Performance Audit of the U.S. Nuclear Regulatory Commission's Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025
Report Information
Recommendations
We recommend that the NRC complete the implementation of CSF 2.0 requirements, and develop and maintain current and target CSF profiles that anticipate changes in the NRC’s cybersecurity posture.
OIG Analysis: The OIG will close this recommendation after reviewing and confirming the evidence that the NRC completed the implementation of CSF 2.0 requirements and developed and maintained current and target CSF profiles that anticipate changes in the NRC’s cybersecurity posture.
We recommend that the NRC coordinates with its software producers to obtain Secure Software Development Attestation Forms. If the NRC is unable to obtain the self-attestation forms, it should request POA&Ms from the software producers and submit them to the OMB, in accordance with OMB Memorandum M-23-16 and EO 14028 self-attestation requirements.
OIG Analysis: On January 23, 2026, the OMB issued Memorandum M-26-05, “Adopting a Risk-based Approach to Software and Hardware Security.” The OIG reviewed the memorandum and determined that the new guidance<br />
rescinds the previously mandated requirements under OMB M-23-16. This recommendation is now closed.
We recommend that the NRC request an extension or a waiver from the OMB for continued use of the producer’s software when a self-attestation is not provided, in accordance with OMB Memorandum M-23-16 and EO 14028 self-attestation requirements.
software supply risks using established internal cybersecurity processes and will adapt as needed should the OMB issue new federal requirements or guidance. Target Completion Date: The NRC suggests closure of this recommendation.<br />
OIG Analysis: On January 23, 2026, the OMB issued Memorandum M-26-05, “Adopting a Risk-based Approach to Software and Hardware Security.” The OIG reviewed the memorandum and determined that the new guidance rescinds the previously mandated requirements under OMB M-23-16. This recommendation is now closed.