NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity
Title 10 Code of Federal Regulations Section 73.54 establishes cybersecurity requirements for nuclear power reactors. It requires licensees to provide high assurance that digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions are protected against cyber attacks. Administered by the US Nuclear Regulatory Commission (NRC).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Access
| Code | Title |
|---|---|
| NRC.IAM-1 | Access Control and Authentication |
Architecture
| Code | Title |
|---|---|
| NRC.DEF-1 | Defensive Architecture |
Configuration
| Code | Title |
|---|---|
| NRC.BASE-1 | Baseline Configurations and Change Control |
Contingency
| Code | Title |
|---|---|
| NRC.CONT-1 | Contingency and Recovery |
Controls
| Code | Title |
|---|---|
| NRC.MIT-1 | Application of Security Controls and Mitigation |
Cybersecurity Program
Program establishment, scope, and defensive architecture
| Code | Title |
|---|---|
| NRC73-PROG-01 | Cybersecurity Plan |
| NRC73-PROG-02 | Scope — Critical Digital Assets |
| NRC73-PROG-03 | Defensive Architecture |
| NRC73-PROG-04 | Cybersecurity Assessment |
Incident Response
| Code | Title |
|---|---|
| NRC.IR-1 | Incident Response and Reporting |
Media
| Code | Title |
|---|---|
| NRC.NTW-1 | Removable Media and Portable Device Controls |
Monitoring
| Code | Title |
|---|---|
| NRC.MON-1 | Monitoring and Assessment |
Oversight
| Code | Title |
|---|---|
| NRC.OVER-1 | Program Oversight and Independent Review |
Physical
| Code | Title |
|---|---|
| NRC.PHY-1 | Physical Protection of Critical Digital Assets |
Plan
| Code | Title |
|---|---|
| NRC.CSP-2 | Cyber Security Plan |
Program
| Code | Title |
|---|---|
| NRC.CSP-1 | Cyber Security Program Establishment |
Records
| Code | Title |
|---|---|
| NRC.DOC-1 | Documentation and Records |
Scope
| Code | Title |
|---|---|
| NRC.SCOPE-1 | Scope of Critical Digital Assets |
Security Controls
Information protection and breach management
| Code | Title |
|---|---|
| CA-ITSG33-SC-01 | Security Control Catalogue |
| CA-ITSG33-SC-02 | Security Profiles |
| CA-ITSG33-SC-03 | Cloud Security |
| KR-CSAP-SC-01 | Information Security Management |
| KR-CSAP-SC-02 | Infrastructure and Network Security |
| KR-CSAP-SC-03 | Virtual Environment Security |
| MARSE-SC-01 | NIST 800-53 Moderate Baseline |
| MARSE-SC-02 | Federal Tax Information Protection |
| MARSE-SC-03 | Identity Verification |
| NRC73-CTL-01 | Access Control for CDAs |
| NRC73-CTL-02 | Network Isolation and Segmentation |
| NRC73-CTL-03 | Configuration Management |
| NRC73-CTL-04 | Monitoring and Incident Response |
| NRC73-CTL-05 | Supply Chain Security for CDAs |
| NRC73-CTL-06 | Training and Awareness |
| NZ-NZISM-SC-01 | Governance and Risk Management |
| NZ-NZISM-SC-02 | ICT Security Controls |
| NZ-NZISM-SC-03 | Cryptography and Cloud |
| PAS1192-5-SC-01 | Technical Controls |
| PAS1192-5-SC-02 | Personnel Security |
| PAS1192-5-SC-03 | Breach Management |
Supply Chain
| Code | Title |
|---|---|
| NRC.SUPPLY-1 | Supply Chain Protection |
Threat
| Code | Title |
|---|---|
| NRC.ATK-1 | Attack Vector Analysis |
Training
| Code | Title |
|---|---|
| NRC.TRAIN-1 | Training and Awareness |
Vulnerability
| Code | Title |
|---|---|
| NRC.VULN-1 | Vulnerability Management |
Your Compliance Coverage
If you comply with NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity, you already cover:
FAA Cybersecurity Framework for Aviation
40%
17 controls mapped
Compare →FedRAMP Rev 5
40%
17 controls mapped
Compare →South Korea ISMS-P
40%
17 controls mapped
Compare →+ 663 more: TISAX — Trusted Information Security Assessment Exchange (40%), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (37%)
See all 666 mapped frameworks ↓Maps to 666 other frameworks
Frequently Asked Questions
What is NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity?
NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity is a compliance framework from United States with 20 domains and 43 controls. Title 10 Code of Federal Regulations Section 73.54 establishes cybersecurity requirements for nuclear power reactors. It requires licensees to provide high assurance that digital computer and communication systems and networks associated with safety, security, and emergency preparedness functions are protected against cyber attacks. Administered by the US Nuclear Regulatory Commission (NRC). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity have?
NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity has 43 controls organised across 20 domains. The largest domains are Security Controls (21 controls), Cybersecurity Program (4 controls), Access (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity map to?
NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity maps to 666 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (40% coverage), FedRAMP Rev 5 (40% coverage), South Korea ISMS-P (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity compliance?
Start your NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NRC 10 CFR 73.54 — Nuclear Facility Cybersecurity requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required