NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
Title 10 Code of Federal Regulations Part 73.54, 'Cyber Security Requirements for Nuclear Power Reactors,' establishes cybersecurity requirements for nuclear power reactors. It requires licensees to provide high assurance that digital computer, communication systems, and networks associated with safety, security, and emergency preparedness functions are protected against cyber threats, that they maintain the confidentiality, integrity, and availability of safety‑related digital assets, and that they implement a comprehensive cyber security program consistent with NRC guidance.
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity is a compliance framework from United States with 14 domains and 33 controls that map to 163 other frameworks. The largest domains are 10 CFR 73.54 Programme Requirements (6 controls), Regulatory Guide 5.71 Appendix C Security Controls (5 controls), Technical Controls for Critical Digital Assets (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
10 CFR 73.54 Programme Requirements
10 CFR 73.54 Programme Requirements
| Code | Title |
|---|---|
| NRC-73.54(a) | Cyber Security Program Scope |
| NRC-73.54(c) | Cyber Security Plan |
| NRC-73.54(d)(1) | Senior Responsible Officer Accountability |
| NRC-73.54(d)(2) | Cyber Security Roles and Responsibilities |
| NRC-73.54(d)(3) | Training, Awareness, and Qualification |
| NRC-73.54(h) | Cyber Security Program Review |
Access Control + Media + Devices
| Code | Title |
|---|---|
| NRC7354-5 | Access Control, Authentication, Removable Media, and Portable Devices |
Attack Mitigation and Monitoring
Attack Mitigation and Monitoring
| Code | Title |
|---|---|
| NRC-73.54(e)(1) | Attack Mitigation Capability |
| NRC-73.54(e)(2) | Mitigation of Adverse Impact |
| NRC-73.54(g) | Ongoing Monitoring and Assessment |
Critical Digital Asset Identification
| Code | Title |
|---|---|
| NRC7354-2 | Critical Digital Asset (CDA) Identification, Scope, and Boundary |
Critical Digital Assets and Defensive Architecture
Critical Digital Assets and Defensive Architecture
| Code | Title |
|---|---|
| NRC-73.54(b)(1) | Critical Digital Asset Identification |
| NRC-73.54(b)(2) | Defensive Architecture |
| NRC-73.54(b)(3) | Application of Security Controls to CDAs |
| NRC-73.54(f) | Defense in Depth |
Cybersecurity Plan and Programme
| Code | Title |
|---|---|
| NRC7354-1 | Cybersecurity Plan, Programme Establishment, and NRC Submission |
Defensive Architecture
| Code | Title |
|---|---|
| NRC7354-3 | Defensive Architecture, Multi-Layer Defense, and Network Segregation |
Incident Reporting and Records
Incident Reporting and Records
| Code | Title |
|---|---|
| NRC-Incident-Reporting | Cyber Incident Reporting to NRC |
| NRC-Records | Records of Cyber Security Program |
Monitoring, IR, Reporting, Contingency
| Code | Title |
|---|---|
| NRC7354-7 | Monitoring, Assessment, Incident Response, Reporting, and Contingency |
Programme Oversight and Records
| Code | Title |
|---|---|
| NRC7354-8 | Programme Oversight, Independent Review, Documentation, Training, Supply Chain |
Regulatory Guide 5.71 Appendix C Security Controls
Regulatory Guide 5.71 Appendix C Security Controls
| Code | Title |
|---|---|
| RG5.71-C.3 | Cyber Security Training |
| RG5.71-C.4 | Incident Response Plan |
| RG5.71-C.5 | Recovery and Restoration |
| RG5.71-C.6 | Configuration Management |
| RG5.71-C.7 | Continuous Monitoring |
Security Controls Implementation
| Code | Title |
|---|---|
| NRC7354-4 | Security Controls Implementation per NRC RG 5.71 Appendix B/C |
Technical Controls for Critical Digital Assets
Technical Controls for Critical Digital Assets
| Code | Title |
|---|---|
| NRC-Access-Control | Access Control to CDAs |
| NRC-Audit-Logging | Audit and Accountability |
| NRC-Configuration-Management | Configuration Management of CDAs |
| NRC-Portable-Media | Portable Media and Mobile Devices |
| NRC-Supply-Chain | Supply Chain Protection |
Vulnerability and Configuration Management
| Code | Title |
|---|---|
| NRC7354-6 | Vulnerability Management, Configuration Management, Baseline Control, and Patching |
Your Compliance Coverage
If you comply with NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity, you already cover:
Singapore Government Instruction Manual on ICT&SS Management (IM8)
21%
7 controls mapped
Compare →ISO 27018
21%
7 controls mapped
Compare →NIST Cybersecurity Framework 2.0
21%
7 controls mapped
Compare →+ 160 more: NIST SP 800-190 (21%), ISO 28001:2007 Supply Chain Security Management (21%)
See all 163 mapped frameworks ↓Maps to 163 other frameworks
What is NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity and who does it apply to?
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity is a compliance framework from United States with 14 domains and 33 controls. Title 10 Code of Federal Regulations Part 73.54, 'Cyber Security Requirements for Nuclear Power Reactors,' establishes cybersecurity requirements for nuclear power reactors. It requires licensees to provide high assurance that digital computer, communication systems, and networks associated with safety, security, and emergency preparedness functions are protected against cyber threats, that they maintain the confidentiality, integrity, and availability of safety‑related digital assets, and that they implement a comprehensive cyber security program consistent with NRC guidance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity actually require?
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity has 33 controls organised across 14 domains. The largest domains are 10 CFR 73.54 Programme Requirements (6 controls), Regulatory Guide 5.71 Appendix C Security Controls (5 controls), Technical Controls for Critical Digital Assets (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity do I already cover?
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity maps to 163 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (21% coverage), ISO 27018 (21% coverage), NIST Cybersecurity Framework 2.0 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity?
Start your NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required