Technical papers
What Makes a Machine-Generated Reactor Record Admissible Evidence?

Technical paper · document control
- Document type
- Technical paper
- Version
- 1.0
- Published
- July 24, 2026
- Revised
- July 24, 2026
- Status
- Issued for technical comment
- Scope of the term admissible
- Capable of being relied upon by a regulator, insurer, lender, or grid operator. This paper contains no analysis of legal admissibility.
- Regulatory status
- RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behaviour are design intent and are subject to analysis, testing, and regulatory review.
Abstract
As reactors move toward reduced-staff operation, a growing share of what a regulator, insurer, lender, or grid operator knows about a facility will arrive as a record produced by a machine rather than reported by a person who was present. This paper asks what properties such a record needs before a party that was not present can rest a decision on it. It states six properties, attributable, complete, contemporaneous, tamper-evident, independently checkable, and durable, defines each, and tests each against the published standards record and the published nuclear oversight record. Admissible is used throughout in a technical sense, meaning capable of being relied upon by those four parties; the paper contains no analysis of legal admissibility and offers no legal advice.
The finding is an absence. Published standards supply form for four of the six properties and supply nothing for two, and no accepted evidentiary standard for machine-generated reactor state appears anywhere in the record cited here. Naming that gap precisely, together with the parties who would have to close each part of it, is the contribution offered. The principal limitation is that the paper is written by an interested party: RankShield Energy is a pre-applicant developing an independent verification layer, and the gap described would be commercially convenient for us to describe. Section 8 applies the six properties to our own position and reports where we fail them.
This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.
Scope and limitations
This paper addresses the properties a machine-generated record of reactor state would need in order to be relied upon by a party that was not present at the facility. Relied upon means used as a basis for a decision by a regulator, an insurer, a lender, or a grid operator. That is the sense in which the word admissible is used in the title and throughout, and it is the sense in which every conclusion below should be read.
What this paper deliberately does not do is as important as what it does. It contains no analysis of legal admissibility, no interpretation of any statute or procedural requirement governing legal proceedings, and no legal advice. Questions about legal proceedings belong to counsel and are outside the scope of this document and the competence of its author. The paper also contains no design detail for any RankShield Energy system, no geometry, no fuel description, and no performance or lifetime figures; it contains no cost or economic analysis; it does not interpret what any rule requires of a third party; and it does not name, rank, or characterise other developers. It does not describe unattended reactor operation. The operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification function under discussion is an assurance function and not a control function.
It draws on twenty primary sources spanning the regulator, the Government Accountability Office, national laboratories, standards bodies, and the International Atomic Energy Agency. Several developments would change its conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft guidance for applications under it, publication of acceptance criteria for automated operating records, a qualification route for an independent verifier, or a published demonstration in which a record of this kind was relied upon in a regulatory determination.
A regulator, an insurer, a lender, and a grid operator share a problem with each other and with almost nobody else in the nuclear supply chain: each has to reach a conclusion about a facility that none of them is standing in. Historically that problem was managed by putting people on site and having them look. As reactors move toward reduced-staff operation, more of what those parties know will arrive as a record produced by a machine. This paper asks what properties such a record needs before a party that was not present can rest a decision on it.
The question has not been posed to the nuclear sector in that form. There is a mature body of work on making a digital record trustworthy in general computing, and a mature body of work on how the NRC oversees operating plants, and remarkably little joining the two. This paper joins them by stating six properties, testing each against what published standards supply and what the nuclear record supplies, and stating plainly where the join fails. The failure is the contribution: no accepted evidentiary standard for machine-generated reactor state appears in the record cited here, and a gap named precisely is more useful to a reviewer than a gap papered over.
Two framing points govern everything below. Relied upon means capable of being used as a basis for a decision by a party that was not present, and nothing in this paper concerns legal proceedings, legal standards of proof, or legal advice. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC and holds no license, permit, or design approval [20]; nothing described here has been demonstrated to or accepted by the NRC. Section 8 applies the paper's own test to our position and reports the places where we fail it.
Key takeaways
- Admissible is used here in a technical sense: capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present. This paper contains no analysis of legal admissibility and no legal advice.
- Six properties recur across the four relying parties: attributable, complete, contemporaneous, tamper-evident, independently checkable, and durable. Tamper-evident is a detection property, not a prevention property.
- Published standards supply form for attribution, tamper-evidence, independent checkability, and durability. They supply nothing for completeness and contemporaneity, which are properties of instrumentation rather than of cryptography.
- No acceptance criteria for machine-generated reactor state appear in the cited record, and form is not acceptance. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) and its associated draft staff guidance are where such criteria could appear.
- The parties who would close the gap mostly do not sell anything: the regulator for acceptance, standards bodies for form, research organisations for validated method, and licensees for the operating experience that calibrates any criterion.
1. What relied upon means here, and what this paper is not
Relied upon, in this paper, means capable of being used as a basis for a decision by a party that was not present when the thing recorded happened. That party may be a regulator forming a view about compliance, an insurer pricing a risk, a lender testing a covenant, or a grid operator committing capacity. The definition is deliberately practical. It asks whether a record changes what a decision-maker does, not whether it satisfies any formal standard of proof.
What this paper is not needs stating with equal precision. It is not an analysis of legal admissibility, and it takes no position on whether a record of the kind described would be received in any legal proceeding. Where the word admissible appears in the title of this paper, it carries the technical-reliance meaning defined above and nothing further. Questions about legal proceedings belong to counsel and sit outside the scope of this document. The nature note above applies without qualification: this is technical analysis and is not legal, regulatory, engineering, or investment advice.
The question arises now because of a change in operating model rather than a change in law. Oak Ridge National Laboratory research on concepts for autonomous operation of microreactors describes an architecture in which monitoring, diagnosis, and supervisory functions are performed by systems rather than by people watching instruments [17]. Brookhaven National Laboratory, in contractor analysis prepared for the NRC, reviews reactor facilities operated without a conventional main control room and sets out what changes when the crew is not co-located with the plant [18]. The licensing frame usually cited in this context is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [11].
The consequence is a change in the character of the evidence rather than in its volume. When an inspector is on site, the record and the observer are separable: a licensee log can be checked against what a person saw, and a person can be asked a question the log did not anticipate. As on-site staffing reduces, the record and the observer converge, because the instrument producing the record becomes the principal observer. A relying party then depends on properties of the record itself rather than on corroboration from somebody who was there.
Claim types are distinguished throughout, because a reviewer left to do that sorting resents it. Requirements in force are identified as in force. Proposals are identified as proposals and carry their status at every mention. Staff and contractor documents are labelled as staff or contractor documents at every mention. Published standards are described by what they specify, never by what they might be taken to imply. Everything remaining is our analysis, and where our reading differs from a common industry reading we say so, so that the disagreement can be argued with.
2. Who the relying parties are, and what each of them needs
The four relying parties are usually collapsed into one in vendor material, which obscures the fact that their questions differ in ways that change what a record must contain. A regulator asks whether a licensee is operating inside its licensing basis and whether the licensee's own account of that is reliable. The NRC's Reactor Oversight Process combines baseline inspection, performance indicators, a significance determination process, and assessment [7], and the Government Accountability Office has examined how heavily agency safety conclusions rest on the information that process produces [9].
An insurer asks a different question. Its interest is in the distribution of losses across a population and over time, so it needs a record that is complete for a period rather than accurate at an instant. A gap in an insurer's record is worse than a lower-resolution record without gaps, because a gap is where an adverse event is most likely to be hiding. An insurer also needs the record to survive the event it describes, which is a durability requirement rather than an accuracy requirement.
A lender's question concerns performance against commitments over the term of the debt, which may be decades. That imposes a requirement almost nobody designs for: the record has to remain checkable long after the software that produced it has been retired, and after the cryptography protecting it has aged. A lender is also the party most likely to want a record produced or appraised by somebody other than the borrower, because the borrower's incentive to present favourably is structural rather than dishonest.
A grid operator's question is the narrowest in time and the most demanding in latency. It needs to know whether capacity committed for the next interval will be delivered, which makes freshness the dominant property and long-term durability close to irrelevant. A record that is authoritative and an hour old is of limited use for dispatch, while an hour-old record may be entirely adequate for an insurer pricing an annual policy. The same record cannot be optimised for both without being designed for both.
The mature example of an independent party drawing conclusions from declarations, measurements, and inspection rather than from presence alone is the IAEA safeguards system [16]. It is instructive rather than transferable, since safeguards address material accountancy under international agreements rather than operational state under a domestic licence. The practical point is that these four sets of requirements do not reduce to one another, so a record designed around whichever party is nearest at hand will disappoint the other three. Our companion note on what a reactor's sensors can and cannot attest works the same problem from the instrument end.
3. The six properties a record needs
Working back from those four sets of needs, six properties recur. They are stated here as a checklist a technical reviewer can apply to any proposed record, including ours. None of the six is novel in general computing. What the field lacks is the assembly, applied to reactor state, with an honest assessment of which are supplied today.
1. Attributable. The record identifies the system that produced it and the configuration that system was running, checkably and without asking the producer. RFC 9334, the RATS architecture, treats this as the base case: evidence carries the identity and software state of the attester [1]. A record whose origin rests on the reporting organisation's assurance gives a relying party nothing new.
2. Complete. The record covers a defined period with no undeclared gaps, and any gap that occurs is itself recorded. Every relying party reads absence of an alarm as evidence of a normal condition. That inference holds when a silent instrument is distinguishable from a quiet plant, and fails when it is not.
3. Contemporaneous. The record is generated as events occur rather than reconstructed afterwards, and it carries a time reference that can be checked against an external source. A reconstruction reflects what its author believed later, and the difference between the two is precisely what an investigation exists to find.
4. Tamper-evident. Later alteration of the record is detectable by a party holding no privileged access to the system that produced it. This is detection and not prevention. A record of this kind is not tamper-proof, not unhackable, and not unbreakable; a vendor using those words about a digital record is describing an aspiration. Append-only structures make undetected alteration expensive rather than impossible.
5. Independently checkable. A relying party can verify the record without the producer's cooperation, tooling, or continued existence. The parties who need the record most are those with least leverage over its producer at the moment they need it.
6. Durable. Both the record and the means of checking it survive the period over which decisions rest on them: for a lender the term of the debt, for a regulator possibly the life of the facility. A scheme with a shorter useful life than the asset transfers the problem rather than resolving it.
The six interact, and treating them as a menu is an error. Completeness and contemporaneity together are what allow silence to be informative. Attribution and independent checkability together separate a verified record from a well-formatted claim. Durability constrains the cryptography chosen for tamper-evidence. The table states what supplies each property today and what remains unresolved for reactor state.
| Property | What supplies it today | What remains unresolved for reactor state |
|---|---|---|
| Attributable | RFC 9334 makes attester identity and software state part of the evidence; device identity is ordinary practice in general computing | No qualification route for the identity of nuclear instrumentation, and no criteria stating which configuration detail must be attested |
| Complete | Nothing in the cited record. Completeness is a property of instrumentation, coverage, and data handling rather than of any standard cited here | How a gap is declared, what sensor coverage suffices, and when silence may be read as evidence of a normal condition |
| Contemporaneous | Nothing in the cited record for the measurement itself; COSE receipts fix the time a statement was registered, which is later than the event | What time source is acceptable, how clock drift is bounded, and how a measured value is distinguished from a value inferred after the fact |
| Tamper-evident | SCITT transparency service with an append-only log; COSE receipts as verifiable inclusion and consistency proofs | Who operates a transparency service for a licensed facility, and whether a receipt is treated as anything at all by a regulator |
| Independently checkable | The RATS separation of attester, verifier, and relying party; receipts checkable without the issuer's cooperation | Who qualifies a verifier, against what criteria, and how independence from the operator is established and maintained over time |
| Durable | The 2024 NIST post-quantum standards, including FIPS 204, give a migration target; SP 800-161r1 addresses supply-chain practice | Retention periods, re-signing practice across facility lifetimes, and custody of the record if its producer ceases to exist |
Two cautions. The middle column describes what a standard specifies, not what any regulator has accepted, and that distinction is the subject of sections 6 and 7. The right-hand column is written from the record cited here; a reader able to close a cell with a source we have missed would be doing us a service.
4. What today's record actually is, and where its limits lie
What a relying party receives today, for an operating power reactor, is largely a record generated by the licensee: control room logs, plant computer histories, procedures with signatures, reports made under licence conditions, and dashboards derived from all of it. The quality of that record varies between organisations and over time. The reason the variation has been tolerable is that the record was never the sole basis for anybody's conclusion.
Presence has substituted for record quality. Licensed-operator conditions attach to a power reactor licence under 10 CFR 50.54(m), a requirement in force [10], and the NRC assigns resident inspectors to operating sites with access to the facility, its people, and its records [8]. The Reactor Oversight Process assembles that inspection with performance indicators and a significance determination process into an assessment [7], and the Government Accountability Office has documented how heavily agency safety conclusions rest on the information the process produces [9].
That substitution is worth stating plainly, because it is the assumption most at risk in a reduced-staffing model. A licensee log carries weight partly because an inspector could have watched the same shift, can ask about an entry, and can compare it against what people at the site say. The record is corroborated by a presence that never appears in the record. Remove the presence and the record is asked to carry a load it was not designed to carry, without anything in its construction having changed.
The technical literature is candid about this. Brookhaven National Laboratory, in contractor analysis prepared for the NRC, examines facilities operated without a conventional main control room and identifies what changes when the operating crew is not co-located with the plant [18]. Oak Ridge National Laboratory research on concepts for autonomous microreactor operation describes layered monitoring and diagnostics as the substitute for continuous human observation [17]. Both are research and contractor products rather than requirements, and both are best read as statements of what specialists regard as unsettled.
A further element of today's record is model output rather than measurement. The Department of Energy reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor [19]. A twin is a powerful diagnostic aid and a weak evidentiary artefact, because its output is a function of its assumptions as much as of the plant. A relying party asking what the plant did needs the measurement; a relying party asking what the plant would do under a hypothetical needs the model. Our explainer on how to verify that an autonomous microreactor is operating safely keeps the two apart deliberately.
5. What published standards already provide
Four bodies of published work supply parts of the six properties, and not one of them was written for this application. RFC 9334 specifies the RATS architecture, which separates three roles: an attester that produces evidence about itself, a verifier that appraises that evidence against an appraisal policy, and a relying party that consumes the verifier's result and acts on it [1]. The separation is the useful part. It supplies a vocabulary for saying precisely who is asserting what to whom, which most discussion of reactor data lacks.
RFC 9943 specifies the SCITT architecture, in which a transparency service records signed statements about artefacts in an append-only log and issues receipts allowing any party to check that a statement was registered and has not been altered since [2]. What this supplies is tamper-evidence coupled to independent checkability, because a receipt can be verified later without the cooperation of the service that issued it. The pattern was designed for software supply chains, and nothing in it is specific to software.
RFC 9942 specifies COSE receipts, the concrete format for the proofs a transparency service issues, expressed as verifiable inclusion and consistency proofs against the log [3]. Its relevance here is unglamorous and load-bearing: a property with no interoperable wire format is a property that stays inside one vendor's system, and a relying party dealing with four suppliers cannot be expected to check four proprietary proof formats.
Durability is where cryptography becomes a nuclear-timescale problem. NIST announced approval of three federal standards for post-quantum cryptography in August 2024 [4], among them FIPS 204, the module-lattice-based digital signature standard [5]. A record signed today that must remain checkable across the operating life of a facility is signed with an algorithm whose useful life is a design assumption rather than a certainty. Treating signature agility and re-signing practice as requirements rather than refinements follows directly from the durability property.
NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organisations [6]. It bears on this paper because attribution is a claim about a device and the software that device is running, and a claim about software is worth what the provenance of that software is worth. A record attributable to a device whose firmware provenance is unknown is attributable in form and not in substance, which is a distinction a technical reviewer will make even if a marketing document does not.
6. What the standards do not provide
The four bodies of work above supply form. None of them supplies acceptance, and conflating the two is the error this section exists to prevent. RFC 9334, RFC 9943, and RFC 9942 are internet standards with no nuclear regulatory standing whatever [1][2][3]. Nothing in them establishes that a regulator will treat a record built to their pattern as a basis for a determination, and citing them in a licensing context establishes vocabulary rather than acceptance.
There are also, so far as the record cited here shows, no acceptance criteria to meet. The NRC publishes guidance on digital instrumentation and controls for advanced reactors [13] and treats cybersecurity as part of its protective mission rather than as an information-technology overlay [14]. Neither addresses the question this paper poses, which is what makes a machine-generated statement about reactor state something a party that was not present can rest a decision on. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [11], together with NUREG-2271, a draft NRC staff guidance document issued for comment and not final guidance [12], is where such criteria could appear.
The second limit is structural and follows from the architecture itself. RFC 9334 separates the attester from the verifier and from the relying party [1], which relocates trust rather than removing it. The relying party now has to trust the verifier: its appraisal policy, its software, its independence from the operator, and its continued existence. Who qualifies a verifier, against what criteria, and who checks the verifier, are questions the architecture raises and does not answer. We treat that problem at length in our note on self-attestation and independent verification.
The third limit sits upstream of everything above. A cryptographic chain establishes that a value was reported by a particular device at a particular time and has not changed since. It establishes nothing about whether the value was correct when the device produced it. A compromised or degraded sensor produces a perfectly attested wrong number, and no amount of transparency logging converts that number into a fact about the plant. IAEA Nuclear Security Series No. 33-T addresses computer security of instrumentation and control systems at nuclear facilities, which is exactly this layer [15].
Supply-chain assurance occupies the same position [6]: it raises the cost of a compromise upstream of the record without converting the record into a statement about physical reality. The honest summary is that these standards make a record hard to alter after the fact and leave the question of whether it was correct when written to instrumentation, qualification, and physical and cyber security. Our microreactor cybersecurity explainer covers that layer in its own terms.
7. The gap, stated precisely
Stated as precisely as we can manage: in the record cited by this paper, there is no accepted evidentiary standard for machine-generated reactor state. There is no published set of properties such a record must have, no acceptance criteria against which one could be assessed, no qualification route for a verifier, and no worked example of a record of this kind being relied upon in a regulatory determination. The absence is not a criticism of any party. The operating models that make the question urgent are themselves proposals and research programmes.
Closing that gap is not within the gift of a vendor. Acceptance belongs to the regulator, through rulemaking, guidance, or determinations on individual dockets. Form belongs to standards bodies, which have supplied a good deal of it already [1][2][3]. Method, meaning validated ways of demonstrating that a record has the properties claimed for it, belongs to research organisations. Operating experience, without which no criterion can be calibrated, belongs to licensees.
A path can be described without any claim to be standing on it. Pre-application interaction with the NRC includes mechanisms by which a developer asks staff to review a discrete technical topic ahead of an application [20]. A topical report addressed to the evidentiary properties of an automated operating record would have to define the properties, define the failure modes, propose acceptance criteria, and propose how each criterion would be demonstrated. We have not submitted such a report. None has been accepted. We are aware of no NRC position on the subject, and pre-application interaction confers no approval of any kind.
A demonstration path is the other half, because a record of this kind cannot be assessed in the abstract. It has to be produced by real instruments in a real configuration over a period long enough for gaps, clock drift, maintenance outages, and instrument failures to occur, since those are the conditions under which completeness and contemporaneity are actually tested. A research or test setting is where that becomes possible before it is possible at a licensed facility. Whether such a demonstration would be credited by anybody is unresolved, and it is one of the entries in our register of open questions.
The framing we would resist is the one in which the gap is presented as a product opportunity. It is a shared problem, and most of the parties who will decide how it closes do not sell anything. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [11] and its associated draft staff guidance issued for comment [12] are where the regulatory half would appear if it appears at all, and neither is final. Naming the gap precisely is what this paper offers, and naming a gap is a different act from filling it.
8. Application to RankShield Energy, honestly
Applying the six properties to our own position produces an uncomfortable result, which is the reason to publish it rather than to omit it. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC [20]. We hold no NRC license, permit, or design approval. Nothing in our design has been demonstrated to or accepted by the NRC, and the pre-application process described in our explainer on it provides early alignment rather than standing of any kind.
On form, our position is ordinary rather than distinguished, and we would rather say so than imply otherwise. Attribution, tamper-evidence, and independent checkability can be built from published standards that anybody can read [1][2][3], and building them competently is engineering rather than an achievement worth advertising. Durability, for us, is a design commitment about signature agility and re-signing practice [4][5] rather than a demonstrated property, because no record of ours has yet had time to age.
On the two properties that depend on the plant rather than on the cryptography, we are materially weaker than the technology makes us sound. Completeness and contemporaneity are properties of instrumentation, sensor coverage, failure detection, and the treatment of gaps. A design-stage answer to any of those is an intention subject to analysis, testing, and regulatory review, and the sensor-level compromise described in section 6 sits upstream of anything we build [15]. Supply-chain provenance for the devices involved is a live obligation for us rather than a solved one [6].
The independence problem applies to us with full force. A verification function supplied by a party holding a commercial relationship with the operator is not independent in the sense a lender or an insurer means, and the honest description of our position is that independence is a governance question we have not resolved rather than a technical property we possess. A verification path also adds a digital interface to a plant, which is a cost in cyber terms that a regulator would weigh against whatever assurance benefit it brings [14].
The load-bearing uncertainty is whether any of this is credited at all. It is entirely possible that a regulator concludes that assurance of this kind belongs inside a licensee's own quality and configuration management programmes, and that an external layer adds a component to be reviewed without reducing anything else that must be reviewed. We hold no evidence bearing on that question, our commercial interest in the answer is direct, and readers should weigh the analysis above accordingly and check every source cited rather than accept our summary of it.
Frequently asked questions
Does admissible in this paper mean admissible as a matter of law?
No. Throughout this paper, and in its title, admissible means capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present at the facility. The paper contains no analysis of legal admissibility, no interpretation of any statute or procedural requirement governing legal proceedings, and no legal advice. Questions about legal proceedings belong to counsel. The technical question this paper does address is narrower and more tractable: what properties a machine-generated record needs before a party that was not present will change a decision on the strength of it.
What are the six properties, in short?
Attributable: the record identifies the system and configuration that produced it, checkably. Complete: it covers a defined period with no undeclared gaps, and records any gap that occurs. Contemporaneous: it is generated as events occur, with a checkable time reference. Tamper-evident: later alteration is detectable by a party with no privileged access, which is detection rather than prevention. Independently checkable: a relying party can verify it without the producer's cooperation or tooling. Durable: the record and the means of checking it outlive the decisions that rest on them.
Do existing standards solve this?
They supply form for four of the six properties and nothing for two. The RATS architecture separates attester, verifier, and relying party. The SCITT architecture adds a transparency service with an append-only log, and COSE receipts give an interoperable proof format. The 2024 NIST post-quantum signature standards give durability a migration target. What none of them supplies is completeness or contemporaneity, which are properties of instrumentation rather than cryptography, and none of them establishes that a regulator would accept any of it.
Has the NRC accepted a standard for machine-generated reactor records?
Nothing in the record cited by this paper establishes acceptance criteria for machine-generated reactor state. NRC guidance on digital instrumentation and controls for advanced reactors and the agency's cybersecurity material address adjacent questions rather than this one. The proposed microreactor licensing rule and its associated draft staff guidance are the instruments where such criteria could appear; the rule is proposed and not final, the guidance is a draft issued for comment, and no developer is licensed under the proposed rule.
Why does a record need to be checkable without the producer?
Because the moments when a relying party most needs the record are the moments when its producer has the least incentive and sometimes the least ability to help. A lender testing a covenant, an insurer investigating a loss, and a regulator examining an event each need to reach a conclusion without depending on the cooperation, the tooling, or the continued existence of the organisation whose conduct is in question. Independent checkability is what makes that possible, and it is a property of the record's construction rather than of anybody's goodwill.
Sources
- Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023
- Internet Engineering Task Force (RFC Editor). RFC 9943: Supply Chain Integrity, Transparency, and Trust (SCITT) Architecture. June 2026
- Internet Engineering Task Force (RFC Editor). RFC 9942: COSE Receipts. 2026
- National Institute of Standards and Technology. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography. August 2024
- National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024
- National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024
- U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026
- U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026
- U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025
- U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition
- U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628). Status: proposed rule, published May 1, 2026, comment period closed June 15, 2026; not final, and no developer is licensed under it
- U.S. Nuclear Regulatory Commission. NUREG-2271, Draft for Comment: NRC staff guidance document issued for public comment, not final guidance. April 2026
- U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026
- U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026
- International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (IAEA Nuclear Security Series No. 33-T). 2018
- International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026
- Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305), laboratory research. September 2019
- Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis prepared for the NRC. February 2025
- U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022
- U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026
Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.
- OQ-1. Acceptance criteria. What properties a machine-generated record of reactor state would have to demonstrate before a regulator would rest a determination on it. Unresolved because nothing in the cited record states criteria of any kind, and the instruments where they could appear are proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [11] and NUREG-2271, a draft NRC staff guidance document issued for comment and not final guidance [12]. Resolver: NRC, through final rulemaking or final guidance.
- OQ-2. Completeness. What sensor coverage, gap declaration, and failure detection would be sufficient before absence of an alarm may be read as evidence of a normal condition rather than evidence of a silent instrument. Unresolved because no published standard cited here addresses completeness at all, and NRC digital instrumentation and controls guidance addresses an adjacent question [13]. Resolver: research organisations for method, NRC for acceptance.
- OQ-3. Contemporaneity and time. What time source is acceptable for a record of this kind, how clock drift is bounded and reported, and how a measured value is distinguished from one inferred after the fact. Unresolved because the proof formats available fix the time a statement was registered rather than the time an event occurred [3]. Resolver: standards bodies for form, licensees for practice.
- OQ-4. Qualification of the verifier. Who qualifies the party that appraises evidence, against what criteria, and who checks that party. Unresolved because the architecture that defines the verifier role defines no qualification route for it [1], and no nuclear equivalent appears in the cited record. Resolver: NRC for acceptance, standards and accreditation bodies for form.
- OQ-5. Durability across a facility lifetime. What retention period applies, how records are re-signed as algorithms age, and who holds custody if the producing organisation ceases to exist. Unresolved because the post-quantum standards supply a migration target without supplying a records-management practice [4][5]. Resolver: NRC and licensees, informed by standards bodies.
- OQ-6. The oversight substitution. What carries the weight that resident inspection carries today [8] if on-site presence is materially reduced, given how heavily safety conclusions rest on the information the oversight process produces [7][9] and given the baseline that licensed-operator conditions set [10]. Resolver: NRC as designer of the oversight framework, with GAO scrutiny.
- OQ-7. Sensor-level compromise. How a relying party is expected to reason about a perfectly attested value produced by a compromised or degraded instrument, which is upstream of every property in section 3. Unresolved because the guidance addressing this layer [15] and supply-chain practice [6] raise the cost of compromise without converting a record into a statement about physical reality. Resolver: NRC and IAEA guidance, with instrumentation research.
- OQ-8. Model output versus measurement. Whether output from a digital twin can ever function as a record of what a plant did, as opposed to a prediction of what it would do. Unresolved because the demonstrated work is a twin of a simulated microreactor [19] and the autonomous-operation concepts that would rely on such models are research [17][18]. Resolver: research organisations, then NRC.
- OQ-9. We cannot answer this one. Whether an independent verification layer would be credited in a licensing basis at all, and whether the four relying parties named in this paper would change any decision on the strength of a record built as described. We hold no evidence on either question, our commercial interest in the answers is direct, and pre-application interaction confers no approval [20]. Resolver: the NRC on a specific docket, and the market for the remainder. The IAEA safeguards experience [16] suggests independent verification can become load-bearing, and suggests nothing about how long that takes.
This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.
Terminology note. Throughout this paper, and in its title, a record described as admissible means a record capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present. The paper contains no analysis of legal admissibility, no interpretation of any statute, and no legal advice of any kind.
This paper reflects the state of NRC microreactor rulemaking and the published standards record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.
About this article. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.
A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application