Cybersecurity

Microreactor Cybersecurity, Explained: Digital I&C and the New Threat Model

Published July 23, 2026 · By Jamie Kloncz, Founder, RankShield Energy

HELIX reactor modules, concept render
HELIX microreactor, concept render. RankShield Energy is a pre-applicant; this depicts a design study, not an operating facility.

Microreactor cybersecurity is the practice of protecting the digital instrumentation and control (I&C) systems, and the remote and autonomous control paths, that a modern microreactor depends on to operate. The threat model is different from the analog fleet because control is now digital and increasingly remote, so a fault or an intrusion can affect physical reactor behavior rather than just data. The relevant NRC cyber requirement for advanced reactors, proposed as 10 CFR 73.110, is still under development and is not yet a finalized prescriptive standard <sup><a href="#src-2">[2]</a></sup>.

That gap between an emerging threat surface and a settled rulebook is the whole subject of this post. As microreactors adopt digital I&C and move toward remote and reduced-staff operation, cybersecurity stops being an IT concern and becomes part of the safety and operational-trust case. The NRC staff has framed advanced-reactor cyber requirements as consequence-based rather than prescriptive [1], and the rule that would carry that approach is not final. So the honest question is not "which standard does this reactor meet," but "how does anyone independently confirm the control system did what it was supposed to."

RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission (NRC), which means we are engaged in early regulatory interaction and hold no license or approval. This article is educational. It explains why reactor cyber is not ordinary IT security, how autonomy widens the attack surface, what standards actually apply today, and why the direction of travel points toward independent attestation.

Key takeaways

  • Digital I&C and remote or autonomous control give a microreactor a cyber attack surface the legacy analog fleet did not have.
  • Reactor cybersecurity is not ordinary IT security: the thing being protected is physical reactor behavior and the integrity of safety functions, not primarily data confidentiality.
  • The NRC's advanced-reactor cyber requirement, proposed as 10 CFR 73.110, is still under development and is not a finalized prescriptive standard [2].
  • The standards landscape is a mix of existing guidance, a proposed rule, and international guidance; there is no single settled microreactor cyber standard yet.
  • Independent attestation of what the control system actually did, performed by a party separate from the operator, is the direction these standards point, and it is a concept RankShield Energy applies rather than a deployed or certified capability.

Why reactor cybersecurity is not ordinary IT security

In most enterprise settings, cybersecurity protects data: keeping information confidential and systems available. In a reactor, the asset is different. Cybersecurity protects the integrity of instrumentation and control, and by extension the physical behavior of the reactor and the reliability of its safety functions. A corrupted sensor reading or a spoofed command is not a privacy problem; it is a question of whether the reactor does what its operators intend. The NRC staff has described advanced-reactor cyber requirements as consequence-based, meaning the level of protection is tied to what an event could actually cause rather than to a fixed checklist [1]. That framing appears in a staff paper, SECY-24-0008, which reflects NRC staff analysis and is not a Commission position [1]. The practical consequence for a buyer is that the interesting question is integrity and trustworthiness of control, not the usual IT metrics. A reactor cyber program has to reason about physical effects, not only about networks.

How autonomy and remote operation widen the attack surface

Remote and autonomous operation change the threat model in a specific way: commands and state now travel across networks, and fewer people are physically present to notice something wrong. When an operator sits outside the site boundary, the path a command takes to reach the reactor becomes part of the safety case, and so does the path telemetry takes on the way back. Autonomy adds software that makes more of the routine decisions, which means the correctness and integrity of that software matters more. None of this implies unattended operation. Reactivity and safety-significant actions keep a human in the loop, and no facility today is licensed to run without operators. What changes is how much of the trust rests on digital pathways that an outsider cannot see directly. More remote control and more automation mean more surface where an intrusion or a fault could, in principle, affect what the reactor is told to do or what it reports about itself.

The standards landscape for microreactor cybersecurity

There is no single settled microreactor cybersecurity standard today. What exists is a mix: established NRC regulatory guidance written for the operating fleet, a proposed rule still in development, and international guidance that is not binding on U.S. licensees. The table below lays out the main reference points and, in the status column, makes clear which are final, which are proposed, and which are guidance rather than requirements. Reading it plainly, the field is mid-transition: the NRC is developing a technology-neutral cyber rule, proposed as 10 CFR 73.110, that is not yet final [2], while existing guidance and international documents fill the space in the meantime. A buyer evaluating a microreactor should therefore be skeptical of any claim that a design already meets a finalized microreactor cyber standard, because the prescriptive federal version of that standard does not yet exist in final form.

Standard or framework What it is Status
NRC RG 5.71 NRC regulatory guidance describing an approach to cyber security programs at nuclear power reactors [4] Existing NRC regulatory guidance (guidance, not itself a rule; written for the operating fleet, not a microreactor-specific requirement)
Proposed 10 CFR 73.110 A technology-neutral cybersecurity requirement the NRC is developing for advanced reactors [2] Proposed / under development; not final and not yet a prescriptive standard
IEC 62645 An international standard on cybersecurity requirements for nuclear I&C systems [5] Published international consensus standard (industry reference, not an NRC requirement)
IAEA SMR computer-security initiative An IAEA initiative addressing computer security for small modular and advanced reactors [6] International guidance initiative (non-binding; supports member states, does not license U.S. designs)

Where the standards point: independent attestation

Across these reference points a common direction shows through: it is not enough to secure a control system; someone has to be able to confirm afterward what the control system actually did. That is where cyber-assurance meets the verification thesis behind [our work on autonomous-microreactor verification](/verify-autonomous-microreactor-operating-safely). In computer security, the internet's attestation architecture (IETF RFC 9334) formalizes an independent Verifier that appraises evidence about a system and produces results a separate relying party can trust [3]. Applied to reactor cyber, the idea is that an independent record of commands and state, held separately from the operator, lets a regulator, insurer, or lender check integrity without relying on the operator to vouch for itself. RankShield Energy's approach is designed around that separation of roles. It is a concept we apply, not a deployed or certified capability, and nothing described here has been demonstrated to or accepted by the NRC; all of it is subject to analysis, testing, and NRC review.

Frequently asked questions

How is microreactor cybersecurity different from protecting an IT network?

The goal is different. IT security is mostly about keeping data confidential and systems available. Microreactor cybersecurity is mostly about protecting the integrity of instrumentation and control, so that the reactor behaves as its operators intend and its safety functions stay reliable. The NRC staff has framed advanced-reactor cyber requirements as consequence-based, tied to what an event could actually cause rather than to a fixed checklist, in a staff paper that reflects staff analysis and not a Commission position <sup><a href="#src-1">[1]</a></sup>. In practice that means a reactor cyber program has to reason about physical effects and the trustworthiness of control, not only about networks and records.

Is there a final NRC cybersecurity rule for microreactors?

Not yet. The NRC is developing a technology-neutral cyber requirement for advanced reactors, proposed as 10 CFR 73.110, and it is still under development rather than final or prescriptive <sup><a href="#src-2">[2]</a></sup>. Existing NRC regulatory guidance and international documents cover the space in the meantime, but they are guidance and consensus standards rather than a single settled microreactor rule. Anyone claiming a design already meets a finalized microreactor cyber standard is overstating where the rulemaking stands.

Does applying attestation standards make a reactor NRC cyber-certified?

No. Applying an attestation architecture such as IETF RFC 9334 is a technical design choice; it is not an NRC determination <sup><a href="#src-3">[3]</a></sup>. A developer can build toward independent, machine-checkable records of control-system behavior and still be, as RankShield Energy is, a pre-applicant with no license or approval. The two are separate: independent attestation is a concept a developer can apply, while cyber requirements for a licensed reactor are set and reviewed by the NRC, and no attestation approach substitutes for that review.

Sources

  1. U.S. Nuclear Regulatory Commission. SECY-24-0008: Micro-Reactor Licensing and Deployment. 2024 (NRC staff paper; reflects staff analysis, not a Commission position)
  2. U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026 (proposed 10 CFR 73.110 technology-neutral cyber requirements still in development; not final or prescriptive)
  3. Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023 (informational architecture, not a certification)
  4. U.S. Nuclear Regulatory Commission. Regulatory Guide 5.71, Revision 1: Cyber Security Programs for Nuclear Power Reactors. February 2023
  5. International Electrotechnical Commission. IEC 62645:2019, Nuclear power plants: Instrumentation and control systems: Requirements for security programmes for computer-based systems. 2019
  6. International Atomic Energy Agency. SMR Digital Technologies and Computer Security: The Interlinkages. Accessed July 2026

This guide reflects the state of microreactor cybersecurity standards and NRC rulemaking as of July 2026. Proposed requirements such as 10 CFR 73.110 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.

About this article. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor

HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.

RankShield Energy · HELIX · pre-application