US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants
US Nuclear Regulatory Commission (NRC) regulation 10 CFR 73.54 establishes requirements for nuclear power plant licensees to protect digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions from cyber attacks. Implemented through NEI 08-09 (Cyber Security Plan for Nuclear Power Reactors), endorsed by NRC Regulatory Guide 5.71. Requires a cyber security programme, assessment of digital assets, defensive architecture, and ongoing monitoring. All US operating nuclear power plants must have NRC-approved cyber security plans.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Assessment and Response
Assessment, monitoring, and incident response
Asset Identification and Security Controls
| Code | Title |
|---|---|
| 73.54(b)(1) | Critical Digital Asset Identification |
| 73.54(b)(2) | Asset Categorisation |
| 73.54(c)(1) | Security Controls Implementation |
| 73.54(c)(2) | Defence-in-Depth Strategies |
Cyber Security Plan
| Code | Title |
|---|---|
| 73.54(e) | Cyber Security Plan Requirement |
| 73.54(e)(2) | Site-Specific Conditions |
| 73.54(e)(3) | Plan Documentation |
| 73.54(f) | Plan Review and Update |
Cyber Security Program Design
| Code | Title |
|---|---|
| 73.54(c)(3) | Attack Mitigation |
| 73.54(c)(4) | Functional Protection Assurance |
| 73.54(d) | Insider Threat Considerations |
| 73.54(e)(1) | Ongoing Assessment and Management |
Scope and High Assurance
| Code | Title |
|---|---|
| 73.54(a) | High Assurance Standard |
| 73.54(a)(1) | Systems in Scope |
| 73.54(a)(2) | Attack Types to Protect Against |
| 73.54(a)(3) | Support Systems Protection |
Training and Incident Response
| Code | Title |
|---|---|
| RG5.71-C.3 | Cyber Security Training |
| RG5.71-C.4 | Incident Response Plan |
| RG5.71-C.5 | Recovery and Restoration |
| RG5.71-C.6 | Configuration Management |
| RG5.71-C.7 | Continuous Monitoring |
Maps to 561 other frameworks
Frequently Asked Questions
What is US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants?
US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants is a compliance framework from United States (NRC) with 6 domains and 21 controls. US Nuclear Regulatory Commission (NRC) regulation 10 CFR 73.54 establishes requirements for nuclear power plant licensees to protect digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions from cyber attacks. Implemented through NEI 08-09 (Cyber Security Plan for Nuclear Power Reactors), endorsed by NRC Regulatory Guide 5.71. Requires a cyber security programme, assessment of digital assets, defensive architecture, and ongoing monitoring. All US operating nuclear power plants must have NRC-approved cyber security plans. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants have?
US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants has 21 controls organised across 6 domains. The largest domains are Training and Incident Response (5 controls), Asset Identification and Security Controls (4 controls), Cyber Security Plan (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants map to?
US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants maps to 561 other compliance frameworks. The top mapping partners are ISO/IEC 27400:2022 (29% coverage), IAEA Nuclear Security Series — Computer Security at Nuclear Facilities (NSS-17-T Rev 1) (29% coverage), NIST Cybersecurity Framework 2.0 (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants compliance?
Start your US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 21 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required