence in this article attributes the general concept to the NRC, the IAEA, or DOE rather than asserting that a particular reactor achieves it. The concept is well established and uncontroversial. The application of the concept to any one machine is the part that requires evidence, and that evidence is produced through analysis and testing under regulatory review rather than through description. When a developer states the concept and lets the reader infer the achievement, that inference is doing work the developer has not earned.

## Why does small size help?
Because the amount of heat a core keeps producing after shutdown scales with the power it was producing before, while the material and surface area available to absorb and shed that heat do not shrink at the same rate. A smaller reactor therefore has a more favorable ratio between the heat it must remove and the mass and area available to remove it.
Decay heat is the specific problem. When the chain reaction stops, the fission products in the fuel keep decaying and keep releasing energy for a long period afterward. In a large light-water plant the absolute quantity of that heat is very large, which is why the conventional safety architecture is built around powered pumps and the emergency electrical supply needed to run them. In the microreactor size class, which DOE describes as roughly one to twenty megawatts [[4]](#src-4), the absolute quantity is far smaller.
The IAEA makes the same point about the small reactor family, noting that reduced size and power allow greater reliance on passive systems and inherent characteristics for safety functions [[2]](#src-2). This is a genuine physical advantage and it is the reason the class can be designed the way it is.
It is not, however, a conclusion. A favorable ratio makes passive heat removal *plausible* for a given design. What turns plausibility into a safety case is the analysis that shows the specific geometry, materials, and heat path actually carry the heat under the specific sequences the regulator asks about, backed by testing that validates the models used. Size helps the argument. It does not make the argument.

## What makes a reactor slow itself down as it heats up?
A property called negative temperature feedback. In plain terms, a core with this property responds to rising temperature by slowing the fission rate, so an unplanned increase in power raises temperature, and the higher temperature pushes the reaction back down without anything being switched on.
The mechanism is physical rather than procedural. As fuel temperature rises, neutron absorption in the fuel changes in a way that reduces the number of neutrons available to sustain fission, and expansion of the core materials as they heat lets more neutrons escape. Both effects push in the same direction. The net result is a reactor whose power tends to self-limit rather than run away, which is why the IAEA and DOE both discuss inherent characteristics of this kind when describing advanced designs [[2]](#src-2) [[3]](#src-3).
This is where precision matters most, because the phrase is often stated as though it were a law of nature that applies to every reactor. It is not. Negative feedback is a design property that depends on core composition, geometry, materials, and operating temperature, and a design has to establish the sign and magnitude of its own feedback through analysis and confirm it through testing under regulatory review. We deliberately publish no reactivity coefficients, core geometry, or fuel loading details for our own design, because that class of technical data is subject to export control under 10 CFR Part 810.
The practical reading for a non-specialist: treat negative temperature feedback as a claim a developer must substantiate about a specific core, not as a category benefit that arrives with the word advanced.

## How does heat leave the core without pumps?
Through three natural mechanisms, usually working together: natural circulation, conduction, and thermal radiation. None requires electrical power, and none requires an operator to start it.
**Natural circulation** is buoyancy doing the work of a pump. Heated fluid becomes less dense and rises, cooler fluid falls to replace it, and a loop establishes itself driven purely by temperature difference and gravity. **Conduction** moves heat through solid material, out of the fuel, through the core structure, and into whatever surrounds it. **Thermal radiation** carries heat from hot surfaces to cooler ones with no medium required at all, and it becomes more effective as surface temperature rises, which is a useful property in exactly the situation where you need it. The NRC names gravity, natural circulation, and conduction explicitly in its definition of passive safety [[1]](#src-1), and the IAEA describes the same reliance in the small reactor context [[2]](#src-2).
The design consequence is that a rigorous safety case keeps the passive heat path independent of the equipment used in normal operation. Whether a design moves heat with a pump, a heat pipe, or natural circulation during normal running, the walk-away case has to be carried by a path that does not depend on any of that equipment continuing to function. If the passive path shares a component with the active path, the independence is nominal.
The ultimate heat sink is the part to ask about. Every one of these mechanisms ends by depositing heat somewhere outside the reactor, whether that is ambient air, ground, or a body of water. A claim that describes the path out of the core but never names where the heat finally goes, and whether that sink can be lost, is incomplete. For a microreactor sized in the range DOE describes [[4]](#src-4), the sink is often ambient air, which is attractive precisely because it is difficult to remove.

## What does the fuel contribute, and what does it not?
Fuel contributes a barrier, not an outcome. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic, with each particle carrying its own containment barrier around the fission products it produces [[5]](#src-5). Distributing that barrier across millions of particles rather than concentrating it in a single boundary is a real engineering property, and DOE presents it as a robust fuel form.
That is DOE characterizing a fuel concept, and the attribution matters. What a particular reactor achieves with TRISO depends on the fuel qualification data submitted for that design, the temperatures the design actually reaches in the sequences under review, and the regulator finding the supporting analysis adequate. Fuel qualification is its own substantial evidentiary program, not an inherited property of the fuel type.
It is also worth being clear about what fuel does not do. A robust fuel particle does not shut a reactor down, does not remove decay heat, and does not substitute for a heat removal path. It limits the consequences if temperatures rise. The shutdown mechanism, the heat path, and the fuel barrier are three separate elements of a safety case and a rigorous claim addresses all three rather than leaning on whichever is most quotable.
Absolute phrasing is the tell. When a claim about fuel is stated as though it removed the need for the rest of the safety case, the claim has outrun its evidence. The more useful framing is the one DOE uses: a fuel form with strong containment characteristics, supported by a specific body of qualification work [[5]](#src-5). Fuel availability is a separate constraint again, and [where HALEU comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel) governs whether any of this reaches a site.

## Designed is not demonstrated, and the difference is the whole argument
A design intent is what analysis predicts. A demonstration is what testing showed, under what conditions, reviewed by whom. Almost every misleading walk-away claim in circulation is a design intent written in the grammar of a demonstration.
The regulatory context makes the difference concrete. Today, assurance for the operating fleet rests substantially on people being present: federal regulation requires a licensed operator at the controls at all times [[8]](#src-8), and the NRC runs a risk-informed Reactor Oversight Process built on inspection findings and performance indicators [[9]](#src-9). Those mechanisms exist because a paper safety case is not by itself considered sufficient assurance about an operating plant.
For microreactors that architecture is being reworked rather than removed. The NRC published a proposed rule, 10 CFR Part 57, addressing licensing requirements for microreactors and other reactors with comparable risk profiles [[6]](#src-6), and in March 2026 published its risk-informed, technology-inclusive Part 53 framework for advanced reactors [[7]](#src-7). Part 57 is **proposed**, not final, it may change, and no developer is licensed under it. The federal microreactor program plan prepared by INL and GAIN for DOE sets out the research and demonstration work the class still requires [[10]](#src-10), which is a clearer statement of where the field stands than any vendor announcement.
Our position, stated so it can be argued with: a walk-away claim made by the party that would benefit from it is an assertion, whatever its technical merit, until someone with no stake in the answer can check it. That is the same reasoning behind [the difference between self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it applies to reduced-staffing operation as directly as to safety analysis, which is the subject of our explainer on [what Part 57 proposes](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained). RankShield Energy is a pre-applicant with no license, permit, or design approval [[11]](#src-11), and we hold our own claims to this standard.

## Four tests to apply to any walk-away claim
These are the questions we would want asked of us, in the order they are most likely to be informative.
**One: does the claim name the failure set?** A meaningful walk-away claim covers the simultaneous loss of power, active cooling, and operators, and states the duration it covers. A claim that names no failure set is not a claim, it is a mood.
**Two: does it distinguish designed from demonstrated?** Look for the verb. Designed to, intended to, and analysis predicts are honest descriptions of design intent. Testing showed, validated against, and reviewed by are descriptions of evidence. A developer that never uses the first set is either not being careful or is counting on you not to notice.
**Three: is the regulatory status stated precisely?** Pre-applicant, applicant, and licensee are distinct. Proposed rules are proposals: Part 57 was published for comment in May 2026 and is not final [[6]](#src-6), and the NRC describes pre-application activities as early interaction preceding any application [[11]](#src-11). Vagueness here is rarely accidental.
**Four: what can an outside party check without the developer helping?** Regulator and laboratory documents are checkable by anyone. A slide is not. This is the test we consider load-bearing, and the extended version is in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) and in [how to verify an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).
**An honest limitation.** We cannot demonstrate our own passive safety performance to you through a blog post, and we are not going to try. The NRC glossary describes the general concept [[1]](#src-1); the specific behavior of any reactor is established through qualified analysis and testing under regulatory review, and we have not completed that process. We also deliberately publish no core geometry, fuel loading, enrichment specifics, or reactivity coefficients, because that data is subject to export control under 10 CFR Part 810. The cost of that decision is that this article stays at the level of concept and method. We think a reader is better served by an explicit boundary than by detail that reads as substantiation and is not.

## Frequently asked questions

### What does walk-away safe mean for a nuclear reactor?
It means the reactor can lose electrical power, active cooling, and its operators at the same time and still shut down and remove its decay heat through natural physical processes rather than through equipment that has to keep working. The demanding part is simultaneity: a claim about a single component failure is describing something much easier. The NRC term for the underlying idea is passive safety, defined as design characteristics that perform a safety function using natural forces such as gravity, natural circulation, and conduction, without electrical power or operator action <sup><a href="#src-1">[1]</a></sup>.

### Is passive safety the same as being completely safe?
No, and treating it that way is the most common error in this subject. Passive safety is a design approach recognized by the NRC <sup><a href="#src-1">[1]</a></sup> and used widely across the small reactor field as described by the IAEA <sup><a href="#src-2">[2]</a></sup>. Applying the approach to a specific machine is a separate matter that has to be established through qualified analysis and testing under regulatory review. The honest formulation is that a reactor is designed to rely on passive features, with performance subject to that review, rather than that it is safe.

### How does a reactor remove heat without pumps?
Through natural circulation, conduction, and thermal radiation working together. Heated fluid rises and cooler fluid falls, establishing a loop driven by temperature difference and gravity; heat conducts out through solid structure; and hot surfaces radiate to cooler ones. The NRC names gravity, natural circulation, and conduction in its definition of passive safety <sup><a href="#src-1">[1]</a></sup>, and the IAEA describes the same reliance in small reactors <sup><a href="#src-2">[2]</a></sup>. The question worth asking of any design is where the heat finally goes and whether that ultimate heat sink can be lost.

### Why does a smaller reactor make passive cooling easier?
Because decay heat scales with the power the reactor was producing, while the structural mass and surface area available to absorb and shed that heat do not scale down as fast. A microreactor, at the roughly one to twenty megawatts DOE describes for the class <sup><a href="#src-4">[4]</a></sup>, has far less heat to remove in absolute terms than a large plant, and the IAEA notes that reduced size and power allow greater reliance on passive systems and inherent characteristics <sup><a href="#src-2">[2]</a></sup>. This makes passive heat removal plausible for a design. It does not by itself substantiate it.

### How do I tell a rigorous walk-away claim from marketing?
Four tests. Does the claim name the failure set, including simultaneous loss of power, cooling, and operators, and the duration covered? Does it distinguish what is designed from what has been demonstrated? Is the regulatory status stated precisely, given that proposed Part 57 was published for comment in May 2026 and is not final <sup><a href="#src-6">[6]</a></sup> and that pre-application activity precedes any application <sup><a href="#src-11">[11]</a></sup>? And can an outside party check the evidence without the developer helping <sup><a href="#src-10">[10]</a></sup>? Absolute phrasing that removes the need for the rest of the safety case is the clearest warning sign.

## Sources

- [U.S. Nuclear Regulatory Commission. Glossary: Passive safety](https://www.nrc.gov/reading-rm/basic-ref/glossary/passive-safety.html)
- [International Atomic Energy Agency. Small Modular Reactors](https://www.iaea.org/topics/small-modular-reactors)
- [International Atomic Energy Agency. What are Small Modular Reactors (SMRs)?](https://www.iaea.org/newscenter/news/what-are-small-modular-reactors-smrs)
- [U.S. Department of Energy, Office of Nuclear Energy. What is a Nuclear Microreactor?](https://www.energy.gov/ne/articles/what-nuclear-microreactor)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [Idaho National Laboratory / GAIN. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). June 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [What is a nuclear microreactor? →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor technology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor/

# What Is a Nuclear Microreactor? A Complete 2026 Guide

> A nuclear microreactor is a factory-built reactor producing roughly 1 to 20 megawatts, per DOE, small enough to ship on a truck to where power is needed.

[Resources](https://rankshieldenergy.com/resources) / Reactor fundamentals Reactor fundamentals

# What is a nuclear microreactor?
Published July 21, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy
A nuclear microreactor is a very small fission reactor that the U.S. Department of Energy describes as producing roughly one to twenty megawatts, small enough to be built in a factory and shipped to a site largely complete, and transportable by truck, rail, or ship. That is the whole definition. It says nothing about which coolant a design uses, what fuel it burns, or how it behaves when power is lost, because those are engineering choices made inside the envelope and they differ enormously between developers. This guide covers what the class is, how these machines work, how they differ from small modular reactors, why the category is drawing attention in 2026, and how to tell a substantiated microreactor claim from a loose one.
The reason the distinction matters is that the word microreactor is doing two jobs in public conversation at once. It is a category term about size, siting, and manufacturing, which is well defined and uncontroversial [[1]](#src-1). It is also, increasingly, a shorthand for a set of safety and autonomy claims that belong to individual designs and that each design has to substantiate on its own through analysis and testing under regulatory review. Those are not the same kind of statement, and conflating them is where most confusion starts.
So this guide keeps them apart. Where something is a settled description of the class, it is attributed to the DOE, the NRC, the IAEA, or a national laboratory. Where something is design intent that has not been demonstrated, it is labeled as such. RankShield Energy is a pre-applicant engaged in early interaction with the NRC and holds no license, permit, or design approval [[12]](#src-12), so the same standard is applied to us in the closing section.
Key takeaways

- DOE defines a microreactor by size and form: roughly one to twenty megawatts, factory built, and transportable.
- The definition covers manufacturing and siting. It does not by itself certify anything about how a specific reactor behaves in an accident.
- Microreactors are a subset of the small reactor family. The IAEA describes small modular reactors as up to about 300 megawatts of electricity per unit.
- Three things changed at once: demand for firm around-the-clock power, licensing modernization at the NRC, and a federal program to make HALEU fuel available.
- Autonomous control of a simulated microreactor has been demonstrated at national-laboratory scale. Commercial fleet operation has not, because no commercial fleet exists.
- The useful question to ask any developer is not what the reactor is designed to do, but what has been demonstrated, to whom, and under what review.

## What is a nuclear microreactor?
A nuclear microreactor is a very small fission reactor that the U.S. Department of Energy describes as generating roughly one to twenty megawatts, built in a factory rather than assembled in place, and small enough to be transported to a site by truck, rail, or ship [[1]](#src-1).
Three attributes carry the definition. It is **small**, measured in single or low double digit megawatts rather than hundreds or thousands. It is **factory fabricated**, which moves most assembly work off a construction site and into a controlled production environment where components can be inspected before shipment. And it is **transportable**, which is what allows a unit to be delivered to a load instead of requiring the load to be built beside a central station [[1]](#src-1).
Notice what the definition leaves out. It says nothing about coolant, fuel form, power conversion, siting rules, or accident behavior. Two machines can both be microreactors and share almost nothing else. One may be cooled by a liquid metal, another by a gas, another by heat pipes that move heat without a pump. They face the same regulator and the same physics, but their safety cases are separate documents built on separate evidence.
That gap between category and design is the single most useful thing to hold onto when reading about this technology. A statement about microreactors in general is usually a statement about size, manufacturing, and siting. A statement about what happens inside a specific reactor when power and cooling and staff are all lost at once is a statement about one design, and it has to be substantiated by that design through analysis and testing under regulatory review. The same discipline applies to every claim about [walk-away safety](https://rankshieldenergy.com/resources/walk-away-safety-explained) you will encounter.

## How small is a microreactor compared with a conventional plant?
Two to three orders of magnitude smaller in power output. A single large light-water unit at a conventional station produces around a thousand megawatts of electricity. A microreactor, at roughly one to twenty megawatts, sits in a different regime entirely [[1]](#src-1).
That difference is not simply a matter of scaling a familiar machine down. Below a certain size the engineering logic inverts. A conventional plant is built around large active systems, redundant pumps, and the emergency power needed to run them, because the amount of heat that has to be moved after shutdown is very large in absolute terms. A reactor producing a small fraction of that heat has correspondingly less to remove, and it can carry proportionally more structural material and surface area per unit of heat. That ratio is the reason designers in this class lean on natural processes rather than pumps, a point the IAEA makes about small reactors generally [[3]](#src-3).
Small size also changes the delivery model. A reactor that leaves a factory as a largely finished module can be manufactured under controlled conditions, quality checked before it ships, and installed on a prepared pad in a fraction of the time a conventional station takes to build [[1]](#src-1). For a data center, a remote community, an industrial process heat customer, or a defense installation, the practical appeal is a unit that arrives rather than a project that begins.
There is a corresponding trade. Small units produce less power each, so serving a large load means operating several of them, which multiplies the number of machines a regulator, an insurer, and an operator all have to keep track of. The industry answer is fleet operation with reduced on-site staffing, and that answer creates its own oversight problem rather than dissolving the original one.

## How does a microreactor actually work?
It works on the same principle as any fission reactor. Neutrons split heavy atoms such as uranium, the fission releases heat, and that heat is carried out of the core and either converted to electricity or used directly as process heat. What varies across designs is how the heat is carried and what the reactor does when the normal heat path stops working.
Most microreactor concepts avoid water as a coolant. Water-cooled reactors operate at high pressure, and much of the conventional safety case is built around keeping that pressure contained and replacing water that boils off. Designs cooled by liquid metals, gases, molten salts, or by heat pipes operate at low pressure by comparison, which removes an entire family of accident sequences and replaces it with a different set of engineering problems, including materials behavior at high temperature and the qualification data needed to support it.
The other common feature is a heavy reliance on passive design characteristics, meaning safety functions carried by natural forces such as gravity, natural circulation, and conduction rather than by powered equipment or operator action. DOE describes this reliance when characterizing the microreactor class [[1]](#src-1), and the IAEA describes the same approach across small reactors generally [[3]](#src-3). It is a design approach recognized by government and international bodies, not a property a reactor is granted by being small. Any specific machine still has to demonstrate that its passive features do what its analysis predicts, through qualified analysis and testing under regulatory review.
Many designs in this class also use TRISO fuel. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic that act as a containment barrier around each individual particle [[2]](#src-2). That is DOE characterizing a fuel concept, and it is worth citing precisely because it is the version of the claim that comes with public technical backing rather than a vendor brochure.

## What fuel do microreactors use, and what does TRISO actually do?
Most designs in the class use some form of high-assay low-enriched uranium, and many of them package it as TRISO. The NRC defines high-assay low-enriched uranium, or HALEU, as uranium enriched to between five and twenty percent in the fissile isotope, above the level used by the current commercial fleet and below the threshold that defines highly enriched material [[8]](#src-8).
The reason the class needs it is straightforward. A very small core has less room for fuel, so a higher fissile fraction is what allows a reactor of that size to sustain a chain reaction and to run for a long interval between refuelings. That is a general property of small cores, not a claim about any one design.
TRISO addresses a different problem. DOE describes TRISO particles as uranium kernels wrapped in successive layers of carbon and silicon carbide, so that each particle carries its own containment barrier around the fission products it produces [[2]](#src-2). The engineering appeal is that the barrier is distributed across millions of particles rather than concentrated in one boundary. DOE presents this as a robust fuel form, and that framing belongs to DOE. What any individual reactor achieves with it depends on the specific fuel qualification data submitted for that design and reviewed by the regulator.
Fuel is also where the schedule risk in this industry actually sits. The supply chain for HALEU is being stood up rather than drawn on, which is why DOE established a HALEU Availability Program to support the availability of that material for advanced reactor developers [[7]](#src-7). A developer with an elegant design and no path to qualified fuel does not have a product. We treat fuel availability as a gating question rather than a procurement detail, and it is worth reading [where HALEU actually comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel) before evaluating any deployment timeline.

## How is a microreactor different from a small modular reactor?
A microreactor is a much smaller subset of the same family. The IAEA describes small modular reactors as advanced reactors producing up to about 300 megawatts of electricity per unit, roughly a third of the capacity of a traditional power reactor, built in modules in a factory setting [[3]](#src-3). Microreactors sit at the far low end of that spectrum, at roughly one to twenty megawatts [[1]](#src-1).
The difference is not only arithmetic. At SMR scale the machine is still a power station in the conventional sense: a fixed site, a substantial construction program, grid interconnection as the primary purpose, and a staffed control room. At microreactor scale the unit is closer to equipment. It is delivered, sited near a specific load, and in many concepts removed and returned rather than serviced in place [[1]](#src-1).
That shift changes which regulatory questions are hard. For a large plant, the demanding questions concern the accident analysis for a big core and the emergency planning zone around it. For a microreactor, the demanding questions concern transport, siting close to industrial or population loads, staffing levels, and how a regulator maintains oversight of many small units rather than a few large ones. The NRC has a dedicated body of work on microreactor-specific regulatory issues for exactly this reason [[4]](#src-4).
One practical consequence for readers: evidence does not transfer across the boundary. A demonstration involving an SMR does not substantiate a microreactor claim, and a licensing milestone reached by an SMR developer says nothing about where a microreactor developer stands. When a company cites progress in the broader advanced reactor sector as though it were its own, that is a category error worth catching.

## Why is this class drawing attention in 2026?
Three things moved at once: demand for firm around-the-clock power, licensing modernization at the NRC, and a federal effort to make advanced reactor fuel available. None of them alone would have been enough.
The demand side is the most visible. Large industrial and data center loads want power that is available continuously and that can be sited where the load is, and the interest in this reactor class follows from that requirement rather than from any claim about the price of electricity, which is outside the scope of this article.
The regulatory side is where the substantive change is. The NRC maintains an active program of microreactor-specific regulatory activities addressing factory fabrication, transport, and staffing [[4]](#src-4). In March 2026 the agency published its risk-informed, technology-inclusive framework for advanced reactors in the Federal Register, the rulemaking known as Part 53 [[6]](#src-6). In May 2026 it published a proposed rule, 10 CFR Part 57, addressing licensing requirements for microreactors and other reactors with comparable risk profiles [[5]](#src-5). Part 57 is a **proposed** rule. It is not final, it may change before it is, and no developer is licensed under it. Anything you read that treats Part 57 as settled law is wrong today, and the detail is worth understanding directly in our explainer on [what Part 57 proposes about remote and reduced-staffing operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The fuel side is the third leg. DOE established the HALEU Availability Program to support availability of high-assay low-enriched uranium for advanced reactor developers [[7]](#src-7), and the NRC has published its own material on the licensing and regulatory treatment of HALEU [[8]](#src-8). Fuel that is being produced changes what a development schedule can honestly promise. Fuel that is planned does not.

## What has been demonstrated, and what is still design intent?
This is the question that separates a serious reading of the field from an enthusiastic one, and the honest answer is that real capability exists at national-laboratory scale while commercial operation does not yet exist at all.
On the demonstrated side: DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10). That is a genuine result, and it belongs to a national laboratory rather than to any vendor. INL also describes MARVEL as a microreactor project being developed at the laboratory to test microreactor applications and integration with end users [[9]](#src-9), which is a test platform rather than a commercial deployment.
On the still-open side: the microreactor program plan prepared by INL and GAIN for DOE lays out a coordinated federal program of research, development, and demonstration for this class [[11]](#src-11). A national program plan exists because the work is not finished. That is the correct way to read it, and it is more informative than any single vendor announcement.
**The counterargument worth taking seriously** is that this is how every new technology looks shortly before it works, and that demanding commercial operating history from a class of machine that has not yet been deployed is an unfalsifiable standard. That is fair as far as it goes. Our response is that the standard being asked for is not operating history, it is *evidence proportional to the claim*. A developer can substantiate a materials result, a fuel qualification result, or a control demonstration today without having operated anything commercially. What a developer cannot do is borrow the credibility of a laboratory result for a claim the laboratory did not make. The practical version of this problem is covered in [how you would verify an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## How should you evaluate a microreactor claim?
Apply four tests, in this order, to any statement you encounter about any developer including us.
**One: is it a claim about the class or about the design?** Statements about size, factory fabrication, and transportability are class facts and are well documented [[1]](#src-1). Statements about how a specific machine behaves in an accident are design claims and require that design to produce evidence.
**Two: designed or demonstrated?** These are different words and the difference is not stylistic. Design intent describes what analysis predicts. Demonstration describes what testing showed, to whom, and under what review. Passive design characteristics are a recognized approach that DOE describes for this class [[1]](#src-1) and the IAEA describes for small reactors generally [[3]](#src-3), and every specific reactor still has to show that its own features perform through qualified analysis and testing under regulatory review.
**Three: what is the regulatory status, stated precisely?** Pre-applicant, applicant, and licensee are distinct positions. Proposed rules are proposals: Part 57 was published for comment in May 2026 and is not final [[5]](#src-5), and the NRC describes pre-application activities as early interaction that precedes any application [[12]](#src-12). A developer that blurs these is telling you something about its rigor.
**Four: who else can check it?** Ask what an outside party could establish without the developer participating. A federal program plan [[11]](#src-11) or a laboratory result [[10]](#src-10) is checkable. A brochure is not. The full version of this checklist is in our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and it is written to be used against us as readily as against anyone else.
**An honest limitation of this article.** Because specific reactor technical data can be export controlled under 10 CFR Part 810, we deliberately keep our own design specifics off a public page. That is a decision with a real cost: this guide is less concrete about our machine than a reader would reasonably want, and we would rather state that plainly than let vague language stand in for detail we are not going to publish. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[12]](#src-12), and nothing here should be read as a representation that anything about our design has been demonstrated to or accepted by the NRC.

## Frequently asked questions

### What is a nuclear microreactor in simple terms?
It is a very small nuclear reactor that DOE describes as producing roughly one to twenty megawatts, built in a factory rather than assembled at the site, and transportable by truck, rail, or ship <sup><a href="#src-1">[1]</a></sup>. The definition is about size, manufacturing, and mobility. It does not by itself say anything about the coolant, the fuel, or how a particular machine behaves in an accident, because those are design choices that vary widely between developers and that each developer has to substantiate separately.

### Is a microreactor the same as a small modular reactor?
No. A microreactor is a much smaller subset of the same family. The IAEA describes small modular reactors as producing up to about 300 megawatts of electricity per unit, roughly a third of the capacity of a traditional power reactor <sup><a href="#src-3">[3]</a></sup>, while microreactors sit at roughly one to twenty megawatts <sup><a href="#src-1">[1]</a></sup>. The practical consequence is that evidence does not transfer across the boundary. A licensing milestone or demonstration achieved by an SMR developer does not substantiate a microreactor claim.

### What fuel do microreactors use?
Most designs use high-assay low-enriched uranium, which the NRC defines as uranium enriched to between five and twenty percent in the fissile isotope <sup><a href="#src-8">[8]</a></sup>, and many package it as TRISO fuel. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic that act as a containment barrier around each particle <sup><a href="#src-2">[2]</a></sup>. Supply is a live constraint rather than a settled one, which is why DOE established a HALEU Availability Program to support fuel availability for advanced reactor developers <sup><a href="#src-7">[7]</a></sup>.

### Are microreactors approved by the NRC?
Not as a class, and no developer should be described as approved on the strength of the category. The NRC maintains an active program of microreactor-specific regulatory activities <sup><a href="#src-4">[4]</a></sup>, published its Part 53 framework for advanced reactors in March 2026 <sup><a href="#src-6">[6]</a></sup>, and published a proposed Part 57 rule for microreactor licensing in May 2026 <sup><a href="#src-5">[5]</a></sup>. Part 57 is proposed, not final. RankShield Energy is a pre-applicant engaged in early interaction with the NRC <sup><a href="#src-12">[12]</a></sup> and holds no license, permit, or design approval.

### Has any microreactor actually been demonstrated?
Real work exists at national-laboratory scale, and commercial operation does not. DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe <sup><a href="#src-10">[10]</a></sup>, and INL describes MARVEL as a microreactor project being developed at the laboratory to test applications and integration with end users <sup><a href="#src-9">[9]</a></sup>. The federal microreactor program plan prepared by INL and GAIN sets out the research and demonstration work still to be done <sup><a href="#src-11">[11]</a></sup>, which is the most honest summary of where the class stands.

## Sources

- [U.S. Department of Energy, Office of Nuclear Energy. What is a Nuclear Microreactor?](https://www.energy.gov/ne/articles/what-nuclear-microreactor)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [International Atomic Energy Agency. What are Small Modular Reactors (SMRs)?](https://www.iaea.org/newscenter/news/what-are-small-modular-reactors-smrs)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Nuclear Regulatory Commission. High-Assay Low-Enriched Uranium (HALEU)](https://www.nrc.gov/materials/new-fuels/haleu)
- [Idaho National Laboratory. MARVEL Project](https://inl.gov/marvel/)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory / GAIN. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). June 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Walk-away safety, explained →](https://rankshieldenergy.com/resources/walk-away-safety-explained)
- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor technology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel/

# Where HALEU Comes From: Fuel for Advanced Reactors

> HALEU is the fuel most advanced reactors need, and supply is still being stood up. Here is where it comes from and why it shapes deployment timelines.

[Resources](https://rankshieldenergy.com/resources) / Deployment Deployment

# Where HALEU Comes From: The Fuel Supply Behind Advanced Reactors
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility. Most advanced reactor designs need a fuel called high-assay low-enriched uranium, or HALEU: uranium enriched above the assay used by today's commercial fleet and below the line that separates low-enriched from highly enriched material. The physics of using it is well understood and has been studied for decades. The binding constraint is supply. Fuel belongs in every honest project schedule as a first-order input with named suppliers and named dates, not as a footnote to be resolved later.
The supply picture has three parts that are easy to run together and should not be. Federal auditors reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers [[10]](#src-10). Congress responded with a statutory program directing the Department of Energy to support availability of the material [[4]](#src-4). And DOE now runs a published process for allocating the limited quantities that exist to developers who apply for them [[5]](#src-5). An authorization, an allocation, and delivered material are three different things.
This article covers what HALEU is and how DOE defines it, why compact long-cycle designs need higher assay, where supply actually stands, the statutory basis for the availability program, what the allocation rounds reveal about demand, how domestic enrichment is scaling, why fabrication and qualification are separate bottlenecks from enrichment, and how to read fuel in a project schedule. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[16]](#src-16), and the closing section applies all of it to us.
Key takeaways

- HALEU is uranium enriched above roughly 5 percent and below 20 percent, though DOE states the upper bound two different ways across its own pages.
- Higher assay is a packing solution: smaller cores running longer between refuelings need more fissile material in less volume.
- The physics is settled; supply is the constraint. GAO reported in 2022 that HALEU was not available at commercial scale from domestic suppliers.
- DOE allocation rounds are evidence of scarcity: an allocation process is what you build when demand exceeds what exists.
- Enrichment, fabrication, and qualification are three separate schedules, and a project is fuel-ready only when all three land.

## HALEU is uranium enriched above 5 percent, and DOE states the upper bound two different ways
High-assay low-enriched uranium is uranium whose uranium-235 content sits above the assay used by the existing commercial fleet and below the line that separates low-enriched from highly enriched material. DOE's explainer defines it as enriched to greater than 5 and less than 20 weight percent uranium-235, and notes that today's commercial light-water reactors run on uranium enriched up to about 5 percent [[1]](#src-1). DOE's HALEU frequently asked questions page uses that same greater-than-5-and-less-than-20 phrasing [[2]](#src-2).
DOE's HALEU Enrichment Services page describes the same material as enriched to between 5 and 19.75 percent [[3]](#src-3). Those two statements are not identical, and the difference is not a typographical accident. One states an open band up to a regulatory boundary. The other states a band that stops at a specific assay below that boundary.
We are flagging this because we ran the primary sources side by side rather than taking one page as the whole answer, and it is the kind of detail that gets lost when writers paraphrase a definition from memory. For a reader orienting to the topic, either phrasing is close enough to be useful. For a schedule assumption, a procurement document, or anything that will end up in front of a regulator, the two are not interchangeable, and the honest move is to cite the specific page you took the number from rather than presenting a single tidy figure as though DOE speaks with one voice on it.
The practical takeaway is small but real. When you see the HALEU band written a particular way in a vendor deck or a news article, check which federal page it traces to. Consistency between a claim and its source is the cheapest available signal of how carefully the rest of the document was assembled.

## Compact designs with long operating cycles need higher assay to carry enough fissile material
The reason so many advanced designs converge on HALEU is a packing problem rather than an exotic one. A smaller core has less room for fuel, and a core intended to run a long interval between refuelings has to hold enough fissile material at the start to sustain the chain reaction all the way to the end of that interval. Raising the assay is how designers get more uranium-235 into a given volume. DOE puts the consequence plainly: higher-assay fuel supports smaller plant designs, longer operating cycles, and higher efficiencies than the existing fleet achieves on conventional low-enriched fuel [[1]](#src-1).
That design logic is what produced the [microreactor class](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor) in the first place. GAO's technology spotlight describes nuclear microreactors as small, factory-fabricated units intended to be transportable and to operate for extended periods, and identifies the fuel they generally require as high-assay low-enriched uranium [[11]](#src-11). The fuel choice is not a preference bolted onto the concept. It is upstream of the concept.
DOE's microreactor program plan reflects the same ordering. The program is organized around technical areas that include fuel alongside the reactor technologies themselves, which is a signal that federal program managers treat fuel development as program-level work rather than as a downstream procurement task to be handled once a design is finished [[15]](#src-15).
The consequence for anyone reading design literature is that the assay decision drags a whole supply chain behind it. A design that needs HALEU does not simply need uranium. It needs enrichment capacity configured for that band, a fabricator able to make its specific fuel form, and a qualification record a regulator will accept. Each of those is a separate organization, a separate schedule, and a separate way for a project to slip.

## The binding constraint today is supply, and the federal government is the main route to material
The physics of using higher-assay fuel is well understood. The constraint is that there is not much HALEU available to buy. GAO reported in September 2022 that "The primary source of commercially available HALEU today is from Russia," and that the material "is not currently available at commercial scale from domestic suppliers" [[10]](#src-10). That report is now several years old and the domestic picture has moved since, which is exactly why the date matters when the sentence gets quoted. Read it as a description of the starting position rather than as a live snapshot.
GAO had flagged the broader vulnerability earlier still, finding in December 2020 that risks to the domestic uranium supply chain needed better planning and coordination across the agencies responsible for them [[12]](#src-12). The HALEU shortfall is a specific instance of a supply-chain problem that federal auditors had already named in general terms.
Today the practical route to material for most U.S. advanced reactor developers runs through the Department of Energy rather than through an open commercial market. DOE stood up an allocation process for distributing limited quantities of HALEU to developers [[5]](#src-5), which is the arrangement you build when demand exceeds what is available. Meanwhile domestic output remains modest in absolute terms: DOE-NE reported that cumulative U.S. HALEU production reached 900 kilograms by the end of June 2025 [[8]](#src-8).
It helps to see the whole chain at once, because the conversation usually collapses into enrichment alone when enrichment is only the first of several gates.

Stages a HALEU-fueled design has to clear, what each requires, and where each stood as of the cited sources

Stage
What it requires
Where it stands in the cited record

Enrichment above 5 percent
Operating enrichment capacity licensed and configured to produce assays above the roughly 5 percent used by the existing fleet
GAO reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers [[10]](#src-10). DOE-NE reported cumulative U.S. production of 900 kilograms by the end of June 2025 from a 16-centrifuge cascade in Piketon, Ohio [[8]](#src-8).

Access to material
A route to obtain quantities, which for most developers today runs through a federal program rather than an open commercial market
DOE established a published allocation process [[5]](#src-5) under the HALEU Availability Program [[4]](#src-4), and has announced conditional commitments in successive rounds [[6]](#src-6) [[7]](#src-7).

Fuel fabrication
Production lines able to turn enriched material into the specific fuel form a given design uses, at rate and to specification
DOE selected four companies for advanced nuclear fuel line pilot projects in September 2025 [[9]](#src-9), which is a signal that domestic fabrication capacity was still being stood up.

Fuel qualification
Irradiation testing and a documented performance dataset that a regulator can review for the form and conditions in question
The DOE Advanced Gas Reactor program was established to develop and qualify TRISO fuel and to produce that dataset [[14]](#src-14). DOE reports that the AGR-1 experiment reached 19 percent peak burnup with zero particle failures [[13]](#src-13).

Every row in that table is a separate industrial capability with its own lead time. A project is not fuel-ready when one of them clears. It is fuel-ready when all of them do, for its specific fuel form, on dates that line up.

## The HALEU Availability Program exists because Congress directed it
The federal effort here is not discretionary enthusiasm. DOE describes the HALEU Availability Program as established by section 2001(a)(1) of the Energy Act of 2020, with the purpose of supporting the availability of HALEU for civilian domestic demonstration and commercial use [[4]](#src-4).
Congress then attached a quantity and a schedule. DOE notes that section 3131(h) of the National Defense Authorization Act for Fiscal Year 2024 set a schedule under which the Department is to seek to make available 21 metric tons of HALEU [[4]](#src-4). That is a directive to seek to make material available, which is a meaningfully different thing from a delivered inventory, and the statutory language is worth reading in exactly those terms.
The program also has an operational face. DOE contracts for HALEU enrichment services as one of the mechanisms for building domestic capability [[3]](#src-3), and publishes the process by which available material is allocated to applicants [[5]](#src-5). Together those give the field something it did not have before: a defined, documented route to request material, with published criteria, rather than an informal queue.
The honest reading of a statutory program is that it tells you what the government has committed to attempt, on what timeline, and under what authority. It does not tell you that the material exists. Both facts can be true at once, and a project schedule that quietly converts the first into the second has introduced an assumption its own authors may not notice. When you see a developer point to the HALEU Availability Program as evidence that fuel is handled, the follow-up question is whether they are pointing at an authorization or at an allocation, because those are different objects.

## Two allocation rounds show demand running ahead of available material
The allocation record is the clearest public evidence of the imbalance, because it shows how many parties asked and how many were served. In April 2025 DOE announced conditional commitments in its initial round to TRISO-X, Kairos Power, Radiant Industries, Westinghouse and TerraPower, and reported that 15 companies had requested HALEU [[6]](#src-6). In August 2025 DOE announced a further round of conditional commitments to Antares Nuclear, Standard Nuclear, and Abilene Christian University together with Natura Resources [[7]](#src-7).
To be explicit about what that paragraph is and is not: it is factual reporting of two Department of Energy announcements. This article does not rank, score, rate, or compare any of the companies named, and nothing about appearing in a DOE round should be read here as an endorsement of a design, a schedule, or an organization. We name them because the composition of the rounds is public information that a reader evaluating the supply picture is entitled to have.
The structural signal is in the arithmetic rather than the names. An allocation process gets built when a resource is scarce enough that it has to be rationed, and DOE published one [[5]](#src-5). More companies requested material than received commitments in the initial round [[6]](#src-6). And the commitments themselves are conditional, which means conditions attach before material moves.
Read alongside the statutory target [[4]](#src-4), the rounds describe a federal program doing what it was directed to do, at a scale set by what is actually available rather than by what the field would like. That is not a criticism of the program. It is the reason fuel deserves a line on a project schedule instead of a footnote.

## Domestic enrichment is scaling up, and the published numbers show how early it is
The most concrete public marker of domestic progress is the Piketon, Ohio cascade. DOE-NE reported that cumulative U.S. HALEU production reached 900 kilograms by the end of June 2025, produced by Centrus from a 16-centrifuge cascade [[8]](#src-8). That is a real, verified, domestically produced quantity where a few years earlier there was effectively none.
Set that against projected need. DOE-NE has estimated that domestic HALEU demand could reach 50 metric tons per year by 2035 [[8]](#src-8). The two figures are not the same kind of measurement and should not be subtracted from one another. One is cumulative output through a date. The other is a projected annual requirement roughly a decade out. Stated in common units, 900 kilograms is 0.9 metric tons of cumulative production, against a projection of 50 metric tons required each year. What the pair describes is the distance between where domestic production had reached and where projected demand sits, and the number of doublings implied by closing it.
The scale-up mechanism is partly contractual. DOE procures HALEU enrichment services as one way of building the domestic capability the statute directs it to pursue [[3]](#src-3), under the availability program Congress established [[4]](#src-4). A 16-centrifuge cascade is a demonstration-scale machine, and moving from demonstration scale to the throughput implied by tens of metric tons per year is a capital, licensing, and construction problem rather than a scientific one.
None of this contradicts GAO's September 2022 finding about the starting position [[10]](#src-10). It refines it. The domestic capability that GAO reported as absent at commercial scale now exists at demonstration scale and is producing measurable output. Whether it arrives at commercial scale in time for any particular project is a schedule question, and the answer is specific to that project rather than general to the industry.

## Fabrication and qualification are separate bottlenecks from enrichment
Enriched uranium is not fuel. A reactor needs fuel elements in a specific geometry and chemical form, fabricated to specification, made on a line that can produce them at rate. That is a distinct industrial capability from enrichment, run by different organizations, and it can bind a schedule even when material is available. DOE selected four companies for advanced nuclear fuel line pilot projects in September 2025 [[9]](#src-9), which tells you domestic fabrication capacity for advanced fuel forms was still being established at that point.
Qualification is a third gate. For the TRISO fuel form, DOE describes a design in which a uranium kernel is surrounded by three layers of carbon and silicon carbide, so that each particle functions as its own containment system, and reports that the particles have been tested to 1,800 degrees Celsius with low fission product release [[13]](#src-13). DOE also reports that the AGR-1 experiment reached 19 percent peak burnup with zero particle failures [[13]](#src-13), results generated within the DOE Advanced Gas Reactor Fuel Development and Qualification Program, which was established to develop and qualify the fuel form and to build the performance dataset that supports it [[14]](#src-14).
Two qualifications on that paragraph, both of which matter. First, those are DOE's characterizations of a fuel form under test conditions, not a safety finding about any particular reactor. A robust fuel form is an input to a safety case, never a substitute for one, and the [passive safety claims](https://rankshieldenergy.com/resources/walk-away-safety-explained) that get made about advanced designs remain subject to analysis, testing, and NRC review for each specific design. Second, a qualification dataset covers the conditions it was generated under. A design operating outside that envelope inherits the testing burden rather than the conclusion.
This is also where the microreactor program plan's treatment of fuel as program-level work reads as sound program management rather than bureaucratic hedging [[15]](#src-15). Enrichment, fabrication, and qualification are three schedules that all have to land, and only one of them is the one everybody talks about.

## How to read fuel in a developer's schedule, including ours
Fuel is where optimistic schedules go to become real, so it is worth a short list of questions that separate a plan from an intention. Which specific fuel form does the design use? Has that form been fabricated at production rate by an identified supplier, or does it exist as a laboratory or pilot article? What qualification dataset covers it, and does the design operate inside the conditions that dataset actually spans? Is there an allocation, a conditional commitment, or a commercial contract, and which one? And what does the schedule do if fuel arrives late, since a design that has no answer there has embedded a single point of failure it has not disclosed.
Those questions belong next to the ones in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they bear directly on the [speed-to-power case for data centers](https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear), because a fuel date that slips moves an energization date with it no matter how well the rest of the project is run. A developer who cannot separate an authorization from an allocation on their own schedule has not done this work.
Applied to us, unsentimentally. RankShield Energy is a pre-applicant engaged in early interaction with the U.S. Nuclear Regulatory Commission [[16]](#src-16). We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. We have not secured HALEU supply, we hold no DOE allocation, and we are not named in any allocation round [[5]](#src-5). HALEU supply is a real constraint on our schedule exactly as it is for the rest of the field, and we would rather write that down than imply otherwise by omission.
Our position, stated so it can be argued with: fuel belongs in the schedule as a first-order input with named suppliers, named dates, and a stated fallback, not as an assumption in a footnote. That is a harder document to write and an easier one to check, which is the tradeoff we are choosing. If you want the regulatory half of the same picture, our explainer on [how NRC pre-application works](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) covers what a pre-applicant can and cannot claim.

## Frequently asked questions

### What exactly is HALEU?
High-assay low-enriched uranium is uranium with a higher uranium-235 content than the fuel used by today's commercial light-water reactors, which run on uranium enriched up to about 5 percent. DOE's explainer defines HALEU as enriched to greater than 5 and less than 20 weight percent uranium-235 <sup><a href="#src-1">[1]</a></sup>, and its frequently asked questions page uses the same phrasing <sup><a href="#src-2">[2]</a></sup>. Worth knowing: DOE's HALEU Enrichment Services page states the band as between 5 and 19.75 percent <sup><a href="#src-3">[3]</a></sup>. Both descriptions come from the Department of Energy, so cite the specific page you are relying on rather than treating one number as settled.

### Why do advanced reactors need higher-assay fuel?
It is a packing problem. A smaller core has less volume for fuel, and a longer interval between refuelings requires more fissile material loaded at the start. Higher assay is how designers fit enough uranium-235 into the space available. DOE states that higher-assay fuel supports smaller plant designs, longer operating cycles, and higher efficiencies <sup><a href="#src-1">[1]</a></sup>, and GAO's technology spotlight identifies HALEU as the fuel the microreactor class generally requires <sup><a href="#src-11">[11]</a></sup>. The fuel choice sits upstream of the design concept rather than downstream of it.

### Is there enough HALEU available today?
Not at commercial scale from domestic suppliers, on the public record. GAO reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers and that the primary source of commercially available material was Russia <sup><a href="#src-10">[10]</a></sup>; note the date, because the domestic picture has moved since. DOE-NE reported cumulative U.S. production of 900 kilograms by the end of June 2025 from a 16-centrifuge cascade, against a DOE-NE estimate that domestic demand could reach 50 metric tons per year by 2035 <sup><a href="#src-8">[8]</a></sup>. Those are different kinds of figure, one cumulative and one annual, and the gap between them is the reason a federal allocation process exists.

### What is the HALEU Availability Program?
It is the federal program DOE describes as established by section 2001(a)(1) of the Energy Act of 2020 to support the availability of HALEU for civilian domestic demonstration and commercial use, with section 3131(h) of the FY2024 National Defense Authorization Act setting a schedule under which the Department is to seek to make 21 metric tons available <sup><a href="#src-4">[4]</a></sup>. In practice it operates through enrichment services contracting <sup><a href="#src-3">[3]</a></sup> and a published allocation process for distributing limited quantities to applicants <sup><a href="#src-5">[5]</a></sup>. A statutory directive to seek to make material available is not the same as material in hand, and it is worth keeping those separate when reading anyone's schedule.

### Does RankShield Energy have HALEU supply secured?
No. We have not secured HALEU supply, we hold no DOE allocation, and we are not named in any DOE allocation round <sup><a href="#src-5">[5]</a></sup>. RankShield Energy is a pre-applicant engaged in early interaction with the NRC, holding no license, permit, or design approval, with nothing about our design demonstrated to or accepted by the NRC <sup><a href="#src-16">[16]</a></sup>. Fuel supply is a genuine constraint on our schedule in the same way it is for other developers working in this class, and we would rather state that directly than let silence imply a position we have not earned.

## Sources

- [U.S. Department of Energy, Office of Nuclear Energy. What is High-Assay Low-Enriched Uranium (HALEU)?. December 2024](https://www.energy.gov/ne/articles/what-high-assay-low-enriched-uranium-haleu)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Frequently Asked Questions. Accessed July 2026](https://www.energy.gov/ne/haleu-frequently-asked-questions)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Enrichment Services. Accessed July 2026](https://www.energy.gov/ne/haleu-enrichment-services)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program. Accessed July 2026](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Department of Energy. High-Assay Low-Enriched Uranium (HALEU) Allocation Process. August 2025](https://www.energy.gov/documents/haleu-allocation-process-08282025)
- [U.S. Department of Energy. U.S. Department of Energy to Distribute First Amounts of HALEU to U.S. Advanced Reactor Developers. April 2025](https://www.energy.gov/articles/us-department-energy-distribute-first-amounts-haleu-us-advanced-reactor-developers)
- [U.S. Department of Energy. U.S. Department of Energy to Distribute Next Round of HALEU to U.S. Nuclear Industry. August 2025](https://www.energy.gov/articles/us-department-energy-distribute-next-round-haleu-us-nuclear-industry)
- [U.S. Department of Energy, Office of Nuclear Energy. Centrus Reaches 900 Kilogram Mark for HALEU Production. June 2025](https://www.energy.gov/ne/articles/centrus-reaches-900-kilogram-mark-haleu-production)
- [U.S. Department of Energy. Energy Department Selects Four Companies for Advanced Nuclear Fuel Line Pilot Projects. September 2025](https://www.energy.gov/articles/energy-department-selects-four-companies-advanced-nuclear-fuel-line-pilot-projects)
- [U.S. Government Accountability Office. Nuclear Energy Projects: DOE Should Institutionalize Oversight Plans for Demonstrations of New Reactor Types (GAO-22-105394). September 2022](https://www.gao.gov/assets/gao-22-105394.pdf)
- [U.S. Government Accountability Office. Science and Tech Spotlight: Nuclear Microreactors (GAO-20-380SP). February 2020](https://www.gao.gov/products/gao-20-380sp)
- [U.S. Government Accountability Office. Uranium Management: Actions to Mitigate Risks to Domestic Supply Chain Could Be Better Planned and Coordinated (GAO-21-28). December 2020](https://www.gao.gov/products/gao-21-28)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth. Updated June 2023](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [Idaho National Laboratory. DOE Advanced Gas Reactor Fuel Development and Qualification Program (INL/MIS-23-75732). December 2023](https://www.osti.gov/biblio/2278790)
- [Idaho National Laboratory / U.S. Department of Energy. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [What is a nuclear microreactor? →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of HALEU supply and advanced-reactor fuel programs as of July 2026. This area is moving quickly. Check back if the Department of Energy or the NRC issues new allocations or guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/safety/

# Safety

> The HELIX safety case: passive shutdown by negative temperature feedback, walk-away decay-heat removal by natural-draft air cooling and radiation with no pumps of any kind, no water and no high pressure, and a verification layer held physically outside the safety boundary that can never command it.

The safety case

# Nothing in the safety case moves, and nothing is powered.
**The HELIX safety concept does not depend on a pump, a valve, an operator, or a network, and there is no pump anywhere in the reactor to begin with.** Reactivity self-limits on the core's own physics, shutdown is fail-safe on loss of power, and decay heat removes itself by natural-draft air cooling and radiation. The verification layer that makes the reactor checkable is deliberately held outside this boundary, across a hardware one-way path, and can never command a safety function. This page states each of those claims plainly and then states what still has to be proven before any of them is credited.
A modern microreactor safety case is judged on one question: what happens when everything that can be lost is lost, no grid, no operators, no cooling, no controls, and no way to intervene. HELIX is designed so that the answer to that question is set by physics and geometry rather than by equipment that has to work. The sections below walk each layer of that answer, from the reaction itself out to the boundary that keeps the verification layer honest.

## How does HELIX shut itself down?
Shutdown happens twice over, once by physics and once by mechanism, and the physics comes first. HELIX is designed for a strongly negative temperature coefficient of reactivity: as the core temperature rises, reactivity falls, so power is self-limiting before any control system is asked to act. This is the same feedback that makes a well-designed reactor inherently stable rather than something that has to be actively held in check.
On top of that physics sit sixteen boron-carbide control drums and one diverse central shutdown rod. Their defining property is that they fail into safety. On any loss of power they rotate or drop their absorbing element into the core under spring return and gravity, needing no generator, no operator command, and no software decision. Our screening shows their combined worth exceeds any credible excess reactivity with margin, and the core remains subcritical even under the conservative assumption that the single most effective drum is stuck out. Those numbers are unqualified screening results and are treated as design inputs, not credited safety analysis, but the architecture they describe is deliberate: the mechanism is a backstop to the feedback, not a substitute for it.

## What happens in a total loss of power and cooling?
This is the scenario that defines a walk-away-safe reactor, and it is where the sealed heat pipes and the low-pressure design earn their place. After a trip, the core still produces decay heat, and in HELIX that heat leaves by natural-draft air cooling and thermal radiation alone. The monolith conducts its heat outward, ambient air rises past the module in a chimney flow driven by nothing but temperature difference, RVACS-style, and the balance radiates away. Nothing has to start, nothing has to be switched, and no operator has to be present.
The consequence is the sentence the whole design is built to earn: a complete loss of power and cooling in HELIX is an availability event, not a safety event. The plant stops making electricity; it does not approach fuel damage. The module's large thermal inertia and the low power density buy time measured in the terms that matter for emergency planning. The heat-transport decision, sodium heat pipes versus an EM-pumped pool, is now made, and it made the safety case even simpler: heat pipes won, so there is no pump of any kind in the reactor. With no pumps there is no loss-of-flow accident class at all, and the safety case never credits a pump for the plainest possible reason, none exists.

## Why is there no water and no high pressure?
The primary coolant is low-pressure liquid sodium, and there is no water in the primary system. That single choice removes an entire family of accidents. There is no high-pressure blowdown, because there is no high pressure to release. There is no loss-of-coolant accident of the light-water kind, because the coolant is not a pressurized fluid flashing to steam. And because the power-conversion side is a dry supercritical-CO2 Brayton cycle rather than a steam plant, there is no energetic sodium-water reaction interface anywhere on the site. Sodium does react with water and air, which is a real engineering constraint we design the sealed boundary and inert cover gas around, but the site is deliberately built so that the aggressive counterpart, water, is never present in the same place as the sodium.
Defense in depth, stated as five independent barriers
Each barrier holds on its own. A release requires all of them to fail at once, and the first two are physics, not equipment.
01

**The fuel kernel**
Each TRISO particle is its own containment. Silicon-carbide layers retain fission products to temperatures far above any operating or accident condition. The first barrier is inside the fuel, before any engineered system.

02

**Negative temperature feedback**
If the core heats, the reaction slows. Power and temperature are self-limiting on physics alone, screened at roughly -6 to -8 pcm/K, before a single control action is taken.

03

**Fail-safe shutdown**
Sixteen control drums and a diverse rod insert on loss of power by spring and gravity. No generator, no operator, no software. Screened shutdown worth far exceeds any credible excess reactivity, even with one drum assumed stuck.

04

**Passive decay-heat removal**
After a trip, decay heat leaves by natural-draft air cooling and radiation alone. Nothing is pumped, nothing is powered, no valve moves and no action is required.

05

**Low-pressure sealed boundary**
The primary is low-pressure sodium with zero water. There is no stored pressure energy to drive a blowdown and no loss-of-coolant accident of the light-water kind.

## Where does the verification layer sit, and why can it never cause harm?
HELIX is instrumented for protection by an independent digital-safety platform on an NRC-approved technology lineage, providing deterministic, analyzable trip logic. The RankShield attestation layer, the thing that makes each reactor independently checkable, is deliberately not part of that platform. It observes reactor integrity from outside the safety boundary, across a hardware one-way path: a physical data diode that lets information flow out to be attested and, by the construction of the wiring itself, cannot carry a command back in toward any safety system.
This is a boundary enforced by physics, not by policy. The attestation layer can prove a module's state to an operator, an insurer, or a regulator; it cannot rotate a control drum, override a trip, or touch a protective function, because there is no wire on which such a command could travel. The layer is classified non-safety and observe-only for exactly this reason, which is also what lets it ride on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists; the network only makes that safety checkable.

## What is proven, and what is still owed?
Every claim on this page is a design intent supported by unqualified reactor-physics screening, produced outside a nuclear quality-assurance program. It is not credited safety analysis and it is not field data. No microreactor of this class has yet operated at its rated life, and we will not describe screening as if it were a demonstrated result. The honest path to crediting these claims is defined: a stood-up NQA-1 quality program, structural and thermal finite-element analysis of the failure boundary, independent physics validation with independent codes and ultimately test data, and NRC review, under the proposed 10 CFR Part 57 microreactor framework once it is final, with Part 53 as the backup pathway. The safety architecture is designed to make that path shorter, because the hardest cases are answered by physics that does not need to be qualified so much as confirmed.
[See the validation program and the failure campaign →](https://rankshieldenergy.com/testing)
[See the licensing pathway →](https://rankshieldenergy.com/licensing)



---

## Page: https://rankshieldenergy.com/specs/

# Specifications & Drawings

> HELIX design-of-record specification and dimensioned engineering drawings, module elevation and core cross-section. All figures are design targets; pre-application.

Design of record · targets held to an honest ceiling

# Specification & engineering drawings.
The HELIX module and core at design-of-record fidelity. Every value is a design target, not field data. Dimensions on the drawings are representative of the current design basis and will be superseded by qualified design documents.

Figure 1 · Module elevation, not to scale · design targets

Figure 2 · Core cross-section, control drums, fuel channels, diverse rod

## Specification sheet
Module output | ~5 MWe net (~12.5 MWth, ~40% net dry sCO₂ target)
Site output | Number-up, 1 to 20+ identical modules; roughly 5–100+ MWe (design target)
Configuration | Identical factory-sealed modules with N+1 reserve per site
Package | ~1.7–1.8 m core; ~2.8 m sealed package (design target)
Heat transport | Sealed sodium heat pipes; no pumps (EM-pumped pool evaluated, not selected)
Fuel | UCO-TRISO, 19.75% HALEU, graphite-moderated
Vessel | 316H, ASME III Div 5 (816 °C / 300,000 h coverage)
Reflector | BeO, 0.50 m radial (graphite-outer split under study)
Control | 16 B4C control drums + 1 diverse shutdown rod
Reactivity feedback | −6 to −8 pcm/K (screening)
Core life | ~4–5 full-power yr as modeled; likely 5–7 with conservatisms removed (screening)
Cooling | Fully dry, forced-draft dry coolers; zero cooling water
Power conversion | Dry sCO₂ Brayton, air-cooled, on skids outside the sealed module
Thermal storage | Molten-nitrate-salt buffer (peak-shave + trip bridge)
Safety I&C | FPGA deterministic (NRC-approved platform lineage)
Attestation | Non-safety, observe-only, behind a hardware one-way path
Transport | Road/rail, factory-sealed, routine oversize permit (no superload); set-and-connect

All values are pre-application design targets. Heat transport is sealed sodium heat pipes; an EM-pumped sodium pool was evaluated and not selected. Physics figures are unqualified screening, pre-QAPD.



---

## Page: https://rankshieldenergy.com/technology/

# Technology

> How the HELIX microreactor works: a graphite-moderated UCO-TRISO core at 19.75% HALEU, sealed sodium heat pipes with no pumps of any kind, fully-dry cooling, passive walk-away safety, and a sealed transportable module. Every subsystem chosen for physics, supply, and licensing, not novelty.

The reactor · design of record

# How the HELIX microreactor works.
**HELIX is a sealed, transportable microreactor built around choices we can defend on physics, supply chain, and licensing, not on novelty.** It uses a graphite-moderated core of UCO-TRISO fuel at 19.75% HALEU, moves heat with sealed sodium heat pipes and no pumps of any kind, rejects that heat to dry air with zero cooling water, and shuts itself down on its own physics. This page walks the reactor from the fuel kernel outward, and states plainly why each subsystem was chosen and where it still has to be proven.
Most advanced-reactor concepts try to win on a single exotic idea. We took the opposite discipline. Every HELIX subsystem was pushed to its honest engineering ceiling, screened in our own reactor-physics simulations, and then checked against one hard filter: can the materials actually be bought, and can the design actually be licensed. Where a more glamorous choice failed that filter, we took the buildable one. What follows is the result of that filtering, subsystem by subsystem.

## What is the HELIX core made of?
The core is a nuclear-graphite monolith drilled with channels that hold UCO-TRISO fuel compacts. The fuel is uranium oxycarbide enriched to 19.75%, which is high-assay low-enriched uranium (HALEU), the highest enrichment allowed below the 20% line that triggers a different security category. TRISO stands for tri-structural isotropic: each microscopic fuel kernel is wrapped in layers of carbon and silicon carbide that form an individual pressure vessel around it. A single fuel compact contains thousands of these kernels, and the silicon-carbide layer retains fission products to temperatures far above anything the reactor reaches in normal operation or in a loss-of-cooling event.
This is the single most important materials choice in the design. TRISO is not a laboratory curiosity; it is the fuel form the US Department of Energy has invested in for a decade, it has NRC licensing precedent, and it is purchasable today from more than one qualified American fabricator. Choosing it means the fuel supply is a procurement question, not a research program. It also means the first and most robust barrier against a radiological release is built into the fuel itself, before any engineered system is credited.

## How does HELIX control the reaction?
Reactivity is held by sixteen boron-carbide control drums arranged around the core and one diverse central shutdown rod. A control drum is a cylinder with a neutron absorber on one face; rotating it toward or away from the core raises or lowers reactivity smoothly, with no fast-moving parts inside the pressure boundary. The drums fail safe: on any loss of power they rotate their absorbing face inward under spring return, driving the core subcritical without a generator, an operator, or a line of software.
Underneath that engineered control sits the physics that actually keeps the reactor stable. HELIX is designed for a strongly negative temperature coefficient of reactivity, screened in the range of roughly negative six to negative eight pcm per kelvin. In plain terms: if the core heats up, the reaction naturally slows down. Power and temperature are self-limiting before any control system has to act. Our screening shows the combined worth of the drums and the diverse rod exceeds any credible excess reactivity with margin to spare, and the core stays subcritical even if the single most effective drum is assumed stuck. Those are screening results, unqualified and pre-QAPD, and they are inputs to the design rather than credited safety analysis, but they are the reason the control system is a backstop to the physics, not the other way around.

## How does heat leave the core?
Heat leaves the core through sealed sodium heat pipes run through the graphite monolith, carrying it at roughly 650 degrees Celsius with no water anywhere in the primary system. Sodium is an excellent heat-transfer fluid at near-atmospheric pressure, which is the whole point: because the working fluid is not pressurized, there is no stored pressure energy waiting to drive a blowdown, and there is no loss-of-coolant accident of the kind that dominates light-water-reactor safety analysis. After a shutdown, decay heat leaves by natural-draft air cooling and radiation, with nothing powered and nothing pumped.
This decision was, until recently, genuinely open on this page, and we will state plainly how it closed. Two heat-transport architectures went through final evaluation: sealed sodium heat pipes, which have no moving parts and no pumping at all, versus an electromagnetically-pumped sodium pool, which uses a pump with no moving mechanical parts. The heat pipes won, and they won on physics and install engineering, not on preference: the pumped pool lost on installed weight, on commissioning complexity, and on the value of having zero pumps of any kind. The safety invariant is now simpler than the one we used to defend. There is no pump anywhere in the reactor, so there is no loss-of-flow accident class, and the safety case never credits a pump for the plainest possible reason: none exists. Shutdown cooling is carried by natural-draft air cooling and radiation alone.

## Why does HELIX carry a beryllium-oxide reflector?
The core is ringed by a beryllium-oxide radial reflector, 0.50 m thick, and this is the one materials choice where we accepted a constrained supply chain because the physics demanded it. BeO is a superb neutron reflector, and in a core small enough to travel on a truck, that reflection is what makes a multi-year sealed life reachable at all: every screening result we publish, criticality, shutdown worth, and lifetime, is computed with this reflector in place. We state the costs as plainly as the benefit. Beryllium oxide is toxic to machine, expensive, and supply-limited, and the module's BeO inventory is a flagged cost item in our own engineering register. A split reflector, BeO on the inner band with nuclear graphite on the outer band, is under study to cut that inventory without giving back the neutron economy, and if it screens well it will be adopted through the same labeled process as every other change to the design basis.
The pressure vessel and core internals are 316H stainless steel, chosen because it is code-qualified under ASME Section III Division 5 in the high-temperature creep regime the reactor operates in, with coverage well beyond the intended design life. This is another availability choice: 316H is a known, code-covered material with a deep supplier base, not a bespoke alloy that needs its own qualification campaign.

## How is the electricity actually made, and where does the waste heat go?
Heat from the heat pipes crosses an intermediate heat exchanger and drives a dry supercritical-CO2 Brayton cycle, air-cooled and targeting roughly 40 percent net conversion, so a module at roughly 12.5 MWth delivers roughly 5 MWe net. Choosing a dry cycle means there is no steam plant on site and therefore no energetic sodium-water interface to engineer around. Critically, the conversion machinery rides on bolt-on skids outside the sealed reactor module and can be serviced or upgraded without ever opening the module.
All of the reactor's waste heat is rejected to forced-draft dry coolers with variable-speed fans. There is no cooling tower and no evaporative water loss, which means zero cooling-water draw against whatever community or facility hosts the plant. For a microreactor meant to sit beside a data center, an industrial site, or a town, removing the water fight is not a minor convenience; it removes one of the most reliable reasons a thermal plant gets blocked in local permitting.

## How does a HELIX site fit together?
A molten-salt thermal buffer sits between the reactor and the load. It lets each module run flat at its most efficient operating point while stored heat follows demand swings and bridges short transients. The reactor never chases load; the buffer does. A site numbers up identical factory-sealed modules of roughly 5 MWe net each, one module for a hotel or a campus, twenty-plus for a hyperscale site, roughly 5 to 100+ MWe, held to an N+1 reserve margin so a single module outage never takes the site down. Staggered sealed-core swaps land on a roughly 5–7 year cadence, and each swapped core goes back to the factory for refurbishment: the modules are multi-year, but the site runs indefinitely on rolling factory recharge. The entire plant, reactor modules, thermal buffer, conversion skids, dry coolers, and grid-interconnection skid, arrives on trucks under a routine oversize permit, connects on a prepared pad in days with no on-site nuclear work and no deep vault excavation, and runs.
The six decisions that define HELIX
Each row is a place we chose the buildable, licensable, purchasable option over the more novel one. The design is the sum of these filters.
Fuel form not: Metallic or oxide pin fuel | **UCO-TRISO at 19.75% HALEU.** TRISO is the only advanced fuel form that is both NRC-precedented and purchasable from multiple US fabricators today. Each kernel is its own containment; fission products stay inside the particle to well above any credible operating temperature.
Moderator not: Hydride or unmoderated fast spectrum | **Nuclear graphite monolith.** Graphite gives a thermal spectrum that pairs with TRISO, a large heat capacity that slows every transient, and a supply chain with several qualified vendors. It carries the negative temperature feedback the safety case is built on.
Heat transport not: High-pressure helium, water, or an EM-pumped sodium pool | **Sealed sodium heat pipes.** Sodium moves heat at near-atmospheric pressure, so there is no stored pressure energy to drive a blowdown and no loss-of-coolant accident of the light-water kind. Sealing it in heat pipes removes the last pump from the reactor entirely; the EM-pumped pool alternative lost on installed weight, commissioning complexity, and the value of having zero pumps.
Reflector not: Graphite-only reflector | **Beryllium oxide, 0.50 m radial.** BeO's neutron reflection is what keeps a truckable ~1.7 m core critical for a multi-year sealed life; the frozen design basis and all of our screening physics carry it. Its mass, cost, and supply are honestly flagged constraints, and a split reflector with a graphite outer band is under study to cut the BeO inventory.
Heat rejection not: Evaporative cooling tower | **Fully dry forced-draft coolers.** A microreactor sited next to a data center or a community cannot compete for water. Dry cooling draws zero water and removes the single most common local-permitting fight over a thermal plant.
Power conversion not: Steam Rankine | **Dry supercritical-CO2 Brayton.** A dry sCO2 Brayton cycle, air-cooled and targeting roughly 40% net conversion, avoids a steam plant entirely, so there is no energetic sodium-water interface anywhere on site. It rides on bolt-on skids outside the sealed module, so the conversion side can be serviced or upgraded without ever opening the reactor.

## What is proven, and what is still owed?
Everything above is a design of record supported by our own continuous-energy Monte Carlo screening in OpenMC with ENDF/B-VII.1 cross-sections. That screening is unqualified and produced outside a nuclear quality-assurance program, so it informs design decisions and is never credited in a safety case. The qualified path is defined and honestly owed: a stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, NRC licensing, under the proposed 10 CFR Part 57 microreactor framework once it is final, with Part 53 as the backup, and validated demand before any hardware is committed. We publish the targets and label the screening as screening because a reactor whose whole promise is that you can check it cannot afford to blur the line between what is designed and what is proven.
[See the full specification and dimensioned engineering drawings →](https://rankshieldenergy.com/specs)
[Read how the safety case works →](https://rankshieldenergy.com/safety)



---

## Page: https://rankshieldenergy.com/testing/

# Testing & Scenarios

> The HELIX validation program: continuous-energy reactor-physics screening in OpenMC, a six-family register of real-life scenarios from nominal to chaotic failure, and the destructive-boundary campaign, all honestly labeled as unqualified pre-QAPD screening rather than credited analysis.

Validation program · unqualified screening, pre-QAPD

# We test the design against reality before we build it.
**HELIX is screened in our own reactor-physics simulations and stress-tested against a structured register of real-life scenarios, nominal, harsh, chaotic, production, grid, and long-run.** Every result on this page is an unqualified screening analysis: an input to design, not credited safety analysis and not field data. The qualified-lane program that will supersede it is defined and honestly owed. What follows is exactly what we have run, what it showed, and what it deliberately does not yet prove.
There is a temptation, in a pre-application program, to show only the numbers that flatter the design. We do the opposite, because the entire premise of RankShield is that our claims are checkable. So this page separates three things that are often blurred together: physics we have actually screened, the full register of real-world conditions the design is being tested against, and the destructive-boundary work that still requires tools we are standing up. Reading it should leave you knowing precisely how far along the validation is.

## What reactor physics have we actually run?
The screening uses OpenMC, an open-source continuous-energy Monte Carlo neutron-transport code from the same national-laboratory ecosystem that qualified codes come from, with ENDF/B-VII.1 nuclear data, run locally on the design of record. Monte Carlo transport is the reference-class method for this work: it tracks individual neutron histories through the real geometry and materials rather than approximating them. The table below is the current state of that screening. Every row is a design input, pre-QAPD, and will be superseded by qualified analyses once the quality program is stood up.
Criticality & core sizing | Continuous-energy Monte Carlo (OpenMC, ENDF/B-VII.1) Design of record resized to reach criticality with a beginning-of-life excess-reactivity bank.
Reactivity-limited lifetime | Depletion, full-power Roughly 4 to 5 full-power years as modeled (screening plus scaling from our validated larger-core depletion run); likely 5 to 7 once known model conservatisms are removed, with an engineering path toward 8.
Temperature feedback | Multi-temperature k-eff Strongly negative coefficient (-6 to -8 pcm/K), self-stabilizing.
Shutdown margin | Drum + diverse-rod worth Combined worth far exceeds any credible excess reactivity, with ample margin under a stuck-drum assumption.
Post-trip xenon | Xenon transient depletion No xenon dead-time at this power density; a tripped module can restart immediately.

The most consequential finding is the least glamorous one. Depletion screening, plus scaling from our validated larger-core run, puts the module's reactivity-limited life at roughly four to five full-power years as modeled, and likely five to seven once known model conservatisms come out, the homogenization bias and the erbium banking not yet applied, with an engineering path toward eight. That number, not power or efficiency, is the binding design constraint, and it is the reason the site architecture is built around staggered sealed-core swaps and rolling factory recharge rather than a single long-lived unit: the modules are multi-year, but the site runs indefinitely. We would rather design honestly around a screened lifetime than advertise a sealed life the physics does not support.

## How do we test against real-world conditions?
Reactor physics tells you whether the core works. It does not tell you what happens on a 49-degree afternoon when the dry coolers are fouled with dust, or when the grid browns out while a neighboring generator is still spinning down. For that we maintain a register of six scenario families that together cover the conditions a deployed reactor actually meets, from ordinary operation to deliberately chaotic failure. Each scenario is mapped to the analytical tool that is meant to prove it, and we are explicit about which of those tools is already running and which is owed.
A · Nominal
Steady full power over the swap interval; daily AI-load swing (the reactor never chases load, storage absorbs it); seasonal ambient sweep; startup and shutdown margins.

B · Harsh environment
Hot-day derate (45 to 50 °C); frozen-sodium cold start; dust, salt, and smoke cooler fouling; seismic; flood; grid-outage islanding.

C · Chaotic / failure
Single worst-position channel failure; cascade (2 tolerated, 3 forces shutdown, more is beyond design basis); module trip with survivors carrying the site for months; xenon restart; stuck drum; station-blackout walk-away; conversion-island failure.

D · Production & logistics
Fabrication-defect containment (block segmentation, 100% acceptance test); weld-yield Monte Carlo; transport damage to a sealed module (attested custody, site acceptance); vendor-failure supply strategy.

E · Grid & electromagnetic
Frequency ride-through; brownout with slow generators (storage bridge, then fast islanding, then fail-safe drum insert); EMI and RFI (self-generated and host-facility); GMD and EMP for defense sites; timing-attack on the attestation layer.

F · Long-run internals & siting
Sodium void reactivity sign (decision-gating); tritium permeation; Na-24 activation dose fields; absorber swelling; graphite dust; state nuclear-law siting screen.

Two design principles show up repeatedly across these families. First, the reactor never chases load: the molten-salt thermal buffer absorbs demand swings so the core runs flat, which turns a whole class of grid-following transients into storage problems rather than reactor problems. Second, failure is designed to degrade gracefully: a number-up site carries an N+1 reserve module so the survivors carry the load for months if one module trips, and the cascade logic tolerates two simultaneous channel failures, forces an orderly shutdown at three, and treats anything beyond that as outside the design basis rather than pretending it is handled.

## What does the failure campaign still owe?
Screening establishes the reactivity and lifetime envelope. It does not establish the destructive boundary, the maximum-power-to-failure case, cascade thermal-stress, and seismic response, because those are structural and thermal problems, not neutronics problems. Answering them requires finite-element analysis, which we are standing up using MOOSE-class multiphysics tools from the same national-laboratory ecosystem as our neutronics. Until that stand-up is complete and validated, we make no claim of demonstrated structural or thermal-mechanical performance, and the failure campaign is explicitly incomplete.
The gates that remain before any hardware are the same ones stated across this site, and the validation program is where several of them are earned: a stood-up NQA-1 quality program so that analysis can be credited at all, independent physics validation with independent codes and ultimately test data, the finite-element failure campaign, NRC licensing under the proposed Part 57 microreactor framework once it is final or under Part 53 as the backup, and validated demand. None of the screening on this page shortcuts those gates. It exists to make sure that when we walk through them, the design already knows where its limits are.
Honesty statement
Everything on this page is unqualified screening produced outside a quality-assurance program. It informs design decisions and is never credited in a safety case. It is superseded by qualified analyses once the QA program is stood up.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/verify/

# Verify this site

> Recompute the SHA-256 of any page on this site in your own browser and compare it to the hash we published. Tamper-evidence you can check yourself, with its limits stated plainly.

Check us

# Verify this site.
We argue that a reactor should be checkable rather than taken on trust. It would be strange to ask that of a reactor and not of our own website. Every page here publishes a hash. This is where you check one.
Content integrity check
Page path Recompute hash and compare Ready.
Published - Recomputed - Build -
This proves the text you were served matches the hash published for this build. It is
tamper-evidence, not a signature and not an independent witness, and we do not present it as one.
The manifest is at [/transparency.json](https://rankshieldenergy.com/transparency.json).

## What this checks
Every build writes a clean Markdown twin of every page, hashes each one with SHA-256, and publishes the result at [/transparency.json](https://rankshieldenergy.com/transparency.json). The tool above refetches a twin in your browser, recomputes the hash with WebCrypto, and compares. Nothing is sent anywhere; the computation happens on your machine.

## What this does not check
This is tamper-evidence, not a signature and not an independent witness. The manifest and the page are served from the same origin, so an operator able to change one could change both. What it rules out is a page being altered after publication without the published hash moving with it. That is a real and narrow guarantee, and it is the only one we claim here.
The module-level attestation described on the [technology](https://rankshieldenergy.com/technology/) and [safety](https://rankshieldenergy.com/safety/) pages is a different and far stronger construction: post-quantum signed telemetry, an append-only log, independent off-site co-signers. It is a design target for the reactor, not something running on this website today, and we label it that way everywhere it appears.

## Do it yourself
The tool is a convenience, not the mechanism. Any page path with a.md extension returns its twin, and /transparency.json lists the expected hash for each route:
curl -s https://rankshieldenergy.com/technology.md | shasum -a 256
curl -s https://rankshieldenergy.com/transparency.json | grep -A2 '"/technology/"' If those two agree, the page you read is the page we published.

## The other machine surfaces
The same discipline applies to what we hand to AI systems. Each of these is generated from one configuration file at build time, so none of them can quietly disagree with the pages:

- [/llms.txt](https://rankshieldenergy.com/llms.txt), a ranked index with the key facts and the honesty rails.
- [/llms-full.txt](https://rankshieldenergy.com/llms-full.txt), the full text of every page in a single fetch.
- [/AGENTS.md](https://rankshieldenergy.com/AGENTS.md), how to cite us accurately and what not to claim on our behalf.
- [/ai-content-index.json](https://rankshieldenergy.com/ai-content-index.json), the same map as JSON.
