Audit of the U.S. Nuclear Regulatory Commission’s (NRC) Cybersecurity Inspection Program for Operating Nuclear Power Plants
Report Information
Recommendations
The OIG recommends that the Executive Director for Operations develop and issue supplemental guidance clarifying the expected implementation of cybersecurity controls, the interpretation of requirements, and methods for evaluating control effectiveness.
The staff has completed three cycles of inspection at each licensee site and makes every effort to be consistent in the oversight of licensees’ cybersecurity plan implementation through the Cybersecurity Issues Forum (Cyber SIF), use of<br />
subject matter expert (SME) contractors, and sharing lessons learned. The staff also updated RG 5.71 in 2023 based on the lessons learned from previous inspection cycles. Staff and industry do not believe that further updates to RG 5.71 or revisions to NEI 08-09 are needed to address this recommendation. However, recent updates to the NRC’s issue screening guidance are expected to enhance consistency. Specifically, in the 2026 update to the cybersecurity significance determination process (SDP), the staff included specific cybersecurity questions in Inspection Manual Chapter (IMC) 0609 Appendix E, Part 4 to improve the minor versus more-than-minor determination process. The new Reactor Oversight Process (ROP) cybersecurity triennial inspection cycle started in 2026. The staff will evaluate inspection consistency based on the first eighteen months of inspections and, if necessary, recommend appropriate changes to the cybersecurity SDP. Target date for completion: September 30, 2027<br />
OIG Analysis: The OIG acknowledges that the intent of RG 5.71 and NEI-08-09 is to provide licensees with flexibility in<br />
implementing their programs, and that recent updates to the issue screening guidance were made to enhance consistency. The OIG reviewed the updated cybersecurity SDP guidance. The OIG will close the recommendation after verifying the agency has evaluated its inspection consistency for the first triennial inspection cycle and made appropriate changes to the cybersecurity SDP based on that evaluation. This recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations update Inspection Procedure 71130.10 to clarify the Cyber Security Issues Forum process and its potential impacts on findings and violations.
Target date for completion: End of fiscal year (FY) 2026<br />
OIG Analysis: The OIG acknowledges that the Cyber SIF process is contained in the Cyber SIF Charter and is not part of the formal inspection procedure. The OIG will close the recommendation once it verifies that the Cyber SIF Charter<br />
has been updated to ensure that the process for reviewing potential findings and the resulting decisions is clearly<br />
documented. This recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations update Inspection Manual Chapter 1245, Appendix D-1, to include periodic refresher training requirements for cybersecurity-qualified inspectors.
Attending the Cybersecurity Inspector Counterpart meeting is already a refresher training requirement. In the future,<br />
the staff will record the Cybersecurity Inspector Counterpart meeting. If a cybersecurity inspector is unable to attend the<br />
Cybersecurity Inspector Counterpart meeting, they may fulfill that requirement by watching the select sessions recorded from the meeting. The bullet for the Cybersecurity Inspector Counterpart meeting in IMC 1245 Appendix D-1 will be clarified to state that attendance at or viewing of the meeting is a requirement.<br />
Target date for completion: End of Calendar Year 2026<br />
OIG Analysis: The OIG will close the recommendation when it verifies that IMC 1245, Appendix D-1, has been updated to clarify that attendance at or viewing of the Cybersecurity Inspector Counterpart meeting is a requirement. This<br />
recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations define a schedule for contractor-led training (in-person or virtual), and ensure sessions are recorded and accessible.
develop and conduct additional training. The contractors assisted in development and delivery of the S-504 course, “Advanced Cyber Security Inspection Training for Inspectors,” and some modules of the 2026 S-504 course were recorded. The Physical and Cyber Security Licensing Branch, which was Cybersecurity Branch prior to June 15, 2026, will add the recordings of these sessions and the other modules after they are recorded in addition to other training going forward to the NRC’s Talent Management System.<br />
Target date for completion: End of FY 2026<br />
OIG Analysis: The OIG acknowledges that contract budget cuts may restrict the SME contractors’ ability to develop and conduct additional training, and that the agency has alternative methods for training. The OIG will close the<br />
recommendation when it verifies that recordings of training sessions have been added to the NRC’s Talent Management<br />
Systems. This recommendation remains open and resolved.
The OIG recommends that the Executive Director for Operations revise the request for information guidance to require inspectors to identify the most current cybersecurity program documents already in the NRC’s possession before issuing the initial request, and to clearly communicate target dates for both issuing requests and receiving licensee responses.
collected during the course of an inspection once the inspection report has been issued. As a result, the staff would not have any material in their possession with the exception of the licensee’s cybersecurity plan when preparing the RFI. In conjunction with the March 2026 revision to IP 71130.10 (Cybersecurity Inspection), the staff revised the RFI<br />
guidance to streamline the process. The revision reduced the first round RFI to a smaller set of information and moved<br />
more detailed requests to the second RFI after the inspection team has selected the system and critical digital asset (CDA) samples for the inspection. The cybersecurity inspectors were trained on the new RFI on February 19, 2026. Based<br />
on feedback from the training, the staff finalized the modified RFI on February 24, 2026. The revision incorporated clear target dates for both issuing requests and receiving licensee responses. Therefore, the staff considers Recommendation 3.1 to be complete.<br />
OIG Analysis: The OIG reviewed the revised RFI guidance and determined that it includes guidance for inspectors to reduce the amount of information requested during the process and reduce the overall burden on licensees. This recommendation is now closed.