# Oversight Models for Fleet-Scale Microreactor Deployment

> A comparative analysis of four candidate oversight models for a deployed microreactor fleet, assessed against five stated criteria and the public record.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# Oversight Models for Fleet-Scale Microreactor Deployment: A Comparative Analysis
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published July 24, 2026 Revised July 24, 2026 Status Comparative analysis, open for comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behaviour are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
Regulatory oversight of U.S. power reactors is delivered today through resident inspection, a structured oversight process, and licensed-operator conditions attached to the license itself. A deployed fleet of microreactors, distributed across many sites with small staffs, would stress every one of those mechanisms at once. The public record contains proposals, staff analysis, and contractor research bearing on the problem, but no published side-by-side comparison of the oversight models that could actually be adopted. This paper supplies that comparison. It defines five criteria an oversight model for a distributed fleet would have to satisfy, namely coverage per unit, timeliness of detection, independence from the operator, evidentiary durability, and scalability of regulator effort. It then assesses four candidate models against those criteria: extended resident inspection, periodic campaign inspection with remote data submission, continuous independent verification with attested records, and a hybrid of the three.
The comparison is the contribution, not the conclusion. No model is recommended, and the model closest to our own commercial interest is assessed with its unsolved problems stated in the same detail as its strengths. The principal limitation is that none of the four models has been reviewed or accepted by any regulator, so every assessment here is analytical rather than evidential. A second limitation is authorship. RankShield Energy is a pre-applicant developing an independent verification layer, and readers should treat the section on model C as the one requiring the most scepticism.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses how a regulator might obtain assurance about a distributed population of microreactors under U.S. Nuclear Regulatory Commission jurisdiction, and how candidate oversight arrangements compare against stated criteria. It draws on twenty primary sources spanning the regulator, the Government Accountability Office, three national laboratories, a standards body, and the International Atomic Energy Agency. Where a document is characterised, it is cited and its status is stated: rule in force, proposed rule, draft guidance, staff paper, contractor analysis, or research.
Several things are deliberately out of scope. The paper contains no design detail for any RankShield Energy system: no geometry, no fuel description, no performance or lifetime figures. It contains no cost or economic analysis, and cost is not among the evaluation criteria. It does not interpret what any rule requires of a third party, and it does not name, rank, or characterise other developers. It does not describe unattended or fully autonomous operation of a reactor; the operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification function under discussion is an assurance function rather than a control function.
Several developments would change the conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft application guidance, a Commission decision adopting or rejecting positions analysed in the staff papers cited here, published agency direction on how inspection resources would be allocated to a distributed fleet, or laboratory results that resolve a human-factors question this paper treats as open. The assessments in section 7 are our reading of the cited record and are offered for disagreement.

Everyone working on microreactor deployment has an implicit answer to the oversight question, and almost nobody has written theirs down next to the alternatives. The published record contains a proposed licensing rule, draft guidance, staff analysis, contractor studies, and an oversight process built for large plants with people on site. What it does not contain is a comparison of the oversight models a distributed fleet could plausibly be given, evaluated against criteria stated in advance. This paper is that comparison.
The method is deliberately unglamorous. Section 1 describes what oversight delivers today and separates the functions it performs from the mechanism that performs them, because a replacement has to reproduce the functions and need not reproduce the mechanism. Section 2 defines five criteria precisely enough to be argued with. Sections 3 through 6 assess four models against those criteria, including the weaknesses of each. Section 7 presents the comparison in a table. Section 8 applies the analysis to developers, including us, without the flattering conclusion a vendor paper would normally reach.
Two framing points govern everything that follows. What is in force is identified as in force: the licensed-operator conditions at 10 CFR 50.54(m) [[4]](#src-4) and the Reactor Oversight Process the agency applies to operating plants [[3]](#src-3). What is proposed is identified as proposed at every mention, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[5]](#src-5), whose companion guidance NUREG-2271 is a draft issued for comment rather than final guidance [[6]](#src-6). RankShield Energy is a pre-applicant engaged in early regulatory interaction and holds no NRC license, permit, or design approval [[20]](#src-20). Nothing described here has been demonstrated to or accepted by the NRC, and none of the four models has been reviewed by any regulator.
Key takeaways

- Oversight today delivers five separable functions, of which independent observation and corroboration of self-reported information are the hardest to reproduce without a person on site.
- The constraint on scaling the existing model is staffing and agency readiness, which the Government Accountability Office has documented directly rather than as a matter of speculation.
- Every model that reduces on-site presence trades observation for reported data, and the quality of that trade depends on provenance and independence rather than on data volume.
- Continuous verification with attested records addresses durability and coverage well, and does not by itself address instrument scope, appraisal capability, or who qualifies the verifier.
- A hybrid is the most probable outcome because each model covers a different failure mode, and Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) does not settle which mix any specific applicant would be held to.

## 1. The oversight function today and what it actually delivers
Oversight of an operating U.S. power reactor is delivered through a small set of identifiable mechanisms, and this analysis depends on separating what those mechanisms deliver from how they deliver it. The NRC assigns resident inspectors to operating power reactor sites, and describes their unescorted access to the facility and their organisational separation from the licensee as defining features of the arrangement [[1]](#src-1) [[2]](#src-2). Their work feeds a structured framework. The Reactor Oversight Process organises inspection findings and performance indicators against cornerstones of safety, applies a significance determination process, and produces a periodic assessment with defined agency responses [[3]](#src-3). Staffing is governed separately: conditions on power reactor licenses at 10 CFR 50.54(m) establish licensed-operator requirements for operation of the facility, and those are requirements in force rather than policy preferences [[4]](#src-4).
The functions this arrangement performs are distinct from the mechanism that performs them, and are worth enumerating, because a replacement model has to deliver the functions and does not have to reproduce the mechanism. Function one is independent observation: somebody who does not report to the licensee sees plant conditions that nobody selected for reporting. Function two is corroboration: self-reported information can be checked against direct observation, which is what lends the reported stream its credibility. Function three is continuity: an inspector who has watched a site for years detects drift that a snapshot cannot show. Function four is consequence: findings enter a defined process with defined outcomes rather than a correspondence file [[3]](#src-3). Function five is external accountability, and the Government Accountability Office has examined how far the agency's own safety conclusions rest on the information this process generates [[11]](#src-11).
The mechanism, by contrast, is contingent. It is a qualified person, physically present at a site large enough to justify the assignment, supported by regional inspection staff and a headquarters programme. Nothing in that description is a safety principle. It is an engineering solution to the assurance problem, chosen when reactors were few, large, and individually significant. A fleet of small units at many sites changes the arithmetic of that solution without changing the functions it was chosen to deliver, which is why the honest question is not whether resident inspection survives but which model delivers the five functions at acceptable cost to the regulator. Our companion explainer on [one operator overseeing many reactors](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) treats the licensee-side version of the same arithmetic.
One caution about function two. Corroboration is not a redundant check on data that would otherwise be trusted. It is the reason the data is trusted at all. Any model that reduces on-site presence is, whatever else it does, converting a corroborated information stream into an uncorroborated one, and it has to replace the corroboration with something. That single observation drives most of the analysis that follows.

## 2. Evaluation criteria for a fleet oversight model
Criteria stated after the fact are advocacy. These five are stated before any model is assessed, they are defined so a reader can apply them independently, and cost is deliberately absent from them.
Criterion 1, coverage per unit. The proportion of safety-relevant plant conditions at a given unit about which the regulator can obtain information, expressed as breadth rather than volume. A model with high coverage produces information about conditions nobody anticipated; a model with low coverage produces information about the conditions somebody chose to report. Coverage is bounded by instrumentation and by physical access, and the two bounds fail in different ways.
Criterion 2, timeliness of detection. The interval between a condition arising and the regulator becoming capable of knowing about it. This is not the interval to formal notification, which is set by reporting rules, but the interval to availability. A model can be strong on coverage and weak on timeliness, which is the characteristic signature of campaign-based inspection.
Criterion 3, independence from the operator. The degree to which the party producing, transmitting, retaining, and appraising the information is organisationally and technically separate from the party being overseen. The resident inspector programme achieves independence structurally, through a person who does not report to the licensee [[2]](#src-2). The International Atomic Energy Agency achieves it institutionally in the safeguards context, where technical measures are applied by an outside body to verify declarations made by a state [[19]](#src-19), a precedent for the institutional machinery independence requires, though safeguards address diversion of material rather than operational safety. RFC 9334 supplies the vocabulary for the split at the technical layer, separating the attester that produces evidence from the verifier that appraises it and the relying party that consumes the appraisal [[17]](#src-17).
Criterion 4, evidentiary durability. Whether a record retains its value as evidence after the moment it was made: whether it can be shown not to have been altered, whether its provenance survives, whether it can be produced and challenged in a later proceeding. Durability is where an oral observation is weakest and a signed record on an append-only transparency service of the kind described in RFC 9943 is strongest [[18]](#src-18).
Criterion 5, scalability of regulator effort. How agency effort grows as units are added. A model scales well when doubling the number of units does not double the qualified staff hours required, and scales badly when it does. This criterion is the reason the comparison matters: the Government Accountability Office has reported that the agency needed additional actions to prepare to license advanced reactors, and maintains priority open recommendations that remain unimplemented [[10]](#src-10) [[12]](#src-12).

## 3. Model A: extended resident inspection
Model A scales what exists. Resident or near-resident inspectors are assigned to microreactor sites in proportion to the number of sites, with the Reactor Oversight Process adapted in detail but retained in structure [[1]](#src-1) [[3]](#src-3). Its virtue is that it requires no new evidentiary theory. Every function described in section 1 is already delivered by it, and the agency has decades of practice in applying it. Where a regulator's tolerance for novel assurance methods is low, this is the model that needs the least argument.
Against criterion 1 it performs well. A person on site observes conditions that were never selected for reporting, which is the coverage property no data pipeline reproduces. Against criterion 2 it performs well for observable conditions and unevenly for the rest, since detection depends on presence at the moment of interest. Against criterion 3 it performs strongly, and structurally rather than contractually: the inspector does not report to the licensee [[2]](#src-2). Against criterion 4 it is moderate. Findings enter the agency record and are durable as findings, but the observation underlying them is not reproducible, and a disputed observation is resolved through process rather than through re-examination of a record.
Criterion 5 is where the model fails, and the constraint is documented rather than speculative. The Government Accountability Office reported that the NRC needed to take additional actions to prepare to license advanced reactors, including matters of staffing and workforce planning [[10]](#src-10), and its priority open recommendations for the agency identify items the agency has not yet implemented [[12]](#src-12). Separately, the Government Accountability Office has documented the extent to which the agency's safety conclusions rest on information produced by the existing oversight process [[11]](#src-11), which means the staffing constraint is not a matter of administrative convenience but of the evidentiary base itself.
The arithmetic is unforgiving. Qualified inspectors are produced through a training and qualification pipeline measured in years, and a distributed fleet multiplies sites faster than any such pipeline responds. Staff analysis of Nth-of-a-kind microreactor licensing and deployment considerations, which is staff analysis presented to the Commission rather than a Commission position or a requirement, examines the consequences of deployment at quantities unlike current practice [[8]](#src-8). The conclusion we draw, and it is our analysis rather than an agency position, is that Model A is sound on four criteria and structurally unable to satisfy the fifth at fleet scale. It remains the correct model for early units, where site counts are small and the value of direct observation during initial operation is highest.

## 4. Model B: periodic campaign inspection with remote data submission
Model B keeps inspection but decouples it from continuous presence. Inspectors visit on a planned cycle or in response to a trigger, and between visits the licensee submits operating data to the regulator on a defined schedule and in a defined format. The structure of the Reactor Oversight Process is retained, with performance indicators carrying more of the weight and baseline inspection carrying less [[3]](#src-3). This is the model most continuous with existing agency practice for facilities that do not host residents, and it is the one an agency under resource pressure can adopt without inventing anything.
Against criterion 5 it performs well, which is its reason for existing. Regulator effort tracks the number of visits and the volume of submissions reviewed rather than the number of hours a person spends standing in a building, and campaign scheduling gives the agency a lever it can adjust as the fleet grows. Against criterion 1 it is moderate: submitted data can cover many parameters at many units, and it covers exactly the parameters somebody chose to submit. The unstructured observation described in section 1 is largely absent between campaigns.
Criterion 2 is its weakest axis. Between campaigns, timeliness is set by the submission schedule and by the licensee's internal reporting judgement. A condition that develops and is corrected between visits may be visible in the data or may not be, depending on what was instrumented and what was transmitted. Criterion 3 is weaker than it appears. The inspection is independent while it is happening; the data path between campaigns is the licensee's, which makes the between-visit stream a self-report. That is the distinction we treat at length in [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is not a criticism of licensee integrity. It is a statement about who is in a position to corroborate.
Criterion 4 is moderate and contingent. A submitted record is durable to the degree that the submitting party's retention and integrity controls make it so, and disputes about what a record showed at the time it was made are resolved by examining the licensee's own systems. Staff analysis of policy and licensing considerations related to micro-reactors, which is staff analysis for Commission consideration rather than an adopted requirement, canvassed questions of this type early [[9]](#src-9), and the draft guidance for applications under the proposed microreactor framework is where some of the detail would land, while it remains a draft issued for comment [[6]](#src-6). The agency maintains a public summary of its microreactor regulatory activities, which is the practical place to watch for movement [[7]](#src-7). Our assessment: Model B scales, and it does so by accepting a reduction in corroboration that nothing in the model itself repairs.

## 5. Model C: continuous independent verification with attested records
Model C replaces continuous human presence with a continuous, independently appraised record. Instrumented plant state is signed at the point of measurement, appraised by a party separate from the operator, and registered so that the resulting record is tamper-evident and can be examined later. RFC 9334 supplies the role separation, distinguishing attester, verifier, and relying party [[17]](#src-17), and RFC 9943 describes registering signed statements on an append-only transparency service so that a relying party can verify them without trusting the issuer [[18]](#src-18). Both are internet standards with no nuclear regulatory standing, and citing them establishes vocabulary rather than acceptance. Our reference architecture for this model is set out [separately](https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state).
Assessed generously, it is strong on two criteria. Criterion 4 is where it performs best: a signed, registered record is durable in a way an observation is not, and it supports challenge after the fact by a party who was not present. Criterion 2 is strong for covered parameters, since detection latency is a property of the pipeline rather than of a visit schedule. Criterion 5 is favourable for volume, because appraisal of records does not scale with unit count the way qualified inspector hours do.
Now the part that matters more. Criterion 1 is where the model is weakest, and the weakness is structural rather than fixable by better engineering. Coverage is bounded absolutely by instrumentation. A verification layer says nothing whatever about a condition nobody instrumented, and an unheard sensor and a healthy plant produce the same silence unless the design distinguishes them. The Brookhaven National Laboratory review of reactor facilities without conventional main control rooms, which is contractor analysis prepared for the NRC rather than a requirement, is a useful corrective on how much of an operator's situational picture is not instrumented [[13]](#src-13). Oak Ridge National Laboratory analysis of licensing challenges associated with autonomous control identifies the difficulty of demonstrating that automated logic behaves acceptably across its envelope [[15]](#src-15), and the companion Oak Ridge work on autonomous operation concepts for microreactors describes the monitoring and diagnostic functions such a system depends on [[16]](#src-16). Neither resolves the qualification question for the software doing the verifying.
Criterion 3 is conditional, and this is the honest verdict. Independence is a property of the arrangement, not of the cryptography. If the operator selects, pays, instructs, and can dismiss the verifier, the mathematics is sound and the independence is decorative. Beyond that, the model requires of a regulator three capabilities that do not exist today: staff qualified to appraise cryptographic evidence and the software that produces it, a stated policy on what appraisal outcome is acceptable and what a gap in coverage means, and some means of qualifying or accrediting a verifier. Nothing in the cited record establishes any of the three, and pre-application interaction confers no approval of any of them [[20]](#src-20). Model C is therefore the model with the strongest evidentiary properties and the largest institutional deficit.

## 6. Model D: the hybrid, and why it is the probable outcome
Model D combines the three: reduced but real inspection presence, campaign inspection on a risk-informed cycle, and a continuous verified record between campaigns whose appraisal sits outside the licensee. It is the least elegant of the four and the most likely to occur, for reasons that have little to do with anyone's preference.
The technical reason is that each model covers a different failure mode. Inspection catches what was never instrumented. Campaign inspection catches accumulated drift and provides the periodic direct corroboration that keeps the reported stream credible. A continuous verified record catches transient and rapidly evolving conditions and preserves them in a form that survives to a later proceeding [[18]](#src-18). No pair of these covers what all three cover, and the three coverage sets overlap partially rather than nesting.
The institutional reason is stronger. Regulators do not replace a functioning assurance arrangement with an untested one; they add and then subtract as evidence accumulates. The Reactor Oversight Process itself is layered in exactly this way, combining inspection, indicators, significance determination, and assessment rather than relying on any single input [[3]](#src-3). Staff analysis of Nth-of-a-kind licensing and deployment considerations, which is staff analysis presented to the Commission and not a Commission position, treats standardisation and repeat deployment as things that accumulate justification over units rather than being granted at the outset [[8]](#src-8). A hybrid is what a graded, evidence-accumulating approach looks like while the evidence is still accumulating.
The human-factors reason is the one most often skipped. Sandia National Laboratories examined human-factors considerations for automating microreactors [[14]](#src-14), and the Brookhaven contractor review of facilities without conventional main control rooms addresses the same territory from the review side [[13]](#src-13). Both point at function allocation: deciding what belongs to automation, what belongs to the person, and how the person retains an accurate picture of a plant they are not standing in. A hybrid oversight model mirrors that allocation on the regulator's side of the fence, which is a coherence argument rather than a proof.
The costs of the hybrid should be stated plainly, since they are the reason it is not obviously correct. It is the hardest of the four to govern: three information streams, three failure modes, and a standing question about which stream prevails when they disagree. It carries the highest design burden and the greatest risk of gaps at the seams, where each layer assumes another layer has coverage. And a hybrid is easy to adopt accidentally, by accretion, rather than by design, which is the version that satisfies criterion 5 worst of all.

## 7. Comparative assessment
The table below compresses sections 3 through 6 into a single view. Two cautions before reading it. The cells are qualitative because the record supports nothing quantitative: no model here has been trialled at fleet scale, and assigning numbers would imply a measurement basis that does not exist. And the assessments are ours. They are an argument, offered in a form that can be contradicted cell by cell.

Table 1. Four candidate oversight models assessed against the five criteria defined in section 2. This table is RankShield Energy analysis of the public record cited in this paper. It is not a regulatory position, it has not been reviewed or accepted by the NRC, and no model shown here is required, endorsed, or approved by any agency.

Model
1. Coverage per unit
2. Timeliness of detection
3. Independence from operator
4. Evidentiary durability
5. Scalability of regulator effort

A. Extended resident inspection
Strong, including conditions nobody selected for reporting
Strong for observable conditions, dependent on presence at the moment of interest
Strong and structural; the inspector does not report to the licensee
Moderate; findings are durable, the underlying observation is not reproducible
Weak; qualified staff hours rise close to linearly with unit count

B. Campaign inspection with remote data submission
Moderate; broad in submitted parameters, thin between campaigns
Weak between campaigns; set by submission schedule and licensee judgement
Moderate at campaign, weak between; the data path belongs to the licensee
Moderate; contingent on the submitting party's retention and integrity controls
Strong; effort tracks visits and submissions reviewed

C. Continuous independent verification with attested records
Weak beyond instrumentation; silent on anything not measured
Strong for covered parameters; requires distinguishing silence from a healthy null
Conditional; a property of the arrangement, not of the cryptography
Strong; signed, registered records support challenge after the fact
Strong for volume, unproven for appraisal; shifts effort to software and verifier qualification

D. Hybrid of A, B and C
Strong where layers overlap; gaps where each assumes another has coverage
Strong for instrumented parameters, campaign-limited elsewhere
Strong if both the inspection and the appraisal sit outside the licensee
Strong; two record types that can be cross-checked
Moderate; lighter per unit, heavier to design and govern

Three patterns are visible across the rows. Criterion 1 and criterion 5 pull against each other in every model: the arrangements that see the most at a unit scale worst, and the arrangements that scale best see a selected subset. No model in the table escapes that tension, and we are not aware of a published proposal that does. Criterion 3 behaves differently from the rest, because independence is structural in Model A and contractual or architectural in the others, and a structural property degrades more gracefully than a contractual one.
The third pattern concerns criterion 4. Evidentiary durability is the axis on which the existing model is weakest and the newest model is strongest, and it is also the axis least discussed in the deployment literature, which tends to treat oversight as a detection problem rather than as a problem of records that survive to be argued over. The durability question becomes acute precisely when something has gone wrong and the reconstruction begins [[18]](#src-18).
What the table does not do is rank the models, and the omission is deliberate. Ranking requires a weighting across the five criteria, weighting is a regulatory judgement rather than a technical one, and no weighting appears in the cited record. A reader who weights criterion 1 highest will prefer Model A; a reader who weights criterion 5 highest will prefer Model B or C; a regulator obliged to weight all five will most likely arrive at Model D. Publishing the criteria separately from the weighting is the point of presenting the analysis this way.

## 8. What this implies for developers, including us
The standard this paper follows requires it to apply its own framework to RankShield Energy and to state where we do not have a strong answer. Three implications follow for any developer, and the third is uncomfortable for us specifically.
The initial implication is that oversight model is a design input and is being treated by much of the field as a downstream compliance matter. Instrumentation scope, data retention, network architecture, and the physical accommodation of an inspector are frozen early in a design and are expensive to revisit. A developer who assumes Model C and instruments to the boundary of what a verification layer needs will discover, if the outcome is Model D, that the coverage gap identified in section 5 is now a licensing issue rather than an engineering preference. The conservative design position is to instrument for the model with the widest coverage requirement.
The second implication concerns claim discipline. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contemplates a licensing framework for this reactor class [[5]](#src-5), and its companion guidance NUREG-2271 is a draft issued for comment rather than final guidance [[6]](#src-6). Neither settles which oversight model any specific applicant would be held to, and that determination would be made on a docket. Pre-application interaction is described by the agency as a means of early alignment, and it confers no approval [[20]](#src-20). Our own explainers on [the proposed rule](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) and on [what a reviewer should ask a vendor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) take the same position.
The third implication applies to us. RankShield Energy is developing an independent verification layer, which is a Model C component. This analysis concludes that Model C is weakest on the criterion a regulator has historically weighted heaviest, namely coverage of conditions nobody selected for reporting, and that its independence property is a feature of the commercial arrangement rather than of the technology. It also concludes that the model requires appraisal and accreditation capabilities that do not exist today, and we have no evidence about whether they will be built. Nothing in our design has been demonstrated to or accepted by the NRC. If the outcome is Model D, the honest description of a verification layer is a component within a larger arrangement that continues to depend on inspection, not a replacement for it, and we would rather write that down now than be held to a stronger claim later.
The final implication concerns the record. The Government Accountability Office has documented both the agency's reliance on oversight information and its readiness gaps for advanced reactor licensing [[11]](#src-11) [[10]](#src-10), and neither closes on a developer's schedule. The register of what remains unsettled is maintained in our [open questions paper](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight); the entries below are what this comparison adds to it.

## Frequently asked questions

### Which oversight model does this paper recommend?
None of them. The contribution is the comparison and the criteria, not a recommendation. The paper assesses four models against five criteria stated in advance, and it declines to rank them because ranking requires a weighting across the criteria, and weighting is a regulatory judgement rather than a technical one. Section 6 does state that a hybrid is the most probable outcome, which is a prediction about how regulators behave rather than an endorsement of the hybrid as the correct answer.

### Why are the five criteria the right ones?
They are defensible rather than uniquely right, and a reader is invited to add or replace one. Coverage per unit, timeliness of detection, independence from the operator, evidentiary durability, and scalability of regulator effort were chosen because each maps to a function that the existing arrangement of resident inspection and the Reactor Oversight Process actually delivers today. Cost is deliberately excluded. If a criterion were added, the most likely candidate is resilience of the oversight arrangement itself to loss of a single input.

### Does the proposed microreactor licensing rule determine which model applies?
No. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). It contemplates a licensing framework for this reactor class, and contemplating a framework is different from establishing which oversight arrangement any specific applicant would be held to. The companion guidance, NUREG-2271, is a draft issued for comment rather than final guidance. The design-specific determination would be made on a docket.

### Is continuous verification a replacement for inspection?
On this analysis, no. Continuous verification with attested records is strong on evidentiary durability and on timeliness for parameters that are instrumented, and it is silent about any condition nobody instrumented, which is precisely the coverage property that on-site observation supplies. It also depends on an appraisal capability, an appraisal policy, and a way of qualifying a verifier, and nothing in the record cited by this paper establishes that any of the three exists.

### What would change the assessments in this paper?
A final microreactor licensing rule, final rather than draft application guidance, a Commission decision on positions analysed in the staff papers cited here, published agency direction on how inspection resources would be allocated across a distributed fleet, or laboratory results establishing what a supervising operator can reliably detect without being on site. Any of those would move cells in the comparison table, and the table is versioned so that movement can be recorded.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg.html)
- [U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description/resident-insp-program.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628); proposed rule, comment period closed June 15, 2026, not final](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. NUREG-2271 (Draft for Comment): guidance associated with the proposed microreactor licensing framework. April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper, not a Commission position). June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper, not a Commission position). October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis. February 2025](https://www.osti.gov/biblio/2529385)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811-concepts-autonomous-operation-microreactors)
- [Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force (RFC Editor). RFC 9943: Supply Chain Integrity, Transparency, and Trust (SCITT) Architecture. June 2026](https://www.rfc-editor.org/info/rfc9943)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Weighting.** How the five criteria would be weighted against one another by a regulator, since the comparison in section 7 declines to rank the models precisely because no weighting appears in the cited record [[3]](#src-3). Resolver: NRC, through rulemaking and guidance.
- **OQ-2. The observation residual.** What proportion of an inspector's contribution is unstructured observation of conditions nobody selected for reporting [[1]](#src-1) [[2]](#src-2), and how much of that residual is transferable to instrumentation. Unresolved because the cited record characterises the programme without decomposing its contribution. Resolver: research, tested against agency inspection experience.
- **OQ-3. Scaling law.** Whether regulator effort under any model scales per site, per unit, or per operating organisation once one organisation oversees many units. Unresolved because staff analysis of Nth-of-a-kind deployment examines options rather than establishing a footprint [[8]](#src-8), and agency readiness for advanced reactor licensing remains an open recommendation area [[10]](#src-10) [[12]](#src-12). Resolver: NRC, with Government Accountability Office scrutiny.
- **OQ-4. Evidentiary standard.** What makes a machine-generated statement about reactor state acceptable to a regulator as evidence, with respect to independence, coverage, freshness, retention, and challenge. Unresolved because the architectures available to point at are specified outside nuclear [[17]](#src-17) [[18]](#src-18) and the cited record contains no accepted nuclear equivalent. Resolver: NRC for acceptance, standards bodies for form, research for method.
- **OQ-5. Who qualifies the verifier.** Whether an independent appraising party would require qualification, accreditation, or inspection itself, and by whom. The safeguards context offers the sole standing example of an institution built for outside verification, and it addresses diversion of material rather than operational safety [[19]](#src-19). Resolver: NRC, potentially with a standards or accreditation body.
- **OQ-6. Software qualification.** How the software performing monitoring, diagnosis, or verification would be qualified, given that laboratory analysis identifies demonstrating acceptable behaviour across an operating envelope as an unsolved licensing challenge [[15]](#src-15) [[16]](#src-16). Resolver: NRC through review practice, informed by laboratory research.
- **OQ-7. Supervisory span.** What evidence would establish an acceptable ratio of units to qualified staff on the licensee side, and how a supervisor retains an accurate picture of a plant they are not standing in. Unresolved because contractor and laboratory work identifies the human-factors problem without setting a limit or a method for setting one [[13]](#src-13) [[14]](#src-14). Resolver: research organisations and NRC human-factors review.
- **OQ-8. We cannot answer this one.** Whether a Model C verification layer would be credited in any licensing basis at all, or whether a regulator concludes that assurance belongs inside the licensee's own quality and configuration-management programmes and that an external appraiser adds a component to be reviewed without reducing anything else that must be reviewed. We hold no evidence either way, our commercial interest in the answer is direct, the guidance that might address it is a draft [[6]](#src-6), and pre-application interaction confers no approval [[20]](#src-20). Resolver: the NRC, on a specific docket.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [Open questions in autonomous microreactor oversight →](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [The NRC pre-application process explained →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of NRC microreactor rulemaking and the published research record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application
