Sorry, you need to enable JavaScript to visit this website.
U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Audit of the U.S. Nuclear Regulatory Commission’s (NRC) Cybersecurity Inspection Program for Operating Nuclear Power Plants

Report Information

Date Issued
Report Number
OIG-NRC-26-A-03
Report Type
Audit
Description
The OIG determined that the current cybersecurity program guidance lacks clarity; expectations for maintaining training qualifications are not well-defined; the cybersecurity inspection process contains redundant and time-consuming tasks; and NRC staff members did not always accurately report their time spent on cybersecurity inspection-related activities.  The OIG makes 9 recommendations to enhance the effectiveness, consistency, and efficiency of the NRC’s cybersecurity inspection program. 
Joint Report
No
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

The OIG recommends that the Executive Director for Operations train staff on the correct Cost Activity Codes for reporting fee-billable and non-billable cybersecurity inspection activities within the Human Capital Management Cloud System.

Agency Response Dated July 10, 2026: The staff agrees with the recommendation. The regional branch chiefs responsible for the cybersecurity inspection have established the proper Cost Activity Code (CAC) &amp; Enterprise Project Identifier (EPID) combinations to be used for cybersecurity inspections. All inspectors have been trained on their use.<br />
Therefore, the staff considers Recommendation 4.1 to be complete.<br />
Target date for completion: Completed June 11, 2026<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This<br />
recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations finalize the Cyber Security Issues Forum Draft Charter to include the Cost Activity Codes used by staff members when participating in or observing meetings.

Agency Response Dated July 10, 2026: The staff partially agrees with the recommendation. The CAC-EPID combinations used by staff for inspection-related activities are the responsibility of their first-line supervisors. The Cyber SIF Charter is not an appropriate place for identification of CACs for use in support of the meetings. All inspectors have been trained on the appropriate CACs to use for future Cyber SIF meetings. Therefore, the staff considers Recommendation 4.2 to be<br />
complete.<br />
Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG acknowledges that the Cyber SIF Charter is not an appropriate place to identify CACs for use in support of meetings. The OIG will close this recommendation after the agency provides documentation confirming that the cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations develop clear guidance on the appropriate use of security oversight Cost Activity Codes.

Agency Response Dated July 10, 2026: The staff agrees with the recommendation. The regional branch chiefs responsible for the cybersecurity inspection have established the proper CAC-EPID combinations to be used for cybersecurity inspections. All inspectors have been trained on their use. Therefore, the staff considers Recommendation 4.3 to be<br />
complete. Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that cybersecurity inspectors were trained on the proper CAC and EPID combinations to be used for cybersecurity inspections. This<br />
recommendation remains open and resolved.

The OIG recommends that the Executive Director for Operations develop and implement Enterprise Project Identifier codes for inspection oversight activities to improve tracking of safety and security related oversight activities.

Agency Response Dated July 10, 2026: The staff agrees with the recommendation. The regional branch chiefs responsible for the cybersecurity inspection have established the proper CAC-EPID combinations to be used for cybersecurity oversight activities. All inspectors have been trained on their use. Therefore, the staff considers Recommendation 4.4 to be<br />
complete. Target date for completion: Completed June 11, 2026.<br />
OIG Analysis: The OIG will close this recommendation after the agency provides documentation confirming that the proper CACEPID combinations were established for cybersecurity inspection oversight activities. This recommendation<br />
remains open and resolved.