Technical papers
Open Questions in Autonomous Microreactor Oversight: A Working Register

Technical paper · document control
- Document type
- Technical paper
- Version
- 1.0
- Published
- July 24, 2026
- Revised
- July 24, 2026
- Status
- Working register, open for comment
- Regulatory status
- RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behaviour are design intent and are subject to analysis, testing, and regulatory review.
Abstract
Oversight of microreactors operated remotely and with substantial automation is being designed in public, across a proposed rule, draft guidance, several staff papers, a body of contractor and national-laboratory analysis, and an oversight process built for a different fleet. This paper argues no position on how that design should end. It maps what the cited public record settles and what it leaves open, in the form of a numbered register: each entry states the question precisely, the evidence that bears on it, the reason it remains unresolved, and the party that would have to resolve it. Eight sections cover the method used to separate settled from open, the regulatory baseline, oversight at reduced inspection intensity, verification and evidence, human factors at fleet scale, cybersecurity requirements still in development, questions we cannot answer, and the rules by which the register will be maintained.
The principal limitation is structural. A register is no better than the record it draws on, and the record used here is the public one as of July 2026, which excludes non-public pre-application interaction, docketed material not publicly available, and proprietary operating experience. A second limitation is that the register is written by an interested party. RankShield Energy is a pre-applicant developing an independent verification layer, and several entries would be commercially convenient for us if they closed a particular way. Section 7 sets out the entries where we have no answer at all, including whether such a layer would be credited in a licensing basis.
This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.
Scope and limitations
This paper addresses oversight and verification questions raised by remote operation and increased automation of microreactors under U.S. Nuclear Regulatory Commission jurisdiction. It draws on twenty-one primary sources spanning the regulator, the Government Accountability Office, national laboratories, a standards body, and the International Atomic Energy Agency. Where a characterisation of a document is made, the document is cited and its status is stated: rule in force, proposed rule, draft guidance, staff paper, contractor analysis, or research.
Several things are deliberately out of scope. The paper contains no design detail for any RankShield Energy system: no geometry, no fuel description, no performance or lifetime figures. It contains no cost or economic analysis. It does not interpret what any rule requires of a third party, and it does not name, rank, or characterise other developers. It does not describe unattended or fully autonomous operation of a reactor; the operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification layer under discussion is an assurance function, not a control function.
Several developments would change the conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft guidance for applications under it, a Commission decision adopting or rejecting positions analysed in the staff papers cited here, a final cybersecurity rule for this reactor class, or published laboratory results that resolve a human-factors or autonomous-control question this paper records as open. Section 8 states the maintenance rule for each case.
A register of open questions is an unusual document for a vendor to publish, which is much of the reason to publish it. The public record on oversight of remotely operated, heavily automated microreactors contains a proposed rule, draft guidance, several staff papers, a set of contractor studies, and an oversight process designed for large plants with people on site. What it does not yet contain is a settled answer to most of the questions a technical reviewer would ask. This paper says which ones, and why.
The framing matters because the alternative is worse. A vendor paper that presents the direction of travel as though it were requirement invites a reviewer to spend the reading sorting proposal from rule, and that sorting is the author's job. So the separation is made explicit here. What is in force is identified as in force, such as the licensed-operator conditions at 10 CFR 50.54(m) [7] and the Reactor Oversight Process the agency applies to operating plants today [8]. What is proposed is identified as proposed, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [1], whose accompanying guidance, NUREG-2271, is a draft issued for comment [2].
The contribution offered is the register itself rather than a solution. Each entry names who would have to resolve it, because the answer is rarely a vendor. Most entries belong to the regulator through rulemaking or guidance, some to research organisations, some to standards bodies, and a few to the market. RankShield Energy is a pre-applicant engaged in early regulatory interaction and holds no NRC license, permit, or design approval [21]. Nothing described here has been demonstrated to or accepted by the NRC, and the register is written on the assumption that a reader will check every cited source rather than take our summary of it.
Key takeaways
- The oversight model for remotely operated microreactors rests today on proposals, draft guidance, and staff analysis rather than on requirements in force, so most of the questions a reviewer would ask remain genuinely open.
- What is settled is narrower than it is often presented: licensed-operator staffing conditions at 10 CFR 50.54(m) and the Reactor Oversight Process are in force, and they were built around large plants with staff on site.
- Nothing in the record cited here establishes an accepted evidentiary standard for machine-generated statements about reactor state, which is the gap an independent verification layer would have to fill before it could be credited.
- Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contemplates the operating model, but a proposal is not permission, and the design-specific determination would still be made on a docket.
- The entry we cannot answer is the load-bearing one for our own business: whether an independent verification layer would be credited in a licensing basis at all.
1. Why a register rather than a position paper
This paper takes the form of a register because the record will not carry anything stronger. Most of the instruments that would settle how a remotely operated, heavily automated microreactor is overseen are proposals, drafts, or analysis rather than requirements in force. The licensing frame under discussion is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [1]. The guidance that would accompany it, NUREG-2271, is a draft issued for public comment rather than final guidance [2]. A position paper built on that footing would be an argument about a rule that does not yet exist in final form.
Two categories are used throughout, and the boundary between them is the method of this paper. An item is treated as settled where it rests on a requirement in force or an agency process in use. The licensed-operator conditions imposed on power reactor licenses at 10 CFR 50.54(m) are a requirement in force [7], and the Reactor Oversight Process is a published framework the agency applies to operating reactors today [8]. An item is treated as open where the governing text is proposed, draft, or staff analysis, or where the cited record does not address the question at all.
That open category is wide. SECY-20-0093, SECY-24-0008, and SECY-25-0052 are staff papers presenting analysis and options to the Commission, not Commission positions and not requirements [4][6][5]. The Brookhaven National Laboratory review of reactor facilities without main control rooms is contractor analysis prepared for the NRC [13], as are the Sandia and Oak Ridge studies of microreactor automation and autonomous control [14][15]. Each is strong evidence about what the technical community regards as unresolved. None is a requirement, and reading one as though it were is the error this register exists to avoid.
Terms carrying regulatory weight are used as follows. Remote operation and autonomous operation are distinguished rather than merged, in line with the Oak Ridge treatment of autonomy concepts for microreactors [16] and with our terminology note. Verification means confirmation of a claim about reactor state by a party other than the party asserting it. Attestation is used in the sense of RFC 9334, which separates the attester that produces evidence, the verifier that appraises it, and the relying party that consumes the appraisal [19]. Where those roles collapse into a single organisation, this paper calls the result self-attestation and treats it as a different thing; see the companion material under Related.
The register claims no resolution by us of any entry. RankShield Energy is a pre-applicant [21], holds no NRC license, permit, or design approval, and has had nothing accepted by the NRC. Several entries would be commercially convenient for us if they closed a particular way, which is a reason to state them in the open.
2. Questions about the regulatory baseline
The baseline is more specific than the discussion usually admits. For power reactors, 10 CFR 50.54(m) attaches licensed-operator conditions to the license itself, setting minimum staffing expectations for the operation of the facility [7]. The oversight built on top of that baseline assumes a resident inspection presence at operating sites [9] and a structured process of inspection, performance indicators, and assessment [8]. Both were constructed around large plants with substantial staff on site, which is the fact that makes microreactor deployment a question rather than an application of existing practice.
Against that baseline, proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) is the instrument most often cited as the answer [1], and the NRC maintains a public summary of the microreactor regulatory activities surrounding it [3]. Our reading of the cited record is narrower than the common industry reading, and we state it plainly so it can be argued with: a proposed framework that contemplates an operating model does not thereby establish the method by which any particular applicant demonstrates that a specific staffing or remote-operation arrangement is acceptable for a specific design. That demonstration would be made on a docket, against guidance that is currently a draft [2]. We treat the direction as informative and the requirement as absent. A companion explainer covers the proposed rule and autonomous operation in less formal terms.
A further band of the baseline sits at staff-paper stage. The policy and licensing considerations for micro-reactors set out in SECY-20-0093 are staff analysis for Commission consideration [4], and the later staff papers on micro-reactor licensing and deployment and on Nth-of-a-kind considerations are likewise staff analysis rather than adopted requirements [6][5]. A policy question that staff have analysed thoroughly is still a policy question until the Commission acts on it and a rule or guidance reflects the outcome.
Three entries follow from this section. Entry 2.1: how the licensed-operator baseline at 50.54(m) translates, if at all, to a facility overseen from a location other than the site. Entry 2.2: what evidence an application would have to present for automated functions, given that the applicable guidance is a draft. Entry 2.3: which of the positions analysed in the staff papers become requirements and which do not. All three belong to the NRC through final rulemaking and final guidance. No amount of vendor engineering resolves them, and any vendor claiming otherwise is describing an intention.
3. Questions about oversight at reduced inspection intensity
The established oversight model has a specific shape. The Reactor Oversight Process combines baseline inspection, performance indicators, a significance determination process, and assessment, and the agency publishes its framework [8]. Part of the inspection input comes from resident inspectors assigned to operating power reactor sites, whose access to the facility is part of the design of the program [9]. The Government Accountability Office has examined how heavily the agency relies on the information this process produces when reaching safety conclusions [12]. That reliance is the reason the question below is not academic.
The question, stated precisely: if on-site presence at a microreactor site is materially lower than at an operating power plant, what carries the oversight weight that resident inspection carries today, and how would the agency know that substitute is working. Part of an inspector's contribution is structured and could in principle be instrumented. Part of it is unstructured observation of things that were not on anyone's list, and that part does not have an obvious instrumented equivalent. The cited record does not establish which portion is which, nor how much of it is transferable to data.
Two further facts in the record bear on the same entry. The Government Accountability Office reported that the NRC needed to take additional actions to prepare to license advanced reactors [10], and it maintains a list of priority open recommendations for the agency, which are by definition recommendations not yet implemented [11]. Staff-paper analysis of Nth-of-a-kind deployment recognises that the scale of deployment being contemplated differs from current practice [5]. Taken together, these establish that oversight capacity is a live agency concern, without establishing how the footprint would scale.
Entry 3.1: what mix of inspection, indicators, and reported data would be applied to a site with reduced staffing, and by what method the agency would validate that mix against the observational base it replaces. Entry 3.2: whether oversight scales per site, per unit, or per operating organisation once one organisation oversees many units, an issue we treat separately in the fleet-scale discussion. Both belong to the NRC as the designer of the oversight framework, with continuing scrutiny from the Government Accountability Office, and both depend on industry producing data of a quality that could carry the weight.
4. Questions about verification and evidence
This is the entry closest to our own work, so it is stated with the least generosity to ourselves. The question is what makes a machine-generated statement about reactor state acceptable to a regulator as evidence. Not persuasive, not useful for operations, but acceptable in the way that an inspection finding or a licensee event report is acceptable, with known provenance, known limitations, and a known method for challenging it.
The record establishes several things around the edges of that question without answering it. RFC 9334 supplies a worked architecture for remote attestation, separating the producer of evidence from the appraiser of it and defining the appraisal step in between [19]. It is an internet architecture with no nuclear regulatory standing whatever, and citing it establishes vocabulary rather than acceptance. Oak Ridge National Laboratory analysis prepared in the autonomous-control context identifies licensing challenges associated with autonomous control, including the difficulty of demonstrating that automated decision logic behaves acceptably across its operating envelope [15], and the companion Oak Ridge work on autonomous operation concepts for microreactors describes the monitoring and diagnostic functions such a system would depend on [16].
What none of that establishes, and what we could not locate in the cited record, is an accepted evidentiary standard for machine-generated reactor state. The unresolved sub-questions are concrete rather than philosophical. Who appraises the evidence when the operator and the reporting system belong to the same organisation. What freshness and coverage a record would need before absence of an alarm counts as evidence of a condition rather than evidence of a silent instrument. How long records are retained and in what form. What procedure exists for challenging a record after the fact, which is the question a lawyer asks before a regulator does. Draft guidance for applications is the obvious place for some of this to land, and it remains a draft [2].
Entry 4.1: whether an evidentiary standard for automated state reporting is established by rule, by guidance, or case by case on individual dockets. Entry 4.2: whether independence between the producer and the appraiser of that evidence is treated as material at all. Resolution here is split: the NRC decides acceptance, standards bodies could supply the form, research organisations would have to supply validated methods, and industry would have to produce records worth appraising. Our own view of what a buyer or reviewer should ask is set out in a separate explainer, and it is a view, not a standard.
5. Questions about human factors at fleet scale
The human-factors record is the strongest part of the technical literature cited in this paper and still does not close the questions. Brookhaven National Laboratory, in contractor analysis prepared for the NRC, reviewed reactor facilities operated without a conventional main control room [13]. Sandia National Laboratories examined human-factors considerations specific to automating microreactors [14]. NRC and Idaho National Laboratory researchers have characterised the human factors of offsite monitoring and remote operation for the nuclear domain in conference work [20]. These are contractor and research products, not requirements, and they are cited here as evidence of what specialists consider unsettled.
The recurring structural issue is function allocation: which functions belong to the automation, which to the human, and how the human retains an accurate picture of a plant they are not standing in. Oak Ridge concepts for autonomous microreactor operation describe layered monitoring and diagnostics as part of that architecture [16], which sharpens rather than removes the question, because a person supervising layered automation is supervising the automation as much as the plant.
At fleet scale a second issue appears that single-unit human-factors work does not fully address. When one crew oversees many units, most differences between units are benign, and sustained attention degrades against high-volume benign variation. The reconciliation task, deciding whether unit seven behaving slightly differently from its siblings is an instrument problem, a maintenance issue, or a genuine divergence, is exactly the task humans perform worst under those conditions. We are not aware of anything in the cited record that establishes a defensible limit on units per crew, or the conditions under which such a limit would be set.
Entry 5.1: what evidence would establish that a given ratio of units to qualified staff is acceptable, and whether that evidence is simulator-based, operational, or analytical. Entry 5.2: how operator qualification is defined when the role shifts from direct control toward supervision of automation. Entry 5.3: whether reconciliation across units is treated as a safety-relevant human-factors task in its own right or as an operational convenience. These belong jointly to research organisations, to the NRC through human-factors review, and to industry, which will generate the operating experience that any eventual answer has to be tested against.
6. Questions about cybersecurity requirements not yet final
A developer designing digital instrumentation, remote connectivity, and an attestation path for a microreactor today is designing against a requirement that does not exist in final form. The technology-neutral cyber requirement referenced as proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive) is the instrument most likely to govern this class, and the NRC describes cybersecurity as part of its protective mission rather than as an information-technology overlay [17]. The microreactor-specific technical case is still an active research topic internationally, with the IAEA coordinated research project on computer security of small modular reactors and microreactors running as research rather than as settled guidance [18].
The licensing frame around it, proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), is in the same condition [1], and the agency's public summary of microreactor regulatory activities is the practical place to watch for movement [3]. The consequence for a developer is specific rather than rhetorical: architectural choices about network separation, remote access paths, and the treatment of an attestation channel are being frozen now, and they will be judged later against a rule whose structure is not yet known. Whether requirements are graded by consequence, and how a small facility with a smaller source term is treated relative to a large plant, is precisely what the cited record leaves open.
A sub-question specific to the verification layer deserves naming, because it is uncomfortable for our own position. An independent verification path is an additional digital interface to the plant. It may reduce reliance on the operator's word while increasing the attack surface, and nothing in the cited record establishes how a regulator would weigh that trade. We treat it as a design constraint rather than as a settled benefit, and we discuss the broader landscape in a separate cybersecurity explainer.
Entry 6.1: what a developer can defensibly design against before a final cyber rule for this class exists, and whether early architectural choices made in good faith are credited later. Entry 6.2: whether an attestation or verification channel is in scope as a protected digital asset, and if so, who verifies the verifier. Entry 6.3: how supply-chain assurance for digital components is expected to be demonstrated for a factory-produced unit. Resolution belongs to the NRC through rulemaking, informed by international research of the kind the IAEA project represents [18].
7. Questions we cannot answer
The standard this paper follows requires it to apply its own method to us, and this section is where that is least comfortable. The entries below are not open in the sense that the field has not got to them yet. They are open in the sense that we have no evidence bearing on them, and our commercial interest in the answers is direct.
The load-bearing one: whether an independent verification layer would be credited in a licensing basis at all. It is entirely possible that a regulator concludes that assurance belongs inside the licensee's quality and configuration-management programs, and that an external verifier adds a component to be reviewed without reducing anything else that must be reviewed. Nothing in the cited record establishes that such a layer would receive credit, and pre-application interaction confers no approval of any kind [21]. The process itself is described in our pre-application explainer, and its value is early alignment, not standing.
The second: whether a regulator would accept a third-party attestation as evidence, as opposed to as useful background. The attestation architecture we build against is well-specified outside nuclear [19], and being well-specified in another domain has no bearing on admissibility in this one. We do not know whether the eventual answer turns on the cryptography, on the independence of the verifier, on the qualification of the software, or on none of those.
The third: what commercial weight buyers actually place on verification. Our working assumption is that lenders, insurers, and large offtakers will want confirmation they do not have to take on trust. That assumption is untested by us at any scale, it is the assumption a company in our position would be inclined to make, and if it is wrong the layer is a technical achievement without a market. The fourth, and the broadest: whether the operating model this paper analyses is the one that gets deployed. Staff analysis of deployment considerations exists [5], and it is analysis of options rather than a forecast. A register that assumed its own premises would be worth less than one that lists them.
8. The register in summary, and how it will be maintained
The table below compresses the register. The middle column is deliberately restricted to what the cited record establishes, which in several rows is less than the surrounding discussion in the industry assumes.
| Question | What the record establishes | Who would need to resolve it |
|---|---|---|
| Whether a reduced or remote staffing arrangement is acceptable for a given design | 10 CFR 50.54(m) imposes licensed-operator conditions on power reactor licenses and is in force; the microreactor licensing rule that contemplates other arrangements is proposed and not final | NRC, through final rulemaking and design-specific review on a docket |
| What evidence an application must present for automated functions | NUREG-2271 is a draft issued for comment; staff papers analyse options for the Commission | NRC, through final guidance |
| How inspection scales when on-site presence is reduced | The Reactor Oversight Process and the resident inspector program are established for operating plants; GAO reports agency reliance on the information they produce | NRC as framework designer, with GAO scrutiny |
| What makes machine-generated state acceptable as evidence | RFC 9334 supplies roles and vocabulary outside nuclear; ORNL identifies licensing challenges for autonomous control; no accepted evidentiary standard appears in the cited record | NRC for acceptance, standards bodies for form, research for validated method |
| How many units one crew can oversee, and under what conditions | BNL, SNL, and NRC and INL work identify the human-factors issues; no limit or method for setting one appears in the cited record | Research organisations and NRC human-factors review, tested against industry operating experience |
| What cyber requirements a developer designs against today | The technology-neutral requirement for this class is proposed, under development, and not final or prescriptive; IAEA work is an active research project | NRC through rulemaking, informed by international research |
| Whether an independent verification layer is credited in a licensing basis | Nothing in the cited record establishes it; pre-application interaction confers no approval | NRC, on a specific docket. We cannot answer this |
Maintenance rules. This document is versioned, and the version and revision date in the control block above are authoritative. An entry closes when a primary source resolves it: publication of a final rule in the Federal Register covering the question, issuance of final rather than draft guidance, a Commission decision adopting or rejecting a position analysed in a staff paper, or a published laboratory or standards result that answers a technical sub-question. Closure will be recorded with the citation that produced it, and the superseded text will be retained rather than deleted so that a reader can see what we believed and when.
An entry can also reopen. A final rule that leaves an implementation question unanswered, a guidance revision that changes an expectation, or a Government Accountability Office finding that an implemented recommendation did not have the intended effect would each reopen the relevant row [11]. The agency's public summary of microreactor regulatory activities is the practical trigger we watch [3], together with the docket for the proposed licensing rule, which as noted throughout is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [1], and the draft application guidance associated with it [2].
Comment is invited, particularly disagreement. If a reader believes an entry is closed by a source we did not cite, that is the most useful correction this document can receive, and it will be reflected with attribution in the next version. The register is intended as a shared artefact for people working the same problem, not as a marketing surface, and it carries no claim that RankShield Energy resolves any row in the table above.
Frequently asked questions
Why would a developer publish open questions rather than answers?
Because on this subject the answers do not yet exist in the public record, and a paper that implied otherwise would fail on the point a technical reviewer checks initially: whether the author can separate a proposal from a requirement. The register states what is in force, such as the licensed-operator conditions at 10 CFR 50.54(m) and the Reactor Oversight Process, and what is not, such as the proposed microreactor licensing rule and its draft guidance. It also names, in section 7, the questions we cannot answer at all, including whether an independent verification layer would be credited in a licensing basis.
Does the proposed microreactor licensing rule settle how these reactors will be overseen?
No. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). It contemplates an operating model, and contemplating a model is different from establishing the method by which a specific applicant would demonstrate that a specific staffing or remote-operation arrangement is acceptable for a specific design. The guidance that would carry much of that detail, NUREG-2271, is a draft issued for comment rather than final guidance. Treat both as regulatory direction and neither as present permission.
What does it mean that SECY papers and laboratory reports are cited here?
SECY documents are staff papers that present analysis and options to the Commission. They are not Commission positions and they are not requirements. Reports from Brookhaven and Sandia National Laboratories cited in this paper are contractor analysis prepared in support of NRC work, and the Oak Ridge reports are laboratory research. All of them are good evidence of what specialists regard as unresolved, which is exactly how this register uses them. None of them establishes an obligation on any party.
Is there an accepted standard for machine-generated evidence about reactor state?
Nothing in the record cited by this paper establishes one. RFC 9334 provides a well-specified remote attestation architecture that separates the producer of evidence from the party that appraises it, but it is an internet standards document with no nuclear regulatory standing, so it supplies vocabulary rather than acceptance. Oak Ridge analysis identifies licensing challenges for autonomous control without resolving them. The open sub-questions include who appraises, what coverage and freshness suffice, how long records persist, and how a record can be challenged after the fact.
What would cause an entry in this register to close?
A primary source that resolves it: a final rule published in the Federal Register covering the question, final rather than draft guidance, a Commission decision adopting or rejecting a position analysed in a staff paper, or a published laboratory or standards result that answers a technical sub-question. Closures are recorded with the citation that produced them, and superseded text is retained rather than deleted. Entries can also reopen, for example when a final rule leaves an implementation question unanswered.
Sources
- U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)
- U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026
- U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026
- U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper). October 2020
- U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper). June 2025
- U.S. Nuclear Regulatory Commission. SECY-24-0008: Micro-Reactor Licensing and Deployment (staff paper). 2024
- U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition
- U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026
- U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026
- U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023
- U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026
- U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025
- Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis. February 2025
- Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020
- Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018
- Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019
- U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026 (proposed 10 CFR 73.110 technology-neutral cyber requirements under development, not final or prescriptive)
- International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (coordinated research project J02021). Accessed July 2026
- Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023
- U.S. Nuclear Regulatory Commission and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025
- U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026
Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.
- OQ-1. Staffing baseline. How, if at all, the licensed-operator conditions imposed at 10 CFR 50.54(m) translate to a facility overseen from somewhere other than the site [7]. Unresolved because the instrument that contemplates another arrangement is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [1]. Resolver: NRC, through final rulemaking.
- OQ-2. Application evidence. What an applicant would have to submit to demonstrate that automated functions behave acceptably across their operating envelope. Unresolved because the guidance that would say so, NUREG-2271, is a draft issued for comment [2], and the licensing challenges identified in laboratory analysis of autonomous control remain open questions rather than accepted methods [15]. Resolver: NRC, through final guidance.
- OQ-3. Oversight footprint. What replaces the unstructured observation that resident inspection contributes today [9], given how heavily safety conclusions rest on information the oversight process produces [12]. Unresolved because agency readiness for advanced reactor oversight is itself an open recommendation area [10][11]. Resolver: NRC, with GAO scrutiny.
- OQ-4. Evidentiary standard. Whether a machine-generated statement about reactor state can be evidence to a regulator, and under what conditions of independence, coverage, freshness, retention, and challenge. Unresolved because the architecture we can point to is specified outside nuclear [19] and the cited record contains no accepted nuclear equivalent. Resolver: NRC for acceptance, standards bodies for form, research for method.
- OQ-5. Units per crew. What evidence would establish an acceptable ratio of units to qualified staff, and how reconciliation across units is treated. Unresolved because the contractor and research literature identifies the human-factors problem without setting a limit or a method for setting one [13][14][20][16]. Resolver: research organisations and NRC human-factors review.
- OQ-6. Cyber design target. What a developer can defensibly design against before a final requirement exists for this class, and whether a verification channel is itself a protected digital asset. Unresolved because the governing instrument is proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive) [17] and the microreactor-specific technical case remains an active research project [18]. Resolver: NRC through rulemaking, informed by international research.
- OQ-7. We cannot answer this one. Whether an independent verification layer would be credited in a licensing basis at all, whether a third-party attestation would be accepted as evidence rather than as background, and what commercial weight buyers place on either. We hold no evidence on any of the three, our interest in the answers is direct, and pre-application interaction confers no approval [21]. Resolver: the NRC on a specific docket, and the market for the rest.
This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.
This paper reflects the state of NRC microreactor rulemaking and the published research record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) and proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive), may change before any final rule issues. Re-check the docket before relying on any section reference here.
About this article. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.
A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application