Technical papers
A Reference Architecture for Independent Verification of Reactor State

Technical paper · document control
- Document type
- Technical paper
- Version
- 1.0
- Published
- 24 July 2026
- Revised
- 24 July 2026
- Status
- Published for technical comment
- Regulatory status
- RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behaviour are design intent and are subject to analysis, testing, and regulatory review.
Abstract
Oversight of United States commercial power reactors has been built around physical presence. The NRC assigns resident inspectors to operating sites and feeds their findings into the Reactor Oversight Process[1][2][3], and 10 CFR 50.54(m) makes minimum licensed operator staffing, including an operator at the controls, a condition of the licence[4]. Microreactor concepts that contemplate remote operation and reduced on-site staffing withdraw part of that presence without yet replacing the evidence it supplied. This paper treats that gap as a design problem rather than a governance argument. It states five criteria a verification layer would have to satisfy, and proposes a reference architecture that satisfies them using published standards rather than new cryptography: attestation roles from RFC 9334[11], transparency and receipts from RFC 9943[12] and RFC 9942[13], and post-quantum signatures standardised by NIST[14][15].
The contribution is the assembly, its mapping to the regulatory record, and an explicit register of what it fails to do. The principal limitation is structural: the architecture produces detection rather than prevention, and it inherits whatever trustworthiness the underlying sensors have. A signed record of a corrupted measurement is a corrupted record, signed. Nothing described here has been demonstrated to or accepted by the NRC[22].
This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.
Scope and limitations
This paper addresses the evidence layer that sits above reactor instrumentation: how a record of reactor state can be produced, appraised by a party other than the operator, signed, logged, and later re-checked by someone who was absent when it was made. It sets out design criteria, names the published standards that already define each component, maps the resulting architecture onto the current regulatory record including the NRC's proposed 10 CFR Part 57 rule (proposed, published in the Federal Register on May 1, 2026, comment period closed June 15, 2026, not final, and no developer is licensed under it), and analyses the failure modes that survive.
It deliberately does not do several things. It is not a safety analysis and makes no safety claim. It is not a control system design; the architecture described here carries evidence outward and exercises no control function, and nothing in it supports a fully autonomous or unmanned operating model. It contains no design-specific parameters for the HELIX microreactor, because a public paper is the wrong surface for those under 10 CFR Part 810. It does not interpret any regulatory requirement on behalf of a third party, and it does not name, rank, or characterise other developers.
Three things would change its conclusions. A final Part 57 rule that differs materially from the May 1, 2026 proposal, or final guidance differing from the draft NUREG-2271 issued for comment in April 2026[6], would change the regulatory mapping in Section 5. A practical break in a standardised post-quantum signature scheme[15] would change the durability argument in Section 4. And credible sensor-level attestation, which does not exist today for qualified nuclear instrumentation, would substantially narrow the residual risk described in Section 6.
United States commercial reactor oversight rests on a fact that is rarely stated as an assumption: someone is there. A resident inspector is assigned to the site and walks the plant. A licensed operator sits at the controls as a condition of the licence. Microreactor concepts that contemplate remote operation and reduced on-site staffing withdraw part of that presence. This paper asks what presence supplied, and proposes an architecture for supplying it another way.
The regulatory direction is far enough along to make the question concrete rather than speculative. The nrc's proposed 10 cfr part 57 rule (proposed, published in the federal register on may 1, 2026, comment period closed june 15, 2026, not final, and no developer is licensed under it) would establish a licensing framework for this reactor class[5], and NRC staff have published draft application guidance for it[6]. Nothing in that record is settled, and this paper does not treat it as settled. What it does treat as settled is that an oversight model built around presence needs a stated replacement for the evidence presence produced, and that the replacement is easier to design before deployment than after.
The contribution here is a reference architecture assembled entirely from published standards, five criteria against which any such architecture can be tested, a register of open questions including several we cannot answer, and an assessment of RankShield Energy against our own criteria that we do not pass. RankShield Energy is a pre-applicant and operates no reactor[22]. The architecture is offered for use and for argument, not as a description of a capability we hold.
Key takeaways
- Resident inspection and the operator-at-controls condition supplied evidence with four properties: contemporaneous, unmediated, contextual, and institutionally independent[1][3][4]. A remote model erodes the middle two most sharply.
- A verification layer has to be per-unit, comparable, independent of the operator, checkable after the fact, and durable, and all five have to hold at once.
- Every component of the proposed architecture is already defined by a published standard: attestation roles[11], transparency services[12], receipts[13], and post-quantum signatures[14][15]. The contribution is the assembly, not the parts.
- The regulatory context is unsettled: proposed Part 57 (proposed, published May 1, 2026, comment period closed June 15, 2026, not final, no developer licensed under it), with draft staff guidance in NUREG-2271[6].
- The architecture is tamper-evident, not tamper-proof, and it inherits the trustworthiness of the sensors beneath it. RankShield Energy does not currently satisfy three of its own five criteria.
1. The oversight function that remote operation displaces
Presence performs an evidential function before it performs a regulatory one. The NRC assigns resident inspectors to operating commercial power reactor sites, where they conduct inspections, observe licensee activities, and hold access to the facility that does not depend on the licensee's own reporting[1][2]. Their findings feed the Reactor Oversight Process, which combines licensee performance indicators with NRC inspection results and assesses both against defined cornerstones of safety[3]. Separately, 10 CFR 50.54(m) establishes minimum licensed operator staffing as a condition of the licence, including the presence of a licensed operator at the controls while the reactor is operating[4].
Four distinct goods come out of that arrangement, and they are worth separating because a remote operating model does not remove them equally. Observation is contemporaneous: an inspector sees the plant in the state it is in, not in the state a report describes some hours later. Observation is unmediated: it does not pass through the licensee's own recording and summarising before it reaches the regulator. Observation is contextual: a person who knows the unit notices that a parameter is ordinary here and would be anomalous next door. And observation is institutionally independent: the observer is employed by the regulator, not by the licensee.
A remote model with reduced on-site staffing erodes the unmediated property most sharply. What reaches an off-site reviewer is a record that the operator's own systems produced, transported, and stored. The contextual property degrades next, because context is expensive to reconstruct from telemetry. The institutional independence of the regulator survives, but it now operates on evidence supplied by the party being regulated, which is a materially weaker epistemic position than walking the plant.
The regulator has been examining this. A February 2025 report prepared for the NRC by Brookhaven National Laboratory, which is contractor analysis and not a Commission position, reviews reactor facilities that operate without main control rooms[21]. Earlier, SECY-20-0093, an NRC staff paper rather than a Commission decision, set out policy and licensing considerations specific to micro-reactors[8]. Both establish that the question is live inside the agency. Neither establishes an answer, and neither should be read as one.
The framing this paper adopts follows from that. The claim is not that remote operation is unsafe; this paper takes no position on that. The claim is narrower and more tractable: presence supplied evidence with four identifiable properties, and a remote model has to supply evidence with those properties by other means or accept a weaker basis for oversight. Stated that way, a governance argument becomes a design specification, which Section 2 attempts to write down.
2. Problem statement and design goals
The design problem is to reproduce the evidential properties of presence, not to reproduce presence itself. The distinction matters, because attempts to reproduce presence lead to more cameras and more telemetry, which increase the volume of operator-produced information without changing who vouches for it. Volume is not assurance. A hundred additional signals routed through the same trust path have the same trust properties as one.
We state the goals as criteria so that a proposed design can be tested against them individually rather than assessed as a whole:
- Per-unit. Evidence describes an individual reactor. A fleet-level aggregate averages away the divergent unit, which is the unit that matters.
- Comparable. Records from different units, sites, and vendors are expressed so that a reviewer can compare them without bespoke reconciliation work. Comparability is what allows an anomaly to stand out rather than requiring someone to notice it.
- Independent of the operator. The party that appraises the evidence is organisationally distinct from the party whose state is being described. Evidence the operator alone can attest to is a claim, not a verification.
- Checkable after the fact. A party absent at the time can later reconstruct what was recorded, when, and by whom, without asking the operator to vouch for the reconstruction.
- Durable. The record remains checkable across key rotation, cryptographic migration, vendor turnover, and the service life of the plant.
A sixth property is deliberately excluded. The layer must not become a control path. Evidence flows outward; nothing flows inward. This is a constraint rather than a convenience, because an evidence channel with a write path into plant systems is a new attack surface on safety functions, and the NRC's digital instrumentation and control guidance treats new digital pathways as requiring justification[10].
These criteria are not new individually, and this paper does not claim them as discoveries. National-laboratory work has treated the assurance burden created by reducing operator involvement as a design input rather than an afterthought: ORNL's concepts for autonomous operation of microreactors[19] and its companion analysis of licensing challenges associated with autonomous control[20] are laboratory technical reports rather than regulatory positions, and both frame the difficulty as one of demonstrating behaviour rather than of the control concept as such. What this paper adds is the insistence that all five criteria hold at once, and an architecture that attempts it. We have written separately about what it would take to verify an autonomous microreactor is operating safely; this paper is the structural version of that argument.
3. Defined terms, with attribution
Several words in this paper carry regulatory weight in one field and a different technical meaning in another. The definitions below are taken from the standards that define them, and are attributed on introduction so a reviewer can check the source rather than our paraphrase.
- Attester. The entity whose state is being described, which produces evidence about itself. RFC 9334, the RATS architecture[11]. In this architecture the attester is the reactor and its instrumentation.
- Evidence. Claims about an attester's state, produced by the attester. RFC 9334[11]. Evidence is an input to verification, never a conclusion.
- Verifier. The entity that appraises evidence against an appraisal policy and produces an attestation result. RFC 9334[11]. The role is defined as distinct from the attester, which is the property this paper relies on.
- Attestation result. The verifier's output, describing what the evidence supports. RFC 9334[11].
- Relying party. The entity that consumes attestation results in order to make a decision. RFC 9334[11]. Here: a regulator, insurer, lender, or grid operator.
- Transparency service. A service that registers signed statements in an append-only, verifiable log. RFC 9943, the SCITT architecture[12].
- Receipt. A signed proof that a statement was registered in such a log, structured so that a holder can check it. RFC 9943[12], with the concrete format specified in RFC 9942[13].
One collision deserves flagging, because it causes real confusion in mixed audiences. In the attestation literature, verification means appraisal of evidence against a policy. In nuclear software practice, verification and validation refer to a distinct discipline concerned with whether a system was built correctly and whether the right system was built. These are separate activities and neither substitutes for the other. Where this paper says verification without qualification, it means the RFC 9334 sense[11].
A second distinction runs through the rest of the paper: attestation by the party being assessed is self-attestation, and self-attestation with a signature is still self-attestation. The signature establishes who made the statement and that it has not been altered since. It establishes nothing about whether the statement is true. We have set out the difference between self-attestation and independent verification in more accessible terms elsewhere; the architecture below exists to achieve independent verification rather than to dress self-attestation up as it.
4. The reference architecture, component by component
The architecture has five components and one consumer. None is novel. The proposal is the assembly, and the constraint that each component is instantiated by a published standard a reviewer can audit independently.
Measurement. Instrumentation produces the state record: power level, temperatures, control element positions, and the status of each safety function. This component is governed by the plant design and by the NRC's guidance on digital instrumentation and control for advanced reactors[10]. It is also the component this architecture does not improve, a point Section 6 returns to. We have described the path from a sensor reading to a checkable attestation record in introductory terms; what follows is the same path stated as a specification.
Independent appraisal. A verifier, organisationally separate from the operator, appraises the evidence against an appraisal policy and issues an attestation result[11]. Agreement and disagreement are both recorded. A verifier that records solely the agreements produces an advertisement.
Signing. The attestation result is signed with a digital signature scheme standardised by NIST, which approved three post-quantum standards in August 2024[14], including FIPS 204, the module-lattice-based digital signature standard[15]. The reason to choose a post-quantum scheme now is not urgency about quantum computers. It is criterion 5: a record that must remain checkable across a plant's service life should not be signed with an algorithm whose assumptions are expected to be revisited within that window.
Transparency log. Signed statements are registered in an append-only transparency service as defined by RFC 9943[12]. The log's value is not storage. It is that a statement cannot be quietly withdrawn or reordered after registration without detection, provided the log is independently witnessed.
Receipt. Registration returns a receipt in the format specified by RFC 9942[13], which a holder can check against the log's published state. This is the component that satisfies criterion 4, because it lets a party who was absent verify that a specific record existed at a specific point in the log's history.
| Component | Function here | Standard that defines it | What it does not establish |
|---|---|---|---|
| Measurement | Produces the reactor state record | Plant design plus NRC digital instrumentation and control guidance[10] | That the instrument is calibrated, correct, or uncompromised |
| Independent appraisal | Verifier appraises evidence, issues an attestation result | RFC 9334, RATS architecture[11] | That the verifier itself is trustworthy |
| Signing | Binds the result to a key and detects alteration | NIST FIPS 204[15], approved August 2024[14] | That the signed content is true |
| Transparency log | Append-only registration of signed statements | RFC 9943, SCITT[12] | That the log operator is honest absent independent witnesses |
| Receipt | Portable proof of registration | RFC 9942, COSE receipts[13] | That the registered claim reflects physical reality |
| Relying-party check | Regulator, insurer, lender, or grid operator verifies independently | RFC 9334 relying party role[11] | Any authority to act; authority comes from elsewhere |
Read down the fourth column and the architecture's honest shape appears. Each component establishes something narrow. The assembly is stronger than any component, and weaker than the sum a casual reader would assume.
5. Mapping the architecture to the regulatory context
The regulatory context is in motion, and this section describes it rather than interpreting it for anyone. The nrc's proposed 10 cfr part 57 rule (proposed, published in the federal register on may 1, 2026, comment period closed june 15, 2026, not final, and no developer is licensed under it) would establish a licensing framework for microreactors and other reactors with comparable risk profiles[5]. Draft guidance for preparing and reviewing applications under that proposed framework was issued as NUREG-2271, a draft for comment and an NRC staff document rather than final guidance[6]. The agency maintains a public summary of its broader microreactor regulatory activities[7]. We have written a plain-language account of what proposed Part 57 does and does not say about autonomous operation; the point here is narrower.
Two staff papers frame the operational questions. SECY-20-0093, staff analysis and not a Commission position, addressed policy and licensing considerations for micro-reactors including operational programmes[8]. SECY-25-0052, likewise a staff paper rather than a Commission decision, addressed nth-of-a-kind microreactor licensing and deployment considerations[9], which is where the oversight-per-unit question becomes acute: an inspection model calibrated to a small number of large sites does not obviously transfer to a large number of small ones.
If a regulator held receipts of the kind described in Section 4, four checks become available without the operator's cooperation. Whether a record for a given unit and period exists in the log at all. Whether the record presented today matches the record registered then. Whether the verifier that appraised it was the expected party. And whether records are missing for periods when the unit was operating, which is often the more informative question. None of these requires the regulator to trust the operator, the vendor, or us.
Four caveats have to sit alongside that, and we state them because omitting them would misrepresent the position. The rule is proposed and not final: proposed Part 57 (proposed, published May 1, 2026, comment period closed June 15, 2026, not final, no developer licensed under it), so nothing here describes a compliance pathway. The NRC has not been asked to accept this architecture and has accepted nothing about it[22]. The record is an input to inspection, not a replacement for inspection authority, and the resident inspector programme[1][2] and the Reactor Oversight Process[3] remain the regulator's framework rather than something a vendor record displaces. And the operator-at-controls condition in 10 CFR 50.54(m)[4] is a current, final requirement for the licences it governs; a verification layer has no bearing on it. Safety-significant actions keep a human in the loop, and nothing in this paper supports a fully autonomous or unmanned operating model.
6. Threat and failure analysis
The architecture is tamper-evident, not tamper-proof. It is not unhackable and not unbreakable, and any description of it in those terms is describing something other than this. Tamper-evidence means an alteration made after registration is detectable by a party holding a receipt. It does not mean the alteration is prevented, and it does not mean anyone is watching. Detection without a party whose job is to look is a property nobody exercises.
Compromised or degraded sensors. This is the dominant residual risk and the honest weak point. Everything downstream of measurement operates on whatever the instrument reported. A drifted, spoofed, or replayed reading that is faithfully appraised, signed, and logged produces a durable, independently checkable record of something untrue. IAEA guidance on computer security of instrumentation and control systems at nuclear facilities treats the I&C layer as a security domain in its own right[18], and no amount of downstream cryptography substitutes for that work. Our introductory treatment of microreactor cybersecurity as an emerging standards space covers the surrounding landscape.
The verifier as a trust anchor. The architecture relocates trust; it does not abolish it. A relying party that accepts an attestation result is trusting the verifier's appraisal policy, key custody, and independence. If the verifier is captured, funded, or staffed by the operator, criterion 3 fails while every cryptographic check still passes, which is the most dangerous failure mode in the set because it looks exactly like success.
Log operator collusion. An append-only log is append-only because independent witnesses observe its published state over time. A log whose witnesses are all operated by the same organisation as the log provides a weaker guarantee than its structure suggests. RFC 9943 defines the technical role[12] and RFC 9942 defines the receipt[13]; neither assigns the institutional independence that makes them meaningful.
Supply chain. Firmware, signing libraries, and hardware roots of trust reach a plant through a supply chain that is itself an attack surface. NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organisations[16]; applying them to qualified nuclear instrumentation, where component substitution is constrained by qualification rather than by procurement preference, is unresolved work.
Cryptographic transition and availability. FIPS 204[15] is standardised, but a record checkable for decades will outlive at least one migration, and migration of a signed historical corpus is an operational problem no standard solves. Separately, the evidence path must be allowed to fail without consequence to the plant. If loss of the verification channel can influence operations, the channel has become a control path, which Section 2 excluded by design.
7. Precedent in adjacent domains
The structural precedent is international safeguards. IAEA safeguards rest on independent verification of a state's declarations by a body outside that state, using the agency's own inspections, instruments, containment and surveillance measures, and analysis[17]. The relevant feature for this paper is not the technology. It is the institutional shape: the party making the declaration and the party verifying it are separate by design, the verifier maintains its own measurement capability rather than relying entirely on the declarant's, and the resulting conclusions are drawn by the verifier rather than negotiated with the declarant.
The analogy has limits that must be stated, because safeguards specialists will notice them immediately. Safeguards address nuclear material accountancy for non-proliferation purposes under a distinct legal basis; they are not an operational safety oversight regime, and conclusions drawn under safeguards say nothing about whether a plant is operating safely[17]. The architecture proposed here borrows the institutional shape and none of the legal authority. Conflating the two would be a serious error, and we are not proposing that a commercial verification record discharges any safeguards obligation.
The technical precedent sits in computing. Remote attestation formalises exactly the separation described above: an attester produces evidence about itself, a verifier appraises it, and a relying party consumes the result, with the roles specified so they can be held by different organisations[11]. Supply chain transparency work extends this to durable records, defining a transparency service that registers signed statements in an append-only log[12] and receipts that let a holder check registration[13]. Those specifications were written for software supply chains, where the problem is structurally similar: a producer makes claims about an artefact, and consumers downstream need a basis for those claims that does not reduce to trusting the producer.
What neither precedent supplies is the nuclear-specific part. Safeguards practice has institutional independence and physical measurement but was not designed for continuous operational state. The attestation specifications have the record structure but assume a computing environment where the attesting device can hold a hardware root of trust, which qualified reactor instrumentation generally cannot[18]. The gap between them is where the engineering work actually sits, and this paper does not close it.
8. Applying the framework to RankShield Energy
A paper proposing a verification architecture should apply it to its author, and the result should be unflattering if it is honest. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC[22]. We hold no licence, permit, or design approval. No aspect of the HELIX microreactor has been demonstrated to or accepted by the NRC. Everything in the preceding sections is analysis and design intent, not capability.
Measured against the five criteria in Section 2, our position is as follows. Criterion 1, per-unit evidence: we have a design intent and no operating unit, so this is untested. Criterion 2, comparability: unmet in any meaningful sense, because comparability across vendors requires a schema the industry does not have and cannot be created by one participant. Criterion 3, independence of the operator: this is the one we are furthest from. A verifier organisationally distinct from the operator does not exist for our design, and standing one up is an institutional problem rather than a technical one.
Criterion 4, checkability after the fact: partially addressed in prototype form and materially weaker than this paper's specification. Our current transparency logging arrangement does not yet provide the third-party verifiability the architecture requires, and the witnesses observing our log are not independent of us. We state this plainly because a reader who assumed otherwise from the preceding sections would have been misled by our omission. Criterion 5, durability: post-quantum signing is design intent[14][15], and we have not exercised a migration of a signed historical corpus.
Two further gaps deserve naming. We have no sensor-level attestation, which means the dominant residual risk identified in Section 6 applies to our design with full force[18]. And our supply chain practices have not been assessed against NIST SP 800-161r1[16] in the form that a qualified instrumentation programme would require.
The reason to publish an architecture we do not yet satisfy is that the alternative is worse. Verification designed after a fleet is deployed is verification bolted on, and bolted-on evidence is precisely the kind an outside party has least reason to trust. Publishing the specification before we meet it also creates a record against which we can be held, which is the property this paper argues reactor operations should have. The criteria in Section 2 are offered for use by anyone, including parties assessing us, and we would rather be measured against a written standard than against our own description of our progress.
Frequently asked questions
What problem does this reference architecture actually solve?
It addresses a narrow and specific gap: when on-site presence is reduced, the evidence reaching an outside reviewer is produced, transported, and stored by the party being reviewed. The architecture separates the entity whose state is described from the entity that appraises the description, then makes the appraisal durable and re-checkable by a party who was absent. It does not make a reactor safer, does not evaluate safety, and does not substitute for inspection. It changes who has to be trusted for an operational record to carry weight, and it narrows that set to parties a reviewer can name.
Why use published standards rather than a purpose-built scheme?
Three reasons. A reviewer can audit the design against documents that no party to the transaction controls, which is the point of citing specifications rather than describing a product. The standards have been reviewed by communities larger than any single vendor engineering team, so their failure modes are documented. And a scheme defined by the party being verified is structurally the thing this architecture exists to avoid. The cost is that none of the standards was written for nuclear instrumentation, so the adaptation work, particularly at the measurement layer, remains genuinely open.
Does this mean a reactor could operate without people?
No, and nothing in this paper supports that reading. The proposed Part 57 rule, which was published May 1, 2026, whose comment period closed June 15, 2026, which is not final and under which no developer is licensed, contemplates remote operation and reduced on-site staffing with a human in the loop for safety-significant actions. The architecture described here carries evidence outward and exercises no control function. It is deliberately excluded from any control path, because an evidence channel with a write path into plant systems would be a new attack surface on safety functions.
Has the NRC accepted any part of this?
No. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC. It holds no licence, permit, or design approval, and no design, product, facility, or operational characteristic has been demonstrated to or accepted by the NRC. The regulatory sections of this paper describe the agency's published framework and staff and contractor analysis; they do not describe a compliance pathway, an agreement, or an expectation of one. Whether such records would be accepted as inspection evidence is listed in the open questions as a matter we cannot answer.
What is the weakest part of the architecture?
Measurement. Every component downstream operates on whatever the instrument reported, so a drifted, spoofed, or replayed reading that is faithfully appraised, signed, and logged yields a durable and independently checkable record of something untrue. Commercial hardware roots of trust are not qualified for the radiation and temperature conditions in which reactor instrumentation operates, so attestation at the measurement point is not currently available. Until that changes, the architecture verifies the handling of a measurement rather than the measurement itself, and any claim beyond that overstates it.
Sources
- U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026
- U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026
- U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026
- U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition
- U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)
- U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026
- U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026
- U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper). October 2020
- U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper). June 2025
- U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026
- Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023
- Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026
- Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026
- National Institute of Standards and Technology. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography. August 2024
- National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024
- National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024
- International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026
- International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018
- Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019
- Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018
- Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025
- U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026
Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.
- Would the NRC accept cryptographically attested operational records as inspection evidence, and under what conditions? We cannot answer this. It is a determination for the Commission and its staff, informed by a docket that does not yet contain such a proposal. No part of this architecture has been submitted to, demonstrated to, or accepted by the NRC[22], and this paper should not be read as predicting the outcome.
- What will the final Part 57 rule require of remote and reduced-staffing operating models? The rule remains proposed: published May 1, 2026, comment period closed June 15, 2026, not final, and no developer is licensed under it[5]. Draft guidance in NUREG-2271, an NRC staff draft issued for comment rather than final guidance, indicates the direction of staff thinking but settles nothing[6].
- Where should the signing boundary sit relative to safety-related instrumentation and control? Signing closer to the sensor narrows the trust gap but introduces digital capability nearer to safety functions, which the NRC's digital instrumentation and control guidance treats as a question requiring justification[10]. We have no general answer and suspect the answer is design-specific.
- How is sensor-level attestation achieved in a radiation and high-temperature environment? Commercial secure elements and trusted platform modules are not qualified for the conditions in which reactor instrumentation operates. Without attestation at the measurement point, the architecture in Section 4 verifies the handling of a measurement rather than the measurement itself[18].
- Who operates a transparency service for reactor evidence, who witnesses it, and under what legal duty? RFC 9943 defines the technical role of a transparency service[12] and RFC 9942 defines receipts that prove registration[13], but neither assigns institutional responsibility. An operator-run log with operator-run witnesses reproduces the problem the architecture exists to solve.
- How does the record survive a cryptographic transition across a plant's service life? NIST approved three post-quantum standards in August 2024[14], including the module-lattice signature standard[15], but a record that must be checkable decades after it was written will outlive at least one migration, and long-term key custody is an operational problem no standard resolves.
- How would a commercial verification record interact with international safeguards obligations? IAEA safeguards rest on independent verification of state declarations under a distinct legal basis[17], and a vendor-produced operational record is neither a substitute for nor obviously separable from that regime for exported units.
This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.
This paper reflects the state of NRC microreactor rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change; Part 57 was published as a proposed rule on May 1, 2026, its comment period closed June 15, 2026, and no developer is licensed under it. This paper is technical analysis and is not legal or regulatory advice.
About this article. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.
A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application