Sorry, you need to enable JavaScript to visit this website.
U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Audit of the U.S. Nuclear Regulatory Commission’s (NRC) Cybersecurity Inspection Program for Operating Nuclear Power Plants

Report Information

Date Issued
Report Number
OIG-NRC-26-A-03
Report Type
Audit
Description
The OIG determined that the current cybersecurity program guidance lacks clarity; expectations for maintaining training qualifications are not well-defined; the cybersecurity inspection process contains redundant and time-consuming tasks; and NRC staff members did not always accurately report their time spent on cybersecurity inspection-related activities.  The OIG makes 9 recommendations to enhance the effectiveness, consistency, and efficiency of the NRC’s cybersecurity inspection program. 
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The OIG recommends that the Executive Director for Operations develop and issue supplemental guidance clarifying the expected implementation of cybersecurity controls, the interpretation of requirements, and methods for evaluating control effectiveness.

Agency Response Dated July 10, 2026: The staff partially agrees with the recommendation. The cybersecurity requirements in 10 CFR 73.54 provide a performance-based approach, implemented through the approval of each licensee&#039;s cybersecurity plan (CSP). The staff has not established specific criteria for the implementation of the technical and administrative controls identified in the CSPs in order to provide industry with flexibility in program implementation.<br />
The staff has completed three cycles of inspection at each licensee site and makes every effort to be consistent in the oversight of licensees’ cybersecurity plan implementation through the Cybersecurity Issues Forum (Cyber SIF), use of<br />
subject matter expert (SME) contractors, and sharing lessons learned. The staff also updated RG 5.71 in 2023 based on the lessons learned from previous inspection cycles. Staff and industry do not believe that further updates to RG 5.71 or revisions to NEI 08-09 are needed to address this recommendation. However, recent updates to the NRC’s issue screening guidance are expected to enhance consistency. Specifically, in the 2026 update to the cybersecurity significance determination process (SDP), the staff included specific cybersecurity questions in Inspection Manual Chapter (IMC) 0609 Appendix E, Part 4 to improve the minor versus more-than-minor determination process. The new Reactor Oversight Process (ROP) cybersecurity triennial inspection cycle started in 2026. The staff will evaluate inspection consistency based on the first eighteen months of inspections and, if necessary, recommend appropriate changes to the cybersecurity SDP. Target date for completion: September 30, 2027<br />
OIG Analysis: The OIG acknowledges that the intent of RG 5.71 and NEI-08-09 is to provide licensees with flexibility in<br />
implementing their programs, and that recent updates to the issue screening guidance were made to enhance consistency. The OIG reviewed the updated cybersecurity SDP guidance. The OIG will close the recommendation after verifying the agency has evaluated its inspection consistency for the first triennial inspection cycle and made appropriate changes to the cybersecurity SDP based on that evaluation. This recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations update Inspection Procedure 71130.10 to clarify the Cyber Security Issues Forum process and its potential impacts on findings and violations.

Agency Response Dated July 10, 2026: The staff partially agrees with the recommendation. The staff does not believe that the cybersecurity inspection procedure is the appropriate place for guidance on the Cyber SIF process. The Cyber SIF is an NRC internal process that is part of the staff&#039;s evaluation of potential inspection findings. As with other inspections, the deliberative activities conducted between the inspection exit and the final inspection report are internal NRC processes and are not part of the formal inspection procedure. The Cyber SIF provides feedback to the regional inspection team as part of these internal deliberations, but does not make the final adjudication of the finding(s). It is up to the inspection team and their branch chief to adjudicate and communicate the finding to the licensee. The conduct of the Cyber SIF is guided by the Cyber SIF Charter. The staff will review the charter and update guidance to ensure that it is the process for review of potential findings and the resulting decisions is clearly documented.<br />
Target date for completion: End of fiscal year (FY) 2026<br />
OIG Analysis: The OIG acknowledges that the Cyber SIF process is contained in the Cyber SIF Charter and is not part of the formal inspection procedure. The OIG will close the recommendation once it verifies that the Cyber SIF Charter<br />
has been updated to ensure that the process for reviewing potential findings and the resulting decisions is clearly<br />
documented. This recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations update Inspection Manual Chapter 1245, Appendix D-1, to include periodic refresher training requirements for cybersecurity-qualified inspectors.

Agency Response Dated July 10, 2026: The staff agrees with the recommendation. The staff will evaluate the Cybersecurity Inspector section in IMC 1245 Appendix D-1 and update the periodic refresher training requirements.<br />
Attending the Cybersecurity Inspector Counterpart meeting is already a refresher training requirement. In the future,<br />
the staff will record the Cybersecurity Inspector Counterpart meeting. If a cybersecurity inspector is unable to attend the<br />
Cybersecurity Inspector Counterpart meeting, they may fulfill that requirement by watching the select sessions recorded from the meeting. The bullet for the Cybersecurity Inspector Counterpart meeting in IMC 1245 Appendix D-1 will be clarified to state that attendance at or viewing of the meeting is a requirement.<br />
Target date for completion: End of Calendar Year 2026<br />
OIG Analysis: The OIG will close the recommendation when it verifies that IMC 1245, Appendix D-1, has been updated to clarify that attendance at or viewing of the Cybersecurity Inspector Counterpart meeting is a requirement. This<br />
recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations define a schedule for contractor-led training (in-person or virtual), and ensure sessions are recorded and accessible.

Agency Response Dated July 10, 2026: The staff partially agrees with the recommendation. The contractors are normally scheduled to provide training as part of the Cybersecurity Inspector Counterpart meeting. Unfortunately, the 2025 counterpart meeting was cancelled due to the agency furlough. All contractor training sessions are recorded and available on the branch’s knowledge management SharePoint site. It is possible that additional training could be organized, but contract budget cuts for FY 2027 and FY 2028 for the subject matter expert (SME) contractors will restrict their ability to<br />
develop and conduct additional training. The contractors assisted in development and delivery of the S-504 course, “Advanced Cyber Security Inspection Training for Inspectors,” and some modules of the 2026 S-504 course were recorded. The Physical and Cyber Security Licensing Branch, which was Cybersecurity Branch prior to June 15, 2026, will add the recordings of these sessions and the other modules after they are recorded in addition to other training going forward to the NRC’s Talent Management System.<br />
Target date for completion: End of FY 2026<br />
OIG Analysis: The OIG acknowledges that contract budget cuts may restrict the SME contractors’ ability to develop and conduct additional training, and that the agency has alternative methods for training. The OIG will close the<br />
recommendation when it verifies that recordings of training sessions have been added to the NRC’s Talent Management<br />
Systems. This recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations revise the request for information guidance to require inspectors to identify the most current cybersecurity program documents already in the NRC’s possession before issuing the initial request, and to clearly communicate target dates for both issuing requests and receiving licensee responses.

Agency Response Dated July 10, 2026: The staff partially agrees with the recommendation. In accordance with IMC 0620, Inspection Documents and Records, inspectors should not request information that is already in the NRC’s possession (this includes verification that none of the requested information is in the Agency-wide Document Access and Management System (ADAMS)) and should minimize the burden on licensees during the request for information (RFI) process. Additionally, it is standard operating procedure for inspectors to delete or dispose of any licensee material<br />
collected during the course of an inspection once the inspection report has been issued. As a result, the staff would not have any material in their possession with the exception of the licensee’s cybersecurity plan when preparing the RFI. In conjunction with the March 2026 revision to IP 71130.10 (Cybersecurity Inspection), the staff revised the RFI<br />
guidance to streamline the process. The revision reduced the first round RFI to a smaller set of information and moved<br />
more detailed requests to the second RFI after the inspection team has selected the system and critical digital asset (CDA) samples for the inspection. The cybersecurity inspectors were trained on the new RFI on February 19, 2026. Based<br />
on feedback from the training, the staff finalized the modified RFI on February 24, 2026. The revision incorporated clear target dates for both issuing requests and receiving licensee responses. Therefore, the staff considers Recommendation 3.1 to be complete.<br />
OIG Analysis: The OIG reviewed the revised RFI guidance and determined that it includes guidance for inspectors to reduce the amount of information requested during the process and reduce the overall burden on licensees. This recommendation is now closed.