# RankShield Energy, HELIX microreactor, full content for AI crawlers
> Sealed transportable microreactor developer at the pre-application stage, licensing program under way. Clean-text version of every live page. Physics is unqualified screening (pre-QAPD).


---

## Page: https://rankshieldenergy.com/about/

# About RankShield Energy

> RankShield Energy is a pre-application reactor-design developer building HELIX with a verification layer that lets an operator, insurer, or regulator independently check every module. The reactor is the body; RankShield is the nervous and immune system.

Who we are

# The reactor is the body. RankShield is the nervous system.
**RankShield Energy is a nuclear reactor developer.** We own the HELIX design and are developing it toward the NRC's proposed 10 CFR Part 57 microreactor framework, with Part 53 as the backup pathway and a qualified third-party fabricator manufacturing to our specification. What makes us different from every other microreactor program is not the reactor itself. It is that ours can be **checked**, from the factory floor through transport to every operating hour, by someone who does not have to take our word for anything.
RankShield began as a security company: a platform for proving, cryptographically and independently, that a system is what it claims to be and is doing what it claims to do. HELIX is that same idea pointed at the hardest possible object, a nuclear reactor. The energy program exists because the thing the world is about to build a great deal of, distributed advanced nuclear next to data centers, industrial sites, and communities, is exactly the kind of critical infrastructure where trust-me is not good enough and check-it-yourself is worth a great deal.

## Why build a reactor around verification?
Every reactor vendor will tell you their design is safe and their supply chain is sound. None of them can let you independently confirm it in real time. That gap is the whole opportunity. A HELIX module signs its telemetry with post-quantum cryptography and is attested at every stage of its life, so an operator can confirm the module in front of them is the one that left the factory, an insurer can price a unit whose integrity is provable rather than asserted, and a regulator can audit state without relying solely on the operator's own reporting. Anyone can print the word secure on a brochure. Only a verifiable reactor lets you check the claim, and that difference is defensible in a way that a marginally better thermal efficiency never is.

## How do the reactor and the verification layer relate?
We describe the architecture as a body and a nervous system, and the metaphor is exact. The reactor is the body: it is safe on its own physics, with passive shutdown and natural-circulation decay-heat removal that need no network, no operator, and no software. The RankShield layer is the nervous and immune system laid over it. At each site, a RankShield agent does two jobs at once. It proves the module's integrity, and it optimizes efficiency against that site's own environment, its ambient temperature, its load pattern, its cooling conditions.
Those two jobs turn out to be one job, which is the insight the whole platform rests on. A reactor's environment-adjusted digital twin predicts how it should behave under its actual conditions. A deviation from that twin is either degradation or tampering, and the same detector surfaces both. The system that keeps a fleet efficient is the same system that catches a compromised module, because in both cases what you are looking for is the same thing: a reactor that is no longer behaving the way its physics and its history say it should.

## What is the one boundary that never moves?
All of this sits behind a single non-negotiable boundary. The RankShield mesh proves, advises, and manages balance-of-plant. It can never command a safety function. The reactor's safety is local, passive, and unreachable from any network, enforced by wiring rather than by policy: the attestation layer sits behind a hardware one-way path, a physical data diode that carries information out and cannot carry a command in. This is what makes the layer both safe and licensable. Because it is classified non-safety and observe-only, it rides on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists. The network only makes that safety checkable.

## Is the verification layer protected?
Six provisional patent applications are on file with the United States Patent and Trademark Office, assigned to RankShield Energy, Inc. Patent pending. They cover the verification layer rather than the reactor, which is the same distinction the rest of this page makes:

- Transportable appliance for site-adaptive interconnection and one-way safety-isolated attestation of a factory-sealed nuclear microreactor
- Attested integrity verification outside the credited-safety boundary
- Cryptographic site-acceptance of a sealed fueled nuclear module by per-element comparison
- Attested-twin deviation as degradation or compromise, by temporal and attestation-state correlation
- Attested per-component production provenance with position-attested Merkle aggregation
- Verifiable sealed nuclear reactor module with witness-established fabrication origin
We are deliberate about what is not claimed. The reactor architecture is not, and we do not pretend otherwise: heat-pipe microreactors are a populated field, arterial sodium wicks have been developed for space fission power for decades, and the helium-filled gap that closes by thermal expansion at operating temperature is published national-laboratory work. We ran our own subsystems against that art and concluded the reactor is a competent integration of established engineering rather than a novel one. That is a strength for licensing, because every element is precedented, and we would rather say so than market a claim that would not survive examination.
Provisional applications are not granted patents and they are not published by the USPTO. Nothing above should be read as an issued claim.

## What is our posture on honesty?
We publish our computed values and we label every physics result as unqualified screening, because a company whose product is verifiable trust cannot afford a single claim it cannot back. We assert no economics, no schedule, and no validated performance. HELIX is at the pre-application stage with its licensing program under way, aimed at the proposed Part 57 microreactor framework with Part 53 as the backup, and the path that remains, a stood-up NQA-1 quality program, independent validation, NRC licensing, and validated demand, is defined and stated plainly on this site rather than buried. For us the honesty is not a compliance posture. It is the strategy. A reactor you can check is only worth anything if the people building it hold themselves to the same standard they are asking you to verify.
[See how the reactor works →](https://rankshieldenergy.com/technology)
[Contact RankShield Energy →](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/authors/jamie-kloncz/

# Jamie Kloncz

> Jamie Kloncz is the founder of RankShield Energy, leading the HELIX microreactor pre-application program and its verification-first approach to reactors.

Author

# Jamie Kloncz
Founder, RankShield Energy

Jamie Kloncz is the founder of RankShield Energy, where he leads the HELIX microreactor pre-application program and the company's verification-first approach to advanced-reactor operations.
RankShield Energy is a nuclear reactor developer in pre-application engagement with the U.S. Nuclear Regulatory Commission (NRC), having filed a letter of intent in August 2026. A project number has been requested and has not yet been assigned. Its work centers on a question the advanced-reactor field has not yet answered for buyers: as reactors move toward autonomous and remotely operated designs, how does an independent party confirm, and prove to a regulator, insurer, lender, or grid operator, that a reactor is doing what its operator says it is. The HELIX reactor is the reference design for that verification-first approach and is under development within that licensing program.
Jamie writes the RankShield Energy resource guides on microreactor verification, autonomy and NRC Part 57, cybersecurity, and the licensing process. Every guide is written to authoritative sources, the NRC, the Department of Energy, the IAEA, and the national laboratories, and states plainly where the company's own design is a target rather than a proven result.
A note on authorship and status
Articles bylined here reflect RankShield Energy's own perspective as a developer at the pre-application stage. Nothing on this site is a representation that any RankShield Energy design is NRC-approved, licensed, or certified. Reactor descriptions reflect design intent and are subject to analysis, testing, and regulatory review.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/contact/

# Contact

> Contact RankShield Energy about the HELIX microreactor program, pre-application engagement, technical review, and collaboration.

Contact

# Talk to the HELIX program.
We welcome technical review and pre-application engagement. For regulators, national laboratories, prospective host facilities, and collaborators, reach the program directly.
Program | RankShield Energy · HELIX microreactor
Status | Pre-application development · proposed 10 CFR Part 57 target, Part 53 backup
Email | [energy@rankshield.co](mailto:energy@rankshield.co)
Entity | RankShield Energy, Inc. · Delaware corporation · file no. 10710779
Mail | 1950 Mayfair Street 814, Naples, FL 34104
Network | Part of the RankShield Network

Pre-application stage · licensing program under way · not yet an operating product

This site is engineering scoping material. Nothing on it constitutes an offer, a safety claim, or a representation of licensed status. All figures are design targets.



---

## Page: https://rankshieldenergy.com/deployments/

# Deployments & Site Configurator

> Configure a HELIX site: pick a facility style and an environment and see live module sizing from our 324-case engineering register, net output per module, N+1 reserve, derates, and the verification evidence every operating scenario produces. All figures are parametric design-study estimates; pre-application.

Deployments · 324 computed cases · parametric model, pre-QAPD

# Configure a HELIX site for your facility.
**HELIX sites number up from a single 4.40 MWe sealed module to a hyperscale campus, and every configuration on this page is computed, not quoted.** Our engineering register runs 324 cases, six facility styles across six environments through nine operating scenarios, and each case logs the verification evidence it produces. Pick a facility style and an environment below and the page sizes the site live from the same parametric models, showing the honest derates along with the capacity. Every figure is a pre-application design target, not field data.
The discipline here is the same as everywhere else on this site: the model is printed, the inputs are visible, and the numbers follow from them. Net output per module falls on a hot afternoon and at altitude, so the configurator shows that fall instead of quoting a nameplate. Module counts carry an N+1 reserve because sealed-core swaps and single-module trips are planned events, not surprises. And every scenario in the register is paired with the attested record an operating site would actually produce, because a deployment you cannot verify is just a promise.

## Which deployment fits your facility?
Choose a facility style and an environment. The results update from the parametric model; without JavaScript the page shows the mid-size colocation case in a Northern Virginia environment.
Facility style
Edge / enterprise data center 4 MW IT · single-tenant compute, hospital-grade reliability Campus CHP hybrid 3 MW IT · power plus district or process heat Colocation, mid-size 20 MW IT · multi-tenant, utility backup retained AI training cluster 40 MW IT · high-density racks, large load steps buffered by molten-salt storage Hyperscale campus 96 MW IT · phased number-up build-out Remote / defense island 2 MW IT · no utility, black-start capable
Environment
Hot-arid (Phoenix class) design ambient 45 °C · 340 m Temperate-humid (N. Virginia) design ambient 35 °C · 90 m Continental (Ohio class) design ambient 32 °C · 300 m High-altitude (Denver class) design ambient 35 °C · 1600 m Cold (Alaska / northern plains) design ambient 25 °C · 150 m Coastal (marine air) design ambient 38 °C · 10 m
Colocation, mid-size · Temperate-humid (N. Virginia)
Net per module 3.61 MWe
Modules (req + reserve) 6 + 1 = 7
Site capacity 25.3 MWe
Margin over IT load +5.3 MWe
Annual attested output 166.4 GWh
Heat rejected 48.6 MWth
Interconnect Grid-parallel
Heat tap (CHP style only) 2–5 MWth per module

Sizing computed live from the parametric model below · pre-QAPD screening

**Why this is lower than the 4.40 MWe on the spec sheet:** 4.40 MWe is the cycle rating, 11.0 MWth at 40% net. The figure above is what reaches the meter at this site, after the ambient derate on cycle efficiency, dry-cooler fan parasitics, house load, transformer losses and altitude. Site ambients here are design highs, not annual averages, so this is the conservative end. Model, exactly as computed: net-cycle efficiency η = 0.395 − 0.0009 × max(0, T − 15); gross = 11.0 MWth × η × 0.98; fan parasitics = 0.25 + 0.006 × (T − 25) MWe; net = (gross − fans − 0.10) × (1 − 0.011) × (1 − 0.01 × altitude_m / 1000). Modules required = ⌈IT ÷ net⌉, plus the reserve for the facility style. Annual attested output assumes a 95% capacity factor against the IT load. Heat rejected per installed module is whatever the cycle does not convert, 11.0 MWth − gross, computed at the same ambient.

## How does this configuration behave when things go wrong?
The register runs every configuration through nine operating scenarios, from an ordinary Tuesday to an extended station blackout. Across all 324 cases in the register, every capacity scenario passes: the N+1 reserve carries a swap or a trip, and the peak-ambient derate never takes a site below its IT load. That is a property of how the sizing rule works, sized against the honest derate with reserve on top, and it is a screening-level claim on the frozen design basis, not credited analysis. The table below is the selected configuration's row of the register, with the verification evidence each scenario produces.
Scenario Capacity vs load RankShield evidence produced
S1 Normal operation | PASS 25.3 MWe available vs 20 MW load | attested net MWh and efficiency baseline
S2 Peak-ambient day (+5 °C) | PASS 24.7 MWe available vs 20 MW load | derate visible and attested, not estimated
S3 Sealed-core swap | PASS 21.7 MWe available vs 20 MW load | N+1 carries the load; swap chain of custody witnessed
S4 Grid loss, island transfer | PASS 25.3 MWe available vs 20 MW load | attested island transfer and frequency record
S5 Black start | PASS 25.3 MWe available vs 20 MW load | attested restart sequence, no external power
S6 50% load step | PASS 25.3 MWe available vs 20 MW load | thermal buffer bridges; reactor never chases load, logged
S7 Single module trip | PASS 21.7 MWe available vs 20 MW load | reserve margin absorbs; transient attested
S8 Extended station blackout | SAFETY CASE Safety case, not a capacity check | passive air cooling, zero operator action; decay-heat state attested
S9 Cooler fouling / efficiency drift | PASS 25.3 MWe available vs 20 MW load | expected-behavior model flags drift from the same signed stream

Capacity checks: swap and trip scenarios use (total modules − 1) × net; the peak-ambient scenario recomputes net output at design ambient + 5 °C. Extended station blackout is a safety scenario, decay heat leaves by passive air cooling with zero operator action, so it is never a capacity question.

## How does net output move with the environment?
This is the curve doing the work in the configurator. Output falls as ambient rises, because the dry cycle rejects heat to hotter air and the cooler fans work harder, and it falls about one percent per thousand meters of altitude. Both lines are computed at build time from the same model printed above; nothing on this chart is drawn by hand.

Figure 3 · Net MWe per module vs design ambient, 10–50 °C · sea level and 1600 m

## How does the verification work here?
Every scenario in the register ends the same way: with evidence. That is the point of deploying HELIX rather than a reactor you have to take on faith, and it works on three layers.
**Protection.** Each module's identity begins with a witnessed genesis at the factory, and its telemetry crosses a hardware one-way path, an observe-only boundary that physically cannot carry a command toward a safety system. Because custody and configuration are attested from the factory floor onward, diversion or tampering is detectable rather than deniable: a module that is moved, opened, or altered stops matching its own signed history.
**Efficiency.** The same signed stream that proves a site's output also polices it. An expected-behavior model, the same parametric model on this page, normalized to the site's own environment, flags a module that drifts from what its conditions predict. Cooler fouling, instrument drift, and tampering all surface as the same signal: attested reality diverging from the model. One detector serves both the maintenance plan and the security case.
**Independence.** A tenant, an insurer, or a regulator verifies a site against the append-only log and its independent off-site witnesses, not against our word. The attested MWh in the table above are checkable by the party buying them. Read [how the reactor works](https://rankshieldenergy.com/technology) and [where the program stands with the NRC](https://rankshieldenergy.com/pre-application).
Honesty statement
Every number on this page is a parametric design-study estimate on the frozen design basis, computed from the models shown above. It is unqualified pre-QAPD screening: an input to design, not credited analysis, not a performance guarantee, and not an offer of sale. It will be superseded by qualified analyses once the quality program is stood up.
RankShield Energy · HELIX · pre-application

Evaluating a real site?
The dimensioned drawing packages and the full 324-case register are deliberately not published here. We share them directly, honestly labeled, with qualified partners and hosts.
[Request the full engineering package](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/

# RankShield Energy

> RankShield Energy is a nuclear reactor developer. HELIX is a sealed, transportable microreactor design, sealed sodium heat pipes with no pumps of any kind, graphite-moderated TRISO core, fully-dry cooling, passive walk-away safety, with a non-safety attestation layer, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway. Pre-application stage, with the licensing program under way. Physics results are unqualified pre-QAPD screening.

The reactor
[Technology](https://rankshieldenergy.com/technology)[Safety](https://rankshieldenergy.com/safety)[Testing & scenarios](https://rankshieldenergy.com/testing)[Specifications](https://rankshieldenergy.com/specs)[Deployments](https://rankshieldenergy.com/deployments) [See the verification layer →](https://rankshieldenergy.com/#verify)
Program
[Licensing](https://rankshieldenergy.com/licensing)[Pre-application readiness](https://rankshieldenergy.com/pre-application)[Resources](https://rankshieldenergy.com/resources)[News](https://rankshieldenergy.com/news)[About](https://rankshieldenergy.com/about)[Verify this site](https://rankshieldenergy.com/verify) [Contact RankShield Energy →](https://rankshieldenergy.com/contact)
[Contact the program →](https://rankshieldenergy.com/contact)
Licensing program under way · physics results are pre-QAPD screening
RankShield Energy · HELIX · Pre-application development

# A microreactor engineered to be verified, not just trusted.
**Firm power now takes years to buy:** interconnection queues run past half a decade and capacity prices have hit record caps. **HELIX** is the alternative, a sealed microreactor with no pumps and no water, walk-away safe by physics, set on a prepared pad in days, and engineered so an operator, insurer, or regulator can **prove** what it is doing instead of taking it on faith.
[The safety case](#safety) [Licensing pathway](#licensing)
Site output
4–100 MWe

Modules
4.40 MWe cycle, number-up

Cooling water
Zero

Core swap
5–7 yr cadence (target)

01, THE CONCEPT

## A sealed module. A site that arrives and connects.
Power that arrives instead of waiting in an interconnection queue. Identical factory-sealed HELIX modules rated 4.40 MWe at the cycle number up from one for a hotel or campus to twenty-plus for a hyperscale site. Each module is set-and-connect on a prepared pad and cooled entirely by dry air, no cooling tower, no water draw. An N+1 reserve module carries an outage. Outbound the module is oversize and permittable at 2.70 m; whether it travels on ordinary roads or needs superload permitting turns on an envelope question we have not closed, and we say so.

INSIDE HELIX

## The core is the point. Everything else gets out of its way.
**RankShield is a verification company first; HELIX is the reactor built on that foundation.** A graphite-moderated TRISO core at the 19.75% HALEU ceiling, sealed sodium heat pipes with **no pumps and no water**, and fully-passive walk-away safety, built to be verified, not just trusted.
Factory-built, trucked to site as an oversize load, and core-exchanged on a roughly 6 to 7 year cadence. A non-safety attestation layer lets an operator, an insurer, or a regulator independently check the module's integrity, from the factory floor to every operating hour.

- 1 **Sealed domed head** & control-rod drive
- 2 **RVACS** passive air shroud
- 3 Sealed **reactor vessel** (low-pressure)
- 4 Graphite-moderated **TRISO core**
- 5 **Sodium heat pipes**, no pumps, no water
- 6 Factory-sealed **swap-and-service base**
Cutaway is illustrative · 2.70 m pressure-boundary diameter · core 3.00 m, overall height not yet fixed

02, THE SAFETY CASE

## Nothing in the safety case moves, and nothing is powered.
Reactivity is held by strong negative-temperature feedback; sixteen control drums and a diverse shutdown rod insert fail-safe on loss of power. Decay heat is removed by natural-draft air cooling and radiation alone, and because there is no pump anywhere in the reactor, there is no loss-of-flow accident class at all, no valve, no operator action. An independent digital-safety platform provides deterministic protection; the attestation layer observes from outside this boundary and can never command it.

03, INSIDE THE CORE

## A graphite-moderated core, screened in our own physics.
UCO-TRISO fuel at 19.75% HALEU in a graphite core block, ringed by sixteen B4C control drums with a diverse central shutdown rod, its heat carried out by sealed sodium heat pipes. Our continuous-energy Monte Carlo screening (unqualified, pre-QAPD) shows a strongly negative temperature coefficient, ample shutdown margin, and a reactivity-limited life of 6.67 full-power years at the current design point, bounded between 6.67 and 6.91 pending resolution of the energy-per-fission normalisation, inputs to design, not credited safety analysis.

04, THE SITE

## A power plant that arrives, connects, and runs dry.
Identical sealed modules on a prepared pad, a molten-salt thermal buffer, dry sCO2 conversion skids, dry coolers, and the grid interconnection skid, the whole plant with no cooling water, no on-site nuclear work, no deep vault excavation, and sealed-core exchange on a roughly 6 to 7 year cadence.

1 5 4 3 2 6 OPERATOR FOR SCALE INSIDE HELIX

## What is actually inside the module.
The whole reactor arrives sealed and never opens on site, though it is rechargeable rather than disposable: the core is exchanged at the factory, not in the field. Cut it away and there are only six things that matter, and no pump, no valve, and no drop of water among them.
Tap a number on the cutaway, or a card below, to highlight the part.

- 1 ### Control-rod drive & sealed head Holds a diverse shutdown rod above the core. On **any loss of power it inserts by gravity**: fail-safe, no operator, no command.
- 2 ### Sodium heat pipes Sealed pipes wick heat straight out of the core. **No pumps, no valves, no water**, so there is no loss-of-flow accident class to license against.
- 3 ### Graphite-moderated TRISO core UCO-TRISO fuel at the 19.75% HALEU ceiling in a graphite block. Strong negative feedback: **as it heats, it powers itself down**.
- 4 ### Sealed pressure vessel A sealed pressure vessel closed at the factory and **never opened in the field**. The module trucks in, sets on a pad, and connects.
- 5 ### Dry sCO₂ power take-off Heat crosses to a dry supercritical-CO₂ loop on bolt-on skids, **~40% net, air-cooled, zero cooling water**.
- 6 ### Monitoring & service base Instruments every operating hour and keeps a tamper-proof record: **the same data that runs the plant efficiently** and that a lender or insurer can check.
Cutaway is illustrative · 2.70 m pressure-boundary diameter · attestation features are design targets

Why HELIX wins the deal

## The reactor is a commodity. Your bottom line is not.
HELIX will not beat a gas turbine on sticker price per megawatt-hour, and several vendors will sell a sealed microreactor this decade. We are not trying to win that number. We are trying to win the one on your P&L: the **delivered, risk-adjusted cost of firm, clean power** over twenty years. Four things move that number, and the reactor core is not one of them.
01 · UPTIME

### More hours on line, more megawatt-hours sold
Dry sCO₂ conversion at **~40% net**, plus continuous self-monitoring that flags wear **before it becomes an outage**. On a plant this size every point of capacity factor is revenue you would otherwise lose, and that monitoring is the same data the verification layer signs.

02 · COST OF CAPITAL

### Cheaper to finance. Cheaper to insure.
A reactor that **continuously proves its own condition** is one a lender and an insurer can underwrite without guessing. Where capital cost dwarfs fuel cost, shaving the rate moves delivered price more than any fuel saving. That is what "verifiable" buys: **a lower rate, not a slogan**.

03 · OPERATING COST

### Runs dry, runs lean, runs unattended
**No cooling water, no pumps, minimal on-site staff.** Passive walk-away safety and hands-off operation take out fixed costs a conventional plant pays every single year of its life.

04 · TIME TO POWER

### Power sooner, revenue sooner
Factory-built, trucked in, set on a prepared pad, targeting the NRC's proposed **fleet-approval** microreactor path. For a buyer who is power-starved today, **months instead of years** is the whole bottom line.

Security = downside
Security is not a feature bolted on top; it is downside protection. One undetected tamper or a quiet degradation is the single event that strands a twenty-year asset. **The same monitoring that runs the plant efficiently is what keeps that from happening**, every hour, without anyone having to watch.

Cheapest electron? No. Lowest cost to own firm, clean power you can bank on? That is the race we are running.
Pre-application program · delivered-cost levers are design targets, not yet demonstrated.

Design basis · targets held to an honest ceiling

## HELIX at a glance.
Site output | 4.40 MWe at the cycle per sealed module; delivered at the meter is lower and site-specific. Sites number up from one module to 20+ (design target)
Heat transport | 421 sealed sodium heat pipes through the core monolith; no pumps of any kind (EM-pumped pool evaluated, not selected)
Fuel & core | UCO-TRISO, 19.75 wt% HALEU, graphite-moderated, inside the NRC-accepted EPRI-AR-1(NP)-A particle envelope; 1.80 m core
Reflector / control | BeO reflector, 0.40 m radial; 16 B4C control drums + 1 diverse shutdown rod
Cooling | Fully dry, forced-draft dry coolers; zero cooling water
Power conversion | Dry sCO₂ Brayton, 40% net, air-cooled, on bolt-on skids outside the sealed module
Core life | 6.67 full-power yr at the current design point, bounded 6.67–6.91 pending the energy-per-fission normalisation (screening; unqualified)
Transport | 2.70 m pressure-boundary OD, oversize and permittable outbound. Road-legal is 2.60 m and costs core life; ordinary-road versus superload permitting is an open question
Safety concept | Passive shutdown + natural-circulation decay-heat removal; walk-away

The verification layer · non-safety, observe-only

## Each reactor proves itself. A fleet cross-checks it.
This is the part we did not have to invent for the reactor: RankShield already operates a production verification network protecting live infrastructure, and HELIX inherits it. Each site signs its telemetry with post-quantum cryptography and normalizes performance against its own environment. The RankShield Network compares every reactor to what its conditions predict, so drift, whether wear or tampering, stands out against an independent-witness fleet. The layer sits outside the safety boundary behind a hardware one-way path: it can prove integrity, and by construction can never command a safety function. Provable power is easier to staff, insure, certify, and buy: the same witnessed record that shows a regulator the module is intact meters every megawatt-hour for the customer and flags efficiency drift before it costs anything.
Core integrity attestation · ML-DSA-87 design-target
Firmware root-of-trust · SLH-DSA / hash-based design-target
Transparency log · RFC 9162-class design-target
Independent off-site witness quorum design-target · recruiting
Safety I&C boundary · hardware one-way path observe-only by design

Fleet cross-verification · teal = attested · coral = flagged for triage

Regulatory pathway

## Licensing: Part 57 primary, Part 53 backup.
TARGET

**10 CFR Part 57 microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026)**
The NRC's proposed microreactor-specific framework, providing fleet approvals of identical reactors and aimed at simple machines with simple safety systems, which the pumpless walk-away design is built to fit. Proposed, not final; we claim no approval and no application is underway.

BACKUP

**10 CFR Part 53 (final rule, effective April 29, 2026)**
The risk-informed, technology-inclusive framework remains the backup pathway, and the scoping work done against it transfers.

PLANNED

**Licensing Project Plan & topical-report sequence**
Phased plan scoped to a verified compliance register: licensing-basis-event selection, SSC safety classification, mechanistic source term, and Division 5 materials qualification.

TRACK

**DOE-authorized test unit, data credited into the commercial case**
A test article under DOE authorization, with quality data collected under NQA-1 from day one, feeding the eventual NRC application, consistent with the NRC's proposed DOE-design-credit pathway.

OWED

**QA program (NQA-1) & PSAR**
Stand up the quality-assurance program and preliminary safety analysis before any credited analysis. All physics shown to date is unqualified screening and is not carried forward as credited.

The engineering · thirteen subsystems

## Engineered to the ceiling, then screened.
01 DESIGN-BASED

### Fuel & core
UCO TRISO at the 19.75% HALEU ceiling in a graphite monolith, the only advanced fuel form purchasable from multiple US fabricators today.

02 DESIGN-BASED

### Sealed sodium heat transport
Sealed sodium heat pipes through the core monolith delivering at 850 °C, no pumps of any kind, which is what lets the same unit serve process heat as well as electricity without redesign. An EM-pumped pool was evaluated and not selected; the decision closed on physics and install engineering, not preference.

03 DESIGN-BASED

### Reactivity & self-regulation
Strong negative temperature feedback measured in screening physics; 16 B4C control drums plus one diverse shutdown rod, shutdown worth far exceeds any credible excess.

04 DESIGN-BASED

### Reflector & shielding
Beryllium-oxide radial reflector, 0.40 m thick, the configuration our screening physics is run on. Thinning it from 0.50 m is what brought the module to 2.70 m; the reflector is the dominant lever on both envelope and core life, and the trade is documented rather than assumed. Layered borated shielding.

05 DESIGN-BASED

### Monolith & vessel
A 50 mm vessel wall around the graphite monolith. Material selection against ASME Section III Division 5 is open and we say so: our maximum operating temperature sits near the boundary where austenitic grades give way to a nickel-base alloy, and that code case is not closed. Not 300,000 hours, comfortably beyond the module's planned service life across factory recharge cycles.

06 DESIGN-BASED

### Passive decay-heat / walk-away
Decay heat leaves by natural-draft air cooling and radiation alone. Nothing powered, nothing moving, no operator action, an availability event, never a safety event.

07 DESIGN-BASED

### Power conversion
Dry supercritical-CO2 Brayton conversion at 40% net, air-cooled, on bolt-on skids outside the sealed module that can be serviced or swapped without ever opening it.

08 IN EVALUATION

### Thermal energy storage
A molten-salt buffer lets modules run flat at their sweet spot while stored heat follows demand swings and bridges transients, the reactor never chases load.

09 DESIGN-BASED

### Dry heat rejection
Forced-draft dry coolers, variable-speed fans. No water, no cooling tower, no draw against the community that hosts it.

10 DESIGN-BASED

### Site architecture
Number-up identical 4.40 MWe modules, one for a campus, twenty-plus for a hyperscale site, with N+1 reserve. Sealed in the field and never opened on site, but not disposable: at end of core life the module is exchanged and its core returns to the factory to be defueled and recharged. The site runs indefinitely on rolling exchange. The honest gap is the return leg, where the irradiated core ships in a Type B cask that is not yet licensed.

11 DESIGN-BASED

### Grid integration
Five reference integration archetypes spanning every US facility class, with a pre-engineered adaptive skid and the IEEE 1547 protocol envelope built in.

12 DESIGN-BASED

### I&C, autonomy & digital twin
FPGA deterministic safety on an NRC-approved platform lineage, plus an attested digital twin behind a one-way data diode.

13 DESIGN-BASED

### Post-quantum attestation
ML-DSA-87 telemetry and SLH-DSA hash-based firmware signing anchored to a witnessed transparency log, from factory floor through transport to every operating hour.

The machine · photoreal cutaway

## The whole reactor, in a single sealed view.
Cut the module open and there is no pump, no valve, and no drop of water. Sodium heat pipes wick heat straight off a graphite-moderated **TRISO core** to a dry power loop, the shutdown rod sits above the core and drops by gravity on any loss of power, and the vessel is closed at the factory and **never opened in the field**. The operator is there for scale.
Core height
3.00 m

Diameter
2.70 m

Output
4.40 MWe cycle

Cutaway is illustrative · 2.70 m is the pressure-boundary diameter; the shipped envelope adds a casing stack we have not yet fixed.

Honest status · what is done, what is owed

## Gates before any hardware.
DONE

**Design of record & adversarial verification**
Reactor and integration design consolidated; hundreds of sourced claims adversarially verified; competitive and materials landscape assessed.

DONE

**Reactor-physics screening (unqualified)**
Continuous-energy Monte Carlo screening of criticality, lifetime, reactivity feedback, shutdown worth, and post-trip xenon. Screening inputs to design; pre-QAPD; not credited.

IN PROGRESS

**Scenario & failure campaign**
Nominal, harsh-environment, chaotic-failure, production, grid/EMC, and long-run internal scenarios; structural/thermal FEA stand-up owed for cascade and stress cases.

OWED

**Independent physics validation**
Qualified-lane confirmation with independent codes and, ultimately, test data. No claim of validated performance is made.

OWED

**NRC licensing & validated demand**
An NRC application, under Part 57 once the rule is final or under Part 53 as the backup, and confirmed offtake demand are prerequisites to any hardware commitment.

Ask the founder

## Every question, answered directly.
The questions a regulator, a partner, or an engineer asks about HELIX, answered by the founder. No forms, no sales pitch.
**Jamie Kloncz** Founder · RankShield Energy

** ONLINE

- 01 What exactly is RankShield Energy building?
- 02 Is this an operating reactor?
- 03 Why should a regulator or partner take a pre-application program seriously?
- 04 How does HELIX make power without water?
- 05 What fuel does it use, and can you actually buy it?
- 06 How big is a site and how often do you swap the core?
- 07 What happens in a total loss of power and cooling?
- 08 Can the verification network ever interfere with safety?
- 09 What does "verifiable" actually mean here?
- 10 How does a fleet catch a problem before it becomes one?
- 11 What is the licensing pathway?
- 12 What still has to happen before you build hardware?

*Pick a question on the left, or search above, and you'll get the direct answer, the way an answer engine would give it.*

← Prev Next → - / 12
[Talk to the founder →](https://rankshieldenergy.com/contact)

What exactly is RankShield Energy building? We are developing HELIX, our own sealed, transportable microreactor, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway, with a qualified third-party fabricator manufacturing to our specification. What makes us different is not the reactor. It is that ours can be independently verified. Every module signs its telemetry and is attested from the factory floor to every operating hour. Is this an operating reactor? Not yet. It is pre-application development, not an operating product. No microreactor of this class has been built or run at its rated life yet, including ours. Every figure we publish is a design target and every physics result is unqualified screening, pre-QAPD. We label all of it honestly. That discipline is what makes the rest credible. Why should a regulator or partner take a pre-application program seriously? Because pre-application is exactly where the credible advanced-reactor cohort is. Part 53 only became final in 2026, the microreactor-specific Part 57 is still a proposed rule, and the leading microreactor developers are all in pre-application or early licensing. We treat the honest labels as milestones on a defined path we are actively executing, not as caveats. How does HELIX make power without water? Heat leaves the core through sealed sodium heat pipes, no pumps of any kind and no water anywhere in the primary. A dry supercritical-CO2 Brayton cycle on skids outside the sealed module converts it to electricity, targeting roughly 40 percent net. All heat is rejected to dry coolers, so there is no cooling tower and no water draw against the community that hosts the plant. What fuel does it use, and can you actually buy it? UCO-TRISO at 19.75 percent HALEU in a graphite core. It is the only advanced fuel form that is both NRC-precedented and purchasable from multiple US fabricators today. Our screening also shows the core reaches its reactivity limit with most of its uranium unburned, over 90 percent of the U-235 remains, so factory recharge re-banks that reactivity rather than discarding a nearly full fuel load. How big is a site and how often do you swap the core? A site numbers up identical sealed modules of roughly 5 megawatts each, one for a hotel or campus, twenty-plus for a hyperscale site. Staggered sealed-core swaps land on a roughly 5 to 7 year cadence and an N+1 reserve module carries an outage, so the modules are multi-year but the site runs indefinitely on rolling factory recharge. Our depletion screening puts module life at roughly four to five full-power years as modeled, likely five to seven once known model conservatisms are removed. What happens in a total loss of power and cooling? Nothing that matters. Reactivity self-limits on a strongly negative temperature coefficient, the control drums insert fail-safe by spring and gravity with no power needed, and decay heat leaves by natural-draft air cooling and radiation alone. A total loss of power and cooling is an availability event, not a safety event. There are no pumps anywhere in the reactor, so there is no loss-of-flow accident class, and the safety case never credits a pump, a valve, an operator, or a network. Can the verification network ever interfere with safety? No, by construction of the wiring. The attestation layer is classified non-safety and observe-only. It sits behind a hardware one-way path, so it can prove a module is intact but it physically cannot send a command toward a safety system. The safety systems are local and passive and unreachable from any network. What does "verifiable" actually mean here? Each module signs its sensor readings and firmware with post-quantum cryptography and anchors them to an append-only log co-signed by independent off-site witnesses. An operator, an insurer, or a regulator can check a module directly rather than take our word for it. Anyone can write the word secure. Only a verifiable reactor lets you check. How does a fleet catch a problem before it becomes one? Each site normalizes its performance against its own environment, then the RankShield Network compares every reactor to what its conditions predict. A reactor that drifts from that expectation stands out against an independent-witness fleet. The elegant part is that the same signal flags both wear and tampering, so one detector serves efficiency and security. What is the licensing pathway? Our primary target is 10 CFR Part 57, the NRC's proposed microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026). It provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems, which the pumpless walk-away design is built to fit. Part 53, final since April 2026, remains the backup pathway and our scoping work against it transfers. We claim no approval, and no application is underway. What still has to happen before you build hardware? A stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, an NRC license, under Part 57 once the rule is final or under Part 53 as the backup, and validated demand. All of it is defined and stated on our licensing page. We make no economic, schedule, or performance guarantee, only honest labeled progress.



---

## Page: https://rankshieldenergy.com/licensing/

# Licensing

> HELIX targets the NRC's proposed 10 CFR Part 57 microreactor framework as its primary licensing pathway, with 10 CFR Part 53 as the backup. The two-track pathway, the Licensing Project Plan, the DOE-authorized test-unit track, and the honest gates that remain before any hardware commitment.

Regulatory pathway

# Licensing: Part 57 primary, Part 53 backup.
**HELIX is being developed against a defined regulatory path, not a hope.** Our primary target is the NRC's proposed 10 CFR Part 57 microreactor framework, with the final Part 53 framework held as the backup pathway, and we scoped the topical-report sequence to a verified compliance register and are structuring a DOE-authorized test unit so its data credits into the commercial case. Below is the honest state of that path: what is targeted, what is planned, and what is owed before any hardware is built.
Licensing is where advanced-reactor programs most often overstate their position, so we are going to be precise about ours. A pre-application developer has not been granted anything by the NRC; it has chosen a pathway and is preparing for the structured engagement that precedes a formal application, an engagement we have not yet begun. That is exactly where HELIX is, and our primary pathway is itself still a proposed rule, which we say plainly rather than bury. What makes the position credible is not a claim of approval, it is that every step is named, sequenced, and tied to a verifiable compliance register rather than to a marketing timeline.

## What is Part 57, and why is it our primary target?
Part 57 is the NRC's proposed licensing framework written specifically for microreactors, proposed on May 1, 2026, with a final rule expected on November 23, 2026. Two things about it matter for HELIX. First, it provides fleet approvals of identical reactors, which is exactly the shape of a number-up site built from identical factory-sealed modules: approve the machine once, then deploy it as a fleet rather than relicensing each unit as a bespoke plant. Second, it is aimed at simple machines with simple safety systems, and a pumpless, walk-away design whose shutdown cooling is carried by natural-draft air and radiation is built to fit that description. We say clearly what this is not: Part 57 is proposed, not final, we hold no approval under it, and no licensing application is underway.

## Where does Part 53 fit now?
Part 53 is the NRC's risk-informed, technology-inclusive framework for commercial nuclear plants, made final in 2026, and it remains our backup pathway. It matters for a design like HELIX because rather than forcing a sodium-cooled microreactor to fit rules written around large light-water plants, it lets a developer make a safety case on the actual physics and risk profile of the design. The work we scoped against it, the compliance register, the topical-report sequence, and the analysis structure, transfers rather than being discarded, so holding it as the backup costs the program nothing and keeps a final, in-force framework available if the Part 57 rule shifts or slips.

## How does the application actually get built?
An application is not a single document; it is a sequence. The Licensing Project Plan lays out the topical-report sequence and ties each report to a specific regulatory requirement in a compliance register we maintain and verify. That sequence includes selecting the licensing-basis events the design must withstand, classifying every structure, system, and component by its safety significance, developing a mechanistic source term that describes what could actually be released and under what conditions, and qualifying the pressure-boundary materials under ASME Section III Division 5 for the high-temperature regime, which is guided by Regulatory Guide 1.87. We have not yet fixed the vessel material or the vessel temperature, so that code case is named here as owed rather than claimed as done. Each of these is a discrete, checkable deliverable, and each is scoped against the register rather than asserted.

## What is the DOE test-unit track, and why does it matter?
There is a faster, more rigorous way to generate the data an application needs than analysis alone: build a test article under Department of Energy authorization and collect quality data from it from day one. Structuring a DOE-authorized test unit, with data gathered under an NQA-1 quality program from the first hour of operation, feeds real measured behavior into the eventual NRC application. This is consistent with the NRC's own proposed pathway to credit DOE-authorized designs, and it converts what would otherwise be a purely paper submission into one anchored by test data. For a first-of-a-kind reactor, that difference is the difference between a credible application and an optimistic one.

## What about manufacturing? It is a second license, and it comes later.
Deploying a fleet needs two separate authorizations, and they are often conflated. The first is the reactor licensing path above. The second is the right to build units in a factory, and it runs on its own track: an Appendix B quality-assurance program, then a Part 21 defect-reporting program, then a contract with an Authorized Inspection Agency, then an ASME Section III Division 5 Certificate of Authorization, and only then a manufacturing license under 10 CFR Part 52 Subpart F.
Two facts about that track are worth stating plainly, because they set the sequence and most vendor sites leave them out. **No manufacturing license has ever been applied for under Subpart F.** And a reactor built under one may only be transported to and installed at a site that already holds a construction permit or a combined license, which means the manufacturing license follows customers rather than creating them. ASME also surveys a physical shop with an implemented quality program, and its certificates last three years, so obtaining one before there is a factory to certify would simply burn it.
The useful consequence is that **the two tracks share their first step**. The same Appendix B quality program that gates every topical report on the reactor side also gates the entire manufacturing side. One workstream unlocks both, which is why it is the item we treat as the bottleneck rather than the paperwork.

## What is honestly still owed?
Two gates sit ahead of any hardware commitment, and we label them as owed rather than dressing them up. The first is a stood-up NQA-1 quality-assurance program and a preliminary safety analysis report. Until that program exists, no analysis can be credited at all, which is exactly why we describe every physics result on this site as unqualified screening: it is produced outside a QA program and is not carried forward as credited work. The second is independent physics validation, confirmation with independent codes and ultimately test data, together with validated offtake demand. We do not commit hardware on the strength of our own screening and our own optimism; both of those external confirmations come first.
TARGET

**10 CFR Part 57 microreactor framework (proposed May 1, 2026; final rule expected November 23, 2026)**
The NRC's proposed microreactor-specific framework, identified as our primary licensing target. It provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems. Proposed, not final; we claim no approval and no application is underway.

BACKUP

**10 CFR Part 53 (final rule, effective April 29, 2026)**
The risk-informed, technology-inclusive framework remains the backup pathway. The scoping work done against it, the compliance register and the topical-report sequence, transfers.

PLANNED

**Licensing Project Plan & topical-report sequence**
A phased plan scoped to a verified compliance register: licensing-basis-event selection, SSC safety classification, mechanistic source term, and ASME Section III Division 5 materials qualification.

TRACK

**DOE-authorized test unit, data credited into the commercial case**
A test article under DOE authorization, with quality data collected under NQA-1 from day one, feeding the eventual NRC application, consistent with the NRC proposal to credit DOE-authorized designs.

LEVER

**Phased construction permit + limited work authorization**
For a first site-anchored application under the backup Part 53 pathway, a phased submission lets early site work proceed while the safety review continues.

OWED

**NQA-1 quality program & PSAR**
The quality-assurance program and preliminary safety analysis must be stood up before any credited analysis. All physics shown to date is unqualified screening and is not carried forward as credited.

OWED

**Independent physics validation & validated demand**
Qualified-lane confirmation with independent codes and, ultimately, test data, plus confirmed offtake demand. Both are prerequisites to any hardware commitment.

## Being pre-application is where the frontier is
Every credible advanced-reactor developer is either in pre-application or early licensing. That is the current phase of the entire cohort: 10 CFR Part 53 itself only became final in 2026, and the microreactor-specific Part 57 is still a proposed rule. We treat the honest labels, design targets, unqualified screening, and pre-QAPD status, not as caveats to apologize for but as the milestones of a path we are actively executing. The discipline of naming exactly where we are is what makes everything else on this site credible, and it is the same discipline that produced a reactor designed to be checked rather than merely trusted.
[See the validation program that feeds the safety case →](https://rankshieldenergy.com/testing)
[Read why verification is the whole strategy →](https://rankshieldenergy.com/about)



---

## Page: https://rankshieldenergy.com/news/

# News and Press Releases

> Company announcements from RankShield Energy, including NRC pre-application regulatory milestones.

Newsroom

# News and press releases
Company announcements, including regulatory milestones in our NRC
pre-application engagement. We publish each milestone as it is reached, including the ones
that do not go our way.

- September 15, 2026 ## [NRC Assigns RankShield Energy Pre-Application Project Number for HELIX Microreactor](https://rankshieldenergy.com/news/nrc-project-number-99902183) Project No. 99902183 puts the company's engagement with the agency on the record. No application has been filed, and the company holds no NRC approval. [Read the release](https://rankshieldenergy.com/news/nrc-project-number-99902183)
Regulatory status
RankShield Energy is a
pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory
Commission. It holds no NRC license, permit, or design approval. Nothing in these releases
is a representation that any RankShield Energy design is NRC-approved, licensed, or
certified.
RankShield Energy · HELIX · pre-application

Media inquiries: [jamie@rankshieldenergy.com](mailto:jamie@rankshieldenergy.com)



---

## Page: https://rankshieldenergy.com/news/nrc-project-number-99902183/

# RankShield Energy Receives NRC Pre-Application Project Number

> The NRC assigned RankShield Energy project number 99902183 for pre-application activities. No application has been filed and the company holds no NRC approval.

[News](https://rankshieldenergy.com/news) / Press release For immediate release

# NRC Assigns RankShield Energy Pre-Application Project Number for HELIX Microreactor
Project No. 99902183 puts the company's engagement with the agency on the record. No application has been filed, and the company holds no NRC approval.
Published September 15, 2026 · RankShield Energy, Inc.
**NAPLES, Fla., Sept. 15, 2026** -- The U.S. Nuclear Regulatory Commission has assigned RankShield Energy, Inc. project number 99902183 under the docket name "RankShield Energy Pre-application Activities," the company said today. The NRC has assigned a project manager to the engagement.
The number was issued Aug. 31, 2026. On Sept. 15 the company completed the identity proofing and multifactor credentialing required to submit documents through the NRC's external partner submission gateway.
A project number is an administrative tracking identifier. It creates a docket name under which correspondence and meeting summaries are filed, assigns a staff point of contact, and establishes the basis on which NRC staff time is billed. It is not a license, a permit, a certification, a design approval, or an endorsement, and it reflects no NRC finding on any technical matter.
“A project number is a file number, not a finding. It means the agency has somewhere to put our correspondence and someone assigned to read it. We have not filed an application, the staff has not reviewed our design, and we are not going to present an administrative step as a technical result. What changed is that our engagement is on the record, and we intend to publish what happens there, including the parts that do not go our way.”
Jamie Kloncz, Founder, RankShield Energy RankShield Energy submitted a letter of intent to the NRC Document Control Desk on Aug. 4, 2026, stating its intent to begin pre-application engagement and requesting a project number. An introductory, non-technical meeting was held with the staff on Aug. 25. Nothing was submitted for review at that meeting, and the staff took no position on any technical matter.

## The fee mechanism behind the milestone
The practical consequence of the engagement is the basis on which it is billed. Section 201 of the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024, the ADVANCE Act, directs the NRC to apply a reduced hourly rate to advanced nuclear reactor applicants and pre-applicants. Under 10 CFR 170.20, the professional hourly rate for fiscal year 2026 is $337 and the reduced hourly rate is $154, which the NRC describes as "an over 50 percent reduction."
For pre-applicants, the reduced rate attaches to review of materials described in a licensing project plan. The provision is time limited: the NRC's fiscal year 2026 final fee rule states that the pre-applicant paragraph "shall cease to be effective on September 30, 2030."
RankShield Energy's next submittal is its Regulatory Engagement Plan, submitted as a licensing project plan. That document is written and staged and has not been submitted. Its first topical report will be a Quality Assurance Program Description committing to ASME NQA-1-2022 as endorsed by NRC Regulatory Guide 1.28, Revision 6.
The plan names a standard design approval under 10 CFR Part 52, Subpart E as the application type the company intends to build toward, on the basis that the instrument exists in final regulation today. The NRC's proposed 10 CFR Part 57 microreactor framework, a proposed rule published May 1, 2026 that is not final and under which no developer is licensed, remains the company's preferred destination if it is finalized substantially as proposed.

## Status of the program
HELIX is a factory-fabricated heat-pipe microreactor in the 11.0 MWth and 4.40 MWe class using HALEU TRISO fuel. It is a design under development. It is not operating, not licensed, and not approved, and no aspect of it has been demonstrated to or accepted by the NRC.
As of this release, RankShield Energy has filed no application of any kind, has not submitted its licensing project plan, has no accepted quality assurance program in place, and has identified no site. Analysis completed to date is unqualified screening work rather than qualified analysis, a distinction the company states in its filings and in its public material.
The company does not publish enrichment levels, core geometry, fuel loading, reactivity coefficients, or lifetime figures for its design, on export-control grounds under 10 CFR Part 810.

## About RankShield Energy
RankShield Energy, Inc. is a Delaware corporation based in Naples, Florida, developing the HELIX factory-fabricated microreactor and a verification-first approach to advanced reactor operations. The company is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. It holds no NRC license, permit, or design approval.

## Media contact
Jamie Kloncz, Founder RankShield Energy, Inc. 1950 Mayfair Street 814, Naples, FL 34104 [jamie@rankshieldenergy.com](mailto:jamie@rankshieldenergy.com) [239-404-8590](tel:2394048590) ###
RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. Nothing in this release should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. Statements about future filings and schedules are forward looking and subject to change. Where this release describes a proposed rule, that rule is not final and may change.

## Related reading

- [What an NRC Pre-Application Project Number Actually Means](https://rankshieldenergy.com/resources/nrc-pre-application-project-number-explained)
- [How the NRC Advanced Reactor Pre-Application Works](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)



---

## Page: https://rankshieldenergy.com/pre-application/

# Pre-application readiness

> RankShield Energy addresses the seven topics the NRC asks a prospective applicant to identify before pre-application engagement: technology, license class, regulatory approach, business model, research and development, policy issues, and a preliminary timeline. Honestly labeled; HELIX is at the pre-application stage with its licensing program under way.

NRC pre-application readiness

# The seven topics, answered in one place.
**Before pre-application engagement, the NRC asks a prospective applicant to identify seven things about its program.** This page states each of them for HELIX, links to the deeper page where the detail lives, and keeps our honest labels intact: HELIX is at the pre-application stage, and every physics result is an unqualified screening analysis, not credited safety analysis or field data.
We built this page so an NRC reviewer, a prospective partner, or an independent engineer can see the whole readiness picture at once rather than reconstructing it from marketing copy. Nothing here asserts a position we have not earned; where a topic is still being scoped, we say so.
[01 TechnologyThe reactor, its subsystems, and the safety concept](https://rankshieldenergy.com/technology)[02 License classThe kind of license we intend to seek](#license-class)[03 Regulatory approachHow we will make the safety case](https://rankshieldenergy.com/licensing)[04 Business modelHow HELIX is developed, built, and deployed](#business-model)[05 Research & developmentWhat has been screened and what is owed](https://rankshieldenergy.com/testing)[06 Policy issuesThe novel regulatory questions to work through early](#policy-issues)[07 Preliminary timelineThe phased path, without committed dates](#timeline)

## 01 · Technology
HELIX is a sealed, transportable microreactor: a graphite-moderated core of UCO-TRISO fuel at 19.75% HALEU, its heat carried by sealed sodium heat pipes with no pumps of any kind and no water in the primary system, rejecting heat to fully-dry coolers. Reactivity self-limits on a strongly negative temperature coefficient; sixteen boron-carbide control drums and a diverse rod insert fail-safe on loss of power; decay heat leaves by natural-draft air cooling and radiation. A site numbers up identical factory-sealed modules rated 4.40 MWe at the cycle, from one module to twenty-plus. A non-safety, observe-only attestation layer lets an operator, insurer, or regulator independently verify each module without ever being able to command a safety function.
[How the reactor works, subsystem by subsystem →](https://rankshieldenergy.com/technology)
[The passive safety case →](https://rankshieldenergy.com/safety)
[Specification and engineering drawings →](https://rankshieldenergy.com/specs)

## 02 · License class
HELIX would be licensed as a commercial nuclear power plant, a utilization facility. Our primary target is **10 CFR Part 57**, the NRC's proposed microreactor-specific framework (proposed May 1, 2026; final rule expected November 23, 2026), which provides fleet approvals of identical reactors and is aimed at simple machines with simple safety systems, a description the pumpless walk-away design is built to fit. Part 57 is proposed, not final; we hold no approval under it and no application is underway. **10 CFR Part 53**, the risk-informed, technology-inclusive framework that became final in 2026, is held as the backup pathway, and the scoping work done against it transfers.
The specific licensing action, under whichever framework applies, is being scoped in our Regulatory Engagement Plan and is a topic we want to align on with NRC staff during pre-application. Separately, any test article would be built under Department of Energy authorization rather than an NRC license, with its quality data credited into the eventual NRC application; that DOE authorization is not itself a commercial license.

## 03 · Regulatory approach
Our approach is to make a risk-informed safety case on the actual physics of the design rather than force a sodium-cooled microreactor into rules written for large light-water plants. The sequence is scoped to a verified compliance register and includes licensing-basis-event selection, safety classification of every structure, system, and component, a mechanistic source term, functional-containment analysis, and materials qualification under ASME Section III Division 5. A DOE-authorized test unit is structured so its measured data feeds the application, and under the backup Part 53 pathway a phased construction permit with a limited work authorization is available for a first site-anchored submission.
[The full licensing pathway, Part 57 primary and Part 53 backup, what is planned and what is owed →](https://rankshieldenergy.com/licensing)

## 04 · Business model
RankShield Energy is a reactor-design developer. We own the HELIX design and license it, with a qualified third-party fabricator manufacturing to our specification under our quality program. The product is a factory-sealed module and the plant around it; the differentiator is the non-safety verification layer that lets a customer, an insurer, or a regulator independently check a unit rather than take our word for it.
The target application is firm, carbon-free power delivered where it is needed: data centers, industrial process loads, and remote or defense sites that need reliable on-site power. We are deliberate about what we do not claim. We make no capital-cost, levelized-cost, schedule, or performance guarantee. The design targets a mid-grade cost position and spends deliberately on safety, efficiency, and longevity rather than trying to be the cheapest option. Any hardware commitment is gated on validated demand.
On economics, stated plainly
We publish no economic projections. A first-of-a-kind advanced reactor that promises a specific cost is making a claim it cannot yet support. Our commitment is honest, labeled progress toward a licensable, buildable design.

## 05 · Research and development activities
**Done:** the design of record was consolidated and its sourced claims adversarially verified; continuous-energy Monte Carlo screening (OpenMC with ENDF/B-VII.1) covered criticality and core sizing, reactivity-limited lifetime, temperature feedback, shutdown margin, and post-trip xenon. **In progress:** a six-family real-life scenario register and the failure campaign, including the structural and thermal finite-element stand-up (MOOSE-class tools) needed for the destructive boundary. **Owed:** a stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, materials qualification, and a DOE-authorized test unit. Every result produced to date is unqualified screening, an input to design, not credited analysis.
[The validation program and the failure campaign →](https://rankshieldenergy.com/testing)

## 06 · Policy issues
We would rather surface the novel regulatory questions early than discover them late. The ones we see for a design of this class are:

- **HALEU fuel.** Security category and safeguards treatment for 19.75% HALEU in a microreactor.
- **Non-light-water coolant.** Regulatory treatment, phenomena, and source term for a sealed sodium heat-pipe system under the Part 57 and Part 53 frameworks.
- **Factory-sealed, transportable modules.** Fabrication under NRC oversight, transport of a sealed unit, and site acceptance of a module built elsewhere.
- **Emergency planning.** How a mechanistic source term and functional containment support a right-sized emergency planning zone.
- **Staffing and operations.** Control-room staffing and remote-monitoring expectations for a small, passively-safe, multi-module plant.
- **The verification layer.** Classification of a networked digital attestation layer as non-safety and observe-only behind a hardware one-way path, and its cyber-security treatment.
- **Physical security and multi-module siting.** Right-sizing physical protection and licensing a number-up fleet of identical modules on one site.
None of these is a reason the design cannot be licensed. They are the conversations we want to have with NRC staff during pre-application so the eventual application resolves them rather than raises them.

## 07 · Preliminary timeline
We publish a phased path rather than committed dates. Stating a firm schedule for a first-of-a-kind reactor would be the kind of unbacked claim this whole program is built to avoid. The sequence, with each phase gated on the one before it, is:
NOW

**Phase 0: Pre-application preparation**
Design of record consolidated and adversarially verified; core reactor-physics screening runs complete, with named re-runs (including heat-pipe void geometry) still pending; the proposed Part 57 microreactor framework identified as the primary licensing target with Part 53 as backup; the request for initial NRC engagement is being prepared and has not yet been made. All results are unqualified screening (pre-QAPD).

NEXT

**Phase 1: Quality program & design maturation**
Stand up an NQA-1 quality-assurance program; mature the design toward a licensing basis; develop the Regulatory Engagement Plan and the topical-report sequence.

THEN

**Phase 2: Independent validation & test data**
Confirm the physics with independent codes and, ultimately, test data; structure a DOE-authorized test unit so its NQA-1 data credits into the commercial case; qualify materials.

THEN

**Phase 3: NRC application**
Submit under 10 CFR Part 57 once the rule is final, or under Part 53 as the backup pathway. The specific licensing action is being scoped in the Regulatory Engagement Plan.

GATED

**Phase 4: Construction & first operation**
Contingent on successful licensing, independent validation, and validated offtake demand. We publish no committed dates and make no schedule guarantee.

Readiness posture
HELIX is in active pre-application development, targeting the NRC's proposed 10 CFR Part 57 microreactor framework with Part 53 as the backup pathway. Every figure is a design target; every physics result is unqualified screening (pre-QAPD). The remaining path is defined and stated: a stood-up NQA-1 quality program, independent validation, NRC licensing, and validated demand.
RankShield Energy · HELIX · pre-application

[Contact the program to begin engagement →](https://rankshieldenergy.com/contact)



---

## Page: https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms/

# Automation vs Remote vs Autonomous Reactor Operation

> Automation, remote operation, and autonomy are not the same, and the difference is regulatory. See what each term means for microreactors under Part 57.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# Automation, Remote Operation, and Autonomy: What the Terms Actually Mean
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Automation, remote operation, and autonomous operation are three different things. Automation is a machine performing a defined function. Remote operation is command and control from outside the site boundary. Autonomous operation is a system acting across a range of conditions without an operator directing each action. The differences are regulatory rather than stylistic, and unmanned, the word that turns up most often in vendor decks, is not a regulatory category at all.
The terms get used interchangeably, and the substitution almost always runs uphill, toward the more impressive claim. That would be a harmless habit if the words were only descriptive. They are not. Proposed 10 CFR Part 57, published by the NRC on May 1, 2026, contemplates remote operation and reduced on-site staffing [[1]](#src-1), and it is proposed rather than final, with a comment period that closed in June 2026. Underneath it, the current requirement is unchanged: 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2). Human involvement in safety-significant actions is the baseline, and no facility is licensed to operate unattended.
This article defines each term, separates remote operation from monitoring, explains what each word implies about who must verify what, sets out how proposed Part 57 frames the question, argues that unmanned should be retired from the vocabulary, and gives four questions that test a developer's usage inside one meeting. It also states the obvious objection to all of this and answers it, and names an honest limitation of the framework. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[13]](#src-13), and the closing section applies the same test to our own language.
Key takeaways

- Automation, remote operation, and autonomous operation are three independent properties, and a facility can have one without the others.
- Remote operation means command and control from outside the site boundary; monitoring means observing plant data and issuing nothing.
- Autonomy is a claim about behavior in conditions that were not individually enumerated, which is why it carries the heaviest evidence burden.
- Proposed Part 57 contemplates remote operation and reduced staffing, but it is proposed, not final, and the comment period closed in June 2026.
- Unmanned is not a regulatory category, no facility is licensed to operate unattended, and 10 CFR 50.54(m) still requires a licensed operator at the controls.

## The three terms describe three different things
Start with plain definitions, because everything downstream depends on them. **Automation** is a machine performing a defined function: a condition is met, and logic fixed in advance executes a response. **Remote operation** is command and control exercised from outside the site boundary, by a qualified person who is not physically at the plant. **Autonomous operation** is a system acting across a range of conditions without an operator directing each action. Those are three separate properties, and a facility can have any one of them without the other two.
The confusion is not random. It runs in one direction, from the weaker claim toward the stronger one. Automation sounds like autonomy, autonomy sounds like nobody is on site, and nobody on site sounds like a settled fact. Each step in that chain is a separate claim requiring separate evidence, and collapsing them lets a speaker inherit the conclusion without doing any of the work.

Four terms used about reactor operation, plus one that is not a regulatory category

Term
What it means
Who or what acts
Regulatory note

Automation
A machine performs a defined function when a defined condition is met
The machine, following logic fixed in advance by people
Long established in reactor instrumentation and control. Does not by itself change staffing requirements [[7]](#src-7)

Offsite monitoring
Plant data is collected and observed from away from the site
People observing. No commands are issued
Treated in human factors research as a topic distinct from remote operation [[3]](#src-3)

Remote operation
Command and control exercised from outside the site boundary
A qualified person, located elsewhere
Contemplated in proposed Part 57, which is proposed and not final [[1]](#src-1). Current 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2)

Autonomous operation
A system acts across a range of conditions without an operator directing each action
The system selects the response; a person supervises
Subject of national laboratory work on licensing implications, including control room location and licensed operator provisions [[4]](#src-4)

Unmanned
Marketing shorthand for nobody being present
Unstated, which is the problem
Not a regulatory category. No status a facility can hold, and no facility is licensed to operate unattended

Note what the table does not contain: a row where the accountable human disappears. Automation reallocates a task. Remote operation relocates a person. Autonomy changes how instructions are issued. None of the three, on its own, removes the requirement that a qualified person is answerable for safety-significant actions, and the human factors literature names offsite monitoring and remote operation as distinct research subjects for exactly that reason [[3]](#src-3).

## The words matter because they carry regulatory weight
The reason to be strict here is not linguistic hygiene. Each term maps to a different set of regulatory questions, and answering the wrong set is how a program discovers late that it assembled evidence nobody asked for.
Automation raises questions about whether the logic does what it is specified to do and how functions are allocated between machine and operator. Remote operation raises questions about the control room itself: where it is, whether it is co-located with the plant, and what happens when the link degrades. Oak Ridge found that autonomous control reaches past staffing into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications, with the control room possibly not co-located with the plant [[4]](#src-4). Brookhaven, working for the NRC, framed the safety question for facilities without main control rooms as verifying that important human actions can be accurately and reliably performed [[8]](#src-8).
The evidence burdens differ in the same pattern. For automation, the burden sits largely inside the plant, where an operator can observe the function and an inspector can examine it in place. For remote operation, part of that burden moves onto a network, because the live questions become whether the command that was sent is the command that executed and whether the reported state is the real state, which is the problem we take apart in [trusting a remotely operated reactor](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state). For autonomy the burden shifts again, toward records that a party other than the operator can check, which is the whole distance between [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The obvious objection is that this is pedantry, and that everyone in the room knows roughly what is meant. Sometimes that is true. But precision matters when the words carry regulatory weight, and these words do. A claim of remote operation invites questions about staffing rules and control room location that a claim of automation does not raise at all. And if a developer uses the strong word in a sales deck and the careful word in a regulatory submission, that is not an inconsistency of style. It is a gap between two audiences, and the docket is permanent.

## Automation is a machine performing a defined function, and it is not new
Automation is the least remarkable of the three words, which is precisely why it gets dressed up. A defined function executes when a defined condition is met, following logic fixed in advance by people who anticipated the condition. Reactors have run on that principle for decades. Protective functions, interlocks, and control loops are automation, and they were automation long before the word started appearing on slides.
Treating automation as a new capability inverts the actual design question. Sandia National Laboratories, examining human factors considerations for automating microreactors on behalf of the NRC, frames the work as how functions are allocated between people and machines rather than whether machines act at all [[7]](#src-7). Allocation is a design decision with consequences for workload, situational awareness, and what the operator is expected to notice. It is not a switch that gets flipped to on.
What automation is not is a staffing claim. Adding automation does not, by itself, change how many licensed operators a facility needs or where they are required to be. That is set by the license and by the rules, and under the current framework a licensed operator is required at the controls at all times [[2]](#src-2). A vendor can automate a great deal and still be subject to exactly the staffing requirements that applied before.
So when someone says the reactor is highly automated, the accurate reading is that it does what reactor instrumentation and control has done for a long time, hopefully well. That is a genuine engineering achievement and this is not a criticism of it. It is simply not a claim about autonomy, and it should not be permitted to become one in the following sentence. A useful probe: ask what the machine does when a condition arises that was not anticipated in the fixed logic. Automation has a clean answer. It does what it was told, or it trips.

## Remote operation is command and control from outside the site boundary
Remote operation means the person exercising command and control is outside the site boundary. The boundary is the entire content of the word. Everything else about that person, the qualification, the accountability, the expectation that a human remains in the loop for safety-significant actions, is intended to survive the move rather than be dissolved by it.
The concept is not speculative. Oak Ridge has published on remote control of reactors as an active research direction [[6]](#src-6), and in July 2026 Idaho National Laboratory reported that researchers achieved remote, autonomous power control of a research reactor in real time [[9]](#src-9). Read that carefully before repeating it. A research reactor, inside a research program. It shows the capability is technically reachable. It does not establish that a commercial power reactor may be operated that way, and the two should never be quoted as if they were the same result.
Because the current framework requires a licensed operator at the controls at all times [[2]](#src-2), remote operation of a commercial plant is not something a developer can simply elect to do. Proposed Part 57 contemplates remote operation and reduced on-site staffing [[1]](#src-1), which is why the proposal draws so much attention, and it remains proposed rather than final.
The verification consequence arrives immediately. When the operator is on site, a large amount of confirmation happens through presence: things are seen, heard, and walked past. When the operator is a network away, that confirmation has to travel as data, and data can be stale, mistaken, or altered without anyone in the loop noticing that it has been. Establishing that both the command and the reported state are genuine is a distinct engineering problem from operating the reactor, and it is the one taken apart in our piece on [command and state in a remotely operated reactor](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state).

## Monitoring is not remote operation, and the difference is whether anyone can act
Monitoring is collecting and observing plant data. Remote operation is issuing commands that change what the plant does. The difference is whether anyone at that console has the authority and the means to act, and it is the single most useful distinction in this entire vocabulary.
The research community keeps them apart deliberately. The NRC and Idaho National Laboratory characterized the human factors of offsite monitoring and remote operation as two named topics inside one study, rather than as one topic with two labels for it [[3]](#src-3). That separation is not editorial fussiness. Observing a plant and commanding a plant place different demands on the person, the interface, and the network between them.
This is also where promotional language does its quietest work. A company describes a remote monitoring center, shows a wall of live plant data, and lets the audience conclude that the plant is being run from that room. Both descriptions can be simultaneously true of different systems, but they are different capabilities with different regulatory footprints, and one of them touches the controls while the other does not. The question to ask is blunt and it has a one-word answer. From that console, can anyone change reactor power?
The distinction gets sharper at fleet scale. Sandia, working for the NRC, described designs in which one control room supervises multiple microreactors [[7]](#src-7). Watching many units from one room is an operations and staffing design. Commanding many units from one room is a different proposition with different failure modes and a different evidence burden, which is why [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) is a harder problem than the single-unit case rather than the same problem repeated.

## Autonomous operation means acting across conditions without an operator directing each action
Autonomous operation means a system acts across a range of conditions without an operator directing each action. The load-bearing phrase is the range of conditions. Automation handles the conditions its designers enumerated in advance. Autonomy is a claim about behavior in conditions that were not individually enumerated, which is exactly why it is the harder thing to license and the harder thing to evidence.
Oak Ridge set out concepts for autonomous operation of microreactors and named the preconditions plainly, including sensor and instrumentation technologies capable of long-term unattended operation and complete system state awareness [[5]](#src-5). Neither of those is a small ask, and neither is satisfied by better software alone. The same laboratory mapped the licensing side separately, finding that autonomous control touches manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications [[4]](#src-4).
Capability in research settings is real and worth stating accurately. Idaho National Laboratory reported remote, autonomous power control of a research reactor in real time [[9]](#src-9), and the Department of Energy reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10). Note the word simulated in the second one. Both are meaningful results. Neither is a licensed commercial reactor operating without an operator, and neither should be cited as though it were.
Autonomy is also not binary, which is why the yes-or-no question is the wrong one. There is a spectrum running from supervisory control, where a person approves what the system proposes, through to systems that select their own responses within a bounded envelope. The better question is which specific decisions the system makes on its own, and what evidence exists that it made them correctly. When no operator is directing each action, the record of what the system did becomes the primary account of what happened, so the record has to be checkable by someone other than the party that produced it. That is the argument developed in [how to verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## Proposed Part 57 treats these separately, and it is proposed, not final
On May 1, 2026 the NRC published proposed 10 CFR Part 57, a licensing framework for microreactors and other reactors with comparable risk profiles [[1]](#src-1). Three qualifiers travel with every mention of it. It is proposed, not final. The comment period closed in June 2026. And no developer is licensed under it, because it is not yet a rule. Anyone describing Part 57 as the framework they operate under today is describing a document, not a permission.
The proposal sits on top of earlier staff work rather than appearing from nowhere. NRC staff set out policy and licensing considerations related to micro-reactors in SECY-20-0093 [[12]](#src-12), and the agency maintains a public page tracking its microreactor regulatory activities [[11]](#src-11). The direction of travel is visible in that record. The destination is not fixed, and the difference between those two statements is where most overclaiming happens.
What has not changed is the current requirement. 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2). Human involvement in safety-significant actions is the operating baseline rather than an optional design choice, and no facility is licensed to operate unattended. Proposed Part 57 is worth reading closely, and we walk through it in [Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), but reading a proposal is not the same as being governed by one.
Which brings us to the word that should be retired. Unmanned is not a regulatory category. It appears in no framework as a status a facility can hold, it maps to no defined set of requirements, and there is no application a developer can file to become it. When it turns up in a deck it is doing promotional work by borrowing the shape of a regulatory term without the substance of one. The same applies to fully autonomous, a phrase that sounds like a specification and functions as a mood. Both describe an end state that no operating framework currently recognizes, so both cost precision and buy nothing.

## How to test a vendor's usage of these words in one meeting
Four questions will tell you, inside a single meeting, whether a developer is using this vocabulary carefully or decoratively. Ask them in order, because each one narrows what the next answer can be.
**One.** From your remote center, can anyone change reactor power, or only observe it? This separates monitoring from remote operation and it has a one-word answer, so hesitation is itself informative. **Two.** Which specific decisions does the system make without an operator directing them? Vagueness here is the clearest tell in the whole exchange. **Three.** Under what rule do you expect to operate that way, and what is that rule's status today? A careful answer names proposed Part 57 and volunteers, unprompted, that it is not final [[1]](#src-1). **Four.** Who other than you can check that the reactor did what you say it did? That question separates a story from an architecture.
An honest limitation applies to everything above. The definitions in this article are working definitions, assembled from national laboratory research and a proposed rule, not codified regulatory definitions lifted from a final framework. Reasonable engineers place the boundary between automation and autonomy in different spots, and if Part 57 issues in changed form some of this vocabulary will shift with it. Treat this as a usable framework for reading claims, not as settled terminology to quote back at a regulator.
Our own usage belongs under the same test. RankShield Energy is a pre-applicant engaged in early interaction with the NRC, holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the agency [[13]](#src-13). We do not describe our work as unmanned or as fully autonomous, and we treat both descriptions as inaccurate rather than as aspirational shorthand. What we build is the assurance layer: evidence about what a reactor did that a party other than the operator can check. If you want these questions turned on developers generally, including on us, they are collected in our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor).

## Frequently asked questions

### What is the difference between automation and autonomy in a reactor?
Automation is a machine performing a defined function when a defined condition is met, following logic fixed in advance by people who anticipated that condition. Autonomy is a system acting across a range of conditions without an operator directing each action, including conditions that were not individually enumerated. That is why the licensing questions differ. Sandia frames the automation problem as how functions are allocated between people and machines [[7]](#src-7), while Oak Ridge, addressing autonomous operation, names preconditions such as long-term unattended sensing and complete system state awareness [[5]](#src-5). Automation is decades old in reactors. Autonomy is a stronger claim that has to be evidenced separately.

### Is remote operation the same as remote monitoring?
No, and conflating them is the most common error in this vocabulary. Monitoring is collecting and observing plant data. Remote operation is exercising command and control from outside the site boundary, meaning someone can change what the plant does. The NRC and Idaho National Laboratory characterized offsite monitoring and remote operation as two distinct human factors topics inside a single study rather than as one topic [[3]](#src-3). The practical test is a single question: from that console, can anyone change reactor power? If the answer is no, what you are looking at is monitoring.

### Does proposed Part 57 allow unmanned reactors?
No. Unmanned is not a regulatory category at all, so no rule grants it. Proposed 10 CFR Part 57 contemplates remote operation and reduced on-site staffing, and it was published on May 1, 2026 [[1]](#src-1). It is proposed rather than final, the comment period closed in June 2026, and the rule may change before it issues. Meanwhile 10 CFR 50.54(m) requires a licensed operator at the controls at all times [[2]](#src-2). Human involvement in safety-significant actions remains the baseline, and no facility is licensed to operate unattended.

### Has anyone actually demonstrated autonomous reactor control?
In research settings, yes, and the qualifier matters. Idaho National Laboratory reported in July 2026 that researchers achieved remote, autonomous power control of a research reactor in real time [[9]](#src-9). The Department of Energy separately reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10). Both are real results from national laboratory programs. Neither is a licensed commercial power reactor running that way, and citing them as if they were is exactly the slippage this article is about.

### Why does RankShield Energy avoid the words unmanned and fully autonomous?
Because we think both are inaccurate, not because they are impolite. Unmanned corresponds to no regulatory status a facility can hold, and fully autonomous describes an end state no current operating framework recognizes. Using either would mean claiming something that cannot be checked against any rule. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval [[13]](#src-13). Our work is the assurance layer, meaning evidence about reactor behavior that a party other than the operator can verify, and we would rather describe that precisely than reach for a word that sounds larger.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Trusting a remotely operated reactor →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects reactor-operation terminology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations/

# Digital Twin as a Remote Reactor Verification Layer

> A digital twin can do more than simulate. See how it becomes a verification layer that independently confirms reactor state for remote and autonomous operation.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# The Digital Twin as a Verification Layer for Remote Reactor Operations
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. A digital twin becomes a verification layer, rather than a simulation, when an independent party uses it to confirm that a reactor’s reported state matches what its physics and its design permit, and records that confirmation so someone outside the control room can check it later. A twin that only mirrors the operator’s own model reassures the operator. A twin used as an independent check tells an outsider something they can rely on. The difference is who runs it.
"Digital twin" now appears in nearly every advanced-reactor pitch, usually offered as proof that the vendor understands its own machine. Understanding your own machine is table stakes. The harder question, for a reactor designed to run remotely and with fewer people on site, is whether the twin can tell an outside party something that party can trust. In July 2026 Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[4]](#src-4). The MARVEL microreactor experiment pairs remote monitoring with a digital twin that supports operator functions [[2]](#src-2), and proposed federal rules now contemplate exactly this kind of remote, reduced-staffing operating model [[10]](#src-10).
This article is educational. It sets out what separates a twin that simulates from a twin that verifies, why that separation depends on who owns the twin, what the standards world already worked out about independent checking, why remote and autonomous operation raises the stakes, and what has actually been demonstrated so far. The part most vendor material skips is the last one. RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission, engaged in early regulatory interaction and holding no license or approval; the closing section applies the argument to us as unsentimentally as to anyone else.
Key takeaways

- A twin that mirrors the operator's own model is simulation; a twin that confirms measured reactor state against model and design limits is verification.
- Verification requires closing the loop: read live measurement, compare it against what the model and design permit, and record any divergence.
- Independence is structural, not intentions: a vendor-internal twin is self-attestation, because the party being checked owns the checker.
- The attestation standards world already split evidence, independent appraisal, and durable records; a verifying twin can borrow that machinery.
- As on-site presence thins under remote-operation rules, more of the safety story rests on self-report, making an independent check more load-bearing, not less.

## Simulation and verification answer opposite questions
A simulation predicts what a reactor should do. A verification layer confirms what the reactor is actually doing. The two use similar math and are easy to conflate, but they point in opposite directions, and a digital twin can be built to serve either one.
A simulation runs the model forward and produces an expected state. It is a forecast. Verification starts from the reactor's reported state and asks whether that state is consistent with the model, the sensors, and what the design permits. It is a check on reality. A twin used purely as a design, training, and monitoring tool is a high-fidelity simulation, and a valuable one. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted the system's thermal behavior and then autonomously controlled it, which is exactly the forecast-and-act pattern a design twin is good at [[1]](#src-1). National-lab work also shows a twin operating alongside remote monitoring in the MARVEL experiment, where the twin is meant to support operator functions rather than replace human oversight [[2]](#src-2).
The problem is that a simulation which agrees with the operator's own assumptions cannot, on its own, tell an outside party that the physical reactor is behaving. It can only tell you the model is internally consistent. To become verification, the twin has to be fed live measurement and made to disagree when the measurement and the model diverge. Not a mirror of the operator's model. A check on it. That shift, from forecasting an expected state to confirming an observed one, is the whole distinction this article is built on, and most vendor material blurs it.

## Closing the loop between measured and modeled state
A digital twin verifies reactor state by closing the loop between measured and modeled state. That means three things happen continuously: the reactor is measured, the measurement is compared against what the model and the design allow, and the comparison is recorded so it can be checked later. A twin that skips any of the three is forecasting, not verifying.
First, live measurement. Temperatures, power level, control positions, and the status of safety functions are read from the reactor itself. Oak Ridge National Laboratory, surveying what autonomous microreactor operation would require, named the preconditions plainly: sensor and instrumentation technologies capable of long-term unattended operation, complete awareness of system state, and control approaches that can act on that awareness [[3]](#src-3). None of the downstream verification works if the measurement layer is thin. Second, comparison. The twin computes what the measured quantities should be, given the model and the commands the reactor received, and flags where measured and modeled values disagree beyond an expected margin. Third, recording. The comparison, and any divergence, is written to a tamper-evident record that a regulator, insurer, or lender can inspect afterward. The path from raw signals to that durable record is its own engineering problem, which we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).
The value of closing the loop is that disagreement becomes visible. A twin that only forecasts will produce a clean-looking state whether or not the hardware agrees with it. A twin that continuously compares measured against modeled state surfaces the gap the moment it opens. When Idaho National Laboratory demonstrated remote, real-time autonomous power control of a research reactor in July 2026, the reactor's safety systems retained control throughout, which is the kind of live, closed-loop operating context in which a verifying twin has to function [[4]](#src-4).

## The independence question: whose twin does the verifying
Closing the loop is necessary but not sufficient. The remaining question is who owns the twin doing the checking. If the operator builds, runs, and interprets its own digital twin, that twin is part of the operator's self-report, however good the engineering is. It is the operator grading its own work, and an outside party has no independent basis to rely on the grade.
Independence here is structural, not a matter of good intentions. A verification result carries weight for a lender, insurer, or regulator only when the party producing it is separate from the party being checked, so the checker has no stake in the reactor looking good. Nuclear already supplies this separation with people rather than software. The NRC stations resident inspectors at operating plants, at least two per site, and describes their function as independently verifying that requirements are being met [[12]](#src-12). The word independently is doing specific work in that sentence: the inspector is not a better observer than the operator, but a differently positioned one. The same reasoning is what separates a twin that reassures from a twin that verifies, and it is the core of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
Applied to a digital twin, independence means the appraisal and the recorded result should sit with a party separate from the operator, rather than inside the operator's own software. A vendor-internal twin answers a narrow question: does our model agree with our model. An independent verification layer answers a harder one: does the reactor agree with reality, in a form someone other than the vendor can check. Those are not the same claim, and conflating them is how a simulation gets sold as an assurance. In my view, drawn from building verification systems rather than operating reactors, this distinction is the entire game, and it is the part a buyer should press hardest.

## Vendor-internal twin versus independent verification twin
The cleanest way to see the difference is side by side. A vendor-internal twin and an independent verification twin can run identical physics and still produce assurances of very different value, because value here comes from who owns the checker and what an outsider can rely on, not from model fidelity. The comparison below is the test to apply to any twin a developer points to.

Vendor-internal digital twin and independent verification twin, compared

Question
Vendor-internal twin
Independent verification twin

Who owns and runs it?
The reactor's operator or vendor
A party separate from operations

What does it actually answer?
Does our model agree with our model
Does the reactor agree with reality, checkably

Who interprets a disagreement?
The operator, privately
The independent verifier, on the record

What can an outsider rely on?
The operator's word
A signed appraisal a third party can check

Characteristic failure mode
Undetectable drift between claim and reality
Detectable divergence, with a timestamped record

The fourth row is where most systems marketed as verification quietly fail. If the only thing an outside party ends up relying on is the operator's word, the twin added polish, not assurance. Computing formalized this split long ago: the RATS architecture defines an Attester that produces evidence, a Verifier that appraises it against a policy, and a Relying Party that acts on the Verifier's result, on the premise that one end of a link needs to know whether the other end is in an intended operating state [[5]](#src-5). A verification twin is that pattern applied to a reactor, with the Verifier deliberately placed outside the operator.

## What the attestation standards already contribute
The independent-checking problem is not new, and the digital-twin conversation does not have to solve it from scratch. Standards bodies outside nuclear have already defined how a separate party appraises a system's reported state and how the result is recorded so anyone can check it later. A verification twin can borrow that machinery directly.
The RATS architecture supplies the roles: evidence, an independent appraisal, and a relying party who consumes the verdict rather than the raw claim [[5]](#src-5). The missing piece, durability, is addressed by transparency work such as SCITT, which describes an append-only, tamper-evident service that issues receipts, so a recorded appraisal can be checked later without asking the operator to vouch for it [[6]](#src-6). Both matter for a reactor precisely because the record needs to outlive the equipment, the software version, and possibly the vendor. On the nuclear side, the guardrails are also taking shape. The NRC has published guidance on digital instrumentation and control for advanced reactors, which is the regulatory frame any verifying twin would have to live inside [[8]](#src-8). The IAEA's guidance on computer security of instrumentation and control systems sets expectations for protecting that measurement and reporting chain across its life cycle, which is exactly the chain a verification twin depends on [[9]](#src-9).
None of this is a RankShield invention, and we do not present it as one. The contribution is applying a settled pattern from computing and international guidance to reactor state, then being honest that the reactor-specific version has not been demonstrated under regulatory review. A standard tells you how independent appraisal should be structured. It does not, by itself, prove that any particular twin is doing it. That gap between an available architecture and a demonstrated capability is where careful reading of vendor claims pays off.

## Why remote and autonomous operation raises the stakes
For a conventionally staffed plant, weak evidence is partly offset by presence: people on site form judgments that instrumentation misses. Thin that presence and the offset goes with it, which is why independent verification moves from good practice to something closer to a requirement as operating models change. The regulatory direction of travel makes this concrete.
Today, federal rules require a licensed operator to be present at the controls at all times [[11]](#src-11). The proposed 10 CFR Part 57 framework contemplates remote operation and reduced on-site staffing for microreactors, a shift explained neutrally in [our walkthrough of Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), and it is a proposed rule, not final, that may change [[10]](#src-10). The national laboratories have been explicit about what this disturbs. Sandia National Laboratories, working on human factors for automating microreactors, described designs in which one control room supervises multiple reactors [[14]](#src-14), which is the [fleet-scale version](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) of the problem and a harder one. Brookhaven National Laboratory, reviewing facilities without traditional main control rooms for the NRC, framed the safety question as verifying that important human actions can still be performed accurately and reliably [[7]](#src-7). Work by the NRC and Idaho National Laboratory on the human factors of offsite monitoring and remote operation points the same way [[13]](#src-13).
Put together, the pattern is straightforward. As on-site presence decreases, the share of the safety story carried by what the system reports about itself increases. A digital twin used as an independent verification layer is one way to keep that curve from ending somewhere uncomfortable, because it puts a separate party between the reactor's self-report and the outside world that has to act on it. Reactivity and safety actions still keep a human in the loop; the twin adds assurance about what is reported, not unsupervised control.

## What has actually been demonstrated, and where it is thin
The honest state of the field is that the operating model is being demonstrated faster than the independent-verification layer for it is being built. That asymmetry is the single most important thing a reader should take from this post, because it is the part vendor decks tend to skip.
On the capability side, the results are real and attributable to the labs. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that forecast the system's behavior and then autonomously controlled it [[1]](#src-1). In July 2026, INL and university partners demonstrated remote, real-time autonomous power control of a research reactor, with safety systems retaining control throughout [[4]](#src-4). The MARVEL experiment pairs a twin with remote monitoring to support operator functions [[2]](#src-2). These are national-lab results, not demonstrations of any commercial reactor's safety, and none of them is RankShield Energy's result.
A fair counterargument is that a sufficiently rigorous vendor-internal twin, audited by regulators, delivers the same assurance without a separate verifier, so the independence point is overstated. The response is that regulatory audit is itself an external check, which proves rather than refutes the point: the assurance comes from a party outside operations, whether that party is an inspector, an auditor, or an independent verifier. Removing the external party is what weakens the claim, not adding one. The honest limitation is that turning demonstrated remote-operation capability into an independent, buyer-facing verification layer, one an outsider can rely on without asking the vendor to vouch for itself, is still in progress across the industry, including at RankShield Energy. Anyone presenting a digital twin as settled proof that an autonomous reactor is safe is overstating where the field is; the accurate framing, for every serious developer, remains design intent subject to analysis, testing, and NRC review. How a buyer should probe a reported state is the subject of [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## Applying this at RankShield, honestly
RankShield Energy treats the independent verification twin as an architecture it applies, not a capability it has deployed or certified. We are a pre-applicant with the NRC, engaged in early regulatory interaction, and we hold no license, permit, or design approval. We have never operated a reactor, and nothing about our approach has been demonstrated to or accepted by the NRC.
What we actually build toward is the separation described throughout this post: an appraisal of reactor state, and the recorded result of that appraisal, sitting with a party structurally distinct from whoever operates the reactor, so that confirming a reported change does not depend on the operator's word. Our real working expertise is in the verification engineering, the signing, the transparency logging, and the independent-appraisal design, not in operating nuclear plants, and we try to keep that line bright. The same separation applies to the harder question of trusting a remotely operated reactor's command state, which a verifying twin only partially addresses.
Stated so it can be argued with: a vendor cannot be its own independent verifier, and that remains true of us, which is why we treat the separation as structural rather than as a feature to bolt on later. The tradeoff is genuine. A separate verifier adds a party to coordinate with and creates a body that can contradict us in public, and we think that last property is the point rather than a defect. If you are evaluating developers on any of this, apply the questions in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) to us as unsentimentally as to anyone else.

## Frequently asked questions

### What is the difference between a simulation and a digital twin used for verification?
A simulation predicts what a reactor should do; a verification twin confirms what the reactor is actually doing and records the result so it can be checked later. Every verifying twin contains a simulation, but not every simulation verifies anything. A twin that only runs the model forward, without being fed live measurement and made to disagree when measurement and model diverge, is a forecast. DOE has reported national-lab work where a twin predicted a simulated microreactor's behavior and then acted on it, which is the forecast-and-act pattern rather than the check-against-reality pattern [[1]](#src-1).

### Can a vendor's own digital twin count as independent verification?
No, not on its own. A vendor-internal twin is run and interpreted by the same party that operates the reactor, which makes it a form of self-attestation: the operator grading its own work. For an outside party such as a regulator, insurer, or lender, the result carries weight only when the appraising party is structurally separate from the operator. Nuclear already supplies that separation with people; the NRC describes its resident inspectors as independently verifying that requirements are being met [[12]](#src-12). An independent verification twin applies the same logic in software.

### What does closing the loop between measured and modeled state mean?
It means the twin continuously does three things: reads live measurement from the reactor, compares that measurement against what the model and the design permit, and records any divergence in a tamper-evident form. A twin that skips the measurement or the recording is forecasting, not verifying. Oak Ridge National Laboratory named the preconditions for this, including sensors capable of long-term unattended operation and complete awareness of system state [[3]](#src-3). Closing the loop is what makes a disagreement between claim and reality visible instead of silent.

### Why does remote or autonomous operation make an independent twin more important?
Because on-site presence was quietly doing part of the assurance work. Current rules require a licensed operator at the controls at all times, while the proposed Part 57 framework contemplates remote operation and reduced staffing, a proposed rule that is not final [[10]](#src-10). National-lab research has described one control room supervising multiple microreactors [[14]](#src-14). As presence thins, more of the safety story rests on what the system reports about itself, which makes an independent check on those reports more load-bearing, not less. Safety actions still keep a human in the loop.

### Does RankShield Energy have a working independent verification twin today?
No, not as a deployed or certified capability. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval, and we have never operated a reactor. The independent verification twin is an architecture we apply and build toward, drawing on established attestation and transparency patterns, but describing an architecture is not the same as having demonstrated it under regulatory review [[10]](#src-10). We would rather state that plainly than let the distinction blur, because the distinction is the entire argument.

## Sources

- [U.S. DOE Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)

## Related

- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [From reactor sensors to an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor digital-twin and remote-operations work as of July 2026. This area is evolving rapidly; national-lab demonstrations are research results, not commercial approvals, and this page will be reviewed as new results are published.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/evidentiary-standards-machine-generated-reactor-records/

# Evidentiary Standards for Machine-Generated Records

> Machine-generated reactor records are becoming the evidence regulators, insurers, lenders, and grid operators rely on. No accepted standard exists yet.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# What Makes a Machine-Generated Reactor Record Admissible Evidence?
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published July 24, 2026 Revised July 24, 2026 Status Issued for technical comment Scope of the term admissible Capable of being relied upon by a regulator, insurer, lender, or grid operator. This paper contains no analysis of legal admissibility. Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
As reactors move toward reduced-staff operation, a growing share of what a regulator, insurer, lender, or grid operator knows about a facility will arrive as a record produced by a machine rather than reported by a person who was present. This paper asks what properties such a record needs before a party that was not present can rest a decision on it. It states six properties, attributable, complete, contemporaneous, tamper-evident, independently checkable, and durable, defines each, and tests each against the published standards record and the published nuclear oversight record. Admissible is used throughout in a technical sense, meaning capable of being relied upon by those four parties; the paper contains no analysis of legal admissibility and offers no legal advice.
The finding is an absence. Published standards supply form for four of the six properties and supply nothing for two, and no accepted evidentiary standard for machine-generated reactor state appears anywhere in the record cited here. Naming that gap precisely, together with the parties who would have to close each part of it, is the contribution offered. The principal limitation is that the paper is written by an interested party: RankShield Energy is a pre-applicant developing an independent verification layer, and the gap described would be commercially convenient for us to describe. Section 8 applies the six properties to our own position and reports where we fail them.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses the properties a machine-generated record of reactor state would need in order to be relied upon by a party that was not present at the facility. Relied upon means used as a basis for a decision by a regulator, an insurer, a lender, or a grid operator. That is the sense in which the word admissible is used in the title and throughout, and it is the sense in which every conclusion below should be read.
What this paper deliberately does not do is as important as what it does. It contains no analysis of legal admissibility, no interpretation of any statute or procedural requirement governing legal proceedings, and no legal advice. Questions about legal proceedings belong to counsel and are outside the scope of this document and the competence of its author. The paper also contains no design detail for any RankShield Energy system, no geometry, no fuel description, and no performance or lifetime figures; it contains no cost or economic analysis; it does not interpret what any rule requires of a third party; and it does not name, rank, or characterize other developers. It does not describe unattended reactor operation. The operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification function under discussion is an assurance function and not a control function.
It draws on twenty primary sources spanning the regulator, the Government Accountability Office, national laboratories, standards bodies, and the International Atomic Energy Agency. Several developments would change its conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft guidance for applications under it, publication of acceptance criteria for automated operating records, a qualification route for an independent verifier, or a published demonstration in which a record of this kind was relied upon in a regulatory determination.

A regulator, an insurer, a lender, and a grid operator share a problem with each other and with almost nobody else in the nuclear supply chain: each has to reach a conclusion about a facility that none of them is standing in. Historically that problem was managed by putting people on site and having them look. As reactors move toward reduced-staff operation, more of what those parties know will arrive as a record produced by a machine. This paper asks what properties such a record needs before a party that was not present can rest a decision on it.
The question has not been posed to the nuclear sector in that form. There is a mature body of work on making a digital record trustworthy in general computing, and a mature body of work on how the NRC oversees operating plants, and remarkably little joining the two. This paper joins them by stating six properties, testing each against what published standards supply and what the nuclear record supplies, and stating plainly where the join fails. The failure is the contribution: no accepted evidentiary standard for machine-generated reactor state appears in the record cited here, and a gap named precisely is more useful to a reviewer than a gap papered over.
Two framing points govern everything below. Relied upon means capable of being used as a basis for a decision by a party that was not present, and nothing in this paper concerns legal proceedings, legal standards of proof, or legal advice. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC and holds no license, permit, or design approval [[20]](#src-20); nothing described here has been demonstrated to or accepted by the NRC. Section 8 applies the paper's own test to our position and reports the places where we fail it.
Key takeaways

- Admissible is used here in a technical sense: capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present. This paper contains no analysis of legal admissibility and no legal advice.
- Six properties recur across the four relying parties: attributable, complete, contemporaneous, tamper-evident, independently checkable, and durable. Tamper-evident is a detection property, not a prevention property.
- Published standards supply form for attribution, tamper-evidence, independent checkability, and durability. They supply nothing for completeness and contemporaneity, which are properties of instrumentation rather than of cryptography.
- No acceptance criteria for machine-generated reactor state appear in the cited record, and form is not acceptance. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) and its associated draft staff guidance are where such criteria could appear.
- The parties who would close the gap mostly do not sell anything: the regulator for acceptance, standards bodies for form, research organizations for validated method, and licensees for the operating experience that calibrates any criterion.

## 1. What relied upon means here, and what this paper is not
Relied upon, in this paper, means capable of being used as a basis for a decision by a party that was not present when the thing recorded happened. That party may be a regulator forming a view about compliance, an insurer pricing a risk, a lender testing a covenant, or a grid operator committing capacity. The definition is deliberately practical. It asks whether a record changes what a decision-maker does, not whether it satisfies any formal standard of proof.
What this paper is not needs stating with equal precision. It is not an analysis of legal admissibility, and it takes no position on whether a record of the kind described would be received in any legal proceeding. Where the word admissible appears in the title of this paper, it carries the technical-reliance meaning defined above and nothing further. Questions about legal proceedings belong to counsel and sit outside the scope of this document. The nature note above applies without qualification: this is technical analysis and is not legal, regulatory, engineering, or investment advice.
The question arises now because of a change in operating model rather than a change in law. Oak Ridge National Laboratory research on concepts for autonomous operation of microreactors describes an architecture in which monitoring, diagnosis, and supervisory functions are performed by systems rather than by people watching instruments [[17]](#src-17). Brookhaven National Laboratory, in contractor analysis prepared for the NRC, reviews reactor facilities operated without a conventional main control room and sets out what changes when the crew is not co-located with the plant [[18]](#src-18). The licensing frame usually cited in this context is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[11]](#src-11).
The consequence is a change in the character of the evidence rather than in its volume. When an inspector is on site, the record and the observer are separable: a licensee log can be checked against what a person saw, and a person can be asked a question the log did not anticipate. As on-site staffing reduces, the record and the observer converge, because the instrument producing the record becomes the principal observer. A relying party then depends on properties of the record itself rather than on corroboration from somebody who was there.
Claim types are distinguished throughout, because a reviewer left to do that sorting resents it. Requirements in force are identified as in force. Proposals are identified as proposals and carry their status at every mention. Staff and contractor documents are labeled as staff or contractor documents at every mention. Published standards are described by what they specify, never by what they might be taken to imply. Everything remaining is our analysis, and where our reading differs from a common industry reading we say so, so that the disagreement can be argued with.

## 2. Who the relying parties are, and what each of them needs
The four relying parties are usually collapsed into one in vendor material, which obscures the fact that their questions differ in ways that change what a record must contain. A regulator asks whether a licensee is operating inside its licensing basis and whether the licensee's own account of that is reliable. The NRC's Reactor Oversight Process combines baseline inspection, performance indicators, a significance determination process, and assessment [[7]](#src-7), and the Government Accountability Office has examined how heavily agency safety conclusions rest on the information that process produces [[9]](#src-9).
An insurer asks a different question. Its interest is in the distribution of losses across a population and over time, so it needs a record that is complete for a period rather than accurate at an instant. A gap in an insurer's record is worse than a lower-resolution record without gaps, because a gap is where an adverse event is most likely to be hiding. An insurer also needs the record to survive the event it describes, which is a durability requirement rather than an accuracy requirement.
A lender's question concerns performance against commitments over the term of the debt, which may be decades. That imposes a requirement almost nobody designs for: the record has to remain checkable long after the software that produced it has been retired, and after the cryptography protecting it has aged. A lender is also the party most likely to want a record produced or appraised by somebody other than the borrower, because the borrower's incentive to present favorably is structural rather than dishonest.
A grid operator's question is the narrowest in time and the most demanding in latency. It needs to know whether capacity committed for the next interval will be delivered, which makes freshness the dominant property and long-term durability close to irrelevant. A record that is authoritative and an hour old is of limited use for dispatch, while an hour-old record may be entirely adequate for an insurer pricing an annual policy. The same record cannot be optimised for both without being designed for both.
The mature example of an independent party drawing conclusions from declarations, measurements, and inspection rather than from presence alone is the IAEA safeguards system [[16]](#src-16). It is instructive rather than transferable, since safeguards address material accountancy under international agreements rather than operational state under a domestic license. The practical point is that these four sets of requirements do not reduce to one another, so a record designed around whichever party is nearest at hand will disappoint the other three. Our companion note on [what a reactor's sensors can and cannot attest](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) works the same problem from the instrument end.

## 3. The six properties a record needs
Working back from those four sets of needs, six properties recur. They are stated here as a checklist a technical reviewer can apply to any proposed record, including ours. None of the six is novel in general computing. What the field lacks is the assembly, applied to reactor state, with an honest assessment of which are supplied today.
1. Attributable. The record identifies the system that produced it and the configuration that system was running, checkably and without asking the producer. RFC 9334, the RATS architecture, treats this as the base case: evidence carries the identity and software state of the attester [[1]](#src-1). A record whose origin rests on the reporting organization's assurance gives a relying party nothing new.
2. Complete. The record covers a defined period with no undeclared gaps, and any gap that occurs is itself recorded. Every relying party reads absence of an alarm as evidence of a normal condition. That inference holds when a silent instrument is distinguishable from a quiet plant, and fails when it is not.
3. Contemporaneous. The record is generated as events occur rather than reconstructed afterwards, and it carries a time reference that can be checked against an external source. A reconstruction reflects what its author believed later, and the difference between the two is precisely what an investigation exists to find.
4. Tamper-evident. Later alteration of the record is detectable by a party holding no privileged access to the system that produced it. This is detection and not prevention. A record of this kind is not tamper-proof, not unhackable, and not unbreakable; a vendor using those words about a digital record is describing an aspiration. Append-only structures make undetected alteration expensive rather than impossible.
5. Independently checkable. A relying party can verify the record without the producer's cooperation, tooling, or continued existence. The parties who need the record most are those with least leverage over its producer at the moment they need it.
6. Durable. Both the record and the means of checking it survive the period over which decisions rest on them: for a lender the term of the debt, for a regulator possibly the life of the facility. A scheme with a shorter useful life than the asset transfers the problem rather than resolving it.
The six interact, and treating them as a menu is an error. Completeness and contemporaneity together are what allow silence to be informative. Attribution and independent checkability together separate a verified record from a well-formatted claim. Durability constrains the cryptography chosen for tamper-evidence. The table states what supplies each property today and what remains unresolved for reactor state.

Six properties of a machine-generated reactor record: what supplies each today, and what remains unresolved

Property
What supplies it today
What remains unresolved for reactor state

Attributable
RFC 9334 makes attester identity and software state part of the evidence; device identity is ordinary practice in general computing
No qualification route for the identity of nuclear instrumentation, and no criteria stating which configuration detail must be attested

Complete
Nothing in the cited record. Completeness is a property of instrumentation, coverage, and data handling rather than of any standard cited here
How a gap is declared, what sensor coverage suffices, and when silence may be read as evidence of a normal condition

Contemporaneous
Nothing in the cited record for the measurement itself; COSE receipts fix the time a statement was registered, which is later than the event
What time source is acceptable, how clock drift is bounded, and how a measured value is distinguished from a value inferred after the fact

Tamper-evident
SCITT transparency service with an append-only log; COSE receipts as verifiable inclusion and consistency proofs
Who operates a transparency service for a licensed facility, and whether a receipt is treated as anything at all by a regulator

Independently checkable
The RATS separation of attester, verifier, and relying party; receipts checkable without the issuer's cooperation
Who qualifies a verifier, against what criteria, and how independence from the operator is established and maintained over time

Durable
The 2024 NIST post-quantum standards, including FIPS 204, give a migration target; SP 800-161r1 addresses supply-chain practice
Retention periods, re-signing practice across facility lifetimes, and custody of the record if its producer ceases to exist

Two cautions. The middle column describes what a standard specifies, not what any regulator has accepted, and that distinction is the subject of sections 6 and 7. The right-hand column is written from the record cited here; a reader able to close a cell with a source we have missed would be doing us a service.

## 4. What today's record actually is, and where its limits lie
What a relying party receives today, for an operating power reactor, is largely a record generated by the licensee: control room logs, plant computer histories, procedures with signatures, reports made under license conditions, and dashboards derived from all of it. The quality of that record varies between organizations and over time. The reason the variation has been tolerable is that the record was never the sole basis for anybody's conclusion.
Presence has substituted for record quality. Licensed-operator conditions attach to a power reactor license under 10 CFR 50.54(m), a requirement in force [[10]](#src-10), and the NRC assigns resident inspectors to operating sites with access to the facility, its people, and its records [[8]](#src-8). The Reactor Oversight Process assembles that inspection with performance indicators and a significance determination process into an assessment [[7]](#src-7), and the Government Accountability Office has documented how heavily agency safety conclusions rest on the information the process produces [[9]](#src-9).
That substitution is worth stating plainly, because it is the assumption most at risk in a reduced-staffing model. A licensee log carries weight partly because an inspector could have watched the same shift, can ask about an entry, and can compare it against what people at the site say. The record is corroborated by a presence that never appears in the record. Remove the presence and the record is asked to carry a load it was not designed to carry, without anything in its construction having changed.
The technical literature is candid about this. Brookhaven National Laboratory, in contractor analysis prepared for the NRC, examines facilities operated without a conventional main control room and identifies what changes when the operating crew is not co-located with the plant [[18]](#src-18). Oak Ridge National Laboratory research on concepts for autonomous microreactor operation describes layered monitoring and diagnostics as the substitute for continuous human observation [[17]](#src-17). Both are research and contractor products rather than requirements, and both are best read as statements of what specialists regard as unsettled.
A further element of today's record is model output rather than measurement. The Department of Energy reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor [[19]](#src-19). A twin is a powerful diagnostic aid and a weak evidentiary artefact, because its output is a function of its assumptions as much as of the plant. A relying party asking what the plant did needs the measurement; a relying party asking what the plant would do under a hypothetical needs the model. Our explainer on [how to verify that an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) keeps the two apart deliberately.

## 5. What published standards already provide
Four bodies of published work supply parts of the six properties, and not one of them was written for this application. RFC 9334 specifies the RATS architecture, which separates three roles: an attester that produces evidence about itself, a verifier that appraises that evidence against an appraisal policy, and a relying party that consumes the verifier's result and acts on it [[1]](#src-1). The separation is the useful part. It supplies a vocabulary for saying precisely who is asserting what to whom, which most discussion of reactor data lacks.
RFC 9943 specifies the SCITT architecture, in which a transparency service records signed statements about artefacts in an append-only log and issues receipts allowing any party to check that a statement was registered and has not been altered since [[2]](#src-2). What this supplies is tamper-evidence coupled to independent checkability, because a receipt can be verified later without the cooperation of the service that issued it. The pattern was designed for software supply chains, and nothing in it is specific to software.
RFC 9942 specifies COSE receipts, the concrete format for the proofs a transparency service issues, expressed as verifiable inclusion and consistency proofs against the log [[3]](#src-3). Its relevance here is unglamorous and load-bearing: a property with no interoperable wire format is a property that stays inside one vendor's system, and a relying party dealing with four suppliers cannot be expected to check four proprietary proof formats.
Durability is where cryptography becomes a nuclear-timescale problem. NIST announced approval of three federal standards for post-quantum cryptography in August 2024 [[4]](#src-4), among them FIPS 204, the module-lattice-based digital signature standard [[5]](#src-5). A record signed today that must remain checkable across the operating life of a facility is signed with an algorithm whose useful life is a design assumption rather than a certainty. Treating signature agility and re-signing practice as requirements rather than refinements follows directly from the durability property.
NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organizations [[6]](#src-6). It bears on this paper because attribution is a claim about a device and the software that device is running, and a claim about software is worth what the provenance of that software is worth. A record attributable to a device whose firmware provenance is unknown is attributable in form and not in substance, which is a distinction a technical reviewer will make even if a marketing document does not.

## 6. What the standards do not provide
The four bodies of work above supply form. None of them supplies acceptance, and conflating the two is the error this section exists to prevent. RFC 9334, RFC 9943, and RFC 9942 are internet standards with no nuclear regulatory standing whatever [[1]](#src-1) [[2]](#src-2) [[3]](#src-3). Nothing in them establishes that a regulator will treat a record built to their pattern as a basis for a determination, and citing them in a licensing context establishes vocabulary rather than acceptance.
There are also, so far as the record cited here shows, no acceptance criteria to meet. The NRC publishes guidance on digital instrumentation and controls for advanced reactors [[13]](#src-13) and treats cybersecurity as part of its protective mission rather than as an information-technology overlay [[14]](#src-14). Neither addresses the question this paper poses, which is what makes a machine-generated statement about reactor state something a party that was not present can rest a decision on. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[11]](#src-11), together with NUREG-2271, a draft NRC staff guidance document issued for comment and not final guidance [[12]](#src-12), is where such criteria could appear.
The second limit is structural and follows from the architecture itself. RFC 9334 separates the attester from the verifier and from the relying party [[1]](#src-1), which relocates trust rather than removing it. The relying party now has to trust the verifier: its appraisal policy, its software, its independence from the operator, and its continued existence. Who qualifies a verifier, against what criteria, and who checks the verifier, are questions the architecture raises and does not answer. We treat that problem at length in our note on [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The third limit sits upstream of everything above. A cryptographic chain establishes that a value was reported by a particular device at a particular time and has not changed since. It establishes nothing about whether the value was correct when the device produced it. A compromised or degraded sensor produces a perfectly attested wrong number, and no amount of transparency logging converts that number into a fact about the plant. IAEA Nuclear Security Series No. 33-T addresses computer security of instrumentation and control systems at nuclear facilities, which is exactly this layer [[15]](#src-15).
Supply-chain assurance occupies the same position [[6]](#src-6): it raises the cost of a compromise upstream of the record without converting the record into a statement about physical reality. The honest summary is that these standards make a record hard to alter after the fact and leave the question of whether it was correct when written to instrumentation, qualification, and physical and cyber security. Our [microreactor cybersecurity explainer](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained) covers that layer in its own terms.

## 7. The gap, stated precisely
Stated as precisely as we can manage: in the record cited by this paper, there is no accepted evidentiary standard for machine-generated reactor state. There is no published set of properties such a record must have, no acceptance criteria against which one could be assessed, no qualification route for a verifier, and no worked example of a record of this kind being relied upon in a regulatory determination. The absence is not a criticism of any party. The operating models that make the question urgent are themselves proposals and research programs.
Closing that gap is not within the gift of a vendor. Acceptance belongs to the regulator, through rulemaking, guidance, or determinations on individual dockets. Form belongs to standards bodies, which have supplied a good deal of it already [[1]](#src-1) [[2]](#src-2) [[3]](#src-3). Method, meaning validated ways of demonstrating that a record has the properties claimed for it, belongs to research organizations. Operating experience, without which no criterion can be calibrated, belongs to licensees.
A path can be described without any claim to be standing on it. Pre-application interaction with the NRC includes mechanisms by which a developer asks staff to review a discrete technical topic ahead of an application [[20]](#src-20). A topical report addressed to the evidentiary properties of an automated operating record would have to define the properties, define the failure modes, propose acceptance criteria, and propose how each criterion would be demonstrated. We have not submitted such a report. None has been accepted. We are aware of no NRC position on the subject, and pre-application interaction confers no approval of any kind.
A demonstration path is the other half, because a record of this kind cannot be assessed in the abstract. It has to be produced by real instruments in a real configuration over a period long enough for gaps, clock drift, maintenance outages, and instrument failures to occur, since those are the conditions under which completeness and contemporaneity are actually tested. A research or test setting is where that becomes possible before it is possible at a licensed facility. Whether such a demonstration would be credited by anybody is unresolved, and it is one of the entries in our [register of open questions](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight).
The framing we would resist is the one in which the gap is presented as a product opportunity. It is a shared problem, and most of the parties who will decide how it closes do not sell anything. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[11]](#src-11) and its associated draft staff guidance issued for comment [[12]](#src-12) are where the regulatory half would appear if it appears at all, and neither is final. Naming the gap precisely is what this paper offers, and naming a gap is a different act from filling it.

## 8. Application to RankShield Energy, honestly
Applying the six properties to our own position produces an uncomfortable result, which is the reason to publish it rather than to omit it. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC [[20]](#src-20). We hold no NRC license, permit, or design approval. Nothing in our design has been demonstrated to or accepted by the NRC, and the pre-application process described in [our explainer on it](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) provides early alignment rather than standing of any kind.
On form, our position is ordinary rather than distinguished, and we would rather say so than imply otherwise. Attribution, tamper-evidence, and independent checkability can be built from published standards that anybody can read [[1]](#src-1) [[2]](#src-2) [[3]](#src-3), and building them competently is engineering rather than an achievement worth advertising. Durability, for us, is a design commitment about signature agility and re-signing practice [[4]](#src-4) [[5]](#src-5) rather than a demonstrated property, because no record of ours has yet had time to age.
On the two properties that depend on the plant rather than on the cryptography, we are materially weaker than the technology makes us sound. Completeness and contemporaneity are properties of instrumentation, sensor coverage, failure detection, and the treatment of gaps. A design-stage answer to any of those is an intention subject to analysis, testing, and regulatory review, and the sensor-level compromise described in section 6 sits upstream of anything we build [[15]](#src-15). Supply-chain provenance for the devices involved is a live obligation for us rather than a solved one [[6]](#src-6).
The independence problem applies to us with full force. A verification function supplied by a party holding a commercial relationship with the operator is not independent in the sense a lender or an insurer means, and the honest description of our position is that independence is a governance question we have not resolved rather than a technical property we possess. A verification path also adds a digital interface to a plant, which is a cost in cyber terms that a regulator would weigh against whatever assurance benefit it brings [[14]](#src-14).
The load-bearing uncertainty is whether any of this is credited at all. It is entirely possible that a regulator concludes that assurance of this kind belongs inside a licensee's own quality and configuration management programs, and that an external layer adds a component to be reviewed without reducing anything else that must be reviewed. We hold no evidence bearing on that question, our commercial interest in the answer is direct, and readers should weigh the analysis above accordingly and check every source cited rather than accept our summary of it.

## Frequently asked questions

### Does admissible in this paper mean admissible as a matter of law?
No. Throughout this paper, and in its title, admissible means capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present at the facility. The paper contains no analysis of legal admissibility, no interpretation of any statute or procedural requirement governing legal proceedings, and no legal advice. Questions about legal proceedings belong to counsel. The technical question this paper does address is narrower and more tractable: what properties a machine-generated record needs before a party that was not present will change a decision on the strength of it.

### What are the six properties, in short?
Attributable: the record identifies the system and configuration that produced it, checkably. Complete: it covers a defined period with no undeclared gaps, and records any gap that occurs. Contemporaneous: it is generated as events occur, with a checkable time reference. Tamper-evident: later alteration is detectable by a party with no privileged access, which is detection rather than prevention. Independently checkable: a relying party can verify it without the producer's cooperation or tooling. Durable: the record and the means of checking it outlive the decisions that rest on them.

### Do existing standards solve this?
They supply form for four of the six properties and nothing for two. The RATS architecture separates attester, verifier, and relying party. The SCITT architecture adds a transparency service with an append-only log, and COSE receipts give an interoperable proof format. The 2024 NIST post-quantum signature standards give durability a migration target. What none of them supplies is completeness or contemporaneity, which are properties of instrumentation rather than cryptography, and none of them establishes that a regulator would accept any of it.

### Has the NRC accepted a standard for machine-generated reactor records?
Nothing in the record cited by this paper establishes acceptance criteria for machine-generated reactor state. NRC guidance on digital instrumentation and controls for advanced reactors and the agency's cybersecurity material address adjacent questions rather than this one. The proposed microreactor licensing rule and its associated draft staff guidance are the instruments where such criteria could appear; the rule is proposed and not final, the guidance is a draft issued for comment, and no developer is licensed under the proposed rule.

### Why does a record need to be checkable without the producer?
Because the moments when a relying party most needs the record are the moments when its producer has the least incentive and sometimes the least ability to help. A lender testing a covenant, an insurer investigating a loss, and a regulator examining an event each need to reach a conclusion without depending on the cooperation, the tooling, or the continued existence of the organization whose conduct is in question. Independent checkability is what makes that possible, and it is a property of the record's construction rather than of anybody's goodwill.

## Sources

- [Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force (RFC Editor). RFC 9943: Supply Chain Integrity, Transparency, and Trust (SCITT) Architecture. June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force (RFC Editor). RFC 9942: COSE Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024](https://csrc.nist.gov/pubs/fips/204/final)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg.html)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628). Status: proposed rule, published May 1, 2026, comment period closed June 15, 2026; not final, and no developer is licensed under it](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. NUREG-2271, Draft for Comment: NRC staff guidance document issued for public comment, not final guidance. April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026](https://www.nrc.gov/security/cybersecurity)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (IAEA Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305), laboratory research. September 2019](https://www.osti.gov/biblio/1615811-concepts-autonomous-operation-microreactors)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis prepared for the NRC. February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Acceptance criteria.** What properties a machine-generated record of reactor state would have to demonstrate before a regulator would rest a determination on it. Unresolved because nothing in the cited record states criteria of any kind, and the instruments where they could appear are proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[11]](#src-11) and NUREG-2271, a draft NRC staff guidance document issued for comment and not final guidance [[12]](#src-12). Resolver: NRC, through final rulemaking or final guidance.
- **OQ-2. Completeness.** What sensor coverage, gap declaration, and failure detection would be sufficient before absence of an alarm may be read as evidence of a normal condition rather than evidence of a silent instrument. Unresolved because no published standard cited here addresses completeness at all, and NRC digital instrumentation and controls guidance addresses an adjacent question [[13]](#src-13). Resolver: research organizations for method, NRC for acceptance.
- **OQ-3. Contemporaneity and time.** What time source is acceptable for a record of this kind, how clock drift is bounded and reported, and how a measured value is distinguished from one inferred after the fact. Unresolved because the proof formats available fix the time a statement was registered rather than the time an event occurred [[3]](#src-3). Resolver: standards bodies for form, licensees for practice.
- **OQ-4. Qualification of the verifier.** Who qualifies the party that appraises evidence, against what criteria, and who checks that party. Unresolved because the architecture that defines the verifier role defines no qualification route for it [[1]](#src-1), and no nuclear equivalent appears in the cited record. Resolver: NRC for acceptance, standards and accreditation bodies for form.
- **OQ-5. Durability across a facility lifetime.** What retention period applies, how records are re-signed as algorithms age, and who holds custody if the producing organization ceases to exist. Unresolved because the post-quantum standards supply a migration target without supplying a records-management practice [[4]](#src-4) [[5]](#src-5). Resolver: NRC and licensees, informed by standards bodies.
- **OQ-6. The oversight substitution.** What carries the weight that resident inspection carries today [[8]](#src-8) if on-site presence is materially reduced, given how heavily safety conclusions rest on the information the oversight process produces [[7]](#src-7) [[9]](#src-9) and given the baseline that licensed-operator conditions set [[10]](#src-10). Resolver: NRC as designer of the oversight framework, with GAO scrutiny.
- **OQ-7. Sensor-level compromise.** How a relying party is expected to reason about a perfectly attested value produced by a compromised or degraded instrument, which is upstream of every property in section 3. Unresolved because the guidance addressing this layer [[15]](#src-15) and supply-chain practice [[6]](#src-6) raise the cost of compromise without converting a record into a statement about physical reality. Resolver: NRC and IAEA guidance, with instrumentation research.
- **OQ-8. Model output versus measurement.** Whether output from a digital twin can ever function as a record of what a plant did, as opposed to a prediction of what it would do. Unresolved because the demonstrated work is a twin of a simulated microreactor [[19]](#src-19) and the autonomous-operation concepts that would rely on such models are research [[17]](#src-17) [[18]](#src-18). Resolver: research organizations, then NRC.
- **OQ-9. We cannot answer this one.** Whether an independent verification layer would be credited in a licensing basis at all, and whether the four relying parties named in this paper would change any decision on the strength of a record built as described. We hold no evidence on either question, our commercial interest in the answers is direct, and pre-application interaction confers no approval [[20]](#src-20). Resolver: the NRC on a specific docket, and the market for the remainder. The IAEA safeguards experience [[16]](#src-16) suggests independent verification can become load-bearing, and suggests nothing about how long that takes.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [What a reactor's sensors can and cannot attest →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [A reference architecture for independent verification of reactor state →](https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state)
- [Open questions in autonomous microreactor oversight →](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*Terminology note. Throughout this paper, and in its title, a record described as admissible means a record capable of being relied upon by a regulator, insurer, lender, or grid operator that was not present. The paper contains no analysis of legal admissibility, no interpretation of any statute, and no legal advice of any kind.*
*This paper reflects the state of NRC microreactor rulemaking and the published standards record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors/

# Fleet-Scale Verification: One Operator

> When one operator oversees many microreactors, verification has to scale too. See what changes and why independent confirmation matters more at fleet scale.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# Fleet-Scale Verification: One Operator, Many Reactors
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. A single reactor can be watched. A fleet cannot be watched the same way. When one operating organization oversees many microreactors across many sites, human attention becomes the scarce resource, and verification does not scale linearly with the fleet. The cost that grows fastest is not checking each unit. It is reconciling them, and that is the part of the problem nobody has solved yet.
This is worth working through now because the regulatory direction points at it. The NRC's proposed Part 57 rule contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1), and NRC staff have examined licensing and deployment beyond the first unit of a design, including standardization of operational programs [[2]](#src-2). Sandia National Laboratories, working for the NRC, has described designs in which one control room supervises multiple microreactors [[10]](#src-10). None of that is settled law. Part 57 is proposed rather than final, its comment period closed in June 2026, and no developer is licensed under it.
What follows is about the structural problem rather than any product: what changes when one organization oversees many units, why verification does not simply multiply, why the failure mode is quiet, the three properties fleet verification has to have, what the NRC's own oversight direction implies, what the national laboratories have described, what the rules require today, and where the field honestly stands. RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval, we operate no fleet, and we have never operated a reactor. The last section applies the argument to us.
Key takeaways

- At fleet scale, attention per reactor falls by design, so more of the safety story has to be carried by evidence rather than by presence.
- Verification does not multiply. The dominant cost is reconciliation: deciding whether one unit behaving differently is a sensor, maintenance, real divergence, or nothing.
- The failure mode is quiet. Small anomalies across many units are what human attention handles worst, so differences stop being investigated because they usually amount to nothing.
- Fleet verification has to be per-unit, comparable across units, and checkable by someone outside the operator. Two out of three is not verification.
- Proposed Part 57 contemplates remote and reduced-staffing operation, but it is not final, the comment period closed in June 2026, and it grants no approval today.
- Honest status: no commercial microreactor fleet is operating, so fleet-scale independent verification exists nowhere, including here.

## What changes is that presence stops scaling
With one reactor, oversight can lean on proximity. People are on site, they know the plant, and their judgment fills gaps that instrumentation misses. That is not an informal arrangement. Federal regulation requires a licensed operator to be present at the controls at all times [[5]](#src-5), and the NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, describing their role as independently verifying that requirements are being met [[6]](#src-6).
Now put one operating organization in charge of many units across many sites. The staff-to-reactor ratio falls by design, because that ratio is part of why modular fleets are attractive in the first place. This is not a hypothetical operating model invented for an article. Sandia National Laboratories, working for the NRC on human factors for automating microreactors, described designs in which operators may monitor from a remote location and in which one control room supervises multiple microreactors [[10]](#src-10).
What replaces proximity is reporting. Each unit describes its own condition, and the operating organization assembles a picture from those descriptions. Many distributed industrial systems already work this way and work well. But the change is worth stating plainly, because it is easy to miss: a claim of safe operation stops resting on what an experienced person observed and starts resting on whether the reporting itself can be trusted. At fleet scale, trust in operations becomes trust in evidence, which is the same shift that makes [verifying a single autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) a different exercise from watching a staffed plant.
The table below maps the oversight functions that presence quietly performed, what happens to each one across a fleet, and what has to take over. The last row is deliberately unresolved.

How single-unit oversight functions change at fleet scale. This mapping is ours, offered as a way to structure the question, not as a regulatory framework.

Oversight function
What it relied on with one reactor
What breaks across a fleet
What has to replace it

Noticing that something is off
A person present who knows the plant
Attention per unit falls as the unit count rises
Per-unit evidence that surfaces divergence before anyone has to notice it

Judging whether it matters
Local knowledge and shift-to-shift memory
Many other units compete for the same judgment
Records comparable across units, so a difference reads as a difference

Recording what happened
Logs kept and interpreted by the operator
Volume grows faster than the capacity to review it
Records signed and checkable later without the operator helping

Outside confirmation
Resident inspectors on site
Inspection presence does not scale one-to-one with sites
Evidence a regulator, insurer, or lender can appraise remotely

Escalating when performance degrades
An action matrix tied to a licensed operating plant
No fleet-level equivalent exists for microreactors today
An open question. Named here rather than answered.

## Verification does not multiply, because the real cost is reconciliation
Verifying twenty reactors is not twenty times verifying one. Handled unit by unit, it is worse than linear, and the reason is that the dominant cost is not checking. It is reconciliation.
Reconciliation is the work of deciding what a difference means. Unit seven is running slightly differently from the other nineteen. Is that a sensor drifting, a maintenance action nobody logged clearly, a real divergence in how that unit is behaving, or nothing at all? Answering that question requires comparing unit seven against its own history and against its siblings, then forming a judgment that is rarely clean. Each additional unit adds a check, but it also adds a new set of comparisons, and comparisons are where the hours go.
This is the claim in this article that we would most like people to argue with, because it cuts against how fleet oversight is usually sold. The pitch is normally aggregation: one screen, all units, green across the board. Aggregation does not remove reconciliation cost. It relocates it, and often it hides it, because a fleet rollup is precisely the presentation in which one divergent unit disappears into an average. A dashboard that is green because nineteen units are fine is not evidence about the twentieth.
The design consequence follows directly. If reconciliation is the expensive part, then the fleet has to emit evidence in a form that makes comparison cheap and divergence conspicuous, rather than leaving reconciliation as an exercise performed by whoever happens to be on shift. That is an argument about the shape of the record, not about how hard people are working, and it starts at the point where a sensor reading becomes something durable, which is the chain we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).

## The failure mode is quiet, not dramatic
The way fleet oversight degrades is not a missed alarm during a crisis. It is a slow normalization in which small differences stop being investigated because they usually amount to nothing.
The mechanism is ordinary and well known outside nuclear. Sustained monitoring of mostly uneventful signals degrades human detection performance over time, which is why vigilance is treated as a design constraint rather than a matter of diligence. Add volume and the second effect arrives: when most flagged differences turn out to be benign, the flags themselves lose meaning, and the rational response of a competent person managing many units is to triage harder. Neither effect is a failure of character. Both are predictable properties of the task, and a fleet is a machine for producing exactly the input that triggers them, which is a high rate of small, mostly uninteresting variation spread across many units.
This is why human factors work in this area treats the human and automation interface as a safety-relevant question rather than a usability nicety, and why function allocation between people and machines is the framing rather than whether machines act at all [[10]](#src-10). Brookhaven National Laboratory, reviewing facilities without main control rooms for the NRC, put the safety question precisely: the issue is not so much justifying why a design has no main control room, but verifying that important human actions can be accurately and reliably performed [[11]](#src-11).
Apply that formulation to a fleet and it does real work. If one of the important human actions is investigating a divergence, then the reliability of that action is a safety question, and it is a question about workload and evidence quality rather than about competence. An organization can staff a fleet with excellent people and still build a system in which the twentieth anomaly of the week gets three seconds of attention. Designing against that means the evidence has to do more of the noticing.

## Fleet verification has to be per-unit, comparable, and externally checkable
Three properties have to hold at once. Any two without the third produces something that looks like verification and does not function as it.
**Per-unit.** Verification attaches to an individual reactor, not to a fleet average. A fleet-level summary that smooths individual behavior is a management view, and management views are useful, but averages are exactly where a single divergent unit becomes invisible. If the artifact cannot be pulled apart into one record per unit, it is not verification of any unit.
**Comparable across units.** If each reactor reports in its own idiosyncratic format, reconciliation stays manual and the cost of oversight grows with fleet size. Comparability is what allows an anomaly to stand out against its siblings rather than requiring a person to notice it unaided. This is also where standardization stops being a procurement convenience and becomes an oversight property.
**Checkable by someone outside the operator.** At single-reactor scale, a regulator can partly compensate for weak evidence with inspection. Across a distributed fleet that compensation does not scale either, which makes machine-checkable evidence more load-bearing rather than less. The architecture that formalizes this separation is settled outside nuclear: RFC 9334 defines an attester that produces evidence about its state, a verifier that appraises that evidence against a policy, and a relying party that acts on the verifier's result [[14]](#src-14). The point of the split is that the party with a stake in the answer is not the party producing it, which is the whole of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The obvious objection is that industrial fleets already run on remote monitoring platforms, and that a well-built one covers all three properties. Sometimes it covers the first two. The third is where these systems generally stop, because they are built to give the operating organization a better view of its own assets, which is a legitimate and different goal. The test that separates them is simple to state and uncomfortable to answer: what could a regulator, insurer, or lender establish about unit seven last month if the operator declined to help, or no longer existed? If the answer depends entirely on the operator's cooperation, the platform is operations tooling. It may be excellent operations tooling.

## The NRC's own oversight direction points at scale and standardization
The regulator has been working on this longer than the vendors have. SECY-20-0093, in October 2020, flagged autonomous operation, remote operation, staffing, and regulatory oversight as open policy questions specific to microreactors [[4]](#src-4). Those questions did not have clean answers inside a framework built for large light-water plants, and naming them was the useful act.
More recently the staff has been planning for repetition rather than for one-off projects. SECY-25-0052 addresses nth-of-a-kind microreactor licensing and deployment, including standardization of operational programs [[2]](#src-2). That is the regulatory shape of many similar units rather than a handful of bespoke ones, and standardization has a direct consequence for verification: units built and operated to a common program are units whose records can be compared. Separately, NRC staff have proposed operational-phase oversight built on a scalable inspection footprint [[3]](#src-3), which is the agency acknowledging in its own terms that inspection presence cannot grow one-for-one with sites.
Set that against what oversight rests on today. The Reactor Oversight Process is risk-informed and tiered, built on safety cornerstones, NRC-developed inspection findings, licensee-reported performance indicators, a significance determination process, and an action matrix that escalates as performance degrades [[7]](#src-7). The Government Accountability Office has described the agency's safety assurance as resting on exactly that, the monitoring and inspection of the activities with the greatest effect on safety [[8]](#src-8).
Two things follow. The first is that performance indicators reported by the licensee are already part of the structure, so the idea of an operator supplying evidence about itself is not foreign to nuclear oversight. The second is that the balance shifts. As inspection presence per unit thins, the licensee-reported share of the picture grows, and the quality of that reporting stops being an administrative matter. It is also worth noting that readiness is not assumed even by the agency's own overseers: GAO reported in July 2023 that the NRC needed to take additional actions to prepare to license advanced reactors [[9]](#src-9). That is a reason to design evidence carefully now, not a reason to wait.

## The national laboratories have already described the fleet operating model
This is not a scenario the industry invented for marketing. Sandia, working for the NRC, described designs where operators may not be located on site and where one control room supervises multiple microreactors [[10]](#src-10). That single clause carries most of the difficulty in this article, because supervising several units from one room changes what a supervisor can actually attend to.
Oak Ridge examined what autonomous control disturbs and found it reaches well past headcount, into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and event notifications, with the control room possibly not co-located with the plant [[12]](#src-12). Each of those is a place where fleet scale multiplies the question rather than repeating it. Technical specifications for one unit are a document. Technical specifications across a fleet, with per-unit deviations and per-unit histories, are a reconciliation problem.
Oak Ridge's work on concepts for autonomous operation of microreactors names the engineering preconditions plainly: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring and control [[13]](#src-13). None of those are trivial, and the third one changes character at fleet scale, since a common software stack across many units is efficient and is also a common surface. That tension is the subject of [microreactor cybersecurity](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained) and it is not resolved by verification alone.
Read together, the lab record supports a narrow and specific conclusion. The operating model of one organization supervising many remote units is described in the literature as a design direction being studied. It is not described as a validated arrangement with a settled oversight answer, and the Brookhaven framing about verifying that important human actions can be accurately and reliably performed [[11]](#src-11) is the standing test that a fleet architecture would have to meet.

## What the rules require today, and what is only proposed
The current baseline is unambiguous. The conditions of an operating license require a licensed operator to be present at the controls at all times [[5]](#src-5). Whatever a fleet architecture eventually looks like, that is the rule as it stands, and no fleet of microreactors is operating under any different arrangement in the United States today.
The proposed 10 CFR Part 57 framework contemplates remote operation and reduced on-site staffing for microreactors, published in the Federal Register on May 1, 2026 [[1]](#src-1). Three qualifications belong in the same breath every time it is mentioned. It is proposed and not final. Its comment period closed in June 2026. No developer is licensed under it, including us. A walkthrough of what the proposal actually says is in [our explainer on Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), and the honest summary is that it sets a direction rather than granting a permission.
It is worth being explicit about what this article is not describing, because the vocabulary in this space runs ahead of the facts. Nothing here describes an unmanned plant, and nothing here describes fully autonomous operation in the sense of a reactor running without human involvement in safety-significant actions. No facility is licensed to operate that way. Human-in-the-loop for reactivity and safety actions is the assumption throughout, and a verification layer does not change it, because a verification layer produces evidence rather than control.
That distinction also answers a question we get asked in a different form: whether better evidence could substitute for the operator or the inspector. It could not, and the argument here does not require it to. The NRC's oversight of licensees stays with the NRC [[7]](#src-7). Independent verification is a technical function that supports regulatory oversight rather than replacing any part of it, and the reason to build it is that the mechanisms outsiders have historically relied on to know anything at all get thinner as unit counts rise.

## Where this actually stands, including where we stand
Nobody is running a commercial microreactor fleet, so nobody is running fleet-scale independent verification. That is the whole status, and it is worth saying without softening. Any vendor presenting fleet verification as a proven, deployed capability is describing an intention. The regulatory framework that would allow the operating model is proposed and not final [[1]](#src-1), and the national-lab work referenced throughout this article consists of research and demonstrations by the laboratories, which belong to those institutions and are not evidence about any vendor's product, ours included.
RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval. We operate no fleet, and we have never operated a reactor. Nothing about our design has been demonstrated to or accepted by the NRC. Our working expertise is on the verification side rather than the operating side: independent verifiers, signing, transparency logs, and the question of what an outside party can check without cooperation from the party being checked.
Here is a concrete decision from that work, stated with what it costs. We design toward per-unit signed records rather than fleet rollups, even though rollups are cheaper to produce, easier to store, and far more pleasant to demonstrate. The tradeoff is real. Per-unit records mean more artifacts, more storage, more surface to keep consistent, and a system that surfaces more differences to a human than a smoothed fleet view would. We accept that because a rollup answers a question about the fleet, and the question that matters in an incident is about one unit. We would rather explain the extra noise than explain, later, why the divergent unit was inside an average.
The honest limitation is that our own architecture is subject to the same test we just applied to everyone else. A verification layer built and run by the party being verified is self-attestation with better engineering, which is why verifier and operator separation has to be structural rather than added later, and why we think a party that can publicly contradict us is a feature rather than a defect. We are not there. If you are evaluating developers on any of this, the questions are in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.

## Frequently asked questions

### Does proposed NRC Part 57 allow one operator to run many reactors?
Not today, and the proposal itself grants nothing. Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors, which points toward fleet-style oversight [[1]](#src-1), but it was published on May 1, 2026, its comment period closed in June 2026, it is not final, and no developer is licensed under it. Meanwhile the operative rule still requires a licensed operator at the controls at all times [[5]](#src-5). Contemplating an operating model is also not the same as approving a staffing arrangement, which would be evaluated for a specific design under review. Treat it as regulatory direction rather than present permission.

### Why is verifying a fleet harder than verifying one reactor twenty times?
Because the expensive part is reconciliation, not checking. With many units, the work is deciding what a difference means: whether one unit behaving slightly differently is a drifting sensor, an unlogged maintenance action, a genuine divergence, or nothing. Most of those turn out to be benign, and that is exactly the condition under which anomalies stop being investigated. Human detection performance degrades against high-volume, mostly uneventful variation, so the fleet has to produce evidence that makes comparison cheap and divergence conspicuous rather than leaving reconciliation to whoever is on shift.

### What does fleet-scale verification actually have to produce?
Three properties at once. Per-unit records, because a fleet average is where a single divergent unit disappears. Comparability across units, because idiosyncratic per-unit reporting keeps reconciliation manual and makes oversight cost grow with fleet size. And checkability by a party outside the operator, because inspection presence does not scale one-for-one with sites. The third property has a standard form outside nuclear: RFC 9334 separates the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [[14]](#src-14). Two out of three produces something that resembles verification without functioning as it.

### Is anyone operating a microreactor fleet under independent verification today?
No. No commercial microreactor fleet is operating at all, so fleet-scale independent verification does not exist in practice. What exists is a regulatory proposal that contemplates the operating model and is not final [[1]](#src-1), national-lab research describing designs in which one control room supervises multiple microreactors [[10]](#src-10), and a set of engineering preconditions the labs have named rather than closed [[13]](#src-13). RankShield Energy is a pre-applicant that operates no fleet and has never operated a reactor [[15]](#src-15).

### What should a buyer ask a vendor about fleet operations?
Ask how evidence from each unit is produced, whether it is directly comparable across units, and who confirms it besides the operator. Then ask the harder version: if one unit diverges, who is alerted, what record is created, and could an outside party reconstruct that sequence afterward without the vendor's help. Answers that describe a monitoring dashboard are describing operations, which is necessary but is the operator grading its own work. Today that outside confirmation is supplied largely by people, with roughly 150 NRC resident inspectors in the field whose stated role is independently verifying that requirements are being met [[6]](#src-6). A fleet answer has to say what supplies it when presence per unit falls.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Trusting a remotely operated reactor's command state →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)
- [Turning reactor state into an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [Digital twins and remote reactor verification →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of NRC microreactor rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. Check back if the rule is finalized or the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor/

# How to Evaluate a Microreactor Vendor: Key Questions

> Choosing an advanced reactor vendor means separating verifiable claims from assertions. Here are the questions to ask about verification, autonomy, and status.

[Resources](https://rankshieldenergy.com/resources) / Buyer guidance Buyer guidance

# How to Evaluate a Microreactor Vendor: The Verification Questions to Ask
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Evaluating a microreactor vendor comes down to one distinction: which of their claims can be checked by someone other than them, and which have to be taken on faith. Almost every developer will tell you their design is safe, efficient, and nearly ready. The useful questions are the ones whose answers are verifiable by a third party, or that a vendor cannot answer without revealing where they actually are.
This is a checklist you can apply to any developer in this market, including us. It is written so that it does not flatter RankShield Energy. We are a pre-applicant with the NRC, holding no license or approval [[5]](#src-5), and the final section runs all six questions against our own program and says plainly where we do not have a strong answer.
A note on what this is not. It is not a ranking, it does not name or score other developers, and it does not tell you who to buy from. It gives you the questions, what a strong answer sounds like, what a weak one sounds like, and enough public reference points to check the answers yourself after the meeting.
Key takeaways

- The test is not whether a vendor claims something, it is whether anyone other than the vendor can check it.
- Regulatory status is the easiest claim to verify independently and the one most often blurred in marketing.
- For autonomous or remote designs, ask who verifies reactor state and whether that party is separate from the operator.
- A vendor claiming a completed NRC cybersecurity approval is describing something that does not exist in final form.
- Ask what staffing the business case assumes and what must change regulatorily to permit it. Costs quoted without that premise are not comparable.

## Why evaluating an autonomous or remote design is different
Conventional plant diligence leans on things you can go and look at: an operating record, a staffed control room, inspectors on site. That surface is real. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, whose stated role is independently verifying that requirements are being met [[1]](#src-1), inside an oversight process built on inspection findings, performance indicators, and a significance determination process [[2]](#src-2).
A microreactor designed for reduced on-site staffing removes much of that. Proposed Part 57 contemplates remote operation and reduced staffing [[3]](#src-3), and NRC staff have separately proposed operational-phase oversight built on a scalable inspection footprint [[4]](#src-4). Fewer people on site, fewer inspector-hours per unit.
The consequence for a buyer is specific. More of what you can know about the reactor arrives as data the operating organization reports about itself. So diligence has to move upstream, from checking outcomes to checking who is positioned to confirm them. That is what the questions below are built to test.
None of these require you to be a nuclear engineer, and none require a vendor to disclose anything proprietary. They test the structure of a claim rather than the physics behind it.

## Question one: what is your exact regulatory status today
This is the easiest claim to verify without the vendor's help, and the one most often softened. A developer in pre-application engagement has not been granted a license, a permit, or a design approval, and pre-application produces no safety finding [[5]](#src-5). That is public.
The vocabulary is close enough to blur deliberately or accidentally. A **pre-applicant** is engaging with the regulator before submitting. An **applicant** has submitted and is under review. A **licensee** holds a license. Phrases like "working with the NRC," "in the NRC process," or "NRC-engaged" can describe any of these, or the earliest.
Two follow-ups do real work. Ask which framework they are pursuing: Part 53 was finalized in March 2026 as a risk-informed, technology-inclusive framework and is available now [[6]](#src-6), while the microreactor-specific Part 57 remains proposed with its comment period closed [[3]](#src-3). A developer betting entirely on a rule that is not final carries schedule risk a developer using an available pathway does not.
Then ask what they expect to submit next, and when. A credible answer names a document. A vague one names a quarter. The distinction between [pre-application and approval](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) is where most marketing language quietly lives.

## Question two: which safety claims are demonstrated, and which are design targets
Every vendor will tell you their design is safe. The useful question is what "safe" is resting on: qualified analysis and test data, or intent that has not been through regulatory review yet.
A strong answer separates the two without prompting and volunteers what testing is still owed. A weak answer presents every safety characteristic as settled. The tell is whether a developer can name a weakness at all.
Context helps you calibrate. Real capability has been demonstrated at national-laboratory scale: DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[7]](#src-7), and INL's MARVEL project exists to test remote monitoring and develop autonomous control technologies [[8]](#src-8). Those are genuine results.
They are also lab results, not commercial operating experience, and they belong to the laboratories rather than to any vendor. A developer citing national-lab demonstrations as though they were their own operating record is doing something you should notice.

## Question three: who verifies reactor state, and are they separate from you
This is the question with the most signal and the one least often asked. If the reactor reports its own condition and the vendor evaluates that report, an outside party has nothing independent to rely on.
The precedent is not speculative. IAEA safeguards exist so that an outside body applies technical measures to independently verify rather than relying on an operator's assertion [[9]](#src-9). Computing standardized the same separation in RFC 9334, splitting the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [[10]](#src-10).
Ask what happens to the result afterwards, because present-tense monitoring does not answer past-tense questions. Standards exist for this too: an append-only transparency service that registers signed statements and issues receipts a third party can audit later [[11]](#src-11), with the receipts themselves standardized as compact cryptographic proofs [[12]](#src-12).
A strong answer names a verification function separate from operations and describes what it records. A weak answer points at a monitoring dashboard. That is the whole of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is worth pressing on because the two sound identical in a sales conversation.

## Question four: which cybersecurity standards, and what is their status
Digital instrumentation and autonomous control change the threat model, and the honest state of the field is that requirements for advanced reactors are still being written. NRC guidance for digital I&C review of non-light-water reactors exists [[13]](#src-13), and cyber requirements for advanced reactors remain consequence-based and in development rather than finalized [[14]](#src-14).
International guidance is further along and worth asking about by name. The IAEA has published technical guidance on protecting reactor instrumentation and control systems across their full life cycle [[15]](#src-15), and has an active research project on computer security for small modular and microreactors that names autonomous and remote operations, digital twins, and centralised fleet management with reduced staffing as the conditions to address [[16]](#src-16).
The disqualifying answer here is specific: a vendor claiming to hold a completed NRC cybersecurity approval for an advanced reactor is describing something that does not yet exist in final form. That is not a nuance, it is a factual error, and it tells you how carefully the rest of their claims are made.
A strong answer names the standards they build toward, distinguishes final guidance from proposed rules, and explains how a third party could check the claim. Our fuller treatment is in [microreactor cybersecurity, explained](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained).

## Question five: where does the fuel come from, and what does it do to the schedule
Fuel is the constraint buyers most often underweight, and it is a schedule risk rather than an engineering one. Most advanced designs need HALEU, and a commercial domestic supply chain at the scale the industry will need does not yet exist, which is why the Energy Act of 2020 directed DOE to establish the HALEU Availability Program [[17]](#src-17).
This is not a vendor-specific failing. Almost nobody has solved fuel independently, so it is a poor basis for choosing between developers. What differentiates them is whether they account for it honestly.
A developer who names fuel as a schedule constraint and describes their supply path is giving you a deployment timeline. One whose plan treats fuel as settled is giving you an engineering timeline, which is a different and less useful thing when you are planning around a delivery date. The detail sits in [where HALEU comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel).

## Question six: what staffing and oversight does your model assume
This one is newer and rarely asked, but it determines what the other answers are worth over twenty years. Current regulation requires a licensed operator at the controls at all times [[18]](#src-18). A design premised on reduced staffing is premised on that requirement changing, or on an exemption being granted.
Oak Ridge examined what autonomous control disturbs and found it reaches well past headcount: staffing, manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and event notifications, with the control room potentially not co-located with the plant [[19]](#src-19). Sandia, working for the NRC, described designs where one control room supervises multiple microreactors [[20]](#src-20).
So ask directly: how many operators per reactor does the business case assume, and what has to be true regulatorily for that to be permitted. Then ask the oversight version, because the GAO has reported that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[21]](#src-21), and still lists licensing advanced reactors among its priority open recommendations [[22]](#src-22).
A developer whose economics depend on thin staffing and thin inspection, without a story for how anyone confirms the reactor between visits, has an unpriced risk in the model. That is the [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) problem arriving through the commercial door.

## What a checkable answer sounds like
The pattern across all six is simple. A strong answer points to a document, a standard, a regulator's public record, or a party with no stake in the outcome. A weak answer points back to the vendor.

Vendor evaluation: what a checkable answer sounds like

Question
Stronger answer
Weaker answer

Exact regulatory status
Names the stage and points to the NRC public record
"We are working closely with the NRC"

Demonstrated vs design target
Separates them and says what testing is owed
Presents all safety characteristics as settled

Who verifies reactor state
Names a function separate from operations and what it records
Points to the vendor monitoring dashboard

Cybersecurity standards
Names standards, distinguishes final from proposed
Claims a completed NRC cyber approval

Fuel and schedule
Names HALEU supply as a real timeline constraint
Treats fuel as solved, or omits it

Staffing and oversight assumptions
States operators per unit and what must change regulatorily
Quotes an operating cost without the staffing premise

*Every stronger answer above can be checked after the meeting. Every weaker one cannot. That is the only property the table is really sorting on.*
One practical note on running the conversation. Ask these questions of the technical lead rather than the commercial team, and ask them in the order above, because status constrains everything after it. A developer who is candid about being early will usually be candid about the rest. A developer who blurs status tends to blur the harder questions too, and you will have learned that in the first five minutes rather than the third meeting.
It is also worth asking one deliberately open question at the end: what would have to go wrong for your schedule to slip two years. The content of the answer matters less than whether they have one. Everyone in this industry is carrying fuel risk, licensing risk, and supply-chain risk simultaneously. A developer who cannot name their own largest risk either has not modeled it or does not want to discuss it, and both are things you want to know before signing.
A final note on how to weigh the answers you get. None of these six questions has a single correct response, and a developer being early is not a failing. What you are testing is whether their account of themselves matches what the public record independently shows, and whether they volunteer the limits before you find them. A developer who is candid about being at an early stage, names the specific framework they are pursuing, and describes their fuel and staffing assumptions honestly is giving you something you can plan around. That is worth more than a confident answer you cannot check.

## Applying all six questions to RankShield Energy, honestly
A buyer's guide written by a vendor is worth very little unless the vendor runs the questions against itself, so here are our answers. **Status:** we are a pre-applicant, we hold no NRC license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[5]](#src-5). **Demonstrated versus target:** our reactor safety characteristics are design intent, subject to analysis, testing, and regulatory review, and we have testing still owed before we would characterize them otherwise.
**Verification:** separation of the verifier from the operator is the core of our approach and the reason this site exists, and it is an architecture we apply rather than a deployed, certified capability. **Cybersecurity:** we build toward standards that are themselves still being finalised, so we claim no completed NRC cyber approval. **Fuel:** HALEU supply is a real schedule constraint for us as it is for the field [[17]](#src-17). **Staffing:** our model assumes reduced on-site staffing, which depends on regulatory change that has not happened yet [[3]](#src-3).
If that reads as less confident than a sales page, that is deliberate. A vendor who cannot tell you where they are weak is not giving you information you can plan around. Apply these six questions to us and to everyone else, and weigh the answers the same way.

## Frequently asked questions

### What is the single most useful question to ask a microreactor vendor?
Ask which of their claims can be checked by someone who does not work for them. It reframes the whole conversation. Safety characteristics, autonomy capability, and schedule confidence all sound similar coming from any vendor, but they differ enormously in whether an outside party can confirm them. A vendor who separates demonstrated results from design targets, points to public regulatory records, and describes verification performed by a party separate from the operator is giving you something you can act on. One who presents everything as settled is giving you a brochure.

### Does working with the NRC mean a reactor is approved?
No. Engagement covers a wide range, and the earliest stage, pre-application, grants no license, permit, or design approval and produces no safety finding [[5]](#src-5). A developer can be in genuine, productive contact with the NRC and still be years from submitting an application. The useful follow-up is which specific stage they are at and where that appears in the public record, because the answer is verifiable without their cooperation.

### How can I tell whether autonomy claims are credible?
Ask who confirms the reactor's reported state and whether that party is separate from the operator. Autonomy claims tend to be architectural rather than demonstrated at this stage, so the meaningful question is not how autonomous a design is but how anyone outside the control room would know it is behaving as described. Also listen to the words. "Unmanned" and "fully autonomous" are not regulatory categories, and a vendor using them loosely is describing an aspiration rather than the framework the NRC has proposed [[3]](#src-3).

### Should fuel supply affect which vendor I choose?
It should affect how you read their schedule more than which vendor you pick, because HALEU availability is an industry-wide constraint rather than a vendor-specific failing [[17]](#src-17). What differentiates developers is whether they account for it honestly. One who names fuel as a schedule risk and describes a supply path is giving you a deployment timeline. One who omits it is giving you an engineering timeline.

### What should I ask about staffing costs?
Ask how many operators per reactor the business case assumes, and what has to change regulatorily for that to be permitted. Current regulation requires a licensed operator at the controls at all times [[18]](#src-18), so a model premised on thinner staffing depends on rule changes that are still proposed [[3]](#src-3). An operating cost quoted without stating the staffing premise behind it is not a number you can compare between vendors.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026](https://www.nrc.gov/security/cybersecurity)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program. Accessed July 2026](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of advanced-reactor licensing and standards as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. Check back if the rule is finalized or the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/

# Microreactor Guides: Verification

> Sourced guides to microreactors, reactor verification, autonomy under NRC rules, cybersecurity, and licensing. Written to NRC, DOE, IAEA and IETF sources.

Resources · reactor fundamentals, plainly explained

# Understand the technology, from the ground up.
Clear, sourced explanations of how microreactors work, how reactor state is independently verified, what autonomy actually means under NRC rules, and how advanced reactors are licensed. Every guide is written to authoritative sources and states plainly where our own HELIX design is a target rather than a proven result.
**22** guides · sourced to NRC, DOE, IAEA, IETF and the national laboratories
All Reactor fundamentals Reactor safety Verification & trust Autonomy & Part 57 Cybersecurity Licensing & pre-application Deployment Technical papers Buyer guidance
[Latest · Licensing & pre-application The NRC has given RankShield Energy a project number. Here is what that does and does not mean. An NRC pre-application project number is a tracking identifier, not an approval. What it changes is the fee basis, and that provision expires in 2030. Read the guide →](https://rankshieldenergy.com/resources/nrc-pre-application-project-number-explained) [Technical papers Who Inspects a Reactor Built in a Factory? Verification of Off-Site Fabrication An analysis of how a factory-built reactor is verified before shipment and how provenance is established when the unit is received at its operating site. Sep 1, 2026 →](https://rankshieldenergy.com/resources/who-inspects-a-reactor-built-in-a-factory)[Technical papers Which Regulations Apply to a Microreactor? A Framework Applicability Analysis A regulatory applicability analysis of the four NRC licensing pathways open to a microreactor developer, the guidance above them, and where the choices lie. Aug 11, 2026 →](https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor)[Deployment Where HALEU Comes From: The Fuel Supply Behind Advanced Reactors HALEU is the fuel most advanced reactors need, and supply is still being stood up. Here is where it comes from and why it shapes deployment timelines. Jul 24, 2026 →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)[Verification & trust Fleet-Scale Verification: One Operator, Many Reactors When one operator oversees many microreactors, verification has to scale too. See what changes and why independent confirmation matters more at fleet scale. Jul 24, 2026 →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)[Technical papers A Reference Architecture for Independent Verification of Reactor State A reference architecture for verifying reactor state independently, assembled from published standards, and assessed honestly against the regulatory record. Jul 24, 2026 →](https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state)[Technical papers Open Questions in Autonomous Microreactor Oversight: A Working Register A working register of what the public record on autonomous microreactor oversight settles, what it leaves open, and who would have to resolve each entry. Jul 24, 2026 →](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight)[Technical papers Oversight Models for Fleet-Scale Microreactor Deployment: A Comparative Analysis A comparative analysis of four candidate oversight models for a deployed microreactor fleet, assessed against five stated criteria and the public record. Jul 24, 2026 →](https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment)[Technical papers What Makes a Machine-Generated Reactor Record Admissible Evidence? Machine-generated reactor records are becoming the evidence regulators, insurers, lenders, and grid operators rely on. No accepted standard exists yet. Jul 24, 2026 →](https://rankshieldenergy.com/resources/evidentiary-standards-machine-generated-reactor-records)[Buyer guidance How to Evaluate a Microreactor Vendor: The Verification Questions to Ask Choosing an advanced reactor vendor means separating verifiable claims from assertions. Here are the questions to ask about verification, autonomy, and status. Jul 23, 2026 →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)[Verification & trust From Sensors to an Attestation Record: How Reactor State Is Confirmed How does raw sensor data become a record a regulator or insurer can trust? Follow the chain from telemetry to a tamper-evident, independently verifiable record. Jul 23, 2026 →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)[Autonomy & Part 57 Automation, Remote Operation, and Autonomy: What the Terms Actually Mean Automation, remote operation, and autonomy are not the same, and the difference is regulatory. See what each term means for microreactors under Part 57. Jul 23, 2026 →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)[Deployment Speed-to-Power for Data Centers: Where Firm Nuclear Fits US data-center load is climbing while interconnection queues stretch. See what firm power actually requires and where advanced nuclear fits on the timeline. Jul 23, 2026 →](https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear)[Licensing & pre-application How the NRC Pre-Application Process Actually Works Pre-applicant does not mean approved. See how NRC advanced-reactor pre-application engagement actually works, step by step, and what it does and does not grant. Jul 23, 2026 →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)[Cybersecurity Microreactor Cybersecurity, Explained: Digital I&C and the New Threat Model Digital instrumentation and autonomous control change the microreactor threat model. See how today's standards point toward independent cyber attestation. Jul 23, 2026 →](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained)[Autonomy & Part 57 Trusting a Remotely Operated Reactor: The Command and State Problem Remote operation splits the operator from the core. Learn the two trust gaps this opens, verified commands and verified state, and how each is being addressed. Jul 23, 2026 →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)[Verification & trust The Digital Twin as a Verification Layer for Remote Reactor Operations A digital twin can do more than simulate. See how it becomes a verification layer that independently confirms reactor state for remote and autonomous operation. Jul 23, 2026 →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)[Autonomy & Part 57 NRC Part 57 and Autonomous Operation, Explained The NRC's proposed Part 57 rule defines autonomous operation for microreactors. Here is what it says, what it does not, and why the trust surface matters now. Jul 23, 2026 →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)[Verification & trust Self-Attestation vs Independent Verification for Autonomous Reactors When a reactor reports its own status, who checks the check? Compare self-attestation and independent verification for autonomous and remote reactor operations. Jul 23, 2026 →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)[Verification & trust How to Verify an Autonomous Microreactor Is Operating Safely An autonomous microreactor runs with fewer people on site. See how independent verification confirms it is operating safely, without taking a vendor's word. Jul 23, 2026 →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)[Reactor safety Walk-away safety, explained Walk-away safety means a reactor shuts itself down and cools itself using physics alone, with no operator, no power, and no pumps. Here is how it works. Jul 21, 2026 →](https://rankshieldenergy.com/resources/walk-away-safety-explained)[Reactor fundamentals What is a nuclear microreactor? A nuclear microreactor is a factory-built reactor producing roughly 1 to 20 megawatts, per DOE, small enough to ship on a truck to where power is needed. Jul 21, 2026 →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
No guides in that topic yet.



---

## Page: https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained/

# Microreactor Cybersecurity and the New Threat Model

> Digital instrumentation and autonomous control change the microreactor threat model. See how today's standards point toward independent cyber attestation.

[Resources](https://rankshieldenergy.com/resources) / Cybersecurity Cybersecurity

# Microreactor Cybersecurity, Explained: Digital I&C and the New Threat Model
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Digital instrumentation and control, plus autonomous and remote operation, change what an attacker can reach in a microreactor, and they change what the safety case depends on. A cyber compromise here can have physical consequences, not just informational ones. This is why the standards landscape keeps pointing in one direction: toward evidence about reactor state that a party other than the operator can independently check.
Reactor cybersecurity is not ordinary IT security, because the systems being protected are the ones that read plant state and move equipment. The NRC frames its cyber work around protecting the digital systems tied to safety and security functions [[1]](#src-1), and its Regulatory Guide 5.71 builds a program around exactly the systems whose compromise would matter physically [[2]](#src-2). When operation moves off site and leans harder on software, more of that safety story travels as data, and the integrity of that data becomes part of the case.
This article covers why reactor cyber is a safety problem rather than an IT problem, how supply chains and connectivity erode the old air gap, how autonomy widens the attack surface, and where the standards actually stand, including which pieces are settled and which are still proposed. It closes with a stated counterargument and an honest limitation. RankShield Energy is a pre-applicant holding no license or approval [[15]](#src-15), and the last section applies the argument to us as unsentimentally as to anyone else.
Key takeaways

- Reactor cyber is a safety discipline: a digital compromise can have physical consequences, so it is scoped around safety-linked I&C, not treated like enterprise IT.
- The air gap has eroded through connectivity and global supply chains, so the threat model has to assume paths in rather than assume isolation.
- Autonomy and remote operation move human actions onto networks, which widens the attack surface without removing the human from safety decisions.
- The standards landscape is mixed: RG 5.71 is existing guidance, proposed 10 CFR 73.110 is under development and not final, and the microreactor-specific case is still being researched.
- Those standards keep pointing toward independent attestation, which RankShield applies as an engineering concept, not a deployed or certified capability.

## Reactor cybersecurity is a safety problem, not an ordinary IT problem
The short answer is that a compromise of the wrong system in a reactor can have physical, not just informational, consequences, and that changes everything about how the risk has to be treated. In ordinary enterprise IT, the worst outcome of an intrusion is usually loss of data, money, or availability. In a reactor, the systems being protected are the instrumentation and control that read plant state and move equipment, so the failure surface includes physical processes rather than only records.
This is why nuclear cyber guidance is written around consequence rather than around convenience. The NRC's Regulatory Guide 5.71 sets out a cyber security program for power reactors that centers on the systems whose compromise could affect safety, security, and emergency preparedness functions, and it builds defensive architecture and controls around exactly those functions [[2]](#src-2). The point is not to secure everything equally, but to identify the systems where a digital compromise becomes a physical problem and to protect those most strongly.
The regulator's own framing keeps cyber tied to the same protective mission as physical security, and its cyber security resources describe the objective as protecting digital systems and networks associated with safety and security functions [[1]](#src-1). That is a narrower and more demanding target than "keep the network safe." It means the threat model has to reason about how a manipulated sensor value or a spoofed command could propagate into the plant.
Advanced reactors sharpen this because they lean harder on digital instrumentation and control than the analog fleet did, and the NRC has published dedicated guidance for digital I&C in that context [[7]](#src-7). The more of the plant that is mediated by software, the more the safety case depends on the integrity of that software and the data moving through it. Treating that as a generic IT problem would miss the part that actually matters, which is why [verifying that a microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) has a cyber dimension that a conventional security audit does not fully cover.

## Why the old air gap no longer protects a microreactor
The honest answer is that the air gap was always partly an assumption, and modern microreactor concepts weaken the parts of it that were real. The traditional mental model was that safety-significant systems sat on isolated networks with no path to the outside world. Two forces erode that: the systems now update, phone home, and integrate with monitoring far more than legacy analog equipment did, and the components arrive through long, global supply chains that carry their own risk before anything is ever connected.
Supply chain is the part that gets underweighted. A component can be compromised in development, manufacturing, or distribution, well before installation, which is why federal guidance now treats cyber supply chain risk as a first-class program rather than an afterthought. NIST SP 800-161r1 lays out practices for managing that risk across the acquisition life cycle, including provenance, integrity, and the assurance of components sourced from third parties [[8]](#src-8). For a reactor built from digital modules, the boundary you are defending starts at the supplier, not at the fence line.
The international standards community reached the same conclusion from the I&C side. IEC 62645 defines requirements for security programs for computer-based systems in nuclear power plants, and it is built around the reality that these systems have life cycles, dependencies, and update paths that must be governed rather than assumed away [[3]](#src-3). It treats security as a program property of the whole system, not a perimeter you draw once.
The IAEA guidance is more explicit still about where the exposure lives. Its Nuclear Security Series No. 33-T addresses computer security of instrumentation and control systems at nuclear facilities and works through the life cycle from design through decommissioning, including the interfaces and remote access paths that a purely perimeter-based model tends to ignore [[4]](#src-4). Put together, the guidance points one direction: for a digital, connected, globally sourced microreactor, "isolated and therefore safe" is not a claim anyone can make at face value, and the threat model has to assume paths in rather than assume them away.

## How autonomy and remote operation widen the attack surface
The direct answer is that every function you move from a person in a control room to software over a network becomes something that can be attacked over that network, and microreactor economics push hard toward exactly that shift. Reduced on-site staffing, remote monitoring, and centralized fleet operation are what make small reactors financially plausible, and each of those design moves converts a physical, local action into a digital, remote one that now has to be secured and verified.
The national laboratories have mapped what this disturbs. Oak Ridge, in its concepts for autonomous operation of microreactors, describes control approaches that reduce human intervention and lean on sensing, state awareness, and remote supervision, and it names the cybersecurity of those monitoring and control paths as a precondition rather than a detail [[13]](#src-13). Autonomy does not remove the human decision so much as move it, and it adds a data path that must be trustworthy for the moved decision to be sound.
Sandia, working on human factors for automating microreactors, examined designs where operators supervise from a distance and where a single control room may oversee multiple units, and it treated the reliability of the human-automation interface as a safety-relevant question rather than a usability nicety [[14]](#src-14). When one operator supervises several reactors through screens fed by remote data, the integrity of that data becomes part of the safety story, which is the through-line of [fleet-scale verification with one operator and many reactors](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
The regulatory frame is catching up to this. The proposed 10 CFR Part 57 rule contemplates licensing microreactors with operating models that include remote and reduced-staffing operation, and it is a proposal rather than a settled requirement [[12]](#src-12). None of this removes the human from reactivity and safety actions, and it should not be read that way. It does mean the attack surface now includes the command, monitoring, and attestation channels that carry operation across a distance, and those channels did not exist in the staffed analog plant. That is explained neutrally in [our walkthrough of Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).

## The standards landscape at a glance, with status
The most important thing to get right about this landscape is status: some of it is existing guidance, some is an international consensus standard, and one central piece is still a proposal. Conflating those is the most common error we see, so the table below separates what a document is from how settled it is. Reading a proposed rule as a present-day requirement, or a research project as a standard, produces bad decisions.

Microreactor cyber standards and frameworks, by scope and status

Instrument
Scope
Status
What it means here

NRC RG 5.71, Rev. 1
Cyber security programs for nuclear power reactors
Existing regulatory guidance for power reactors
The established baseline the field reasons from

Proposed 10 CFR 73.110
Technology-neutral cyber requirements
Proposed, under development, not final or prescriptive
A direction of travel, not a rule anyone meets yet

IEC 62645:2019
Security programs for computer-based I&C
International consensus standard
Widely referenced technical program requirements

IAEA NSS 33-T
Computer security of I&C at nuclear facilities
International guidance
Life-cycle guidance, advisory not binding

IAEA CRP J02021
Computer security of SMRs and microreactors
Active research project
Open questions being studied, not settled answers

Two rows deserve emphasis. The proposed 10 CFR 73.110 is a technology-neutral cyber rule that remains under development and is not final or prescriptive, so it should be read as where the NRC may be heading and not as a requirement in force [[1]](#src-1). RG 5.71 is the existing guidance that the current power fleet actually works from, and it is the concrete reference point when people ask what "good" looks like today [[2]](#src-2).
The international layer runs in parallel rather than underneath. IEC 62645 supplies consensus program requirements [[3]](#src-3), NSS 33-T supplies life-cycle guidance [[4]](#src-4), and the IAEA's coordinated research project J02021 is explicitly aimed at the SMR and microreactor case, which tells you the specialist questions for this reactor class are still being researched rather than resolved [[5]](#src-5).

## Why the standards point toward independent attestation
Read together, these documents keep circling the same requirement: a party that relies on a system needs evidence about that system's state that does not simply come from the system's own operator. That is the definition of attestation, and the general-purpose computing world has already standardized the architecture for it, which is why it is worth borrowing rather than reinventing.
RFC 9334, the Remote Attestation Procedures architecture, formalizes the split cleanly: an Attester produces evidence about its state, a Verifier appraises that evidence against a policy, and a Relying Party acts on the Verifier's result, on the premise that one party needs to know whether another is in an expected operating state before trusting it [[10]](#src-10). Mapped onto a reactor, the operator is not asked to be believed; the operator is asked to produce evidence a separate party can appraise, which is exactly the shape [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) describes.
The supply chain problem has an analogous emerging pattern. RFC 9943 sets out an architecture for trustworthy and transparent digital supply chains using signed statements recorded on an append-only transparency service, so that a later party can check what was claimed and when, without trusting the claimant to have been honest after the fact [[11]](#src-11). For a reactor assembled from digital modules, that maps directly onto proving what software and components went in and stayed in.
Durability is the piece people forget, and it is where cryptography choices become a long-horizon decision. Records meant to outlive a reactor design cycle have to survive advances in computing, which is why NIST's approval of post-quantum signature standards in 2024 is relevant to a nuclear conversation at all [[9]](#src-9). None of this makes a system "unhackable," and we do not use that word, because it is not a property any real system has. Attestation does something narrower and more useful: it makes divergence between claim and reality detectable by someone other than the party making the claim. That is the property the standards keep reaching for.

## What is settled versus what is still proposed
The honest summary is that the direction is clearer than the destination, and it is worth being precise about which is which. What is settled: reactor cyber is a safety-linked discipline, RG 5.71 is the working baseline for the power fleet, and the international standards for computer-based I&C exist and are referenced. What is not settled: the technology-neutral rule aimed at this class, and much of the microreactor-specific detail, is still in development.
The proposed 10 CFR 73.110 illustrates the gap exactly. It is a proposal under development, technology-neutral in intent, and it is not final or prescriptive, so a vendor cannot truthfully say it complies with a rule that does not yet exist in final form [[1]](#src-1). The same discipline applies to the licensing frame around it: proposed Part 57 is a proposal whose provisions may change through the rulemaking process, not a set of requirements in force [[12]](#src-12).
Staff analysis is another place precision matters. The NRC staff paper SECY-24-0008 on micro-reactor licensing and deployment lays out options and considerations for how this reactor class might be licensed, and it is staff analysis rather than a Commission decision or an adopted policy [[6]](#src-6). Reading a SECY paper as settled agency position is a common and consequential misread, because the staff can analyze a path the Commission does not ultimately take. We treat these documents as signals of direction and open questions, not as commitments.
So the defensible posture, and the one we hold, is to design toward where the guidance is clearly pointing while stating plainly that the specific rules for microreactor cyber are not final. That is not hedging for its own sake. It is the difference between a claim that survives contact with a docket and one that does not, and it is the standard we apply when we help others [evaluate a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) on exactly these questions.

## A counterargument, stated plainly and answered
The strongest objection to all of this deserves to be stated in its own words rather than a strawman. It runs like this: nuclear operators already run mature cyber programs under existing NRC guidance, the fleet has a strong operational record, and adding an independent attestation layer is expensive complexity that duplicates controls the operator already has. On this view, self-run cyber programs plus regulatory inspection are sufficient, and a separate verifier is a solution in search of a problem.
That objection has real force for a staffed plant, and we do not dismiss it. Where it weakens is precisely the shift this article is about. When operation moves to remote and reduced-staffing models, the local human checks that quietly backstopped a self-run program thin out, and more of the assurance has to travel as data across a network the attacker can reach. The labs studying autonomous and automated operation flag the integrity of exactly those monitoring and control paths as a precondition, not a side issue [[13]](#src-13) [[14]](#src-14). An independent appraisal of state is not duplicating the operator's controls; it is covering the failure mode where the operator's own reporting path is the thing that is wrong.
The second half of the answer is that the specialist questions here are openly unresolved, which cuts against declaring any current program sufficient for this reactor class. The IAEA is running an active research project specifically on the computer security of SMRs and microreactors, which is a strong signal that the field itself does not consider the microreactor case closed [[5]](#src-5). The NRC's dedicated digital I&C guidance for advanced reactors exists for the same reason: the digital, autonomous case raises questions the analog fleet did not have to answer [[7]](#src-7). Our position, stated so it can be argued with, is that independent attestation is a hedge against an assurance gap that autonomy widens, and that the burden of proof sits with anyone claiming a self-run program alone closes it. This is where [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) stops being abstract.

## Where RankShield sits, honestly, and one limitation
To be clear about our own standing: RankShield Energy is a pre-applicant engaged in early interaction with the NRC. We hold no license, permit, or design approval, and nothing about our design or our attestation approach has been demonstrated to or accepted by the NRC [[15]](#src-15). Independent, verifier-separate attestation of reactor and I&C state is a concept we apply in our engineering work, not a deployed or certified capability, and we will not describe it as one. We do not claim to meet any finalized cyber standard, because for this reactor class the central rule is still proposed and under development.
Where our actual first-hand experience lives is worth naming precisely, because it bounds what we can honestly assert. Our working domain is attestation and verification engineering: independent verifiers, signing, append-only transparency logs, and post-quantum signature choices. That is real hands-on work, and it is the lens through which we read the reactor cyber problem. It is also not reactor operating experience, which we do not have and do not claim, and none of it removes the human from reactivity and safety decisions.
The honest limitation is this: attestation proves properties of records and system state, and it is only as meaningful as the sensors and the appraisal policy behind it. A verifier can prove that a signed measurement was recorded and not altered, and that it matched a stated policy at the time. It cannot, by itself, prove that the underlying sensor was correctly calibrated or that the policy captured every failure worth catching. Those are engineering and analysis problems that sit upstream of the cryptography, and any vendor telling you attestation alone makes a reactor secure is overselling it. We would rather draw that boundary ourselves than have a regulator or a customer draw it for us.
So the defensible claim, and the only one we make, is narrow: as microreactors move toward autonomous and remote operation, the standards landscape is pointing toward evidence a party other than the operator can check, the specific rules for this class are not yet final, and we are building toward the verifier-separate version of that architecture as a pre-applicant with everything still to prove. That is less exciting than a guarantee, and it is the version that will still be true after the rulemaking closes.

## Frequently asked questions

### Why is microreactor cybersecurity treated differently from normal IT security?
Because a compromise can have physical consequences, not just informational ones. The systems being protected are the instrumentation and control that read plant state and move equipment, so a manipulated value or spoofed command can propagate into the plant itself. That is why the NRC's Regulatory Guide 5.71 organizes a reactor cyber program around the systems whose compromise could affect safety, security, and emergency preparedness functions, rather than protecting everything equally [[2]](#src-2), and why the agency ties cyber to the same protective mission as physical security [[1]](#src-1).

### Is the microreactor cyber rulebook finalized?
No. The technology-neutral cyber rule commonly referenced as proposed 10 CFR 73.110 is still under development and is not final or prescriptive, so no vendor can truthfully claim to comply with it [[1]](#src-1). The licensing frame around it, proposed 10 CFR Part 57, is likewise a proposal that may change through rulemaking [[12]](#src-12). Existing guidance such as RG 5.71 is the working baseline for the current power fleet, and international standards like IEC 62645 apply, but the microreactor-specific detail is still being worked out.

### How does autonomy change the threat model?
Every function moved from a person on site to software over a network becomes something an attacker can reach over that network. Oak Ridge's work on autonomous microreactor operation names the cybersecurity of the monitoring and control paths as a precondition [[13]](#src-13), and Sandia's human factors work examines remote supervision and one control room overseeing multiple units, where the integrity of the data feeding those screens becomes safety-relevant [[14]](#src-14). Proposed Part 57 contemplates remote and reduced-staffing operation, and it does not remove the human from reactivity and safety actions [[12]](#src-12).

### What does independent attestation actually add?
It gives a party that relies on the reactor evidence about its state that does not simply come from the operator. The computing world standardized this in RFC 9334, which separates an attester that produces evidence, a verifier that appraises it, and a relying party that acts on the result [[10]](#src-10), and RFC 9943 applies a similar transparency pattern to supply chains so later parties can check what was claimed and when [[11]](#src-11). It does not make anything unhackable, a word we avoid. It makes divergence between claim and reality detectable by someone other than the party making the claim.

### Does RankShield Energy meet the NRC cyber standard today?
No, and it would be inaccurate to say so, because the central rule for this reactor class is still proposed and under development. RankShield Energy is a pre-applicant with no license, permit, or design approval, and nothing about our approach has been demonstrated to or accepted by the NRC [[15]](#src-15). Independent, verifier-separate attestation is a concept we apply in our engineering work, not a deployed or certified capability. Our first-hand expertise is in attestation and verification engineering, not reactor operations, and human-in-the-loop control of safety actions is preserved throughout.

## Sources

- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026 (proposed 10 CFR 73.110 technology-neutral cyber requirements still in development, not final or prescriptive)](https://www.nrc.gov/security/cybersecurity)
- [U.S. Nuclear Regulatory Commission. Regulatory Guide 5.71, Rev. 1: Cyber Security Programs for Nuclear Power Reactors. February 2023](https://www.nrc.gov/docs/ML2225/ML22258A204.pdf)
- [International Electrotechnical Commission. IEC 62645:2019, Nuclear power plants: I&C systems: Requirements for security programmes for computer-based systems. 2019](https://webstore.iec.ch/en/publication/32904)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Nuclear Regulatory Commission. SECY-24-0008: Micro-Reactor Licensing and Deployment (staff paper). 2024](https://www.nrc.gov/docs/ML2320/ML23207A250.pdf)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Turning reactor state into an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor cybersecurity standards and NRC rulemaking as of July 2026. Proposed requirements such as 10 CFR 73.110 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained/

# NRC Part 57 and Autonomous Reactor Operation

> The NRC's proposed Part 57 rule defines autonomous operation for microreactors. Here is what it says, what it does not, and why the trust surface matters now.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# NRC Part 57 and Autonomous Operation, Explained
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Proposed 10 CFR Part 57 is the NRC's draft licensing framework for microreactors, and its most consequential feature is that it contemplates remote operation and reduced on-site staffing. It is a proposal, not law. The comment period closed in June 2026, no developer is licensed under it, and the text can still change before any final rule is issued.
What makes it worth understanding anyway is the direction it sets. Today federal regulation requires a licensed operator to be present at the controls at all times [[6]](#src-6), and the NRC keeps roughly 150 resident inspectors in the field to independently verify that requirements are being met [[11]](#src-11). Part 57 contemplates changing the first of those, and NRC staff have separately proposed a scalable inspection footprint that would change the second [[5]](#src-5).
This guide covers where the rule stands, the problem it is trying to solve, what it changes about human presence, how it differs from the final Part 53 rule, what autonomous operation does and does not mean, and the verification question the rule opens without answering. RankShield Energy is a pre-applicant holding no license or approval [[17]](#src-17), and we are not licensed under Part 57 or any other rule.
Key takeaways

- Part 57 is a proposed rule published May 1, 2026. The comment period closed in June 2026 and no developer is licensed under it.
- Its substantive change is contemplating remote operation and reduced on-site staffing, against a current rule requiring an operator at the controls at all times.
- Part 53 is final and available now; Part 57 is proposed and microreactor-specific. They are not interchangeable.
- Automation, remote operation, and autonomous operation are three different things, and 'unmanned' is not a regulatory category.
- NRC staff have proposed a scalable inspection footprint, so fewer regulator eyes per reactor is the explicit direction, not a side effect.

## Where the proposed rule actually stands today
The Nuclear Regulatory Commission published proposed 10 CFR Part 57 in the Federal Register on May 1, 2026, as a licensing framework for microreactors and other reactors with comparable risk profiles [[1]](#src-1). The public comment period closed on June 15, 2026. The rule is not final.
Three consequences follow, and they are worth stating before anything else because most coverage blurs them. No developer is licensed under Part 57, because a proposed rule confers no licensing authority. The text can change between proposal and final rule, sometimes substantially. And a developer describing itself as operating under Part 57 today is describing an intention rather than a status.
Companion draft guidance, NUREG-2271, was issued for comment alongside it, framed by the NRC around rapid licensing of first-of-a-kind microreactors and high-volume deployment [[2]](#src-2). Guidance and rule move together, and both are drafts.
None of that makes the proposal unimportant. It makes it a direction rather than a destination, and reading it as a direction is what lets you plan against it honestly.

## The problem Part 57 is trying to solve
The NRC has been circling microreactor policy for years. SECY-20-0093, in October 2020, flagged autonomous operation, remote operation, staffing, and regulatory oversight as open policy questions specific to this class of reactor [[3]](#src-3). Those questions did not have clean answers inside a framework built for large light-water plants.
More recently the agency has been planning explicitly for repetition. SECY-25-0052 addresses nth-of-a-kind microreactor licensing and deployment, including standardization of operational programs [[4]](#src-4), which is the regulatory shape of many identical units rather than a handful of bespoke ones.
The statutory push comes from the ADVANCE Act, which directs the NRC to develop microreactor strategies across eight areas including staffing and operations, and oversight and inspections [[5]](#src-5). Congress asked for the thing Part 57 is attempting.
Underneath all of it is an arithmetic problem. A licensing and oversight model that assumes a large staffed plant does not scale to many small ones. If each microreactor consumes the regulatory attention of a conventional unit, the deployment numbers the industry describes are not reachable. Part 57 is the NRC trying to change that ratio deliberately rather than letting it be eroded by pressure.

## What the rule changes about who has to be present
To see what is actually being proposed, you have to look at the requirement it sits against. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times, and a licensed operator or senior operator must be present at the controls at all times [[6]](#src-6). That is a condition of the license for the operating fleet, not a convention.
Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1). That is the substantive shift: not automation for its own sake, but relocating and reducing the human presence that current regulation fixes in place.
A distinction the NRC and INL have drawn matters here, because the industry uses these words loosely. Remote means command and control moved outside the reactor site boundary, and monitoring, meaning collecting and observing plant data, is a different activity from operations [[7]](#src-7). A vendor claiming remote capability may mean either, and the two carry very different regulatory weight.
Sandia National Laboratories, working for the NRC, described the operational picture the rules would have to accommodate: operators may not be located on site and may monitor from a remote location, and some designs contemplate one control room supervising multiple microreactors [[8]](#src-8). That last clause is the [fleet-scale question](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors), and it is the one with the least settled answer.
It is worth being concrete about why this could not simply be handled by exemption. Oak Ridge National Laboratory examined what autonomous control actually disturbs in the existing regulatory structure and found the list runs well beyond headcount: staffing requirements, manipulation of the controls, licensed operator provisions, technical specifications, cybersecurity, and event notification obligations, with the added wrinkle that a control room may not be co-located with the plant at all [[18]](#src-18).
That is the case for a purpose-built framework rather than a series of carve-outs. Each item on that list is a separate place where regulation written for a staffed plant assumes a person who is now somewhere else, or nowhere. Granting exemptions one at a time would leave a licensing basis stitched together from exceptions, which is difficult to review consistently and harder still to replicate across many identical units. Part 57 is an attempt to write the assumptions down once.
The tradeoff is that a new framework has to earn its own confidence. An exemption sits against decades of operating experience with the underlying rule. A new rule for a class of reactor that has not yet operated commercially has no such record behind it, which is part of why the oversight provisions discussed further down matter as much as the licensing ones.

## Part 57 compared with the final Part 53 rule
Two frameworks are often mentioned together and they are not interchangeable. Part 53 is final. Part 57 is proposed and microreactor-specific.

Proposed Part 57 and final Part 53, compared

10 CFR Part 53
10 CFR Part 57 (proposed)

Status
Final rule, published March 30, 2026
Proposed rule, published May 1, 2026; comment period closed June 2026

Scope
Broad, risk-informed and technology-inclusive framework for advanced reactors
Microreactors and other reactors with comparable risk profiles

Autonomy and staffing
General advanced-reactor framework
Contemplates remote operation and reduced on-site staffing

What it grants a developer today
An available licensing pathway
Nothing yet; no one can be licensed under a proposed rule

Part 53 was finalized as a risk-informed, technology-inclusive framework for advanced reactors [[9]](#src-9). It is optional, and it is available now. Part 57 is the narrower, faster instrument aimed at a specific class, and it is not.
The practical read for a buyer: ask which framework a developer is pursuing and why. A developer betting entirely on a rule that has not been finalized is carrying a schedule risk that a developer using an available pathway is not. Neither choice is wrong. The absence of an answer is the signal.

## What autonomous operation does not mean
The proposed rule introduces vocabulary, and vocabulary is where most of the public confusion lives. Three terms get used interchangeably and should not be.
**Automation** is a machine performing a defined function without a person executing it, and it has existed in reactors for decades. **Remote operation** is command and control from outside the site boundary. **Autonomous operation** describes a system taking action across a range of conditions without an operator directing each one. A plant can be heavily automated with people on site, or lightly automated and operated remotely.
What none of them means is a reactor with nobody responsible for it. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended. "Unmanned" and "fully autonomous" are not regulatory categories, which is why we treat them as language to avoid rather than goals to advertise, and why we cover the [terminology distinctions](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms) on their own.
The framing that has held up best comes from Brookhaven National Laboratory, in work for the NRC on facilities without main control rooms: the safety question is not so much justifying why a design has no main control room, but rather verifying that important human actions can be accurately and reliably performed [[10]](#src-10). Autonomy does not remove the human actions. It changes how anyone confirms they happened.

## The oversight half of the rule that gets less attention
Licensing is only one side. The other is what happens for decades afterwards, and here the NRC has been unusually direct. In December 2025, staff proposed operational-phase microreactor oversight built on innovative inspection methodologies and a scalable inspection footprint [[5]](#src-5).
Set that against the current baseline. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, describing their role as independently verifying that requirements are being met [[11]](#src-11), inside a Reactor Oversight Process built on inspection findings, performance indicators, and a significance determination process [[12]](#src-12).
A scalable footprint across many small units means fewer inspector-hours per reactor. That is the explicit intent, not an unintended consequence. Meanwhile the Government Accountability Office has reported that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[13]](#src-13), and still lists licensing advanced reactors among its priority open recommendations [[14]](#src-14).
So the trajectory is fewer regulator eyes per reactor, arriving alongside more reactors. Something has to carry the confirmation load that presence used to carry, which is precisely the [verification problem](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) the rest of this site is about.
There is a reasonable counterargument worth stating fairly. A microreactor is a smaller source term than a gigawatt-class plant, so proportionally lighter oversight is not obviously wrong, and the entire premise of risk-informed regulation is that attention should follow consequence rather than be distributed evenly. On that reading, a scalable inspection footprint is the framework working as designed rather than a weakening of it.
The response is not that the reasoning is wrong, it is that it is incomplete. Reduced consequence justifies reduced inspection intensity. It does not by itself establish how anyone confirms a reactor is behaving as described between those less frequent inspections. Those are separate questions, and the second is the one with no settled answer yet. A framework can be correct about proportionality and still leave a gap in confirmation, which is what we think is happening here.

## The trust surface the proposed rule opens
If a reactor is operated from outside the site boundary and inspected less often, then more of what anyone knows about it arrives as data the operating organization produces about itself. That is not a criticism of any operator. It is a structural description of the model Part 57 contemplates.
It creates a question the rule does not answer, and arguably should not: who confirms the reported state, and are they separate from the party reporting it. Nuclear already contains the precedent for the answer, since IAEA safeguards exist so that an outside body can independently verify rather than rely on an operator's assertion [[15]](#src-15). Computing standardized the same split, with a verifier appraising evidence separately from the attester that produced it [[16]](#src-16).
This is why [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) are worth separating carefully when reading any vendor claim made under a Part 57 framing. The rule opens the operating model. It does not supply the trust layer that model needs, and no developer should imply that it does.

## What this means if you are evaluating a developer, including us
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, we are not licensed under Part 57 or any other rule, and nothing about our design has been demonstrated to or accepted by the NRC [[17]](#src-17). Describing the rule is not the same as satisfying it, and we are not claiming to.
Three questions travel well here. Which framework is the developer pursuing, and is it final or proposed. When they say remote or autonomous, which of the three definitions do they mean. And who confirms reactor state independently of the operator. Those are the questions in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they are answerable without any proprietary disclosure.
Our own view, stated plainly so it can be argued with: the staffing and oversight changes Part 57 contemplates are reasonable, and the verification layer they imply is not yet built by anyone, including us. Treating that gap as solved is the most common overclaim in this market right now.

## Frequently asked questions

### Is NRC Part 57 in effect?
No. Proposed Part 57 was published in the Federal Register on May 1, 2026, and the public comment period closed on June 15, 2026 [[1]](#src-1). It is a proposed rule, which means it is the NRC's draft framework for public review rather than law. No developer is licensed under it, the text can change before any final version is issued, and any description of what Part 57 permits or requires is a description of a draft. Companion draft guidance, NUREG-2271, was issued for comment alongside it [[2]](#src-2).

### Does Part 57 allow reactors to run with nobody present?
It contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1), which is a meaningful change from the current requirement that a licensed operator be present at the controls at all times [[6]](#src-6). But reduced is not absent. Safety-significant actions keep a human in the loop, no facility is licensed to operate unattended, and "unmanned" is not a regulatory category. Whether any specific design can operate with a given staffing arrangement would be evaluated for that design under review.

### What is the difference between Part 53 and Part 57?
Part 53 is a final rule, published March 30, 2026, establishing a broad risk-informed and technology-inclusive framework for advanced reactors [[9]](#src-9). It is optional and available now. Proposed Part 57 is narrower, aimed specifically at microreactors and reactors with comparable risk profiles, and is not final [[1]](#src-1). The practical difference for a developer is that one is an available pathway today and the other is a proposal that may change. Ask which a developer is pursuing and why.

### What does autonomous operation actually mean here?
It describes a system taking action across a range of conditions without an operator directing each one. It is distinct from automation, which is a machine performing a defined function and has existed in reactors for decades, and from remote operation, which is command and control from outside the site boundary. A plant can be heavily automated with staff on site, or lightly automated and run remotely. Vendors frequently blur all three, so the useful follow-up is which specific meaning they intend.

### Why does Part 57 matter for verification?
Because it shifts how anyone outside the operating organization learns what a reactor is doing. With operation possible from outside the site boundary and the NRC proposing a scalable inspection footprint for operational oversight [[5]](#src-5), more of the picture arrives as data the operator reports about itself. The rule opens that model without supplying the layer that makes such reports checkable by an outside party, which is why independent verification becomes more load-bearing under Part 57 rather than less.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Automation vs remote vs autonomous →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)
- [HELIX licensing approach →](https://rankshieldenergy.com/licensing)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of NRC microreactor rulemaking as of July 2026. Proposed 10 CFR Part 57 is not final and may change; its comment period closed in June 2026. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/nrc-pre-application-process-explained/

# How the NRC Advanced Reactor Pre-Application Works

> Pre-applicant does not mean approved. See how NRC advanced-reactor pre-application engagement actually works, step by step, and what it does and does not grant.

[Resources](https://rankshieldenergy.com/resources) / Licensing & pre-application Licensing & pre-application

# How the NRC Pre-Application Process Actually Works
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Pre-application is the early, voluntary stage in which a reactor developer engages the U.S. Nuclear Regulatory Commission about a design it may later seek to license. It is engagement, not approval. It grants no license, no permit, no construction authorization, no design approval, and no safety finding, and a developer that describes it as more than that is telling you something the public record does not support.
The word "pre-applicant" does a lot of quiet work in press releases. It sounds like a rung on an approval ladder, as though a regulator had reviewed a design and advanced it one step. The NRC describes pre-application activities as a way to become familiar with a developer technology and plans before an application is submitted [[1]](#src-1), which is a different thing entirely. Familiarity is not endorsement, and a conversation is not a finding.
This article covers what a pre-applicant actually is, the mechanics of the process from letter of intent through project number, Regulatory Engagement Plan, meetings, and topical reports [[3]](#src-3), what engagement does and does not grant, why serious developers still engage early, which licensing framework a developer may pursue now that Part 53 is final [[4]](#src-4) and Part 57 is proposed and not final [[5]](#src-5), how to check a claimed status against the public record, and what the Government Accountability Office has said about NRC readiness for this workload [[10]](#src-10). RankShield Energy is a pre-applicant holding no license, permit, or design approval, and the closing section applies every test in this article to us.
Key takeaways

- Pre-application is engagement with the NRC, not approval by it: no license, no permit, no design approval, no safety finding.
- A pre-applicant is two full legal transitions away from being a licensed, overseen operating plant.
- The Regulatory Engagement Plan is the substantive artifact; a project number is administrative and routinely over-read.
- Part 53 is a final rule as of March 30, 2026; Part 57 is a proposed rule and is not final, so claims keyed to it are claims against a proposal.
- Test any claimed status by asking whether it names a retrievable document and whether it separates a narrow staff conclusion from approval of a design.

## Pre-application is engagement, not approval
The plainest version is this: pre-application is a conversation. A developer tells the NRC what it intends to build and how it intends to license it, and the NRC uses that interaction to become familiar with the technology and the plan before any application is submitted [[1]](#src-1). Nothing in that conversation issues a license, a permit, a construction authorization, a design approval, or a safety finding.
The confusion is structural rather than accidental. The label "pre-applicant" reads like an early rung on an approval ladder, as though a regulator had looked at a design and advanced it one step. It is not a rung on that ladder. It is the stage before the ladder, and the NRC organizes it as general guidance on how to interact productively ahead of a submittal [[3]](#src-3), not as a grading exercise.

What NRC pre-application engagement grants, and what it does not

Question
Pre-application engagement

Does it grant a license or permit?
No. No operating license, no construction permit, no construction authorization.

Does it grant a design approval or certification?
No. Design approval and design certification are separate regulatory actions with their own applications and reviews.

Does it produce a safety finding?
No. The NRC makes safety findings on applications under review, not on pre-application discussion.

Does it mean the NRC endorses the technology?
No. Engagement is not endorsement, and the NRC does not promote the designs it interacts with.

Does it commit the developer to apply?
No. Pre-application activity is voluntary and a developer may never file.

What does it actually do?
It lets the NRC become familiar with a technology and a developer plan before an application arrives, and lets the developer surface regulatory issues while the design can still absorb them.

Read the bottom row of that table carefully, because it is the honest case for the process. Pre-application has real value, and serious developers use it. The value is informational and procedural. It is not a credential. When a reader treats it as a credential, the error is expensive in a specific direction: money, land, offtake conversations, and community expectations all get committed against a status that carries no regulatory finding at all. That is why this post exists, and why we apply the same test to ourselves in the closing section. If you only remember one sentence, remember that the NRC becoming familiar with a design is not the NRC accepting it [[1]](#src-1).

## A pre-applicant is a developer in conversation, not one the NRC has cleared
A pre-applicant is a developer that has begun interacting with the NRC about a design or project it may later seek to license, but that has not necessarily submitted an application and certainly has not received one back approved. The NRC maintains public pages describing the advanced reactor developers it is working with in this posture [[1]](#src-1). Appearing there means the interaction exists. It says nothing about whether the design is sound, whether the schedule is credible, or whether the developer will ever file.
It helps to hold three distinct statuses in your head. A **pre-applicant** is talking to the regulator. An **applicant** has filed something the NRC has docketed and is reviewing, which puts the submittal into a formal review process with defined acceptance criteria [[3]](#src-3). A **licensee** has been granted a license and has become subject to ongoing regulatory oversight, which for operating power reactors runs through the Reactor Oversight Process and its inspections and performance indicators [[13]](#src-13).
Those are not shades of the same thing. They are three different legal positions, and the distance between them is measured in years of technical review, not in press releases. A pre-applicant is two full transitions away from being an overseen operating plant. Anyone describing pre-application status as evidence that a reactor is "on track for approval" is compressing a gap that the regulator itself does not compress [[1]](#src-1).
This also explains why the oversight regime you may have read about does not yet apply to any pre-applicant. The Reactor Oversight Process is a framework for plants that already hold licenses and are already operating [[13]](#src-13). It is a useful thing to understand early, because it tells you what real regulatory scrutiny of an operating plant looks like, and it makes the comparatively light weight of a pre-application conversation obvious by contrast.

## The mechanics: intent, project number, engagement plan, meetings, topical reports
The process has recognizable machinery, and knowing the pieces makes vendor claims much easier to parse. A developer that wants to engage generally notifies the NRC in writing of its intent to interact, which allows the staff to set up a project and plan the resources the interaction will consume [[3]](#src-3). Assignment of a project number is an administrative act. It is a filing-cabinet label, and it is one of the most commonly over-read artifacts in this whole space.
The substantive document is the **Regulatory Engagement Plan**. The NRC asks developers to lay out what they intend to submit, in what order, and on what schedule, so the staff can anticipate workload and the developer can see the sequence of its own regulatory obligations [[2]](#src-2). This is the artifact that most rewards honesty, because a plan that promises a heavy stream of submittals a developer cannot actually produce becomes visible fast.
From our own side of that exercise, the useful part was not the document but what writing it forced. Sequencing planned submittals made it immediately obvious which technical questions we had actually closed and which we had merely deferred, because you cannot schedule a topical report on a subject you have not yet decided. That is an uncomfortable and genuinely valuable output, and it happens before anything is filed.
The interaction itself runs through pre-application meetings with the staff and, where a developer chooses, through **topical reports** and white papers that isolate a single technical or methodological question ahead of a full application [[3]](#src-3). Related guidance for microreactor developers specifically is collected on the NRC pages tracking microreactor regulatory activities [[7]](#src-7). None of these steps produces an approval of a design. A topical report review can produce a staff conclusion on the narrow question the report addresses, which is a real and useful thing, and it is still not a license.

## Developers engage early because late regulatory surprises force redesign
If pre-application grants nothing, why bother? Because the alternative is discovering a regulatory expectation after the design is frozen. The NRC frames pre-application interaction as a way to identify and resolve issues before an application is submitted [[3]](#src-3), and the practical translation is that a question raised in year one is a design input, while the same question raised in year four is a costly redesign.
The staff has also been thinking about the deployment problem beyond a single unit. SECY-25-0052 examines licensing and deployment considerations for microreactors on an nth-of-a-kind basis, which is the question of what happens when the same design is built repeatedly rather than treated as a bespoke project each time [[12]](#src-12). A developer that understands where the staff is heading on standardization can design toward it instead of against it, and pre-application is where that alignment is cheapest to achieve.
There is also a resourcing reality. NRC review work is generally subject to fee recovery, and the agency publishes how its fee structure applies to advanced reactor activities [[9]](#src-9). Congress addressed the efficiency of advanced reactor licensing directly through the ADVANCE Act, which the NRC summarizes on its own governing-laws pages [[8]](#src-8). The point for a reader is not the dollar figures. It is that regulatory engagement consumes real agency effort and real developer effort, which is precisely why a developer with nothing to submit tends not to engage for long.
Our position, stated so it can be argued with: the honest reason to engage early is to have your assumptions contradicted while contradiction is still affordable. Developers who treat pre-application as a marketing milestone get the opposite value, because they optimize for the announcement rather than for the correction. The process rewards the developer who arrives with specific unresolved questions and is willing to hear an unwelcome answer.

## Which framework applies: Part 53 is final, Part 57 is proposed and not final
A developer engaging today faces a genuine framework question, and the two options are at very different stages of maturity. The NRC published its risk-informed, technology-inclusive regulatory framework for advanced reactors, 10 CFR Part 53, as a final rule in the Federal Register on March 30, 2026 [[4]](#src-4). That is a completed rulemaking and a real licensing pathway.
Separately, the NRC published proposed licensing requirements for microreactors and other reactors with comparable risk profiles, designated 10 CFR Part 57, in the Federal Register on May 1, 2026 at 91 FR 23628 [[5]](#src-5). Part 57 is **proposed**. It is not a final rule, no developer is licensed under it, and its content may change before any final version exists, if a final version exists. Anyone describing a design as compliant with Part 57 is describing compliance with a proposal.
The supporting guidance carries the same caveat. The NRC issued NUREG-2271, guidelines for preparing and reviewing applications under 10 CFR Part 57, in April 2026 as a draft for comment [[6]](#src-6). Draft guidance attached to a proposed rule is doubly provisional, and it is worth reading precisely because it shows the direction of staff thinking, not because it settles anything. The NRC also maintains a running summary of microreactor regulatory activities that ties these threads together [[7]](#src-7).
The practical consequence for a developer is that engagement has to be framework-aware without being framework-dependent. A design premised entirely on a proposed rule surviving unchanged is carrying a risk that belongs on the risk register rather than in the marketing. For readers trying to understand what the proposed microreactor rule actually contemplates around staffing and remote operation, we walk through it separately in [our explainer on Part 57 as proposed](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), including the qualifiers that get dropped when the topic is summarized elsewhere.

## How to check a developer's claimed status against the public record
You do not have to take a developer at its word, including us. The NRC publishes pages describing the advanced reactor developers it is engaged with in pre-application, which is the natural starting point for confirming that an interaction exists at all [[1]](#src-1). The microreactor regulatory activities pages give the adjacent picture for this class of design [[7]](#src-7).
Then apply four questions to whatever the developer has claimed. **One:** is the claim about engagement, or about a regulatory action? Engagement means a conversation exists. A regulatory action means the NRC issued something. **Two:** if a framework is named, is that framework final? Part 53 is a final rule [[4]](#src-4); Part 57 is a proposal [[5]](#src-5), and a claim keyed to Part 57 inherits every uncertainty of a rule that is not finished.
**Three:** is any document identified specifically enough to look up? A named topical report on a stated subject is checkable. "Ongoing NRC engagement" is not. **Four:** does the developer distinguish between a staff conclusion on a narrow question and an approval of a design? That distinction is where most overstatement lives, because a narrow favorable conclusion is genuinely good news and is genuinely not a license.
A point on visibility that cuts in the developer's favor, and that we had originally been too cautious to state. The NRC's own description of the pre-application process includes a kickoff public meeting, held so a developer can introduce its project to NRC staff and to the public, and a later public outreach meeting near the vicinity of a proposed site as a submission date approaches [[3]](#src-3). So early engagement is not a private correspondence between a company and its regulator. Parts of it are conducted in the open, which is one more reason a developer's characterization of its own status is checkable rather than something you have to accept.

## What the GAO has said about NRC readiness for advanced reactor licensing
The regulator side of this deserves the same scrutiny as the developer side. In July 2023 the Government Accountability Office published a report whose title states its conclusion directly: the NRC needs to take additional actions to prepare to license advanced reactors [[10]](#src-10). The concerns in that body of work center on workforce and readiness questions, meaning whether the agency has the staff, skills, and processes lined up for a wave of technologies unlike the light-water fleet it has regulated for decades.
That thread did not close in 2023. GAO maintains priority open recommendation letters for federal agencies, and it issued one for the NRC in June 2026 [[11]](#src-11). The existence of an open priority recommendation letter is itself informative: it tells you an external auditor still considers some recommendations unimplemented. Congress moved on the same problem legislatively through the ADVANCE Act, which the NRC describes on its own pages as directing improvements to the efficiency of its licensing work [[8]](#src-8).
**The counterargument, stated fairly:** if the regulator has documented readiness gaps, then pre-application engagement is a formality that mostly generates paperwork, and a developer would be better served building and letting the licensing catch up later. That argument is not stupid, and versions of it are common in the industry.
**Our response:** it points in the opposite direction from the one intended. When agency review capacity is a constrained resource, arriving with unresolved fundamental questions is the most expensive possible way to consume it. Early engagement is how a developer reduces the amount of review capacity its application will need, and how the staff sees the technology before it is under schedule pressure. The readiness gaps GAO describes [[10]](#src-10) [[11]](#src-11) make disciplined pre-application more valuable rather than less, and they also argue for humility about timelines from every developer, including this one.

## Where RankShield Energy actually is, stated without softening
RankShield Energy is a pre-applicant. We hold no license, no construction permit, no design approval, and no design certification. Nothing about our design has been demonstrated to or accepted by the NRC, and no safety, performance, or operational characteristic described anywhere on this site has been reviewed or endorsed by the agency. Everything in the preceding sections about what pre-application does not grant [[1]](#src-1) applies to us without exception.
We also are not licensed under the proposed microreactor rule, because nobody is. Part 57 is a proposal in the Federal Register [[5]](#src-5), and any statement that our design aligns with it is a statement about design intent measured against a document that could change. We would rather write that sentence ourselves than let a reader infer something warmer.
A concrete decision and its tradeoff, since this article has been asking developers to make theirs visible. We decided that every public page would state the pre-applicant limitation in plain language rather than in a footnote. The cost is real: next to a competitor describing the same regulatory position in more flattering terms, we look less advanced than we are, and that has a commercial price in early conversations. We accepted it because a public claim that contradicts a future application is a durable liability, and because a company whose entire technical thesis is verifiable claims cannot start by making unverifiable ones.
The honest limitation, since we have been demanding that others state theirs: our claim about our own regulatory status is, at this moment, mostly a self-report. The public record establishes what the NRC publishes about engagement [[1]](#src-1), and it does not establish the internal detail of our program. Treat our claims with the same skepticism this article recommends everywhere else. If you want the technical side of that argument, it runs through [how you would verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely), and the vocabulary problem underneath it is unpacked in [automation, remote, and autonomous as separate terms](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms).

## Frequently asked questions

### Does NRC pre-application status mean a reactor design is approved?
No. Pre-application is early, voluntary engagement in which the NRC becomes familiar with a technology and a developer plan before an application is submitted [[1]](#src-1). It grants no license, no construction permit, no design approval, no design certification, and no safety finding. The NRC organizes it as guidance for interacting productively ahead of a submittal [[3]](#src-3), not as an evaluation that produces a verdict. A developer can be in pre-application for years and hold exactly the same regulatory authorizations at the end of it as at the beginning, which is none. Approval language attached to pre-application status is the single most common overstatement in this part of the industry.

### What is a Regulatory Engagement Plan?
It is the document in which a developer sets out what it intends to submit to the NRC, in what order, and on what schedule, so the staff can anticipate the workload and plan resources [[2]](#src-2). It is the most substantive artifact of early engagement, and it is more revealing than a project number, because a project number is administrative while a plan exposes sequence and commitment. In our own experience of preparing one, the exercise mattered more than the document: you cannot schedule a submittal on a question you have not yet decided, so the act of sequencing separates closed technical questions from deferred ones.

### Is 10 CFR Part 57 a rule a developer can be licensed under today?
No. The NRC published licensing requirements for microreactors and other reactors with comparable risk profiles as a **proposed** rule in the Federal Register on May 1, 2026 at 91 FR 23628 [[5]](#src-5). It is not final, and no developer is licensed under it. The supporting guidance, NUREG-2271, was issued in April 2026 as a draft for comment [[6]](#src-6), which carries the same provisional status. By contrast, 10 CFR Part 53, the risk-informed and technology-inclusive framework for advanced reactors, was published as a final rule on March 30, 2026 [[4]](#src-4). Any claim of Part 57 compliance is a claim against a proposal.

### How can I verify a developer's claimed pre-application status myself?
Start with what the NRC publishes about the advanced reactor developers it is working with [[1]](#src-1) and its summary of microreactor regulatory activities [[7]](#src-7). Then test the claim itself. Is it about engagement or about a regulatory action the NRC issued? If a framework is named, is that framework final [[4]](#src-4) or proposed [[5]](#src-5)? Is any document identified specifically enough to retrieve? Does the developer separate a staff conclusion on a narrow technical question from approval of a design? This article does not assert that pre-application meetings are public, so do not assume visibility that the record has not established.

### Has anyone questioned whether the NRC is ready to license advanced reactors?
Yes. The Government Accountability Office reported in July 2023 that the NRC needed to take additional actions to prepare to license advanced reactors [[10]](#src-10), and it issued a priority open recommendations letter to the agency in June 2026 [[11]](#src-11), which indicates that external oversight still tracks unimplemented items. Congress addressed licensing efficiency through the ADVANCE Act, summarized on the NRC governing-laws pages [[8]](#src-8), and NRC staff have examined nth-of-a-kind microreactor licensing and deployment considerations in SECY-25-0052 [[12]](#src-12). Readiness questions argue for engaging early and carefully, not for skipping engagement.

## Sources

- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [U.S. Nuclear Regulatory Commission. Regulatory Engagement Plan. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/engagement)
- [U.S. Nuclear Regulatory Commission. Pre-application Process (general guidance). Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/pre-app-process)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. About the ADVANCE Act. Accessed July 2026](https://www.nrc.gov/about-nrc/governing-laws/advance-act/about-advance-act)
- [U.S. Nuclear Regulatory Commission. NRC Fees, Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-info/fees)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)

## Related

- [NRC Part 57 and autonomous operation, as proposed →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the NRC's advanced-reactor pre-application process as of July 2026. NRC guidance and process pages are updated periodically; check the NRC's pre-application pages if you need the current procedure.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/nrc-pre-application-project-number-explained/

# What an NRC Pre-Application Project Number Actually Means

> An NRC pre-application project number is a tracking identifier, not an approval. What it changes is the fee basis, and that provision expires in 2030.

[Resources](https://rankshieldenergy.com/resources) / Licensing & pre-application Licensing & pre-application

# The NRC has given RankShield Energy a project number. Here is what that does and does not mean.
Published September 15, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Published September 15, 2026 Subject NRC pre-application project number 99902183 Regulatory status RankShield Energy is a pre-applicant. It holds no NRC license, permit, or design approval, and no application has been filed. Nature of document Public communication. Not a submittal to the NRC, and not legal or regulatory advice.
The U.S. Nuclear Regulatory Commission has assigned RankShield Energy, Inc. project number 99902183, under the docket name RankShield Energy Pre-application Activities, with an assigned NRC project manager. The number was issued on August 31, 2026, and on September 15, 2026 the company completed the credentialing required to submit documents through the NRC's external partner submission gateway. A project number is an administrative tracking identifier. It is not a license, a permit, a certification, a design approval, or an endorsement of any kind, and no application has been filed.
The honest description of what changed is narrow. RankShield Energy's interactions with the NRC staff now have a place on the record, a named staff contact, and a defined billing basis. That last item is the part most often reported incorrectly, and it is the part worth explaining at length.
Under a statutory change Congress made in 2024, the staff review work associated with a pre-applicant's licensing project plan is billed at a reduced hourly rate [[1]](#src-1). For fiscal year 2026 that is the difference between $337 and $154 per staff-hour [[2]](#src-2), and the provision expires on September 30, 2030 [[2]](#src-2). This article sets out the sequence to date, the mechanism behind that fee treatment, the licensing framework choice the company has made and why, the quality assurance gate that governs everything else, and the specific things RankShield Energy has not yet done.
Key takeaways

- A project number confers nothing. It creates a docket name, assigns a project manager, and establishes a billing basis. It is not a finding on any technical matter.
- The substantive consequence is fee treatment. Section 201 of the ADVANCE Act of 2024 directs a reduced hourly rate for advanced reactor applicants and pre-applicants [[1]](#src-1).
- The reduced rate is conditional. It attaches to work described in a licensing project plan [[3]](#src-3), not to pre-applicant status generally.
- The provision sunsets on September 30, 2030 [[2]](#src-2), which is less time than a first-of-a-kind licensing effort typically takes.
- RankShield Energy has not filed an application, has not submitted its licensing project plan, and does not yet have an accepted quality assurance program.

## 1. What a project number is, and what it is not
A project number is how the NRC tracks a prospective applicant's interactions with the staff before any application exists. It creates a docket name under which correspondence and meeting summaries can be filed, it assigns a project manager as the point of contact, and it establishes the basis on which staff time is billed to the company.
It confers nothing. It is not a finding, not a determination, and not a statement by the NRC that any aspect of a design is acceptable. The NRC has not reviewed the HELIX design. No RankShield Energy document has been accepted, approved, or endorsed. A reader who takes a project number as a signal of technical merit has misread it, and any company that encourages that reading is misrepresenting its position.
The reason to announce it anyway is that pre-application is where most of the durable work happens, and it is almost entirely invisible from outside. We have written separately on [how the NRC advanced reactor pre-application process works](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained). Publishing the milestones, including the unflattering ones, is a way for a company at this stage to be judged on something other than its own adjectives.

## 2. The sequence to date
**August 4, 2026.** RankShield Energy submitted a letter of intent to the NRC Document Control Desk stating its intent to begin pre-application engagement and requesting a project number. This article cites that letter by date rather than by accession number, because the accession has not been verified as publicly retrievable.
**August 25, 2026.** An introductory meeting was held with the NRC staff. The meeting was introductory and non-technical. Nothing was submitted for review, and the staff took no position on any technical matter.
**August 31, 2026.** The project number was assigned, with a docket name and an assigned project manager.
**September 15, 2026.** The company completed identity proofing and multifactor credentialing for the NRC's external partner submission gateway. This is purely administrative. It is the difference between having something to file and being able to file it. Roughly six weeks separate the letter of intent from a working submission channel, which is a reasonable expectation for anyone measuring their own path.

## 3. What the project number actually changes: the fee mechanism
This is the substantive consequence, and it rests on a specific and recent change in federal law. On July 9, 2024, the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024, the ADVANCE Act, was signed into law. Section 201 of that Act, titled "Fees for Advanced Nuclear Reactor Application Review," directs the NRC to apply a reduced hourly rate to advanced nuclear reactor applicants and pre-applicants [[1]](#src-1). The NRC implemented the provision in the fiscal year 2025 final fee rule [[4]](#src-4) and carried it forward in the fiscal year 2026 final fee rule [[2]](#src-2).
The operative regulation is 10 CFR 170.20, "Average cost per professional staff-hour," which establishes two rates [[3]](#src-3). For fiscal year 2026 the professional hourly rate is $337 per hour and the Reduced Hourly Rate is $154 per hour, which the NRC describes as "an over 50 percent reduction from the professional hourly rate" [[2]](#src-2). The fees themselves are assessed under the schedule at 10 CFR 170.21 [[5]](#src-5).
The condition attached to the reduced rate for pre-applicants is the part most easily missed. The rule provides that for advanced nuclear reactor pre-applicants, fees relating to "the review of submitted materials as described in the licensing project plan" are calculated using the reduced hourly rate [[2]](#src-2). The reduced rate is not a general discount on being a pre-applicant. It attaches to work that a licensing project plan has described in advance.
Two consequences follow, and we state them plainly because they govern our own sequencing. First, the plan is the instrument: technical material submitted before a licensing project plan describes it does not obviously fall within the reduced-rate provision, and at small company scale the gap between $337 and $154 per staff-hour is a direct constraint on how much regulatory interaction is affordable. Second, the provision sunsets. The rule states that the pre-applicant paragraph "shall cease to be effective on September 30, 2030" [[2]](#src-2). Companies entering pre-application after that date, or still in pre-application when it passes, should not assume the treatment persists.
RankShield Energy has not yet submitted its licensing project plan. It is written and staged. Until it is filed and the staff has acted on it, the company should be understood as not yet having secured the treatment described above.

## 4. The licensing project plan
RankShield Energy's next submittal is its Regulatory Engagement Plan, submitted as a licensing project plan. The document identifies the application the company intends to build toward, the technical topics it expects to bring to the staff, the topical reports it intends to submit, and a preliminary schedule.
A licensing project plan is not a technical submission and asks for no approval. It is a statement of intent detailed enough that the staff can plan resources against it. Its value to the company is sequencing: it establishes what will be submitted and in what order, which is the precondition for the fee treatment described above and, more importantly, the precondition for the staff being able to schedule anything at all.
The plan is complete and staged for submission. It has not been submitted as of publication.

## 5. Which licensing framework, and why
There are three candidate frameworks, and the choice among them is a live question across the advanced reactor industry rather than a settled one. We have set out the full analysis in [which regulations apply to a microreactor today](https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor).
**10 CFR Part 52, Subpart E, Standard Design Approvals** [[6]](#src-6) is the pathway RankShield Energy names in its plan. The reason is unglamorous: it exists in final regulation today. A standard design approval is a staff determination on a design, separable from any particular site, and the rules governing it are in force and have been for years.
**10 CFR Part 53** [[7]](#src-7), the risk-informed, technology-inclusive framework for commercial nuclear plants, is final and available. It was written with advanced reactors in view.
**proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it)** is the framework written specifically for microreactors and other reactors with comparable risk profiles [[8]](#src-8). The NRC maintains a public index of its microreactor regulatory activities, including the staff papers behind that rulemaking [[12]](#src-12). Proposed Part 57 remains RankShield Energy's preferred destination if it is finalized substantially as proposed, and the company has said so in its plan. But a pre-applicant that builds its schedule on a proposed rule has taken on a risk it does not control, and the honest position is that a rule which has not been finalized cannot be relied upon. Our reading of what that framework would and would not carry forward is set out in [our analysis of off-site fabrication oversight](https://rankshieldenergy.com/resources/who-inspects-a-reactor-built-in-a-factory).
Choosing the instrument that exists over the instrument that would be more convenient is not a statement that Part 52 is the better framework for a microreactor. It is a statement about what can be planned against today.

## 6. The gate in front of everything else: quality assurance
The constraint that governs the technical program is not a technical one. It is quality assurance. Under the NRC's framework, analysis that supports a licensing submittal must be produced under an accepted quality assurance program. Regulatory Guide 1.28, Revision 6 [[9]](#src-9) endorses specified editions of the ASME NQA-1 standard, including NQA-1-2022. RankShield Energy's first topical report will be a Quality Assurance Program Description committing to NQA-1-2022 as endorsed by that guide.
The practical effect is severe and worth stating without softening. Work performed before an accepted quality assurance program is in place does not become qualified retroactively. It is screening work. It is useful for deciding what to build and where the sensitivities are, and it is not usable as the basis for a regulatory finding.
RankShield Energy's physics results to date are unqualified pre-program screening results. The company labels them that way in its own filings rather than presenting them as qualified analysis, and it labels them that way here. Any figure the company has published about reactor behavior should be read in that light. This is the same standard we apply when we write about [how to evaluate a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and it applies to us.

## 7. Where the design stands, and what we do not publish
HELIX is a factory-fabricated heat-pipe microreactor in the 11.0 MWth and 4.40 MWe class, using HALEU TRISO fuel, with sealed heat pipes and no primary coolant pumps or loops. It is a design under development. It is not operating, not licensed, and not approved. Everything said about how the design is intended to behave is design intent, and none of it has been demonstrated to or accepted by the NRC.
This article does not publish enrichment levels, core geometry, fuel loading, reactivity coefficients, or lifetime figures for the design. That is a deliberate restriction the company applies to all of its public material, on export-control grounds under 10 CFR Part 810 [[10]](#src-10). Readers accustomed to vendor material that leads with such figures should read their absence as a policy rather than an omission. Class-level context on the fuel is covered in [where HALEU comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel).

## 8. What RankShield Energy has not done
A status article that lists only progress is marketing. The following are accurate as of publication. No application of any kind has been filed: not a standard design approval application, not a construction permit application, not a combined license application. The licensing project plan has not been submitted; it is written and staged. No topical report has been submitted, and the Quality Assurance Program Description is the earliest one queued. No accepted quality assurance program is in place, so the company's analysis is screening work rather than qualified analysis.
No site has been identified and no host institution agreement is in place. No NRC staff position has been obtained on any technical question, because the August meeting was introductory and non-technical. The fee treatment described above is not yet secured, because it depends on a plan that has not been filed.
The immediate next step is submission of the licensing project plan, followed by the Quality Assurance Program Description as the first topical report. Beyond that, the sequence the company expects to follow is the one set out in the NRC's content-of-application roadmap for risk-informed, technology-inclusive advanced reactor applications, DANU-ISG-2022-01 (interim staff guidance, which is guidance and not a requirement) [[11]](#src-11), which identifies the pre-application topics a developer can usefully close before an application exists. That guidance ties a meaningful review-schedule benefit to completing pre-application work, and conditions it on the design not changing significantly in between [[11]](#src-11). That is a real engineering constraint rather than a formality: the design of record has to be closed before the engagement is worth much, which is a harder problem than it sounds for a company still doing screening analysis. Pre-application engagement is measured in years. We will publish each milestone as it is reached, including the ones that do not go the company's way.

## Frequently asked questions

### Does an NRC project number mean the reactor is approved?
No. A project number is an administrative tracking identifier. It creates a docket name, assigns a project manager, and establishes a billing basis. It is not a license, a permit, a certification, a design approval, or an endorsement, and it reflects no NRC finding on any technical matter. RankShield Energy has filed no application.

### What does a project number actually change?
Principally the fee basis. Section 201 of the ADVANCE Act of 2024 directs a reduced hourly rate for advanced reactor applicants and pre-applicants, implemented at 10 CFR 170.20. For fiscal year 2026 the professional rate is $337 per hour and the reduced rate is $154 per hour. For pre-applicants the reduced rate attaches to work described in a licensing project plan.

### Is the reduced fee rate permanent?
No. The fiscal year 2026 final fee rule states that the pre-applicant paragraph shall cease to be effective on September 30, 2030. That is less time than a first-of-a-kind licensing effort typically takes, so companies entering pre-application should not assume the treatment persists through their program.

### Which licensing framework is RankShield Energy pursuing?
Its plan names a standard design approval under 10 CFR Part 52, Subpart E, because that instrument exists in final regulation today. 10 CFR Part 53 is also final and available. The microreactor-specific framework at proposed 10 CFR Part 57 is a proposed rule that is not final, and no developer is licensed under it, so it cannot be relied upon for schedule.

### Why does this article not give enrichment or core dimensions?
Because specific reactor design data can be export-controlled under 10 CFR Part 810. RankShield Energy speaks publicly at the architecture, concept, and regulatory level and does not publish enrichment levels, core geometry, fuel loading, reactivity coefficients, or lifetime figures for its design.

## Sources

- [U.S. Nuclear Regulatory Commission. Description of the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024 (ADVANCE Act), section 201, Fees for Advanced Nuclear Reactor Application Review, as set out in the fiscal year 2026 final fee rule](https://www.federalregister.gov/documents/2026/06/16/2026-12067/fee-schedules-fee-recovery-for-fiscal-year-2026)
- [U.S. Nuclear Regulatory Commission. Fee Schedules; Fee Recovery for Fiscal Year 2026. Final rule, 91 FR 36470, June 16, 2026](https://www.federalregister.gov/documents/2026/06/16/2026-12067/fee-schedules-fee-recovery-for-fiscal-year-2026)
- [10 CFR 170.20, Average cost per professional staff-hour. Office of the Federal Register, current CFR](https://www.ecfr.gov/current/title-10/chapter-I/part-170/section-170.20)
- [U.S. Nuclear Regulatory Commission. Fee Schedules; Fee Recovery for Fiscal Year 2025. Final rule, 90 FR 26730, June 24, 2025](https://www.federalregister.gov/documents/2025/06/24/2025-11544/fee-schedules-fee-recovery-for-fiscal-year-2025)
- [10 CFR 170.21, Schedule of fees for production and utilization facilities, review of standard referenced design approvals, special projects, inspections, and import and export licenses](https://www.ecfr.gov/current/title-10/chapter-I/part-170/section-170.21)
- [10 CFR Part 52, Subpart E, Standard Design Approvals. Office of the Federal Register, current CFR](https://www.ecfr.gov/current/title-10/chapter-I/part-52/subpart-E)
- [10 CFR Part 53, Risk-Informed, Technology-Inclusive Regulatory Framework for Commercial Nuclear Plants. Office of the Federal Register, current CFR](https://www.ecfr.gov/current/title-10/chapter-I/part-53)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles. Proposed rule, 91 FR 23628, May 1, 2026; comment period closed June 15, 2026; not final](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Regulatory Guide 1.28, Revision 6, Quality Assurance Program Criteria (Design and Construction), September 2023. Endorses specified editions of ASME NQA-1, including NQA-1-2022](https://www.nrc.gov/reading-rm/doc-collections/reg-guides/power-reactors/rg/)
- [10 CFR Part 810, Assistance to Foreign Atomic Energy Activities. Office of the Federal Register, current CFR](https://www.ecfr.gov/current/title-10/chapter-III/part-810)
- [U.S. Nuclear Regulatory Commission. DANU-ISG-2022-01, Review of Risk-Informed, Technology-Inclusive Advanced Reactor Applications, Roadmap. Interim staff guidance, March 2024](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/rulemaking-and-guidance.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)

This article reflects the state of the cited record as of its publication date. Fee schedules are set annually and regulatory proposals are subject to change. Section references should be re-checked against the current docket before use.

## Related

- [How the NRC Advanced Reactor Pre-Application Works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)
- [Which NRC Regulations Apply to a Microreactor Today? →](https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor)
- [Who Inspects a Nuclear Reactor Built in a Factory? →](https://rankshieldenergy.com/resources/who-inspects-a-reactor-built-in-a-factory)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.
Where this article describes a proposed rule, that rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight/

# Open Questions in Autonomous Microreactor Oversight

> A working register of what the public record on autonomous microreactor oversight settles, what it leaves open, and who would have to resolve each entry.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# Open Questions in Autonomous Microreactor Oversight: A Working Register
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published July 24, 2026 Revised July 24, 2026 Status Working register, open for comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
Oversight of microreactors operated remotely and with substantial automation is being designed in public, across a proposed rule, draft guidance, several staff papers, a body of contractor and national-laboratory analysis, and an oversight process built for a different fleet. This paper argues no position on how that design should end. It maps what the cited public record settles and what it leaves open, in the form of a numbered register: each entry states the question precisely, the evidence that bears on it, the reason it remains unresolved, and the party that would have to resolve it. Eight sections cover the method used to separate settled from open, the regulatory baseline, oversight at reduced inspection intensity, verification and evidence, human factors at fleet scale, cybersecurity requirements still in development, questions we cannot answer, and the rules by which the register will be maintained.
The principal limitation is structural. A register is no better than the record it draws on, and the record used here is the public one as of July 2026, which excludes non-public pre-application interaction, docketed material not publicly available, and proprietary operating experience. A second limitation is that the register is written by an interested party. RankShield Energy is a pre-applicant developing an independent verification layer, and several entries would be commercially convenient for us if they closed a particular way. Section 7 sets out the entries where we have no answer at all, including whether such a layer would be credited in a licensing basis.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses oversight and verification questions raised by remote operation and increased automation of microreactors under U.S. Nuclear Regulatory Commission jurisdiction. It draws on twenty-one primary sources spanning the regulator, the Government Accountability Office, national laboratories, a standards body, and the International Atomic Energy Agency. Where a characterization of a document is made, the document is cited and its status is stated: rule in force, proposed rule, draft guidance, staff paper, contractor analysis, or research.
Several things are deliberately out of scope. The paper contains no design detail for any RankShield Energy system: no geometry, no fuel description, no performance or lifetime figures. It contains no cost or economic analysis. It does not interpret what any rule requires of a third party, and it does not name, rank, or characterize other developers. It does not describe unattended or fully autonomous operation of a reactor; the operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification layer under discussion is an assurance function, not a control function.
Several developments would change the conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft guidance for applications under it, a Commission decision adopting or rejecting positions analyzed in the staff papers cited here, a final cybersecurity rule for this reactor class, or published laboratory results that resolve a human-factors or autonomous-control question this paper records as open. Section 8 states the maintenance rule for each case.

A register of open questions is an unusual document for a vendor to publish, which is much of the reason to publish it. The public record on oversight of remotely operated, heavily automated microreactors contains a proposed rule, draft guidance, several staff papers, a set of contractor studies, and an oversight process designed for large plants with people on site. What it does not yet contain is a settled answer to most of the questions a technical reviewer would ask. This paper says which ones, and why.
The framing matters because the alternative is worse. A vendor paper that presents the direction of travel as though it were requirement invites a reviewer to spend the reading sorting proposal from rule, and that sorting is the author's job. So the separation is made explicit here. What is in force is identified as in force, such as the licensed-operator conditions at 10 CFR 50.54(m) [[7]](#src-7) and the Reactor Oversight Process the agency applies to operating plants today [[8]](#src-8). What is proposed is identified as proposed, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[1]](#src-1), whose accompanying guidance, NUREG-2271, is a draft issued for comment [[2]](#src-2).
The contribution offered is the register itself rather than a solution. Each entry names who would have to resolve it, because the answer is rarely a vendor. Most entries belong to the regulator through rulemaking or guidance, some to research organizations, some to standards bodies, and a few to the market. RankShield Energy is a pre-applicant engaged in early regulatory interaction and holds no NRC license, permit, or design approval [[21]](#src-21). Nothing described here has been demonstrated to or accepted by the NRC, and the register is written on the assumption that a reader will check every cited source rather than take our summary of it.
Key takeaways

- The oversight model for remotely operated microreactors rests today on proposals, draft guidance, and staff analysis rather than on requirements in force, so most of the questions a reviewer would ask remain genuinely open.
- What is settled is narrower than it is often presented: licensed-operator staffing conditions at 10 CFR 50.54(m) and the Reactor Oversight Process are in force, and they were built around large plants with staff on site.
- Nothing in the record cited here establishes an accepted evidentiary standard for machine-generated statements about reactor state, which is the gap an independent verification layer would have to fill before it could be credited.
- Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contemplates the operating model, but a proposal is not permission, and the design-specific determination would still be made on a docket.
- The entry we cannot answer is the load-bearing one for our own business: whether an independent verification layer would be credited in a licensing basis at all.

## 1. Why a register rather than a position paper
This paper takes the form of a register because the record will not carry anything stronger. Most of the instruments that would settle how a remotely operated, heavily automated microreactor is overseen are proposals, drafts, or analysis rather than requirements in force. The licensing frame under discussion is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[1]](#src-1). The guidance that would accompany it, NUREG-2271, is a draft issued for public comment rather than final guidance [[2]](#src-2). A position paper built on that footing would be an argument about a rule that does not yet exist in final form.
Two categories are used throughout, and the boundary between them is the method of this paper. An item is treated as settled where it rests on a requirement in force or an agency process in use. The licensed-operator conditions imposed on power reactor licenses at 10 CFR 50.54(m) are a requirement in force [[7]](#src-7), and the Reactor Oversight Process is a published framework the agency applies to operating reactors today [[8]](#src-8). An item is treated as open where the governing text is proposed, draft, or staff analysis, or where the cited record does not address the question at all.
That open category is wide. SECY-20-0093, SECY-24-0008, and SECY-25-0052 are staff papers presenting analysis and options to the Commission, not Commission positions and not requirements [[4]](#src-4) [[6]](#src-6) [[5]](#src-5). The Brookhaven National Laboratory review of reactor facilities without main control rooms is contractor analysis prepared for the NRC [[13]](#src-13), as are the Sandia and Oak Ridge studies of microreactor automation and autonomous control [[14]](#src-14) [[15]](#src-15). Each is strong evidence about what the technical community regards as unresolved. None is a requirement, and reading one as though it were is the error this register exists to avoid.
Terms carrying regulatory weight are used as follows. Remote operation and autonomous operation are distinguished rather than merged, in line with the Oak Ridge treatment of autonomy concepts for microreactors [[16]](#src-16) and with our [terminology note](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms). Verification means confirmation of a claim about reactor state by a party other than the party asserting it. Attestation is used in the sense of RFC 9334, which separates the attester that produces evidence, the verifier that appraises it, and the relying party that consumes the appraisal [[19]](#src-19). Where those roles collapse into a single organization, this paper calls the result self-attestation and treats it as a different thing; see the companion material under Related.
The register claims no resolution by us of any entry. RankShield Energy is a pre-applicant [[21]](#src-21), holds no NRC license, permit, or design approval, and has had nothing accepted by the NRC. Several entries would be commercially convenient for us if they closed a particular way, which is a reason to state them in the open.

## 2. Questions about the regulatory baseline
The baseline is more specific than the discussion usually admits. For power reactors, 10 CFR 50.54(m) attaches licensed-operator conditions to the license itself, setting minimum staffing expectations for the operation of the facility [[7]](#src-7). The oversight built on top of that baseline assumes a resident inspection presence at operating sites [[9]](#src-9) and a structured process of inspection, performance indicators, and assessment [[8]](#src-8). Both were constructed around large plants with substantial staff on site, which is the fact that makes microreactor deployment a question rather than an application of existing practice.
Against that baseline, proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) is the instrument most often cited as the answer [[1]](#src-1), and the NRC maintains a public summary of the microreactor regulatory activities surrounding it [[3]](#src-3). Our reading of the cited record is narrower than the common industry reading, and we state it plainly so it can be argued with: a proposed framework that contemplates an operating model does not thereby establish the method by which any particular applicant demonstrates that a specific staffing or remote-operation arrangement is acceptable for a specific design. That demonstration would be made on a docket, against guidance that is currently a draft [[2]](#src-2). We treat the direction as informative and the requirement as absent. A companion explainer covers [the proposed rule and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) in less formal terms.
A further band of the baseline sits at staff-paper stage. The policy and licensing considerations for micro-reactors set out in SECY-20-0093 are staff analysis for Commission consideration [[4]](#src-4), and the later staff papers on micro-reactor licensing and deployment and on Nth-of-a-kind considerations are likewise staff analysis rather than adopted requirements [[6]](#src-6) [[5]](#src-5). A policy question that staff have analyzed thoroughly is still a policy question until the Commission acts on it and a rule or guidance reflects the outcome.
Three entries follow from this section. Entry 2.1: how the licensed-operator baseline at 50.54(m) translates, if at all, to a facility overseen from a location other than the site. Entry 2.2: what evidence an application would have to present for automated functions, given that the applicable guidance is a draft. Entry 2.3: which of the positions analyzed in the staff papers become requirements and which do not. All three belong to the NRC through final rulemaking and final guidance. No amount of vendor engineering resolves them, and any vendor claiming otherwise is describing an intention.

## 3. Questions about oversight at reduced inspection intensity
The established oversight model has a specific shape. The Reactor Oversight Process combines baseline inspection, performance indicators, a significance determination process, and assessment, and the agency publishes its framework [[8]](#src-8). Part of the inspection input comes from resident inspectors assigned to operating power reactor sites, whose access to the facility is part of the design of the program [[9]](#src-9). The Government Accountability Office has examined how heavily the agency relies on the information this process produces when reaching safety conclusions [[12]](#src-12). That reliance is the reason the question below is not academic.
The question, stated precisely: if on-site presence at a microreactor site is materially lower than at an operating power plant, what carries the oversight weight that resident inspection carries today, and how would the agency know that substitute is working. Part of an inspector's contribution is structured and could in principle be instrumented. Part of it is unstructured observation of things that were not on anyone's list, and that part does not have an obvious instrumented equivalent. The cited record does not establish which portion is which, nor how much of it is transferable to data.
Two further facts in the record bear on the same entry. The Government Accountability Office reported that the NRC needed to take additional actions to prepare to license advanced reactors [[10]](#src-10), and it maintains a list of priority open recommendations for the agency, which are by definition recommendations not yet implemented [[11]](#src-11). Staff-paper analysis of Nth-of-a-kind deployment recognizes that the scale of deployment being contemplated differs from current practice [[5]](#src-5). Taken together, these establish that oversight capacity is a live agency concern, without establishing how the footprint would scale.
Entry 3.1: what mix of inspection, indicators, and reported data would be applied to a site with reduced staffing, and by what method the agency would validate that mix against the observational base it replaces. Entry 3.2: whether oversight scales per site, per unit, or per operating organization once one organization oversees many units, an issue we treat separately in [the fleet-scale discussion](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors). Both belong to the NRC as the designer of the oversight framework, with continuing scrutiny from the Government Accountability Office, and both depend on industry producing data of a quality that could carry the weight.

## 4. Questions about verification and evidence
This is the entry closest to our own work, so it is stated with the least generosity to ourselves. The question is what makes a machine-generated statement about reactor state acceptable to a regulator as evidence. Not persuasive, not useful for operations, but acceptable in the way that an inspection finding or a licensee event report is acceptable, with known provenance, known limitations, and a known method for challenging it.
The record establishes several things around the edges of that question without answering it. RFC 9334 supplies a worked architecture for remote attestation, separating the producer of evidence from the appraiser of it and defining the appraisal step in between [[19]](#src-19). It is an internet architecture with no nuclear regulatory standing whatever, and citing it establishes vocabulary rather than acceptance. Oak Ridge National Laboratory analysis prepared in the autonomous-control context identifies licensing challenges associated with autonomous control, including the difficulty of demonstrating that automated decision logic behaves acceptably across its operating envelope [[15]](#src-15), and the companion Oak Ridge work on autonomous operation concepts for microreactors describes the monitoring and diagnostic functions such a system would depend on [[16]](#src-16).
What none of that establishes, and what we could not locate in the cited record, is an accepted evidentiary standard for machine-generated reactor state. The unresolved sub-questions are concrete rather than philosophical. Who appraises the evidence when the operator and the reporting system belong to the same organization. What freshness and coverage a record would need before absence of an alarm counts as evidence of a condition rather than evidence of a silent instrument. How long records are retained and in what form. What procedure exists for challenging a record after the fact, which is the question a lawyer asks before a regulator does. Draft guidance for applications is the obvious place for some of this to land, and it remains a draft [[2]](#src-2).
Entry 4.1: whether an evidentiary standard for automated state reporting is established by rule, by guidance, or case by case on individual dockets. Entry 4.2: whether independence between the producer and the appraiser of that evidence is treated as material at all. Resolution here is split: the NRC decides acceptance, standards bodies could supply the form, research organizations would have to supply validated methods, and industry would have to produce records worth appraising. Our own view of what a buyer or reviewer should ask is set out in [a separate explainer](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely), and it is a view, not a standard.

## 5. Questions about human factors at fleet scale
The human-factors record is the strongest part of the technical literature cited in this paper and still does not close the questions. Brookhaven National Laboratory, in contractor analysis prepared for the NRC, reviewed reactor facilities operated without a conventional main control room [[13]](#src-13). Sandia National Laboratories examined human-factors considerations specific to automating microreactors [[14]](#src-14). NRC and Idaho National Laboratory researchers have characterized the human factors of offsite monitoring and remote operation for the nuclear domain in conference work [[20]](#src-20). These are contractor and research products, not requirements, and they are cited here as evidence of what specialists consider unsettled.
The recurring structural issue is function allocation: which functions belong to the automation, which to the human, and how the human retains an accurate picture of a plant they are not standing in. Oak Ridge concepts for autonomous microreactor operation describe layered monitoring and diagnostics as part of that architecture [[16]](#src-16), which sharpens rather than removes the question, because a person supervising layered automation is supervising the automation as much as the plant.
At fleet scale a second issue appears that single-unit human-factors work does not fully address. When one crew oversees many units, most differences between units are benign, and sustained attention degrades against high-volume benign variation. The reconciliation task, deciding whether unit seven behaving slightly differently from its siblings is an instrument problem, a maintenance issue, or a genuine divergence, is exactly the task humans perform worst under those conditions. We are not aware of anything in the cited record that establishes a defensible limit on units per crew, or the conditions under which such a limit would be set.
Entry 5.1: what evidence would establish that a given ratio of units to qualified staff is acceptable, and whether that evidence is simulator-based, operational, or analytical. Entry 5.2: how operator qualification is defined when the role shifts from direct control toward supervision of automation. Entry 5.3: whether reconciliation across units is treated as a safety-relevant human-factors task in its own right or as an operational convenience. These belong jointly to research organizations, to the NRC through human-factors review, and to industry, which will generate the operating experience that any eventual answer has to be tested against.

## 6. Questions about cybersecurity requirements not yet final
A developer designing digital instrumentation, remote connectivity, and an attestation path for a microreactor today is designing against a requirement that does not exist in final form. The technology-neutral cyber requirement referenced as proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive) is the instrument most likely to govern this class, and the NRC describes cybersecurity as part of its protective mission rather than as an information-technology overlay [[17]](#src-17). The microreactor-specific technical case is still an active research topic internationally, with the IAEA coordinated research project on computer security of small modular reactors and microreactors running as research rather than as settled guidance [[18]](#src-18).
The licensing frame around it, proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), is in the same condition [[1]](#src-1), and the agency's public summary of microreactor regulatory activities is the practical place to watch for movement [[3]](#src-3). The consequence for a developer is specific rather than rhetorical: architectural choices about network separation, remote access paths, and the treatment of an attestation channel are being frozen now, and they will be judged later against a rule whose structure is not yet known. Whether requirements are graded by consequence, and how a small facility with a smaller source term is treated relative to a large plant, is precisely what the cited record leaves open.
A sub-question specific to the verification layer deserves naming, because it is uncomfortable for our own position. An independent verification path is an additional digital interface to the plant. It may reduce reliance on the operator's word while increasing the attack surface, and nothing in the cited record establishes how a regulator would weigh that trade. We treat it as a design constraint rather than as a settled benefit, and we discuss the broader landscape in [a separate cybersecurity explainer](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained).
Entry 6.1: what a developer can defensibly design against before a final cyber rule for this class exists, and whether early architectural choices made in good faith are credited later. Entry 6.2: whether an attestation or verification channel is in scope as a protected digital asset, and if so, who verifies the verifier. Entry 6.3: how supply-chain assurance for digital components is expected to be demonstrated for a factory-produced unit. Resolution belongs to the NRC through rulemaking, informed by international research of the kind the IAEA project represents [[18]](#src-18).

## 7. Questions we cannot answer
The standard this paper follows requires it to apply its own method to us, and this section is where that is least comfortable. The entries below are not open in the sense that the field has not got to them yet. They are open in the sense that we have no evidence bearing on them, and our commercial interest in the answers is direct.
The load-bearing one: whether an independent verification layer would be credited in a licensing basis at all. It is entirely possible that a regulator concludes that assurance belongs inside the licensee's quality and configuration-management programs, and that an external verifier adds a component to be reviewed without reducing anything else that must be reviewed. Nothing in the cited record establishes that such a layer would receive credit, and pre-application interaction confers no approval of any kind [[21]](#src-21). The process itself is described in [our pre-application explainer](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained), and its value is early alignment, not standing.
The second: whether a regulator would accept a third-party attestation as evidence, as opposed to as useful background. The attestation architecture we build against is well-specified outside nuclear [[19]](#src-19), and being well-specified in another domain has no bearing on admissibility in this one. We do not know whether the eventual answer turns on the cryptography, on the independence of the verifier, on the qualification of the software, or on none of those.
The third: what commercial weight buyers actually place on verification. Our working assumption is that lenders, insurers, and large offtakers will want confirmation they do not have to take on trust. That assumption is untested by us at any scale, it is the assumption a company in our position would be inclined to make, and if it is wrong the layer is a technical achievement without a market. The fourth, and the broadest: whether the operating model this paper analyses is the one that gets deployed. Staff analysis of deployment considerations exists [[5]](#src-5), and it is analysis of options rather than a forecast. A register that assumed its own premises would be worth less than one that lists them.

## 8. The register in summary, and how it will be maintained
The table below compresses the register. The middle column is deliberately restricted to what the cited record establishes, which in several rows is less than the surrounding discussion in the industry assumes.

Register summary: open questions in autonomous microreactor oversight, version 1.0

Question
What the record establishes
Who would need to resolve it

Whether a reduced or remote staffing arrangement is acceptable for a given design
10 CFR 50.54(m) imposes licensed-operator conditions on power reactor licenses and is in force; the microreactor licensing rule that contemplates other arrangements is proposed and not final
NRC, through final rulemaking and design-specific review on a docket

What evidence an application must present for automated functions
NUREG-2271 is a draft issued for comment; staff papers analyze options for the Commission
NRC, through final guidance

How inspection scales when on-site presence is reduced
The Reactor Oversight Process and the resident inspector program are established for operating plants; GAO reports agency reliance on the information they produce
NRC as framework designer, with GAO scrutiny

What makes machine-generated state acceptable as evidence
RFC 9334 supplies roles and vocabulary outside nuclear; ORNL identifies licensing challenges for autonomous control; no accepted evidentiary standard appears in the cited record
NRC for acceptance, standards bodies for form, research for validated method

How many units one crew can oversee, and under what conditions
BNL, SNL, and NRC and INL work identify the human-factors issues; no limit or method for setting one appears in the cited record
Research organizations and NRC human-factors review, tested against industry operating experience

What cyber requirements a developer designs against today
The technology-neutral requirement for this class is proposed, under development, and not final or prescriptive; IAEA work is an active research project
NRC through rulemaking, informed by international research

Whether an independent verification layer is credited in a licensing basis
Nothing in the cited record establishes it; pre-application interaction confers no approval
NRC, on a specific docket. We cannot answer this

Maintenance rules. This document is versioned, and the version and revision date in the control block above are authoritative. An entry closes when a primary source resolves it: publication of a final rule in the Federal Register covering the question, issuance of final rather than draft guidance, a Commission decision adopting or rejecting a position analyzed in a staff paper, or a published laboratory or standards result that answers a technical sub-question. Closure will be recorded with the citation that produced it, and the superseded text will be retained rather than deleted so that a reader can see what we believed and when.
An entry can also reopen. A final rule that leaves an implementation question unanswered, a guidance revision that changes an expectation, or a Government Accountability Office finding that an implemented recommendation did not have the intended effect would each reopen the relevant row [[11]](#src-11). The agency's public summary of microreactor regulatory activities is the practical trigger we watch [[3]](#src-3), together with the docket for the proposed licensing rule, which as noted throughout is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[1]](#src-1), and the draft application guidance associated with it [[2]](#src-2).
Comment is invited, particularly disagreement. If a reader believes an entry is closed by a source we did not cite, that is the most useful correction this document can receive, and it will be reflected with attribution in the next version. The register is intended as a shared artefact for people working the same problem, not as a marketing surface, and it carries no claim that RankShield Energy resolves any row in the table above.

## Frequently asked questions

### Why would a developer publish open questions rather than answers?
Because on this subject the answers do not yet exist in the public record, and a paper that implied otherwise would fail on the point a technical reviewer checks initially: whether the author can separate a proposal from a requirement. The register states what is in force, such as the licensed-operator conditions at 10 CFR 50.54(m) and the Reactor Oversight Process, and what is not, such as the proposed microreactor licensing rule and its draft guidance. It also names, in section 7, the questions we cannot answer at all, including whether an independent verification layer would be credited in a licensing basis.

### Does the proposed microreactor licensing rule settle how these reactors will be overseen?
No. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). It contemplates an operating model, and contemplating a model is different from establishing the method by which a specific applicant would demonstrate that a specific staffing or remote-operation arrangement is acceptable for a specific design. The guidance that would carry much of that detail, NUREG-2271, is a draft issued for comment rather than final guidance. Treat both as regulatory direction and neither as present permission.

### What does it mean that SECY papers and laboratory reports are cited here?
SECY documents are staff papers that present analysis and options to the Commission. They are not Commission positions and they are not requirements. Reports from Brookhaven and Sandia National Laboratories cited in this paper are contractor analysis prepared in support of NRC work, and the Oak Ridge reports are laboratory research. All of them are good evidence of what specialists regard as unresolved, which is exactly how this register uses them. None of them establishes an obligation on any party.

### Is there an accepted standard for machine-generated evidence about reactor state?
Nothing in the record cited by this paper establishes one. RFC 9334 provides a well-specified remote attestation architecture that separates the producer of evidence from the party that appraises it, but it is an internet standards document with no nuclear regulatory standing, so it supplies vocabulary rather than acceptance. Oak Ridge analysis identifies licensing challenges for autonomous control without resolving them. The open sub-questions include who appraises, what coverage and freshness suffice, how long records persist, and how a record can be challenged after the fact.

### What would cause an entry in this register to close?
A primary source that resolves it: a final rule published in the Federal Register covering the question, final rather than draft guidance, a Commission decision adopting or rejecting a position analyzed in a staff paper, or a published laboratory or standards result that answers a technical sub-question. Closures are recorded with the citation that produced them, and superseded text is retained rather than deleted. Entries can also reopen, for example when a final rule leaves an implementation question unanswered.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper). October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper). June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. SECY-24-0008: Micro-Reactor Licensing and Deployment (staff paper). 2024](https://www.nrc.gov/docs/ML2320/ML23207A250.pdf)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg.html)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis. February 2025](https://www.osti.gov/biblio/2529385)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811-concepts-autonomous-operation-microreactors)
- [U.S. Nuclear Regulatory Commission. Cyber Security. Accessed July 2026 (proposed 10 CFR 73.110 technology-neutral cyber requirements under development, not final or prescriptive)](https://www.nrc.gov/security/cybersecurity)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (coordinated research project J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Staffing baseline.** How, if at all, the licensed-operator conditions imposed at 10 CFR 50.54(m) translate to a facility overseen from somewhere other than the site [[7]](#src-7). Unresolved because the instrument that contemplates another arrangement is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[1]](#src-1). Resolver: NRC, through final rulemaking.
- **OQ-2. Application evidence.** What an applicant would have to submit to demonstrate that automated functions behave acceptably across their operating envelope. Unresolved because the guidance that would say so, NUREG-2271, is a draft issued for comment [[2]](#src-2), and the licensing challenges identified in laboratory analysis of autonomous control remain open questions rather than accepted methods [[15]](#src-15). Resolver: NRC, through final guidance.
- **OQ-3. Oversight footprint.** What replaces the unstructured observation that resident inspection contributes today [[9]](#src-9), given how heavily safety conclusions rest on information the oversight process produces [[12]](#src-12). Unresolved because agency readiness for advanced reactor oversight is itself an open recommendation area [[10]](#src-10) [[11]](#src-11). Resolver: NRC, with GAO scrutiny.
- **OQ-4. Evidentiary standard.** Whether a machine-generated statement about reactor state can be evidence to a regulator, and under what conditions of independence, coverage, freshness, retention, and challenge. Unresolved because the architecture we can point to is specified outside nuclear [[19]](#src-19) and the cited record contains no accepted nuclear equivalent. Resolver: NRC for acceptance, standards bodies for form, research for method.
- **OQ-5. Units per crew.** What evidence would establish an acceptable ratio of units to qualified staff, and how reconciliation across units is treated. Unresolved because the contractor and research literature identifies the human-factors problem without setting a limit or a method for setting one [[13]](#src-13) [[14]](#src-14) [[20]](#src-20) [[16]](#src-16). Resolver: research organizations and NRC human-factors review.
- **OQ-6. Cyber design target.** What a developer can defensibly design against before a final requirement exists for this class, and whether a verification channel is itself a protected digital asset. Unresolved because the governing instrument is proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive) [[17]](#src-17) and the microreactor-specific technical case remains an active research project [[18]](#src-18). Resolver: NRC through rulemaking, informed by international research.
- **OQ-7. We cannot answer this one.** Whether an independent verification layer would be credited in a licensing basis at all, whether a third-party attestation would be accepted as evidence rather than as background, and what commercial weight buyers place on either. We hold no evidence on any of the three, our interest in the answers is direct, and pre-application interaction confers no approval [[21]](#src-21). Resolver: the NRC on a specific docket, and the market for the rest.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [NRC Part 57 and autonomous operation →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Microreactor cybersecurity explained →](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of NRC microreactor rulemaking and the published research record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) and proposed 10 CFR 73.110 (proposed, under development, and not final or prescriptive), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment/

# Oversight Models for Fleet-Scale Microreactor Deployment

> A comparative analysis of four candidate oversight models for a deployed microreactor fleet, assessed against five stated criteria and the public record.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# Oversight Models for Fleet-Scale Microreactor Deployment: A Comparative Analysis
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published July 24, 2026 Revised July 24, 2026 Status Comparative analysis, open for comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
Regulatory oversight of U.S. power reactors is delivered today through resident inspection, a structured oversight process, and licensed-operator conditions attached to the license itself. A deployed fleet of microreactors, distributed across many sites with small staffs, would stress every one of those mechanisms at once. The public record contains proposals, staff analysis, and contractor research bearing on the problem, but no published side-by-side comparison of the oversight models that could actually be adopted. This paper supplies that comparison. It defines five criteria an oversight model for a distributed fleet would have to satisfy, namely coverage per unit, timeliness of detection, independence from the operator, evidentiary durability, and scalability of regulator effort. It then assesses four candidate models against those criteria: extended resident inspection, periodic campaign inspection with remote data submission, continuous independent verification with attested records, and a hybrid of the three.
The comparison is the contribution, not the conclusion. No model is recommended, and the model closest to our own commercial interest is assessed with its unsolved problems stated in the same detail as its strengths. The principal limitation is that none of the four models has been reviewed or accepted by any regulator, so every assessment here is analytical rather than evidential. A second limitation is authorship. RankShield Energy is a pre-applicant developing an independent verification layer, and readers should treat the section on model C as the one requiring the most scepticism.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses how a regulator might obtain assurance about a distributed population of microreactors under U.S. Nuclear Regulatory Commission jurisdiction, and how candidate oversight arrangements compare against stated criteria. It draws on twenty primary sources spanning the regulator, the Government Accountability Office, three national laboratories, a standards body, and the International Atomic Energy Agency. Where a document is characterized, it is cited and its status is stated: rule in force, proposed rule, draft guidance, staff paper, contractor analysis, or research.
Several things are deliberately out of scope. The paper contains no design detail for any RankShield Energy system: no geometry, no fuel description, no performance or lifetime figures. It contains no cost or economic analysis, and cost is not among the evaluation criteria. It does not interpret what any rule requires of a third party, and it does not name, rank, or characterize other developers. It does not describe unattended or fully autonomous operation of a reactor; the operating model discussed throughout keeps a human in the loop for reactivity and safety actions, and the verification function under discussion is an assurance function rather than a control function.
Several developments would change the conclusions materially and should trigger a revision: issuance of a final microreactor licensing rule, final rather than draft application guidance, a Commission decision adopting or rejecting positions analyzed in the staff papers cited here, published agency direction on how inspection resources would be allocated to a distributed fleet, or laboratory results that resolve a human-factors question this paper treats as open. The assessments in section 7 are our reading of the cited record and are offered for disagreement.

Everyone working on microreactor deployment has an implicit answer to the oversight question, and almost nobody has written theirs down next to the alternatives. The published record contains a proposed licensing rule, draft guidance, staff analysis, contractor studies, and an oversight process built for large plants with people on site. What it does not contain is a comparison of the oversight models a distributed fleet could plausibly be given, evaluated against criteria stated in advance. This paper is that comparison.
The method is deliberately unglamorous. Section 1 describes what oversight delivers today and separates the functions it performs from the mechanism that performs them, because a replacement has to reproduce the functions and need not reproduce the mechanism. Section 2 defines five criteria precisely enough to be argued with. Sections 3 through 6 assess four models against those criteria, including the weaknesses of each. Section 7 presents the comparison in a table. Section 8 applies the analysis to developers, including us, without the flattering conclusion a vendor paper would normally reach.
Two framing points govern everything that follows. What is in force is identified as in force: the licensed-operator conditions at 10 CFR 50.54(m) [[4]](#src-4) and the Reactor Oversight Process the agency applies to operating plants [[3]](#src-3). What is proposed is identified as proposed at every mention, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[5]](#src-5), whose companion guidance NUREG-2271 is a draft issued for comment rather than final guidance [[6]](#src-6). RankShield Energy is a pre-applicant engaged in early regulatory interaction and holds no NRC license, permit, or design approval [[20]](#src-20). Nothing described here has been demonstrated to or accepted by the NRC, and none of the four models has been reviewed by any regulator.
Key takeaways

- Oversight today delivers five separable functions, of which independent observation and corroboration of self-reported information are the hardest to reproduce without a person on site.
- The constraint on scaling the existing model is staffing and agency readiness, which the Government Accountability Office has documented directly rather than as a matter of speculation.
- Every model that reduces on-site presence trades observation for reported data, and the quality of that trade depends on provenance and independence rather than on data volume.
- Continuous verification with attested records addresses durability and coverage well, and does not by itself address instrument scope, appraisal capability, or who qualifies the verifier.
- A hybrid is the most probable outcome because each model covers a different failure mode, and Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) does not settle which mix any specific applicant would be held to.

## 1. The oversight function today and what it actually delivers
Oversight of an operating U.S. power reactor is delivered through a small set of identifiable mechanisms, and this analysis depends on separating what those mechanisms deliver from how they deliver it. The NRC assigns resident inspectors to operating power reactor sites, and describes their unescorted access to the facility and their organizational separation from the licensee as defining features of the arrangement [[1]](#src-1) [[2]](#src-2). Their work feeds a structured framework. The Reactor Oversight Process organizes inspection findings and performance indicators against cornerstones of safety, applies a significance determination process, and produces a periodic assessment with defined agency responses [[3]](#src-3). Staffing is governed separately: conditions on power reactor licenses at 10 CFR 50.54(m) establish licensed-operator requirements for operation of the facility, and those are requirements in force rather than policy preferences [[4]](#src-4).
The functions this arrangement performs are distinct from the mechanism that performs them, and are worth enumerating, because a replacement model has to deliver the functions and does not have to reproduce the mechanism. Function one is independent observation: somebody who does not report to the licensee sees plant conditions that nobody selected for reporting. Function two is corroboration: self-reported information can be checked against direct observation, which is what lends the reported stream its credibility. Function three is continuity: an inspector who has watched a site for years detects drift that a snapshot cannot show. Function four is consequence: findings enter a defined process with defined outcomes rather than a correspondence file [[3]](#src-3). Function five is external accountability, and the Government Accountability Office has examined how far the agency's own safety conclusions rest on the information this process generates [[11]](#src-11).
The mechanism, by contrast, is contingent. It is a qualified person, physically present at a site large enough to justify the assignment, supported by regional inspection staff and a headquarters program. Nothing in that description is a safety principle. It is an engineering solution to the assurance problem, chosen when reactors were few, large, and individually significant. A fleet of small units at many sites changes the arithmetic of that solution without changing the functions it was chosen to deliver, which is why the honest question is not whether resident inspection survives but which model delivers the five functions at acceptable cost to the regulator. Our companion explainer on [one operator overseeing many reactors](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) treats the licensee-side version of the same arithmetic.
One caution about function two. Corroboration is not a redundant check on data that would otherwise be trusted. It is the reason the data is trusted at all. Any model that reduces on-site presence is, whatever else it does, converting a corroborated information stream into an uncorroborated one, and it has to replace the corroboration with something. That single observation drives most of the analysis that follows.

## 2. Evaluation criteria for a fleet oversight model
Criteria stated after the fact are advocacy. These five are stated before any model is assessed, they are defined so a reader can apply them independently, and cost is deliberately absent from them.
Criterion 1, coverage per unit. The proportion of safety-relevant plant conditions at a given unit about which the regulator can obtain information, expressed as breadth rather than volume. A model with high coverage produces information about conditions nobody anticipated; a model with low coverage produces information about the conditions somebody chose to report. Coverage is bounded by instrumentation and by physical access, and the two bounds fail in different ways.
Criterion 2, timeliness of detection. The interval between a condition arising and the regulator becoming capable of knowing about it. This is not the interval to formal notification, which is set by reporting rules, but the interval to availability. A model can be strong on coverage and weak on timeliness, which is the characteristic signature of campaign-based inspection.
Criterion 3, independence from the operator. The degree to which the party producing, transmitting, retaining, and appraising the information is organizationally and technically separate from the party being overseen. The resident inspector program achieves independence structurally, through a person who does not report to the licensee [[2]](#src-2). The International Atomic Energy Agency achieves it institutionally in the safeguards context, where technical measures are applied by an outside body to verify declarations made by a state [[19]](#src-19), a precedent for the institutional machinery independence requires, though safeguards address diversion of material rather than operational safety. RFC 9334 supplies the vocabulary for the split at the technical layer, separating the attester that produces evidence from the verifier that appraises it and the relying party that consumes the appraisal [[17]](#src-17).
Criterion 4, evidentiary durability. Whether a record retains its value as evidence after the moment it was made: whether it can be shown not to have been altered, whether its provenance survives, whether it can be produced and challenged in a later proceeding. Durability is where an oral observation is weakest and a signed record on an append-only transparency service of the kind described in RFC 9943 is strongest [[18]](#src-18).
Criterion 5, scalability of regulator effort. How agency effort grows as units are added. A model scales well when doubling the number of units does not double the qualified staff hours required, and scales badly when it does. This criterion is the reason the comparison matters: the Government Accountability Office has reported that the agency needed additional actions to prepare to license advanced reactors, and maintains priority open recommendations that remain unimplemented [[10]](#src-10) [[12]](#src-12).

## 3. Model A: extended resident inspection
Model A scales what exists. Resident or near-resident inspectors are assigned to microreactor sites in proportion to the number of sites, with the Reactor Oversight Process adapted in detail but retained in structure [[1]](#src-1) [[3]](#src-3). Its virtue is that it requires no new evidentiary theory. Every function described in section 1 is already delivered by it, and the agency has decades of practice in applying it. Where a regulator's tolerance for novel assurance methods is low, this is the model that needs the least argument.
Against criterion 1 it performs well. A person on site observes conditions that were never selected for reporting, which is the coverage property no data pipeline reproduces. Against criterion 2 it performs well for observable conditions and unevenly for the rest, since detection depends on presence at the moment of interest. Against criterion 3 it performs strongly, and structurally rather than contractually: the inspector does not report to the licensee [[2]](#src-2). Against criterion 4 it is moderate. Findings enter the agency record and are durable as findings, but the observation underlying them is not reproducible, and a disputed observation is resolved through process rather than through re-examination of a record.
Criterion 5 is where the model fails, and the constraint is documented rather than speculative. The Government Accountability Office reported that the NRC needed to take additional actions to prepare to license advanced reactors, including matters of staffing and workforce planning [[10]](#src-10), and its priority open recommendations for the agency identify items the agency has not yet implemented [[12]](#src-12). Separately, the Government Accountability Office has documented the extent to which the agency's safety conclusions rest on information produced by the existing oversight process [[11]](#src-11), which means the staffing constraint is not a matter of administrative convenience but of the evidentiary base itself.
The arithmetic is unforgiving. Qualified inspectors are produced through a training and qualification pipeline measured in years, and a distributed fleet multiplies sites faster than any such pipeline responds. Staff analysis of Nth-of-a-kind microreactor licensing and deployment considerations, which is staff analysis presented to the Commission rather than a Commission position or a requirement, examines the consequences of deployment at quantities unlike current practice [[8]](#src-8). The conclusion we draw, and it is our analysis rather than an agency position, is that Model A is sound on four criteria and structurally unable to satisfy the fifth at fleet scale. It remains the correct model for early units, where site counts are small and the value of direct observation during initial operation is highest.

## 4. Model B: periodic campaign inspection with remote data submission
Model B keeps inspection but decouples it from continuous presence. Inspectors visit on a planned cycle or in response to a trigger, and between visits the licensee submits operating data to the regulator on a defined schedule and in a defined format. The structure of the Reactor Oversight Process is retained, with performance indicators carrying more of the weight and baseline inspection carrying less [[3]](#src-3). This is the model most continuous with existing agency practice for facilities that do not host residents, and it is the one an agency under resource pressure can adopt without inventing anything.
Against criterion 5 it performs well, which is its reason for existing. Regulator effort tracks the number of visits and the volume of submissions reviewed rather than the number of hours a person spends standing in a building, and campaign scheduling gives the agency a lever it can adjust as the fleet grows. Against criterion 1 it is moderate: submitted data can cover many parameters at many units, and it covers exactly the parameters somebody chose to submit. The unstructured observation described in section 1 is largely absent between campaigns.
Criterion 2 is its weakest axis. Between campaigns, timeliness is set by the submission schedule and by the licensee's internal reporting judgment. A condition that develops and is corrected between visits may be visible in the data or may not be, depending on what was instrumented and what was transmitted. Criterion 3 is weaker than it appears. The inspection is independent while it is happening; the data path between campaigns is the licensee's, which makes the between-visit stream a self-report. That is the distinction we treat at length in [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is not a criticism of licensee integrity. It is a statement about who is in a position to corroborate.
Criterion 4 is moderate and contingent. A submitted record is durable to the degree that the submitting party's retention and integrity controls make it so, and disputes about what a record showed at the time it was made are resolved by examining the licensee's own systems. Staff analysis of policy and licensing considerations related to micro-reactors, which is staff analysis for Commission consideration rather than an adopted requirement, canvassed questions of this type early [[9]](#src-9), and the draft guidance for applications under the proposed microreactor framework is where some of the detail would land, while it remains a draft issued for comment [[6]](#src-6). The agency maintains a public summary of its microreactor regulatory activities, which is the practical place to watch for movement [[7]](#src-7). Our assessment: Model B scales, and it does so by accepting a reduction in corroboration that nothing in the model itself repairs.

## 5. Model C: continuous independent verification with attested records
Model C replaces continuous human presence with a continuous, independently appraised record. Instrumented plant state is signed at the point of measurement, appraised by a party separate from the operator, and registered so that the resulting record is tamper-evident and can be examined later. RFC 9334 supplies the role separation, distinguishing attester, verifier, and relying party [[17]](#src-17), and RFC 9943 describes registering signed statements on an append-only transparency service so that a relying party can verify them without trusting the issuer [[18]](#src-18). Both are internet standards with no nuclear regulatory standing, and citing them establishes vocabulary rather than acceptance. Our reference architecture for this model is set out [separately](https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state).
Assessed generously, it is strong on two criteria. Criterion 4 is where it performs best: a signed, registered record is durable in a way an observation is not, and it supports challenge after the fact by a party who was not present. Criterion 2 is strong for covered parameters, since detection latency is a property of the pipeline rather than of a visit schedule. Criterion 5 is favorable for volume, because appraisal of records does not scale with unit count the way qualified inspector hours do.
Now the part that matters more. Criterion 1 is where the model is weakest, and the weakness is structural rather than fixable by better engineering. Coverage is bounded absolutely by instrumentation. A verification layer says nothing whatever about a condition nobody instrumented, and an unheard sensor and a healthy plant produce the same silence unless the design distinguishes them. The Brookhaven National Laboratory review of reactor facilities without conventional main control rooms, which is contractor analysis prepared for the NRC rather than a requirement, is a useful corrective on how much of an operator's situational picture is not instrumented [[13]](#src-13). Oak Ridge National Laboratory analysis of licensing challenges associated with autonomous control identifies the difficulty of demonstrating that automated logic behaves acceptably across its envelope [[15]](#src-15), and the companion Oak Ridge work on autonomous operation concepts for microreactors describes the monitoring and diagnostic functions such a system depends on [[16]](#src-16). Neither resolves the qualification question for the software doing the verifying.
Criterion 3 is conditional, and this is the honest verdict. Independence is a property of the arrangement, not of the cryptography. If the operator selects, pays, instructs, and can dismiss the verifier, the mathematics is sound and the independence is decorative. Beyond that, the model requires of a regulator three capabilities that do not exist today: staff qualified to appraise cryptographic evidence and the software that produces it, a stated policy on what appraisal outcome is acceptable and what a gap in coverage means, and some means of qualifying or accrediting a verifier. Nothing in the cited record establishes any of the three, and pre-application interaction confers no approval of any of them [[20]](#src-20). Model C is therefore the model with the strongest evidentiary properties and the largest institutional deficit.

## 6. Model D: the hybrid, and why it is the probable outcome
Model D combines the three: reduced but real inspection presence, campaign inspection on a risk-informed cycle, and a continuous verified record between campaigns whose appraisal sits outside the licensee. It is the least elegant of the four and the most likely to occur, for reasons that have little to do with anyone's preference.
The technical reason is that each model covers a different failure mode. Inspection catches what was never instrumented. Campaign inspection catches accumulated drift and provides the periodic direct corroboration that keeps the reported stream credible. A continuous verified record catches transient and rapidly evolving conditions and preserves them in a form that survives to a later proceeding [[18]](#src-18). No pair of these covers what all three cover, and the three coverage sets overlap partially rather than nesting.
The institutional reason is stronger. Regulators do not replace a functioning assurance arrangement with an untested one; they add and then subtract as evidence accumulates. The Reactor Oversight Process itself is layered in exactly this way, combining inspection, indicators, significance determination, and assessment rather than relying on any single input [[3]](#src-3). Staff analysis of Nth-of-a-kind licensing and deployment considerations, which is staff analysis presented to the Commission and not a Commission position, treats standardization and repeat deployment as things that accumulate justification over units rather than being granted at the outset [[8]](#src-8). A hybrid is what a graded, evidence-accumulating approach looks like while the evidence is still accumulating.
The human-factors reason is the one most often skipped. Sandia National Laboratories examined human-factors considerations for automating microreactors [[14]](#src-14), and the Brookhaven contractor review of facilities without conventional main control rooms addresses the same territory from the review side [[13]](#src-13). Both point at function allocation: deciding what belongs to automation, what belongs to the person, and how the person retains an accurate picture of a plant they are not standing in. A hybrid oversight model mirrors that allocation on the regulator's side of the fence, which is a coherence argument rather than a proof.
The costs of the hybrid should be stated plainly, since they are the reason it is not obviously correct. It is the hardest of the four to govern: three information streams, three failure modes, and a standing question about which stream prevails when they disagree. It carries the highest design burden and the greatest risk of gaps at the seams, where each layer assumes another layer has coverage. And a hybrid is easy to adopt accidentally, by accretion, rather than by design, which is the version that satisfies criterion 5 worst of all.

## 7. Comparative assessment
The table below compresses sections 3 through 6 into a single view. Two cautions before reading it. The cells are qualitative because the record supports nothing quantitative: no model here has been trialled at fleet scale, and assigning numbers would imply a measurement basis that does not exist. And the assessments are ours. They are an argument, offered in a form that can be contradicted cell by cell.

Table 1. Four candidate oversight models assessed against the five criteria defined in section 2. This table is RankShield Energy analysis of the public record cited in this paper. It is not a regulatory position, it has not been reviewed or accepted by the NRC, and no model shown here is required, endorsed, or approved by any agency.

Model
1. Coverage per unit
2. Timeliness of detection
3. Independence from operator
4. Evidentiary durability
5. Scalability of regulator effort

A. Extended resident inspection
Strong, including conditions nobody selected for reporting
Strong for observable conditions, dependent on presence at the moment of interest
Strong and structural; the inspector does not report to the licensee
Moderate; findings are durable, the underlying observation is not reproducible
Weak; qualified staff hours rise close to linearly with unit count

B. Campaign inspection with remote data submission
Moderate; broad in submitted parameters, thin between campaigns
Weak between campaigns; set by submission schedule and licensee judgment
Moderate at campaign, weak between; the data path belongs to the licensee
Moderate; contingent on the submitting party's retention and integrity controls
Strong; effort tracks visits and submissions reviewed

C. Continuous independent verification with attested records
Weak beyond instrumentation; silent on anything not measured
Strong for covered parameters; requires distinguishing silence from a healthy null
Conditional; a property of the arrangement, not of the cryptography
Strong; signed, registered records support challenge after the fact
Strong for volume, unproven for appraisal; shifts effort to software and verifier qualification

D. Hybrid of A, B and C
Strong where layers overlap; gaps where each assumes another has coverage
Strong for instrumented parameters, campaign-limited elsewhere
Strong if both the inspection and the appraisal sit outside the licensee
Strong; two record types that can be cross-checked
Moderate; lighter per unit, heavier to design and govern

Three patterns are visible across the rows. Criterion 1 and criterion 5 pull against each other in every model: the arrangements that see the most at a unit scale worst, and the arrangements that scale best see a selected subset. No model in the table escapes that tension, and we are not aware of a published proposal that does. Criterion 3 behaves differently from the rest, because independence is structural in Model A and contractual or architectural in the others, and a structural property degrades more gracefully than a contractual one.
The third pattern concerns criterion 4. Evidentiary durability is the axis on which the existing model is weakest and the newest model is strongest, and it is also the axis least discussed in the deployment literature, which tends to treat oversight as a detection problem rather than as a problem of records that survive to be argued over. The durability question becomes acute precisely when something has gone wrong and the reconstruction begins [[18]](#src-18).
What the table does not do is rank the models, and the omission is deliberate. Ranking requires a weighting across the five criteria, weighting is a regulatory judgment rather than a technical one, and no weighting appears in the cited record. A reader who weights criterion 1 highest will prefer Model A; a reader who weights criterion 5 highest will prefer Model B or C; a regulator obliged to weight all five will most likely arrive at Model D. Publishing the criteria separately from the weighting is the point of presenting the analysis this way.

## 8. What this implies for developers, including us
The standard this paper follows requires it to apply its own framework to RankShield Energy and to state where we do not have a strong answer. Three implications follow for any developer, and the third is uncomfortable for us specifically.
The initial implication is that oversight model is a design input and is being treated by much of the field as a downstream compliance matter. Instrumentation scope, data retention, network architecture, and the physical accommodation of an inspector are frozen early in a design and are expensive to revisit. A developer who assumes Model C and instruments to the boundary of what a verification layer needs will discover, if the outcome is Model D, that the coverage gap identified in section 5 is now a licensing issue rather than an engineering preference. The conservative design position is to instrument for the model with the widest coverage requirement.
The second implication concerns claim discipline. Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contemplates a licensing framework for this reactor class [[5]](#src-5), and its companion guidance NUREG-2271 is a draft issued for comment rather than final guidance [[6]](#src-6). Neither settles which oversight model any specific applicant would be held to, and that determination would be made on a docket. Pre-application interaction is described by the agency as a means of early alignment, and it confers no approval [[20]](#src-20). Our own explainers on [the proposed rule](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) and on [what a reviewer should ask a vendor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) take the same position.
The third implication applies to us. RankShield Energy is developing an independent verification layer, which is a Model C component. This analysis concludes that Model C is weakest on the criterion a regulator has historically weighted heaviest, namely coverage of conditions nobody selected for reporting, and that its independence property is a feature of the commercial arrangement rather than of the technology. It also concludes that the model requires appraisal and accreditation capabilities that do not exist today, and we have no evidence about whether they will be built. Nothing in our design has been demonstrated to or accepted by the NRC. If the outcome is Model D, the honest description of a verification layer is a component within a larger arrangement that continues to depend on inspection, not a replacement for it, and we would rather write that down now than be held to a stronger claim later.
The final implication concerns the record. The Government Accountability Office has documented both the agency's reliance on oversight information and its readiness gaps for advanced reactor licensing [[11]](#src-11) [[10]](#src-10), and neither closes on a developer's schedule. The register of what remains unsettled is maintained in our [open questions paper](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight); the entries below are what this comparison adds to it.

## Frequently asked questions

### Which oversight model does this paper recommend?
None of them. The contribution is the comparison and the criteria, not a recommendation. The paper assesses four models against five criteria stated in advance, and it declines to rank them because ranking requires a weighting across the criteria, and weighting is a regulatory judgment rather than a technical one. Section 6 does state that a hybrid is the most probable outcome, which is a prediction about how regulators behave rather than an endorsement of the hybrid as the correct answer.

### Why are the five criteria the right ones?
They are defensible rather than uniquely right, and a reader is invited to add or replace one. Coverage per unit, timeliness of detection, independence from the operator, evidentiary durability, and scalability of regulator effort were chosen because each maps to a function that the existing arrangement of resident inspection and the Reactor Oversight Process actually delivers today. Cost is deliberately excluded. If a criterion were added, the most likely candidate is resilience of the oversight arrangement itself to loss of a single input.

### Does the proposed microreactor licensing rule determine which model applies?
No. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). It contemplates a licensing framework for this reactor class, and contemplating a framework is different from establishing which oversight arrangement any specific applicant would be held to. The companion guidance, NUREG-2271, is a draft issued for comment rather than final guidance. The design-specific determination would be made on a docket.

### Is continuous verification a replacement for inspection?
On this analysis, no. Continuous verification with attested records is strong on evidentiary durability and on timeliness for parameters that are instrumented, and it is silent about any condition nobody instrumented, which is precisely the coverage property that on-site observation supplies. It also depends on an appraisal capability, an appraisal policy, and a way of qualifying a verifier, and nothing in the record cited by this paper establishes that any of the three exists.

### What would change the assessments in this paper?
A final microreactor licensing rule, final rather than draft application guidance, a Commission decision on positions analyzed in the staff papers cited here, published agency direction on how inspection resources would be allocated across a distributed fleet, or laboratory results establishing what a supervising operator can reliably detect without being on site. Any of those would move cells in the comparison table, and the table is versioned so that movement can be recorded.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg.html)
- [U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description/resident-insp-program.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628); proposed rule, comment period closed June 15, 2026, not final](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. NUREG-2271 (Draft for Comment): guidance associated with the proposed microreactor licensing framework. April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper, not a Commission position). June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper, not a Commission position). October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE), contractor analysis. February 2025](https://www.osti.gov/biblio/2529385)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811-concepts-autonomous-operation-microreactors)
- [Internet Engineering Task Force (RFC Editor). RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force (RFC Editor). RFC 9943: Supply Chain Integrity, Transparency, and Trust (SCITT) Architecture. June 2026](https://www.rfc-editor.org/info/rfc9943)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Weighting.** How the five criteria would be weighted against one another by a regulator, since the comparison in section 7 declines to rank the models precisely because no weighting appears in the cited record [[3]](#src-3). Resolver: NRC, through rulemaking and guidance.
- **OQ-2. The observation residual.** What proportion of an inspector's contribution is unstructured observation of conditions nobody selected for reporting [[1]](#src-1) [[2]](#src-2), and how much of that residual is transferable to instrumentation. Unresolved because the cited record characterizes the program without decomposing its contribution. Resolver: research, tested against agency inspection experience.
- **OQ-3. Scaling law.** Whether regulator effort under any model scales per site, per unit, or per operating organization once one organization oversees many units. Unresolved because staff analysis of Nth-of-a-kind deployment examines options rather than establishing a footprint [[8]](#src-8), and agency readiness for advanced reactor licensing remains an open recommendation area [[10]](#src-10) [[12]](#src-12). Resolver: NRC, with Government Accountability Office scrutiny.
- **OQ-4. Evidentiary standard.** What makes a machine-generated statement about reactor state acceptable to a regulator as evidence, with respect to independence, coverage, freshness, retention, and challenge. Unresolved because the architectures available to point at are specified outside nuclear [[17]](#src-17) [[18]](#src-18) and the cited record contains no accepted nuclear equivalent. Resolver: NRC for acceptance, standards bodies for form, research for method.
- **OQ-5. Who qualifies the verifier.** Whether an independent appraising party would require qualification, accreditation, or inspection itself, and by whom. The safeguards context offers the sole standing example of an institution built for outside verification, and it addresses diversion of material rather than operational safety [[19]](#src-19). Resolver: NRC, potentially with a standards or accreditation body.
- **OQ-6. Software qualification.** How the software performing monitoring, diagnosis, or verification would be qualified, given that laboratory analysis identifies demonstrating acceptable behavior across an operating envelope as an unsolved licensing challenge [[15]](#src-15) [[16]](#src-16). Resolver: NRC through review practice, informed by laboratory research.
- **OQ-7. Supervisory span.** What evidence would establish an acceptable ratio of units to qualified staff on the licensee side, and how a supervisor retains an accurate picture of a plant they are not standing in. Unresolved because contractor and laboratory work identifies the human-factors problem without setting a limit or a method for setting one [[13]](#src-13) [[14]](#src-14). Resolver: research organizations and NRC human-factors review.
- **OQ-8. We cannot answer this one.** Whether a Model C verification layer would be credited in any licensing basis at all, or whether a regulator concludes that assurance belongs inside the licensee's own quality and configuration-management programs and that an external appraiser adds a component to be reviewed without reducing anything else that must be reviewed. We hold no evidence either way, our commercial interest in the answer is direct, the guidance that might address it is a draft [[6]](#src-6), and pre-application interaction confers no approval [[20]](#src-20). Resolver: the NRC, on a specific docket.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [Open questions in autonomous microreactor oversight →](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [The NRC pre-application process explained →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of NRC microreactor rulemaking and the published research record as of July 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record/

# How Reactor State Becomes a Trusted Attestation Record

> How does raw sensor data become a record a regulator or insurer can trust? Follow the chain from telemetry to a tamper-evident, independently verifiable record.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# From Sensors to an Attestation Record: How Reactor State Is Confirmed
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. A reactor state attestation record is what raw telemetry becomes once an independent party has appraised it, signed the appraisal, and written it to an append-only log that returns a receipt. The chain runs in four steps: measure, appraise, sign and log, verify. The fourth step carries the weight, because it is the one that lets a regulator, insurer, lender, or grid operator check what happened without the operator's cooperation.
A live dashboard answers a different question than a record does. It shows what a vendor's software wants to show right now, filtered and rendered by the same organization whose performance is being judged. What a regulator, insurer, lender, or grid operator needs is something else: an account of what the plant did that they can check for themselves, later, on their own terms. Computing worked this out already and standardized the roles, separating the party that produces evidence about its state from the party that appraises that evidence and the party that acts on the result [[1]](#src-1).
This article follows the chain from a sensor reading to a record an outside party can rely on, then covers why signature choices matter for records meant to outlive the equipment, why supply-chain integrity of the measuring and signing components sits underneath all of it, and what tamper-evident actually means, since it means detection rather than prevention. It closes with a stated objection, an honest limitation, and where we actually stand. RankShield Energy is a pre-applicant holding no license or approval [[14]](#src-14), and everything described here is design intent rather than a demonstrated capability.
Key takeaways

- Telemetry is an input, not evidence: it originates with, travels through, and is rendered by the party whose performance is in question.
- An appraisal becomes durable evidence when a party separate from the operator signs it and registers it in an append-only log that issues a receipt.
- The test of the whole architecture is whether a third party can check the record later without the operator's help, or its solvency, or its existence.
- Tamper-evident means alterations and omissions are detectable. It does not mean tamper-proof, and nothing here is unhackable.
- Post-quantum signature standards matter because a reactor record may need to be verifiable long after the equipment and the organization are gone.
- RankShield Energy is a pre-applicant. This chain is design intent and an architecture we apply, not a deployed or NRC-accepted capability.

## Raw telemetry is data, and data by itself is not proof
A sensor reading is a claim made by equipment the operator owns, carried over a path the operator controls, into a display the operator renders. Nothing in that sequence establishes for an outside party that the value is complete, current, and unaltered. It is perfectly good data for running a plant. It is not, on its own, evidence anyone else can rely on months or years later, because every step of its journey traces back to the party whose performance is in question.
Measurement quality sits upstream of everything else, and the national labs have named what it demands. Oak Ridge identified sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring as preconditions for operating microreactors with reduced on-site presence [[7]](#src-7). If the measurement layer is thin, no amount of cryptography downstream improves it. Signing a bad number produces a durable record of a bad number.
The transport path matters just as much as the sensor. The IAEA's guidance on computer security of instrumentation and control systems at nuclear facilities treats those systems as protected assets across their life cycle rather than as ordinary information technology [[9]](#src-9), and the reason is that a compromised I&C path does not announce itself. It produces plausible readings. A viewer looking at a rendered feed has no way to distinguish a healthy plant from a healthy-looking report.
So the chain has to start at measurement, but it cannot end at a screen. It has to end at a record. Model-based cross-checks help here, and we cover that separately in [how digital twins fit remote reactor verification](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations), but a model is another input to appraisal rather than a substitute for it.

## Appraisal by a party separate from the operator is what turns data into evidence
The second step is appraisal, and the internet already standardized what appraisal means. RFC 9334 defines an architecture in which an Attester produces evidence about its state, a Verifier appraises that evidence against an appraisal policy, and a Relying Party acts on the Verifier's result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[1]](#src-1). The separation of those three roles is not incidental. It is the whole design.
Nuclear has the same insight in a different form. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, and describes their function as independently verifying that requirements are being met [[10]](#src-10). The IAEA safeguards system exists so that an outside body applies its own technical measures to independently verify that facilities are not misused, rather than relying on a state or operator assertion [[8]](#src-8). Safeguards address non-proliferation rather than operational safety, so do not overread the analogy, but the structural move is identical: place the checker outside the checked.
Applied to reactor state, appraisal means comparing what the plant reports against what independent measurement shows and what the design permits, then recording the comparison. The property that matters most is unglamorous: disagreement has to be recorded as faithfully as agreement. A system that writes a record only when everything matches is not verifying anything. It is publishing.
That distinction is the subject of a companion piece on [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it is the reason [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) is a different job from monitoring one.

## Signing and logging are what make an appraisal durable
An appraisal that lives in a database is an opinion with a timestamp. Signing it binds the content to a key, so a later reader can tell whether the bytes changed. That is necessary and still not sufficient, because a signature says nothing about what was not shown. A party holding a set of signed statements cannot tell whether it received all of them, or whether an inconvenient one was quietly withdrawn before anyone looked.
Closing that gap is what append-only transparency infrastructure is for. RFC 9943 describes an architecture in which statements are registered into an append-only service that issues a receipt for each registration, so that the existence of a statement becomes checkable rather than asserted [[2]](#src-2). The record stops being something the issuer holds and becomes something the issuer has committed to in a place it cannot silently edit.
The receipt is the portable part. RFC 9942 standardizes receipts as compact cryptographic proofs, carrying inclusion proofs that a given statement is in the log and consistency proofs that the log has not been rewritten between two points in time [[3]](#src-3). A holder can check both without contacting the party that produced the statement.
It is worth being precise about what this does and does not establish. A receipt proves what was claimed, by whom, and when it entered the record. It does not prove the reactor was safe. Safety is established by analysis, testing, and regulatory review. What the record contributes is that the account of what happened cannot be quietly revised after the fact to suit the outcome, which is a narrower claim and a more defensible one.

## The test that matters is what an outsider can check without the operator's help
The fourth step is the one that decides whether any of the preceding work was real. If checking the record requires the operator to hand something over, stay online, or vouch for something, then the operator is still the source of trust and the architecture is decorative. The useful question is what a party can establish unaided, which is exactly the Relying Party role RFC 9334 separates out [[1]](#src-1).
This is where a table earns its place, because it says something the four-step chain above the article does not: different parties want different things from the same record.

What each party can establish from an attestation record without the operator's cooperation

Party
What the record lets them establish on their own
What it still does not settle for them

Regulator
That a stated appraisal existed at a stated time and has not been altered since
Whether the underlying operation complied, which remains a review judgment

Insurer or lender
That the operating account they were given matches the account committed to at the time
Loss likelihood, which needs actuarial and engineering analysis beyond the record

Grid operator
That availability and dispatch claims were recorded contemporaneously, not reconstructed later
Future behavior, since a record is history rather than a forecast

Any later reviewer
Inclusion in the log and consistency of the log across two points in time
Whether the measurement feeding the appraisal was itself sound

Every row in the middle column is checkable with the receipt, the verifier's public key, and the log [[3]](#src-3). None of it requires the operating organization to be cooperative, solvent, or in existence. Every row in the right-hand column is a reminder that a record is a floor rather than a ceiling. It removes a category of dispute about what was said and when, which frees the harder conversation to be about engineering rather than about whose screenshot to believe.

## Records meant to outlive the equipment need post-quantum signatures
A reactor operating record may need to be checkable for decades, and potentially long after the equipment that produced it has been decommissioned and the organization that operated it has been reorganized or dissolved. That makes the choice of signature algorithm a durability decision rather than a security fashion. The question is not only whether a signature is sound today. It is whether a reviewer in the 2050s will still regard the algorithm as sound enough to settle a dispute.
The standards ground has moved recently enough that this is now a concrete choice rather than a speculative one. NIST announced approval of three Federal Information Processing Standards for post-quantum cryptography in August 2024 [[4]](#src-4), and FIPS 204 specifies a module-lattice-based digital signature standard [[5]](#src-5). A signature scheme intended for long-lived records now has a published, standardized option rather than a research paper.
It also pays to be careful about the threat model, because post-quantum marketing tends to blur it. The exposure for signatures is not identical to the exposure for encrypted data. Data captured today and decrypted later is a harvesting problem. Signatures face a different issue: a key that remains in use, or a record that must still be verified long after the algorithm has fallen out of trust, is the thing that ages badly. That argues for algorithm agility and for planning key lifetimes deliberately rather than for treating a single algorithm choice as permanent.
This is the part of the problem where our own hands-on work actually sits, and the tradeoff we accepted is worth stating plainly. Building for signature agility means carrying more than one verification path and accepting the operational overhead of maintaining both. It is slower and more complex than picking one algorithm and moving on. We took the overhead because a record that becomes unverifiable is indistinguishable from a record that was never made.

## The evidence is only as trustworthy as the components that produce it
There is a quiet assumption underneath every attestation architecture: that the components doing the measuring, appraising, and signing are the components their manufacturer intended. If a signing module, gateway, or sensor was altered before installation, the resulting record is well formed, correctly signed, verifiable by anyone, and wrong. Cryptography faithfully propagates whatever it is fed.
This is a supply-chain discipline rather than a cryptographic one, and federal guidance for it already exists. NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organizations, updated in November 2024 [[6]](#src-6). The relevant idea for a reactor evidence chain is that assurance about a component has to be established and maintained across acquisition, integration, and operation, not asserted once at purchase.
The nuclear-specific version of the same point is in the IAEA's I&C computer security guidance, which frames protection of instrumentation and control as a life-cycle obligation covering design, procurement, and maintenance rather than a deployment-time checklist [[9]](#src-9). A reactor is a long-lived asset. Components get replaced, firmware gets updated, and vendors change hands, all while the record is expected to remain continuous.
There is a recursion here that deserves an honest word. Attestation about a component is itself an attestation, appraised by something, signed by something else. That regress has to stop somewhere, and where it stops is a design decision with real consequences. We treat the placement of that root of trust as an explicit, documented choice rather than an implementation detail, because a root of trust nobody can name is a root of trust nobody can evaluate.

## Tamper-evident means changes are detectable, not that they are impossible
This distinction is worth stating bluntly, because it is the one most often blurred in vendor language. Tamper-evident is a defined property: an alteration to a record, or a withdrawal of one, is detectable by a party who checks. That is a claim about detection. It is not a claim about prevention. Nothing described in this article is tamper-proof, unhackable, or unbreakable, we do not use those words about our own work, and a vendor who does is telling you something about their marketing rather than their architecture.
What detection buys is specific. An altered statement fails signature verification. A statement missing from the log fails its inclusion proof. A log that has been rewritten between two checks fails its consistency proof [[3]](#src-3), and the registration model that produces those proofs is what makes absence detectable rather than merely suspected [[2]](#src-2). The result is not that misconduct becomes impossible. It is that misconduct becomes visible to someone who was not present when it happened.
The obvious objection is that this is over-engineering for a reactor, since nuclear already has among the most demanding recordkeeping and inspection regimes of any industry. The objection is fair and the answer is that the existing regime was built around presence. It assumed inspectors on site who could look, ask, and form a judgment that instrumentation missed [[10]](#src-10). Those records were trustworthy in large part because people were standing next to the thing being recorded. As that presence thins, the same obligations travel as data over networks, and the mechanism that made them credible does not travel with them automatically. This is not extra rigor bolted onto a solved problem. It is the existing rigor relocated into a medium that needs different machinery to hold it.
The honest limitation is that none of this fixes a bad input. A faithfully signed record of a miscalibrated sensor is a faithful record of a wrong number, and the chain will confirm that wrong number with perfect fidelity for decades. Calibration, sensor diversity, and validation are separate engineering problems, and they stay separate. Evidence integrity and measurement quality are two different disciplines, and buying one does not get you the other.

## Why thinning on-site presence raises the stakes, and where we actually are
The reason this matters more now than it did a decade ago is that the compensating mechanism is being reconsidered. Proposed 10 CFR Part 57 contemplates remote operation and reduced on-site staffing for microreactors [[11]](#src-11), and the NRC's microreactor regulatory activities page tracks that work as it develops [[12]](#src-12). Part 57 is a proposal rather than a final rule, it may change, and no developer is licensed under it. It is also not a move to unattended operation: reactivity and safety actions keep a human in the loop, and we take care not to describe anything as unmanned or fully autonomous, because that is not what is on the table. We walk through that framework in [our explainer on Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
Meanwhile, the operations side has been advancing faster than the verification side, and it is worth saying so. DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[13]](#src-13), while Oak Ridge's own framing of autonomous operation named the instrumentation and state-awareness preconditions that remain open [[7]](#src-7). Capability to run with fewer people is arriving ahead of capability to independently confirm what those systems did, and the gap widens further at [fleet scale, where one organization oversees many units](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
On where we stand, plainly. RankShield Energy is a pre-applicant engaged in early interaction with the NRC [[14]](#src-14). We hold no license, permit, or design approval, and nothing about our design or our attestation architecture has been demonstrated to or accepted by the NRC. The chain described in this article is design intent and an architecture we apply in our attestation engineering work. It is not a deployed reactor capability and not a certified one, and we would rather say that flatly than let the distinction blur.
One further limitation belongs here, since it is the sharpest one we know about our own position. A verifier is only as independent as the witnesses that observe its log, and witnesses an organization hosts itself do not establish independence no matter how they are engineered. External witnesses are the open item, and we do not currently have them. If you are evaluating developers on any of this, the questions in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) should be aimed at us as unsentimentally as at anyone else.

Interactive · illustrative

## Follow the chain, from a sensor reading to a checkable record
Select each step. This is an educational illustration of the concept, not a live system, a control interface, or a safety function.
1 · Measure 2 · Appraise 3 · Sign and log 4 · Verify

### Measure
Instruments capture reactor state: power level, temperatures, control-element positions, and the status of each safety function. On their own these are numbers on the operator's own system, and nothing yet makes them trustworthy to an outside party.

### Appraise
An independent verifier, separate from the operator, compares the measured state against what the operator reports and what the design permits. Both agreement and disagreement are recorded, so a later reviewer can see what was checked.

### Sign and log
The verifier's result is signed with a post-quantum digital signature (NIST FIPS 204 and 205) and written to an append-only transparency log, which returns a receipt. The record is designed so it cannot be quietly changed after the fact.

### Verify
Later, a regulator, insurer, lender, or grid operator checks the receipt against the log and the signature, and confirms the record independently, without asking the operator to vouch for itself. This is the property that a plain dashboard cannot provide.

## Frequently asked questions

### What is a reactor state attestation record?
It is what reactor telemetry becomes after it has been appraised by a party separate from the operator, signed, and written to an append-only log that returns a receipt. The chain runs measure, appraise, sign and log, verify. The final step is the point of the exercise: a party that was not present, and that the operator does not control, can still check what was claimed and when. The role separation follows the model RFC 9334 defines, with an attester producing evidence, a verifier appraising it, and a relying party acting on the result [[1]](#src-1).

### Is a vendor dashboard enough to show a reactor is operating as reported?
No, and not because vendors are dishonest. A dashboard renders data the operator collected, over a path the operator controls, in a form the operator chooses, so every element traces back to the party being evaluated. It also shows the present rather than preserving the past. The IAEA treats instrumentation and control systems as protected assets across their life cycle precisely because a compromised path produces plausible readings rather than obvious errors [[9]](#src-9), and a rendered feed gives an outside reviewer no way to tell the difference after the fact.

### What does tamper-evident mean, and is it the same as tamper-proof?
They are different claims and the difference matters. Tamper-evident means an alteration or a withdrawal is detectable by anyone who checks: an altered statement fails signature verification, a missing one fails its inclusion proof, and a rewritten log fails its consistency proof [[3]](#src-3). Tamper-proof would mean alteration is impossible, which is not a property this architecture has or that we claim. Nothing described here is tamper-proof or unhackable. The value is detection, which converts a silent failure into a visible one.

### Why do post-quantum signatures matter for reactor records?
Because a reactor record may need to be verifiable decades after the equipment and possibly the operating organization are gone, which makes signature choice a durability question. NIST announced approval of three post-quantum FIPS in August 2024 [[4]](#src-4), including FIPS 204 for module-lattice-based digital signatures [[5]](#src-5), so a standardized option now exists for long-lived records. The practical takeaway is less about any single algorithm than about agility: build so the verification path can change without invalidating the archive, since a record that becomes unverifiable is worth about as much as one never made.

### Does RankShield Energy have this running on a reactor today?
No. RankShield Energy is a pre-applicant with the NRC holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[14]](#src-14). Proposed Part 57 is a proposal whose terms may change, and no developer is licensed under it [[11]](#src-11). The attestation chain described here is design intent and the architecture our attestation engineering work applies, not a deployed or certified reactor capability. The most significant gap we can name in our own position is external witnesses, which we do not have.

## Sources

- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024](https://csrc.nist.gov/pubs/fips/204/final)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Digital twins and remote reactor verification →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of attestation and post-quantum signature standards as of July 2026. This area is evolving; check back if the referenced standards are revised or if the NRC issues new guidance relevant to operational recordkeeping.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state/

# A Reference Architecture for Reactor State Verification

> A reference architecture for verifying reactor state independently, assembled from published standards, and assessed honestly against the regulatory record.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# A Reference Architecture for Independent Verification of Reactor State
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published 24 July 2026 Revised 24 July 2026 Status Published for technical comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
Oversight of United States commercial power reactors has been built around physical presence. The NRC assigns resident inspectors to operating sites and feeds their findings into the Reactor Oversight Process [[1]](#src-1) [[2]](#src-2) [[3]](#src-3), and 10 CFR 50.54(m) makes minimum licensed operator staffing, including an operator at the controls, a condition of the license [[4]](#src-4). Microreactor concepts that contemplate remote operation and reduced on-site staffing withdraw part of that presence without yet replacing the evidence it supplied. This paper treats that gap as a design problem rather than a governance argument. It states five criteria a verification layer would have to satisfy, and proposes a reference architecture that satisfies them using published standards rather than new cryptography: attestation roles from RFC 9334 [[11]](#src-11), transparency and receipts from RFC 9943 [[12]](#src-12) and RFC 9942 [[13]](#src-13), and post-quantum signatures standardized by NIST [[14]](#src-14) [[15]](#src-15).
The contribution is the assembly, its mapping to the regulatory record, and an explicit register of what it fails to do. The principal limitation is structural: the architecture produces detection rather than prevention, and it inherits whatever trustworthiness the underlying sensors have. A signed record of a corrupted measurement is a corrupted record, signed. Nothing described here has been demonstrated to or accepted by the NRC [[22]](#src-22).

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses the evidence layer that sits above reactor instrumentation: how a record of reactor state can be produced, appraised by a party other than the operator, signed, logged, and later re-checked by someone who was absent when it was made. It sets out design criteria, names the published standards that already define each component, maps the resulting architecture onto the current regulatory record including the NRC's proposed 10 CFR Part 57 rule (proposed, published in the Federal Register on May 1, 2026, comment period closed June 15, 2026, not final, and no developer is licensed under it), and analyses the failure modes that survive.
It deliberately does not do several things. It is not a safety analysis and makes no safety claim. It is not a control system design; the architecture described here carries evidence outward and exercises no control function, and nothing in it supports a fully autonomous or unmanned operating model. It contains no design-specific parameters for the HELIX microreactor, because a public paper is the wrong surface for those under 10 CFR Part 810. It does not interpret any regulatory requirement on behalf of a third party, and it does not name, rank, or characterize other developers.
Three things would change its conclusions. A final Part 57 rule that differs materially from the May 1, 2026 proposal, or final guidance differing from the draft NUREG-2271 issued for comment in April 2026 [[6]](#src-6), would change the regulatory mapping in Section 5. A practical break in a standardized post-quantum signature scheme [[15]](#src-15) would change the durability argument in Section 4. And credible sensor-level attestation, which does not exist today for qualified nuclear instrumentation, would substantially narrow the residual risk described in Section 6.

United States commercial reactor oversight rests on a fact that is rarely stated as an assumption: someone is there. A resident inspector is assigned to the site and walks the plant. A licensed operator sits at the controls as a condition of the license. Microreactor concepts that contemplate remote operation and reduced on-site staffing withdraw part of that presence. This paper asks what presence supplied, and proposes an architecture for supplying it another way.
The regulatory direction is far enough along to make the question concrete rather than speculative. The nrc's proposed 10 cfr part 57 rule (proposed, published in the federal register on may 1, 2026, comment period closed june 15, 2026, not final, and no developer is licensed under it) would establish a licensing framework for this reactor class [[5]](#src-5), and NRC staff have published draft application guidance for it [[6]](#src-6). Nothing in that record is settled, and this paper does not treat it as settled. What it does treat as settled is that an oversight model built around presence needs a stated replacement for the evidence presence produced, and that the replacement is easier to design before deployment than after.
The contribution here is a reference architecture assembled entirely from published standards, five criteria against which any such architecture can be tested, a register of open questions including several we cannot answer, and an assessment of RankShield Energy against our own criteria that we do not pass. RankShield Energy is a pre-applicant and operates no reactor [[22]](#src-22). The architecture is offered for use and for argument, not as a description of a capability we hold.
Key takeaways

- Resident inspection and the operator-at-controls condition supplied evidence with four properties: contemporaneous, unmediated, contextual, and institutionally independent [[1]](#src-1) [[3]](#src-3) [[4]](#src-4). A remote model erodes the middle two most sharply.
- A verification layer has to be per-unit, comparable, independent of the operator, checkable after the fact, and durable, and all five have to hold at once.
- Every component of the proposed architecture is already defined by a published standard: attestation roles [[11]](#src-11), transparency services [[12]](#src-12), receipts [[13]](#src-13), and post-quantum signatures [[14]](#src-14) [[15]](#src-15). The contribution is the assembly, not the parts.
- The regulatory context is unsettled: proposed Part 57 (proposed, published May 1, 2026, comment period closed June 15, 2026, not final, no developer licensed under it), with draft staff guidance in NUREG-2271 [[6]](#src-6).
- The architecture is tamper-evident, not tamper-proof, and it inherits the trustworthiness of the sensors beneath it. RankShield Energy does not currently satisfy three of its own five criteria.

## 1. The oversight function that remote operation displaces
Presence performs an evidential function before it performs a regulatory one. The NRC assigns resident inspectors to operating commercial power reactor sites, where they conduct inspections, observe licensee activities, and hold access to the facility that does not depend on the licensee's own reporting [[1]](#src-1) [[2]](#src-2). Their findings feed the Reactor Oversight Process, which combines licensee performance indicators with NRC inspection results and assesses both against defined cornerstones of safety [[3]](#src-3). Separately, 10 CFR 50.54(m) establishes minimum licensed operator staffing as a condition of the license, including the presence of a licensed operator at the controls while the reactor is operating [[4]](#src-4).
Four distinct goods come out of that arrangement, and they are worth separating because a remote operating model does not remove them equally. Observation is contemporaneous: an inspector sees the plant in the state it is in, not in the state a report describes some hours later. Observation is unmediated: it does not pass through the licensee's own recording and summarizing before it reaches the regulator. Observation is contextual: a person who knows the unit notices that a parameter is ordinary here and would be anomalous next door. And observation is institutionally independent: the observer is employed by the regulator, not by the licensee.
A remote model with reduced on-site staffing erodes the unmediated property most sharply. What reaches an off-site reviewer is a record that the operator's own systems produced, transported, and stored. The contextual property degrades next, because context is expensive to reconstruct from telemetry. The institutional independence of the regulator survives, but it now operates on evidence supplied by the party being regulated, which is a materially weaker epistemic position than walking the plant.
The regulator has been examining this. A February 2025 report prepared for the NRC by Brookhaven National Laboratory, which is contractor analysis and not a Commission position, reviews reactor facilities that operate without main control rooms [[21]](#src-21). Earlier, SECY-20-0093, an NRC staff paper rather than a Commission decision, set out policy and licensing considerations specific to micro-reactors [[8]](#src-8). Both establish that the question is live inside the agency. Neither establishes an answer, and neither should be read as one.
The framing this paper adopts follows from that. The claim is not that remote operation is unsafe; this paper takes no position on that. The claim is narrower and more tractable: presence supplied evidence with four identifiable properties, and a remote model has to supply evidence with those properties by other means or accept a weaker basis for oversight. Stated that way, a governance argument becomes a design specification, which Section 2 attempts to write down.

## 2. Problem statement and design goals
The design problem is to reproduce the evidential properties of presence, not to reproduce presence itself. The distinction matters, because attempts to reproduce presence lead to more cameras and more telemetry, which increase the volume of operator-produced information without changing who vouches for it. Volume is not assurance. A hundred additional signals routed through the same trust path have the same trust properties as one.
We state the goals as criteria so that a proposed design can be tested against them individually rather than assessed as a whole:

- **Per-unit.** Evidence describes an individual reactor. A fleet-level aggregate averages away the divergent unit, which is the unit that matters.
- **Comparable.** Records from different units, sites, and vendors are expressed so that a reviewer can compare them without bespoke reconciliation work. Comparability is what allows an anomaly to stand out rather than requiring someone to notice it.
- **Independent of the operator.** The party that appraises the evidence is organizationally distinct from the party whose state is being described. Evidence the operator alone can attest to is a claim, not a verification.
- **Checkable after the fact.** A party absent at the time can later reconstruct what was recorded, when, and by whom, without asking the operator to vouch for the reconstruction.
- **Durable.** The record remains checkable across key rotation, cryptographic migration, vendor turnover, and the service life of the plant.

A sixth property is deliberately excluded. The layer must not become a control path. Evidence flows outward; nothing flows inward. This is a constraint rather than a convenience, because an evidence channel with a write path into plant systems is a new attack surface on safety functions, and the NRC's digital instrumentation and control guidance treats new digital pathways as requiring justification [[10]](#src-10).
These criteria are not new individually, and this paper does not claim them as discoveries. National-laboratory work has treated the assurance burden created by reducing operator involvement as a design input rather than an afterthought: ORNL's concepts for autonomous operation of microreactors [[19]](#src-19) and its companion analysis of licensing challenges associated with autonomous control [[20]](#src-20) are laboratory technical reports rather than regulatory positions, and both frame the difficulty as one of demonstrating behavior rather than of the control concept as such. What this paper adds is the insistence that all five criteria hold at once, and an architecture that attempts it. We have written separately about [what it would take to verify an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely); this paper is the structural version of that argument.

## 3. Defined terms, with attribution
Several words in this paper carry regulatory weight in one field and a different technical meaning in another. The definitions below are taken from the standards that define them, and are attributed on introduction so a reviewer can check the source rather than our paraphrase.

- **Attester.** The entity whose state is being described, which produces evidence about itself. RFC 9334, the RATS architecture [[11]](#src-11). In this architecture the attester is the reactor and its instrumentation.
- **Evidence.** Claims about an attester's state, produced by the attester. RFC 9334 [[11]](#src-11). Evidence is an input to verification, never a conclusion.
- **Verifier.** The entity that appraises evidence against an appraisal policy and produces an attestation result. RFC 9334 [[11]](#src-11). The role is defined as distinct from the attester, which is the property this paper relies on.
- **Attestation result.** The verifier's output, describing what the evidence supports. RFC 9334 [[11]](#src-11).
- **Relying party.** The entity that consumes attestation results in order to make a decision. RFC 9334 [[11]](#src-11). Here: a regulator, insurer, lender, or grid operator.
- **Transparency service.** A service that registers signed statements in an append-only, verifiable log. RFC 9943, the SCITT architecture [[12]](#src-12).
- **Receipt.** A signed proof that a statement was registered in such a log, structured so that a holder can check it. RFC 9943 [[12]](#src-12), with the concrete format specified in RFC 9942 [[13]](#src-13).

One collision deserves flagging, because it causes real confusion in mixed audiences. In the attestation literature, verification means appraisal of evidence against a policy. In nuclear software practice, verification and validation refer to a distinct discipline concerned with whether a system was built correctly and whether the right system was built. These are separate activities and neither substitutes for the other. Where this paper says verification without qualification, it means the RFC 9334 sense [[11]](#src-11).
A second distinction runs through the rest of the paper: attestation by the party being assessed is self-attestation, and self-attestation with a signature is still self-attestation. The signature establishes who made the statement and that it has not been altered since. It establishes nothing about whether the statement is true. We have set out the difference between [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) in more accessible terms elsewhere; the architecture below exists to achieve independent verification rather than to dress self-attestation up as it.

## 4. The reference architecture, component by component
The architecture has five components and one consumer. None is novel. The proposal is the assembly, and the constraint that each component is instantiated by a published standard a reviewer can audit independently.
**Measurement.** Instrumentation produces the state record: power level, temperatures, control element positions, and the status of each safety function. This component is governed by the plant design and by the NRC's guidance on digital instrumentation and control for advanced reactors [[10]](#src-10). It is also the component this architecture does not improve, a point Section 6 returns to. We have described the path from [a sensor reading to a checkable attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) in introductory terms; what follows is the same path stated as a specification.
**Independent appraisal.** A verifier, organizationally separate from the operator, appraises the evidence against an appraisal policy and issues an attestation result [[11]](#src-11). Agreement and disagreement are both recorded. A verifier that records solely the agreements produces an advertisement.
**Signing.** The attestation result is signed with a digital signature scheme standardized by NIST, which approved three post-quantum standards in August 2024 [[14]](#src-14), including FIPS 204, the module-lattice-based digital signature standard [[15]](#src-15). The reason to choose a post-quantum scheme now is not urgency about quantum computers. It is criterion 5: a record that must remain checkable across a plant's service life should not be signed with an algorithm whose assumptions are expected to be revisited within that window.
**Transparency log.** Signed statements are registered in an append-only transparency service as defined by RFC 9943 [[12]](#src-12). The log's value is not storage. It is that a statement cannot be quietly withdrawn or reordered after registration without detection, provided the log is independently witnessed.
**Receipt.** Registration returns a receipt in the format specified by RFC 9942 [[13]](#src-13), which a holder can check against the log's published state. This is the component that satisfies criterion 4, because it lets a party who was absent verify that a specific record existed at a specific point in the log's history.
Component Function here Standard that defines it What it does not establish
Measurement | Produces the reactor state record | Plant design plus NRC digital instrumentation and control guidance [[10]](#src-10) | That the instrument is calibrated, correct, or uncompromised
Independent appraisal | Verifier appraises evidence, issues an attestation result | RFC 9334, RATS architecture [[11]](#src-11) | That the verifier itself is trustworthy
Signing | Binds the result to a key and detects alteration | NIST FIPS 204 [[15]](#src-15), approved August 2024 [[14]](#src-14) | That the signed content is true
Transparency log | Append-only registration of signed statements | RFC 9943, SCITT [[12]](#src-12) | That the log operator is honest absent independent witnesses
Receipt | Portable proof of registration | RFC 9942, COSE receipts [[13]](#src-13) | That the registered claim reflects physical reality
Relying-party check | Regulator, insurer, lender, or grid operator verifies independently | RFC 9334 relying party role [[11]](#src-11) | Any authority to act; authority comes from elsewhere

Read down the fourth column and the architecture's honest shape appears. Each component establishes something narrow. The assembly is stronger than any component, and weaker than the sum a casual reader would assume.

## 5. Mapping the architecture to the regulatory context
The regulatory context is in motion, and this section describes it rather than interpreting it for anyone. The nrc's proposed 10 cfr part 57 rule (proposed, published in the federal register on may 1, 2026, comment period closed june 15, 2026, not final, and no developer is licensed under it) would establish a licensing framework for microreactors and other reactors with comparable risk profiles [[5]](#src-5). Draft guidance for preparing and reviewing applications under that proposed framework was issued as NUREG-2271, a draft for comment and an NRC staff document rather than final guidance [[6]](#src-6). The agency maintains a public summary of its broader microreactor regulatory activities [[7]](#src-7). We have written a plain-language account of [what proposed Part 57 does and does not say about autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained); the point here is narrower.
Two staff papers frame the operational questions. SECY-20-0093, staff analysis and not a Commission position, addressed policy and licensing considerations for micro-reactors including operational programs [[8]](#src-8). SECY-25-0052, likewise a staff paper rather than a Commission decision, addressed nth-of-a-kind microreactor licensing and deployment considerations [[9]](#src-9), which is where the oversight-per-unit question becomes acute: an inspection model calibrated to a small number of large sites does not obviously transfer to a large number of small ones.
If a regulator held receipts of the kind described in Section 4, four checks become available without the operator's cooperation. Whether a record for a given unit and period exists in the log at all. Whether the record presented today matches the record registered then. Whether the verifier that appraised it was the expected party. And whether records are missing for periods when the unit was operating, which is often the more informative question. None of these requires the regulator to trust the operator, the vendor, or us.
Four caveats have to sit alongside that, and we state them because omitting them would misrepresent the position. The rule is proposed and not final: proposed Part 57 (proposed, published May 1, 2026, comment period closed June 15, 2026, not final, no developer licensed under it), so nothing here describes a compliance pathway. The NRC has not been asked to accept this architecture and has accepted nothing about it [[22]](#src-22). The record is an input to inspection, not a replacement for inspection authority, and the resident inspector program [[1]](#src-1) [[2]](#src-2) and the Reactor Oversight Process [[3]](#src-3) remain the regulator's framework rather than something a vendor record displaces. And the operator-at-controls condition in 10 CFR 50.54(m) [[4]](#src-4) is a current, final requirement for the licenses it governs; a verification layer has no bearing on it. Safety-significant actions keep a human in the loop, and nothing in this paper supports a fully autonomous or unmanned operating model.

## 6. Threat and failure analysis
The architecture is tamper-evident, not tamper-proof. It is not unhackable and not unbreakable, and any description of it in those terms is describing something other than this. Tamper-evidence means an alteration made after registration is detectable by a party holding a receipt. It does not mean the alteration is prevented, and it does not mean anyone is watching. Detection without a party whose job is to look is a property nobody exercises.
**Compromised or degraded sensors.** This is the dominant residual risk and the honest weak point. Everything downstream of measurement operates on whatever the instrument reported. A drifted, spoofed, or replayed reading that is faithfully appraised, signed, and logged produces a durable, independently checkable record of something untrue. IAEA guidance on computer security of instrumentation and control systems at nuclear facilities treats the I&C layer as a security domain in its own right [[18]](#src-18), and no amount of downstream cryptography substitutes for that work. Our introductory treatment of [microreactor cybersecurity as an emerging standards space](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained) covers the surrounding landscape.
**The verifier as a trust anchor.** The architecture relocates trust; it does not abolish it. A relying party that accepts an attestation result is trusting the verifier's appraisal policy, key custody, and independence. If the verifier is captured, funded, or staffed by the operator, criterion 3 fails while every cryptographic check still passes, which is the most dangerous failure mode in the set because it looks exactly like success.
**Log operator collusion.** An append-only log is append-only because independent witnesses observe its published state over time. A log whose witnesses are all operated by the same organization as the log provides a weaker guarantee than its structure suggests. RFC 9943 defines the technical role [[12]](#src-12) and RFC 9942 defines the receipt [[13]](#src-13); neither assigns the institutional independence that makes them meaningful.
**Supply chain.** Firmware, signing libraries, and hardware roots of trust reach a plant through a supply chain that is itself an attack surface. NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for systems and organizations [[16]](#src-16); applying them to qualified nuclear instrumentation, where component substitution is constrained by qualification rather than by procurement preference, is unresolved work.
**Cryptographic transition and availability.** FIPS 204 [[15]](#src-15) is standardized, but a record checkable for decades will outlive at least one migration, and migration of a signed historical corpus is an operational problem no standard solves. Separately, the evidence path must be allowed to fail without consequence to the plant. If loss of the verification channel can influence operations, the channel has become a control path, which Section 2 excluded by design.

## 7. Precedent in adjacent domains
The structural precedent is international safeguards. IAEA safeguards rest on independent verification of a state's declarations by a body outside that state, using the agency's own inspections, instruments, containment and surveillance measures, and analysis [[17]](#src-17). The relevant feature for this paper is not the technology. It is the institutional shape: the party making the declaration and the party verifying it are separate by design, the verifier maintains its own measurement capability rather than relying entirely on the declarant's, and the resulting conclusions are drawn by the verifier rather than negotiated with the declarant.
The analogy has limits that must be stated, because safeguards specialists will notice them immediately. Safeguards address nuclear material accountancy for non-proliferation purposes under a distinct legal basis; they are not an operational safety oversight regime, and conclusions drawn under safeguards say nothing about whether a plant is operating safely [[17]](#src-17). The architecture proposed here borrows the institutional shape and none of the legal authority. Conflating the two would be a serious error, and we are not proposing that a commercial verification record discharges any safeguards obligation.
The technical precedent sits in computing. Remote attestation formalises exactly the separation described above: an attester produces evidence about itself, a verifier appraises it, and a relying party consumes the result, with the roles specified so they can be held by different organizations [[11]](#src-11). Supply chain transparency work extends this to durable records, defining a transparency service that registers signed statements in an append-only log [[12]](#src-12) and receipts that let a holder check registration [[13]](#src-13). Those specifications were written for software supply chains, where the problem is structurally similar: a producer makes claims about an artefact, and consumers downstream need a basis for those claims that does not reduce to trusting the producer.
What neither precedent supplies is the nuclear-specific part. Safeguards practice has institutional independence and physical measurement but was not designed for continuous operational state. The attestation specifications have the record structure but assume a computing environment where the attesting device can hold a hardware root of trust, which qualified reactor instrumentation generally cannot [[18]](#src-18). The gap between them is where the engineering work actually sits, and this paper does not close it.

## 8. Applying the framework to RankShield Energy
A paper proposing a verification architecture should apply it to its author, and the result should be unflattering if it is honest. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC [[22]](#src-22). We hold no license, permit, or design approval. No aspect of the HELIX microreactor has been demonstrated to or accepted by the NRC. Everything in the preceding sections is analysis and design intent, not capability.
Measured against the five criteria in Section 2, our position is as follows. Criterion 1, per-unit evidence: we have a design intent and no operating unit, so this is untested. Criterion 2, comparability: unmet in any meaningful sense, because comparability across vendors requires a schema the industry does not have and cannot be created by one participant. Criterion 3, independence of the operator: this is the one we are furthest from. A verifier organizationally distinct from the operator does not exist for our design, and standing one up is an institutional problem rather than a technical one.
Criterion 4, checkability after the fact: partially addressed in prototype form and materially weaker than this paper's specification. Our current transparency logging arrangement does not yet provide the third-party verifiability the architecture requires, and the witnesses observing our log are not independent of us. We state this plainly because a reader who assumed otherwise from the preceding sections would have been misled by our omission. Criterion 5, durability: post-quantum signing is design intent [[14]](#src-14) [[15]](#src-15), and we have not exercised a migration of a signed historical corpus.
Two further gaps deserve naming. We have no sensor-level attestation, which means the dominant residual risk identified in Section 6 applies to our design with full force [[18]](#src-18). And our supply chain practices have not been assessed against NIST SP 800-161r1 [[16]](#src-16) in the form that a qualified instrumentation program would require.
The reason to publish an architecture we do not yet satisfy is that the alternative is worse. Verification designed after a fleet is deployed is verification bolted on, and bolted-on evidence is precisely the kind an outside party has least reason to trust. Publishing the specification before we meet it also creates a record against which we can be held, which is the property this paper argues reactor operations should have. The criteria in Section 2 are offered for use by anyone, including parties assessing us, and we would rather be measured against a written standard than against our own description of our progress.

## Frequently asked questions

### What problem does this reference architecture actually solve?
It addresses a narrow and specific gap: when on-site presence is reduced, the evidence reaching an outside reviewer is produced, transported, and stored by the party being reviewed. The architecture separates the entity whose state is described from the entity that appraises the description, then makes the appraisal durable and re-checkable by a party who was absent. It does not make a reactor safer, does not evaluate safety, and does not substitute for inspection. It changes who has to be trusted for an operational record to carry weight, and it narrows that set to parties a reviewer can name.

### Why use published standards rather than a purpose-built scheme?
Three reasons. A reviewer can audit the design against documents that no party to the transaction controls, which is the point of citing specifications rather than describing a product. The standards have been reviewed by communities larger than any single vendor engineering team, so their failure modes are documented. And a scheme defined by the party being verified is structurally the thing this architecture exists to avoid. The cost is that none of the standards was written for nuclear instrumentation, so the adaptation work, particularly at the measurement layer, remains genuinely open.

### Does this mean a reactor could operate without people?
No, and nothing in this paper supports that reading. The proposed Part 57 rule, which was published May 1, 2026, whose comment period closed June 15, 2026, which is not final and under which no developer is licensed, contemplates remote operation and reduced on-site staffing with a human in the loop for safety-significant actions. The architecture described here carries evidence outward and exercises no control function. It is deliberately excluded from any control path, because an evidence channel with a write path into plant systems would be a new attack surface on safety functions.

### Has the NRC accepted any part of this?
No. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC. It holds no license, permit, or design approval, and no design, product, facility, or operational characteristic has been demonstrated to or accepted by the NRC. The regulatory sections of this paper describe the agency's published framework and staff and contractor analysis; they do not describe a compliance pathway, an agreement, or an expectation of one. Whether such records would be accepted as inspection evidence is listed in the open questions as a matter we cannot answer.

### What is the weakest part of the architecture?
Measurement. Every component downstream operates on whatever the instrument reported, so a drifted, spoofed, or replayed reading that is faithfully appraised, signed, and logged yields a durable and independently checkable record of something untrue. Commercial hardware roots of trust are not qualified for the radiation and temperature conditions in which reactor instrumentation operates, so attestation at the measurement point is not currently available. Until that changes, the architecture verifies the handling of a measurement rather than the measurement itself, and any claim beyond that overstates it.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg.html)
- [U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description/resident-insp-program.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper). October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper). June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 2024](https://csrc.nist.gov/pubs/fips/204/final)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811-concepts-autonomous-operation-microreactors)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- Would the NRC accept cryptographically attested operational records as inspection evidence, and under what conditions? **We cannot answer this.** It is a determination for the Commission and its staff, informed by a docket that does not yet contain such a proposal. No part of this architecture has been submitted to, demonstrated to, or accepted by the NRC [[22]](#src-22), and this paper should not be read as predicting the outcome.
- What will the final Part 57 rule require of remote and reduced-staffing operating models? The rule remains proposed: published May 1, 2026, comment period closed June 15, 2026, not final, and no developer is licensed under it [[5]](#src-5). Draft guidance in NUREG-2271, an NRC staff draft issued for comment rather than final guidance, indicates the direction of staff thinking but settles nothing [[6]](#src-6).
- Where should the signing boundary sit relative to safety-related instrumentation and control? Signing closer to the sensor narrows the trust gap but introduces digital capability nearer to safety functions, which the NRC's digital instrumentation and control guidance treats as a question requiring justification [[10]](#src-10). We have no general answer and suspect the answer is design-specific.
- How is sensor-level attestation achieved in a radiation and high-temperature environment? Commercial secure elements and trusted platform modules are not qualified for the conditions in which reactor instrumentation operates. Without attestation at the measurement point, the architecture in Section 4 verifies the handling of a measurement rather than the measurement itself [[18]](#src-18).
- Who operates a transparency service for reactor evidence, who witnesses it, and under what legal duty? RFC 9943 defines the technical role of a transparency service [[12]](#src-12) and RFC 9942 defines receipts that prove registration [[13]](#src-13), but neither assigns institutional responsibility. An operator-run log with operator-run witnesses reproduces the problem the architecture exists to solve.
- How does the record survive a cryptographic transition across a plant's service life? NIST approved three post-quantum standards in August 2024 [[14]](#src-14), including the module-lattice signature standard [[15]](#src-15), but a record that must be checkable decades after it was written will outlive at least one migration, and long-term key custody is an operational problem no standard resolves.
- How would a commercial verification record interact with international safeguards obligations? IAEA safeguards rest on independent verification of state declarations under a distinct legal basis [[17]](#src-17), and a vendor-produced operational record is neither a substitute for nor obviously separable from that regime for exported units.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [From reactor state sensors to an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [NRC Part 57 and autonomous operation →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Fleet-scale verification: one operator, many reactors →](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of NRC microreactor rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change; Part 57 was published as a proposed rule on May 1, 2026, its comment period closed June 15, 2026, and no developer is licensed under it. This paper is technical analysis and is not legal or regulatory advice.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors/

# Self-Attestation vs Independent Reactor Verification

> When a reactor reports its own status, who checks the check? Compare self-attestation and independent verification for autonomous and remote reactor operations.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# Self-Attestation vs Independent Verification for Autonomous Reactors
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Self-attestation is a reactor reporting on itself: the operator runs the reactor and also produces the account of how it is behaving. Independent verification adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer. Both can be accurate. Only one is checkable by anyone else.
The distinction sounds academic until presence is removed. Today the NRC keeps roughly 150 resident inspectors in the field, at least two per plant, whose stated role is independently verifying that requirements are being met [[1]](#src-1). A design premised on reduced on-site staffing removes that layer, and what replaces it determines whether an outside party can establish anything at all.
This article sets out the difference, three structural tests that separate the two models, how two adjacent fields already solved the same problem, what independence has to mean concretely, and why autonomy converts this from good practice into a requirement. RankShield Energy is a pre-applicant holding no license or approval [[20]](#src-20), and the last section applies the argument to us.
Key takeaways

- Self-attestation is the operator vouching for itself; independent verification adds a party with no stake in the answer.
- The useful test: if the operator went silent, what could an outsider still establish about last month?
- Independence is structural and testable: who signs, who can alter it, and what an outsider can check unaided.
- IAEA safeguards and the internet's attestation standards both solved this by putting the checker outside the checked.
- As on-site presence thins, more of the safety story rests on self-report, which makes independent confirmation more load-bearing, not less.

## The distinction, stated as plainly as possible
**Self-attestation** is a system reporting on itself. The operator runs the reactor and also produces the account of how the reactor is behaving. **Independent verification** adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer.
Both can be accurate. The difference is not honesty, and framing it as a trust problem about vendors misses the point. The difference is what an outside party is able to establish for themselves.
A useful test: if the operating organization went silent tomorrow, what would a regulator, insurer, or lender still be able to determine about what the reactor did last month? Under self-attestation the answer is roughly nothing, because every artifact traces back to the party being evaluated. Under independent verification the answer is bounded but real.
That gap is the entire subject of this article, and it becomes load-bearing precisely when people stop being physically present.
One clarification before going further, because it is the most common misreading of this argument. Nothing here implies that operators are untrustworthy or that vendor engineering is weak. The claim is narrower and structural: a party cannot supply the independence of its own account, however competent or honest it is. That is a property of the arrangement rather than a judgment about the people inside it.

## Why self-monitoring is necessary but never sufficient
Nothing here argues against operator monitoring. A reactor cannot be run without it, and a vendor with excellent internal instrumentation is in better shape than one without. Self-monitoring detects the large majority of problems, and it detects them fastest.
What it cannot do, by construction, is catch the class of problem where the reporting path itself is the thing that is wrong. If a model is miscalibrated, a sensor drifts, or a reporting chain is compromised, the dashboard can look healthy while the underlying picture is not. There is no second party positioned to notice the discrepancy, because the only observer is the one being observed.
This is not a hypothetical failure mode invented for marketing purposes. It is the ordinary reason auditors exist in every other high-consequence domain, and the reason no serious institution accepts a self-certified financial statement as equivalent to an audited one.
Nuclear has historically solved it with people. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, and describes their function as independently verifying that requirements are being met [[1]](#src-1). That word "independently" is doing specific work in that sentence. The inspector is not a better observer than the operator. The inspector is a differently positioned one.

## Three tests that separate the two models
Independence is not a matter of intentions, and it cannot be established by assertion. It is structural, and it can be tested with three questions that a buyer can ask in a meeting.

Self-attestation and independent verification, compared across three structural tests

Test
Self-attestation
Independent verification

Who signs the record?
The operator, or its software
A party separate from operations

Who can alter or withdraw it?
The same party that produced it
No one silently; changes are detectable

What can an outsider check unaided?
Only what the operator chooses to show
The signature, the log, and the inclusion proof

Failure mode
Undetectable divergence between claim and reality
Detectable, with a record of when detection occurred

The second row is where most systems marketed as verification actually fail. Logs that the operator can rewrite are not evidence, however well formatted. The property that matters is not that a record cannot be changed, but that it cannot be changed quietly.
The third row is the one buyers should press hardest, because it is answerable with a demonstration rather than a description. Ask what an outside party can check without the vendor participating. If the answer requires the vendor to hand something over or vouch for something, the separation is nominal.

## How other high-consequence fields already solved this
Nuclear contains the precedent already, in a different problem domain. The IAEA safeguards system exists so that an outside body applies technical measures through which it can independently verify that facilities are not misused, rather than relying on a state or operator assertion [[2]](#src-2). Safeguards address non-proliferation rather than operational safety, so do not overread the analogy. But the structural insight is identical: for a claim that matters enough, the verifying party is placed outside the party being verified.
Computing formalized the same split and standardized it. RFC 9334 defines an architecture with an Attester that produces evidence, a Verifier that appraises it against an appraisal policy, and a Relying Party that acts on the Verifier's result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[3]](#src-3).
The reason that architecture exists is worth noting: the industry that most wanted self-attestation to be sufficient concluded, after trying, that it was not. Remote attestation was developed precisely because a machine's own claim about its state is not usable by a party that has reason to care.
So the model this article argues for is not novel and we are not claiming to have invented it. It is a settled pattern in two adjacent fields, and the contribution is applying it to reactor operations, which is what [verifying an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) actually requires.

## What independence has to mean in practice
Vendors will describe many things as independent. Four properties are worth insisting on, because each closes a specific loophole.
**Separation of function.** The party appraising reactor state is not the party operating the reactor. Not a different team inside the same organization with the same incentives, and not a subsidiary whose budget depends on favorable results.
**Completeness of the record.** Disagreement is recorded as faithfully as agreement. A system that only writes a record when everything matches is not verifying, it is publishing.
**Durability.** The record survives the equipment and the vendor. This is why signature choices matter for records intended to outlive a reactor design cycle, and why NIST approving post-quantum signature standards in August 2024 is relevant to a nuclear conversation at all [[4]](#src-4).
**Checkability without cooperation.** A third party can verify the record later without asking the operator for help. That is exactly what an append-only transparency service with issued receipts provides [[5]](#src-5), using receipts standardized as compact cryptographic proofs of inclusion and consistency [[6]](#src-6). Assurance over the components involved sits under established federal supply-chain guidance [[7]](#src-7).

## Why autonomy moves this from good practice to necessity
For a staffed plant, weak evidence is partly compensated by presence. An inspector on site can form a judgment that instrumentation missed, inside an oversight process built on inspection findings and performance indicators [[8]](#src-8). The GAO has described NRC safety assurance as resting on exactly that monitoring and inspection of the most safety-significant activities [[9]](#src-9).
Remove or thin that presence and the compensation goes with it. Proposed Part 57 contemplates remote operation and reduced on-site staffing [[10]](#src-10), against a current requirement that a licensed operator be present at the controls at all times [[11]](#src-11). NRC staff have separately proposed operational-phase oversight built on a scalable inspection footprint [[12]](#src-12).
The national laboratories have been explicit about what this disturbs. Oak Ridge found autonomous control reaches past staffing into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications, with the control room possibly not co-located with the plant [[13]](#src-13). Sandia, working for the NRC, described designs where one control room supervises multiple microreactors [[14]](#src-14). Brookhaven, also for the NRC, framed the safety question for facilities without main control rooms as verifying that important human actions can be accurately and reliably performed [[15]](#src-15).
Put together: as presence decreases, the share of the safety story carried by self-report increases. Independent verification is what stops that curve from ending somewhere uncomfortable, and it is why the [fleet-scale version](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors) of this problem is harder still.
There is a fair objection to all of this, and it deserves a direct answer rather than being skipped. Independent verification adds cost, adds a party, and adds latency to a system that already carries heavy regulatory overhead. For a single well-run reactor with inspectors on site, a reasonable person can argue the marginal benefit is small relative to that burden.
We think that argument is correct for exactly the case it describes, and stops being correct as soon as the model changes. The value of independence scales with two things: how consequential the claim is, and how difficult it is for an outsider to check by other means. A staffed plant with regular inspection scores low on the second. A remotely operated unit inspected on a scalable footprint scores high on both. So the cost stays roughly constant while the benefit grows, which is the opposite of the usual argument for skipping an audit layer.
The other consideration is timing. Verification designed after deployment tends to be verification bolted on, and bolted-on evidence is the kind an outside party has least reason to trust, because the system was not built to produce it. Doing it late is not merely more expensive. It produces a weaker artifact.

## What this looks like applied to reactor state
Concretely, the chain has four steps. Reactor state is measured. An independent party appraises the measurements against what the operator reports and what the design permits. The appraisal is signed and written to an append-only log that returns a receipt. Later, a third party checks the receipt and the signature without needing the operator's cooperation. That is the sequence we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).
The engineering preconditions are not trivial and the labs have named them: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring [[16]](#src-16). Guidance on protecting reactor instrumentation and control across its life cycle exists internationally [[17]](#src-17), and the IAEA has an active research project on computer security for small modular and microreactors that names autonomous and remote operations and centralised fleet management with reduced staffing as the conditions to address [[18]](#src-18).
Capability on the operations side is real and demonstrated. DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[19]](#src-19). The verification side is where the field is thinner, which is the honest asymmetry in this whole discussion.

## Where we actually are, including us
No commercial microreactor fleet operates today, so no fleet operates under continuous independent verification either. Proposed Part 57 is a proposal whose comment period has closed and under which no developer is licensed [[10]](#src-10). Anyone presenting independent verification of reactor state as a deployed, proven capability is describing an intention.
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[20]](#src-20). Verifier-operator separation is the architecture we build toward and the reason this site exists. It is not a certified capability, and we do not present it as one.
Our position, stated so it can be argued with: a vendor cannot be its own independent verifier, and this remains true of us. It is why we treat the separation as structural rather than as a feature to be added later, and the tradeoff is genuine. A separate verifier costs more, adds a party to coordinate with, and creates a body that can contradict us in public. We think that last property is the point rather than a defect.
If you are evaluating developers on this, the questions are in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.

## Frequently asked questions

### Is a vendor monitoring its own reactor the same as independent verification?
No. Monitoring is the operator observing its own plant, which is necessary for running it. Independent verification adds a party structurally separate from the operator that appraises those reports and records the result. The difference is not about vendor honesty. It is that under self-attestation every artifact traces back to the party being evaluated, so an outside reviewer has nothing to rely on that does not depend on that party. Nuclear has traditionally supplied this separation with resident inspectors whose stated role is independently verifying that requirements are being met [[1]](#src-1).

### What makes verification genuinely independent?
Four properties, each closing a loophole. Separation of function, meaning the appraising party is not the operating party and not a team with the same incentives. Completeness, meaning disagreement is recorded as faithfully as agreement. Durability, meaning the record outlives the equipment and the vendor. And checkability without cooperation, meaning a third party can verify the record later without asking the operator for anything. If any one is missing, independence is nominal rather than structural.

### Has any other industry actually solved this?
Two have, in different ways. IAEA safeguards place verification with an outside body that applies its own technical measures rather than relying on operator assertion [[2]](#src-2). Computing standardized it in RFC 9334, separating the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [[3]](#src-3). Notably, remote attestation was developed because the industry that most wanted self-attestation to be sufficient found that it was not.

### Why does autonomy make this more important rather than less?
Because presence was silently doing part of the work. With staff and inspectors on site, weak evidence is partly compensated by human judgment inside an inspection-based oversight process [[8]](#src-8). Proposed Part 57 contemplates remote operation and reduced staffing [[10]](#src-10), and NRC staff have proposed a scalable inspection footprint for operational oversight [[12]](#src-12). As presence decreases, the share of the safety story resting on self-report increases, which makes independent confirmation more load-bearing, not less.

### Does RankShield Energy have independent verification today?
No, not as a deployed or certified capability. We are a pre-applicant with the NRC holding no license, permit, or design approval [[20]](#src-20). Verifier-operator separation is the architecture we build toward and our reason for existing, but describing an architecture is not the same as having demonstrated it under regulatory review. We would rather say that plainly than let the distinction blur, since the distinction is the entire argument we are making.

## Sources

- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [From sensors to an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [How RankShield approaches verification →](https://rankshieldenergy.com/technology)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of reactor verification concepts and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear/

# Speed-to-Power: Data Centers and Firm Nuclear Power

> US data-center load is climbing while interconnection queues stretch. See what firm power actually requires and where advanced nuclear fits on the timeline.

[Resources](https://rankshieldenergy.com/resources) / Deployment Deployment

# Speed-to-Power for Data Centers: Where Firm Nuclear Fits
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Speed-to-power is the time from choosing a data center site to having firm, around-the-clock electricity available to energize the load. It has become the governing variable in site selection because electricity demand from data centers is rising faster than the grid can connect new load. The useful question is not which source looks best in the abstract. It is what can actually be energized, and when.
The demand side is documented and the supply side is constrained by process. Lawrence Berkeley National Laboratory reported that U.S. data centers used about 176 TWh in 2023, roughly 4.4% of U.S. electricity, with a projected range of 325 to 580 TWh by 2028, or about 6.7% to 12.0% [[1]](#src-1), and the Department of Energy released that assessment as an evaluation of rising data center demand [[2]](#src-2). EIA now forecasts the strongest four-year growth in U.S. electricity demand since 2000, attributed substantially to data centers [[3]](#src-3). Meanwhile NERC reports that 13 of 23 assessment areas face resource adequacy challenges over the next decade [[9]](#src-9). Load is arriving faster than firm supply is being connected.
One scope note before anything else. This article does not compare what any option costs. There are no unit-cost figures here, no energy-rate figures, and no ranking of the options by expense, because cost is a separate analysis with its own assumptions and it is deliberately out of scope for this piece. What follows compares three things only: time to power, firmness, and the constraint that actually governs each route. RankShield Energy is a pre-applicant with the U.S. Nuclear Regulatory Commission, holding no license, permit, or design approval [[15]](#src-15), and the closing section states our position on this timeline as plainly as we can.
Key takeaways

- Speed-to-power, not resource selection in the abstract, is the variable that decides where and when a large data center can be built.
- LBNL put U.S. data center use at about 176 TWh in 2023, roughly 4.4% of U.S. electricity, with a projected 325 to 580 TWh by 2028 [[1]](#src-1).
- The interconnection process is the first gate. LBNL reports a median above four years from request to commercial operation for generation projects completed 2018 to 2024, which describes completed projects rather than the current queue [[6]](#src-6).
- Firmness is not the same as capacity factor. EIA reports 2025 factors of 91.0% for nuclear, 58.4% for gas combined cycle, 34.2% for wind, and 24.4% for solar photovoltaic, and the gas figure reflects dispatch rather than availability [[11]](#src-11) [[12]](#src-12).
- Advanced nuclear is a 2030s option gated by licensing progress and fuel supply rather than by physics, and this article makes no claim that it is faster than any other route.

## Data center electricity demand is growing faster than new firm supply is being connected
The demand side is the least ambiguous part of this discussion. Lawrence Berkeley National Laboratory reported that United States data centers used about 176 TWh in 2023, roughly 4.4% of total U.S. electricity consumption, and projected a range of 325 to 580 TWh by 2028, or roughly 6.7% to 12.0% of national consumption [[1]](#src-1). The Department of Energy released that report and framed it as an evaluation of the increase in electricity demand coming from data centers [[2]](#src-2).
The federal forecasting picture points the same direction. EIA has stated that it expects the strongest four-year growth in U.S. electricity demand since 2000, and attributes that growth substantially to data centers [[3]](#src-3). The Annual Energy Outlook 2026 carries the same demand growth into EIA's long-term projections [[4]](#src-4).
The near-term supply response is worth noticing because it is not what most site plans assume. EIA has written that fossil generation could rise if data center power demand grows faster than expected [[5]](#src-5). In other words, the first answer to a demand surge is usually existing dispatchable units running more hours, not new plants of any kind arriving on the schedule the load wants.
One honest observation about that LBNL range: 325 to 580 TWh is close to a factor of two. Anyone building a campus around a single point estimate inside that band is planning against a number the source itself declined to give. The useful way to read it is as a statement that demand growth is large and its magnitude is genuinely uncertain, which argues for supply arrangements that can be staged rather than committed all at once.

## Interconnection timing, not generation capacity, is the first thing that gates a new large load
The bottleneck most buyers hit first is procedural. Lawrence Berkeley National Laboratory's Queued Up analysis reports a median duration of more than four years from interconnection request to commercial operation [[6]](#src-6). That figure has to be stated precisely to be useful: it describes projects that were completed between 2018 and 2024. It is not a statement about how long projects currently sitting in the queue will take, and it says nothing about requests that were withdrawn without ever reaching operation. Read it as evidence that the process has been slow for the projects that finished, not as a forecast for the project you are contemplating.
Reform is underway and is itself a multi-year process. FERC issued Order No. 2023 to improve generator interconnection procedures and agreements [[7]](#src-7), and the practical effect on any given region depends on how each transmission provider implements it through compliance filings and how the resulting study cycles run. A rule that improves a queue does not clear a queue.
Underneath the queue sits physical transmission. The Department of Energy's National Transmission Needs Study documents where the system needs additional transfer capability [[8]](#src-8). Transmission is the slowest element in the chain and the one least responsive to a single buyer's urgency.
There is a distinction worth drawing that often gets blurred in coverage of this topic. The queue statistics above describe generator interconnection. A data center is a load, and large load interconnection runs through its own studies and its own utility or regional processes. The two are related, because a new load frequently depends on new generation and new transmission being connected as well, but they are not the same process. When a developer quotes you a queue number, ask which queue.

## Firm means available around the clock, and capacity factor is the closest public measure of it
Firm power is electricity that is available when it is called for, around the clock, without depending on weather or time of day. A data center running training and inference workloads has a load shape that is close to flat and close to continuous, which is why firmness rather than annual energy volume is the property that governs procurement.
The most accessible public evidence on how different resources actually perform is EIA's capacity factor reporting. For 2025, EIA reports nuclear at 91.0%, wind at 34.2%, and solar photovoltaic at 24.4% [[11]](#src-11), and natural gas combined cycle at 58.4% [[12]](#src-12).
Those four numbers are frequently misused, so here is the qualification that belongs with them. Capacity factor is actual output divided by output at continuous full power. It blends two very different things: whether a unit was available, and whether it was called to run. The nuclear and renewable figures are dominated by availability and resource. The combined cycle figure is dominated by dispatch, meaning market conditions and system need determined how many hours those units ran. Nothing in the 58.4% figure implies that a gas unit could not have run more. Treating it as a firmness ceiling would be a misreading, and this article does not do that.
For a buyer, the operational definition of firm is narrower than the statistic: the capacity is available, the fuel or energy source is secured, and the dispatch right belongs to you or to a counterparty obligated to serve you. Several routes in the comparison below can satisfy that definition. They differ on what stands between the decision and the energized load, which is the only axis this article ranks them on.

## Resource adequacy is tightening at the same time the load is arriving
The system this load is joining is already under study for adequacy. NERC's 2025 Long-Term Reliability Assessment identifies 13 of 23 assessment areas as facing resource adequacy challenges over the ten-year assessment period, and reports that new data centers account for most of the projected increase in demand [[9]](#src-9).
The Department of Energy's July 2025 report on grid reliability and security supplies the capacity arithmetic behind that concern. DOE states that 104 GW of firm capacity is scheduled to retire by 2030, that 209 GW of new generation is planned over that period, and that only 22 GW of the planned additions is firm baseload [[10]](#src-10). Those are DOE's figures and DOE's definitions of firm and baseload, and they are cited here as that agency's characterization rather than as an independent finding.
The near-term consequence follows from the same arithmetic. EIA has noted that fossil generation could rise if data center demand grows faster than expected [[5]](#src-5), which is what happens when new firm additions do not keep pace with retirements and new load in the same window.
What this means for a specific project is less dramatic than the headline numbers suggest, but it is more binding. An interconnection request for several hundred megawatts of new load does not arrive in a neutral system. It arrives in a planning process that is already tracking a firm capacity gap, and that context shapes how long the studies take, what upgrades get assigned, and what conditions come attached. The adequacy picture is not background color for this topic. It is part of the schedule.

## Co-location is a partial workaround, and its limits are being worked out in public
Because the queue is the bottleneck, the obvious move is to sit next to generation that is already connected. Co-location places the load beside an existing plant and reduces or avoids the need for new transmission service to reach it. It is a real strategy, it is being pursued seriously, and it is the reason several announced projects have timelines that would be implausible through a standard interconnection path.
It also introduces questions the industry has not finished answering. NERC published a white paper on the characteristics and risks of emerging large loads that treats these loads as behaving differently from conventional load, with characteristics that need to be understood and modeled rather than assumed [[13]](#src-13). That is a reliability question independent of who supplies the electricity, and it applies to a co-located load as much as to a grid-connected one.
The commercial and regulatory terms are equally unsettled. FERC has an open proceeding on co-location at PJM under Docket Nos. EL25-49-000 and related dockets [[14]](#src-14). The questions in front of the Commission include how a large load sitting behind or beside an existing generator should be treated for purposes of transmission service and cost allocation to other customers. This article takes no position on the outcome and does not assume one.
The honest summary is that co-location can shorten one path while opening another. It converts a queue and transmission problem into a regulatory and reliability question that is currently being adjudicated. For a buyer, that means a co-location strategy carries schedule risk of a different kind rather than no schedule risk, and the risk is harder to estimate because the governing rules are still being written.

## Advanced nuclear is a 2030s answer gated by licensing and fuel, not by physics
A [microreactor](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor) is small enough to be factory-built and sited near the load it serves, and it is designed to deliver firm baseload output continuously. The reason it is not a near-term answer has nothing to do with whether the physics works. It has to do with two gates that both take years.
The first gate is licensing. The NRC's risk-informed, technology-inclusive framework for advanced reactors, 10 CFR Part 53, was published in the Federal Register on March 30, 2026 and took effect in April 2026 [[15]](#src-15). A framework existing is not the same as a license being issued under it. A developer still moves through [pre-application engagement](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained), then an application, then review. The NRC has separately proposed Part 57 for microreactors, which is a proposed rule and not final, and which we cover in [a separate article](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The second gate is fuel. Most designs in this class need HALEU, and a commercial domestic supply chain for it is still being established. We set out where that fuel comes from, and the primary sources for it, in [our guide to HALEU supply](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel). For scheduling purposes the point is simply that fuel availability is a first-order input to any deployment date, not a detail to resolve later.
On timing, the most defensible public characterization comes from the program itself. The Idaho National Laboratory and DOE microreactor program plan describes the program as focused on designs that could be deployed as early as the late 2020s [[16]](#src-16). That is INL and DOE's characterization of a research and development program, not a delivery commitment from any vendor, and it should not be read as a schedule any specific buyer can procure against. This article makes no claim that advanced nuclear is faster than any other route on this list. For a load that needs energizing in the next two or three years, it is not the route to plan around.

## Firm-power routes, compared by what they deliver and what gates the timing
The table below compares six routes on two questions only: whether the route delivers firm 24/7 output, and what actually governs when it can be energized. There is no cost column, and no cost comparison is implied anywhere in it. Where a cell can be supported by one of the sources cited in this article, the citation is in the cell. Where it cannot, the cell is qualitative and says so, because filling a comparison table with confident numbers that have no primary source is how these comparisons usually go wrong.

Firm-power routes for a large data center load, compared by whether they deliver firm 24/7 output and by the primary constraint on timing. This table contains no comparison of cost.

Route
Delivers firm 24/7
Primary constraint on timing

New grid interconnection for a large load
Yes, once the connection is energized
Interconnection and transmission timing. LBNL reports a median of more than four years from interconnection request to commercial operation for generation projects that were completed between 2018 and 2024 [[6]](#src-6), and the FERC Order No. 2023 reforms are still being implemented through compliance filings [[7]](#src-7).

New on-site or adjacent gas generation
Yes, when fueled and dispatched
Permitting, air authorization, fuel delivery arrangements, and equipment lead times. Stated qualitatively because no figure in the cited set covers equipment delivery. EIA reports the natural gas combined cycle fleet at a 58.4% capacity factor in 2025, which reflects how often units were dispatched rather than a limit on their availability [[12]](#src-12).

Co-location beside an existing generator
Yes, subject to the terms of the arrangement
Unsettled regulatory questions. The terms are before FERC in the PJM co-location proceeding [[14]](#src-14), and NERC has documented reliability characteristics of emerging large loads that bear on how such arrangements are studied [[13]](#src-13).

Wind or solar paired with storage
Not firm on its own. Firmness depends on how storage is sized and operated
Resource availability plus the same interconnection process. EIA reports 2025 capacity factors of 34.2% for wind and 24.4% for solar photovoltaic [[11]](#src-11).

Existing nuclear capacity, through contracts or uprates
Yes. EIA reports the U.S. nuclear fleet at a 91.0% capacity factor in 2025 [[11]](#src-11)
Bounded by the units that already exist and by what is contractually available. Stated qualitatively.

Advanced nuclear, microreactor class
Firm baseload as designed. Not demonstrated in commercial service
Licensing stage and fuel supply. The Part 53 framework was published in the Federal Register on March 30, 2026 and took effect in April 2026 [[15]](#src-15). INL and DOE characterize the program as focused on designs that could be deployed as early as the late 2020s [[16]](#src-16), which is a program characterization rather than a delivery commitment.

*Reading notes. The four-year median in row one applies to generation projects completed between 2018 and 2024 [[6]](#src-6) and is not a prediction for any project now in a queue. Capacity factor figures describe fleet-wide 2025 performance and blend availability with dispatch, so they are not a ranking of reliability [[11]](#src-11) [[12]](#src-12). Rows two and five are deliberately qualitative because the cited sources do not carry equipment lead time or contract availability figures. Nothing in this table compares what any route costs, and nothing in it should be read as a claim that one route is faster than another in the general case, because the binding constraint is site-specific.*
The pattern that emerges is not that one route wins. It is that every route is gated by something procedural or physical rather than by the availability of the technology itself. Interconnection is gated by studies and upgrades. Gas is gated by permitting and equipment. Co-location is gated by an open regulatory question. Advanced nuclear is gated by licensing progress and fuel. A buyer who knows which gate applies to their site is in a much better position than one comparing headline lead times across regions that share almost no relevant conditions.

## What a buyer should actually do, and where RankShield Energy stands
The first action is unglamorous and often deferred: enter the applicable interconnection or large load study process, and find out which study cycle you are in and what upgrades are provisionally assigned to you. Everything else on the schedule is downstream of that answer. The second is to define firm in the contractual sense rather than the marketing sense, meaning availability, secured fuel or energy source, and a dispatch right that belongs to you. The third is to stage supply rather than commit it all at once, which is the reasonable response to a demand projection whose authors published a range spanning nearly a factor of two [[1]](#src-1) and to an adequacy picture federal assessments describe as tightening [[9]](#src-9) [[10]](#src-10).
For the portion of demand that lands in the 2030s, the evaluation questions shift from queue mechanics to developer diligence. Ask about licensing path and fuel path in the same conversation, because a project can be on schedule on one and stalled on the other. We set those questions out in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and the harder version of the problem, how anyone confirms what many units are doing across many sites, is in our piece on [fleet-scale verification](https://rankshieldenergy.com/resources/fleet-scale-verification-one-operator-many-reactors).
Our own status, stated plainly so it cannot be misread. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the NRC. We hold no license, no permit, and no design approval. Nothing about our design has been demonstrated to or accepted by the NRC. We have never operated a reactor and we operate no fleet. We are not offering firm power to any buyer on any date, and this article is not an offer of supply.
The reason we write about speed-to-power at all is that its honest framing is also the framing that disciplines us. If the question is what can actually be energized and when, the answer for advanced nuclear is governed by licensing progress and fuel availability, both visible, both slow, and neither improved by a vendor claiming otherwise. Our working domain is the verification and attestation layer around reactor operations rather than the reactor itself. The tradeoff we accept in saying all of this is a timeline that sounds less exciting than one from a competitor willing to quote a date, and a buyer planning a multi-hundred-megawatt campus is better served by the version that holds up.

## Frequently asked questions

### How long does it take to get firm power to a new data center site?
It depends on the route and the site, and the most defensible public anchor is narrower than it is often quoted as being. Lawrence Berkeley National Laboratory reports a median of more than four years from interconnection request to commercial operation for generation projects completed between 2018 and 2024 [[6]](#src-6). That describes completed projects, not projects currently waiting and not requests that were withdrawn, so it is evidence about how the process has behaved rather than a forecast for a new request. FERC Order No. 2023 is intended to improve those procedures, and its effect in any region depends on how each transmission provider implements it [[7]](#src-7). Underlying transfer capability is documented in DOE's National Transmission Needs Study [[8]](#src-8). The practical answer for a specific site comes from entering the study process and learning which cycle you are in.

### What does firm power mean, and does capacity factor measure it?
Firm power is electricity available on demand around the clock, independent of weather or time of day, which matches the near-continuous load shape of an AI data center. Capacity factor is the closest public proxy but it is not the same thing. EIA reports 2025 capacity factors of 91.0% for nuclear, 34.2% for wind, and 24.4% for solar photovoltaic [[11]](#src-11), and 58.4% for natural gas combined cycle [[12]](#src-12). The nuclear and renewable figures are driven mostly by availability and resource. The combined cycle figure is driven mostly by dispatch, meaning how often the market called those units to run, so it is not a statement about whether they could have run more. Firmness in a contract sense means available capacity, secured fuel or energy source, and a dispatch right.

### Is there enough capacity on the system to serve this load?
Federal assessments describe the margin as tightening rather than comfortable. NERC's 2025 Long-Term Reliability Assessment identifies 13 of 23 assessment areas as facing resource adequacy challenges over the ten-year period and reports that new data centers account for most of the projected demand increase [[9]](#src-9). The Department of Energy reports that 104 GW of firm capacity is scheduled to retire by 2030, that 209 GW of new generation is planned, and that only 22 GW of those additions is firm baseload [[10]](#src-10). Those are DOE's figures and definitions. EIA has separately noted that fossil generation could rise if data center demand grows faster than expected [[5]](#src-5), which is the near-term consequence of that same arithmetic.

### Does co-locating next to an existing power plant solve the timing problem?
It addresses part of it and opens a different question. Placing a large load beside generation that is already connected can reduce or avoid new transmission service, which is why several announced projects use this approach. But NERC has published a white paper documenting the characteristics and risks of emerging large loads, treating them as behaving differently from conventional load in ways that need to be modeled rather than assumed [[13]](#src-13). And the commercial and regulatory terms are being decided now, with FERC running an open proceeding on co-location at PJM under Docket Nos. EL25-49-000 and related dockets [[14]](#src-14). Co-location therefore substitutes one category of schedule risk for another rather than removing it, and the substitute is harder to estimate while the rules are still being set.

### When is advanced nuclear realistically available, and what is RankShield Energy's status?
Advanced nuclear is a 2030s option for most buyers, and the gates are licensing and fuel rather than physics. The NRC's Part 53 framework was published in the Federal Register on March 30, 2026 and took effect in April 2026 [[15]](#src-15), though a framework existing is not a license being issued under it. INL and DOE characterize the microreactor program as focused on designs that could be deployed as early as the late 2020s [[16]](#src-16), which is a program characterization rather than a vendor delivery commitment. HALEU supply is the second gate. As for us: RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, nothing about our design has been demonstrated to or accepted by the NRC, and we have never operated a reactor and operate no fleet. We are not offering firm power on any date.

## Sources

- [Lawrence Berkeley National Laboratory. 2024 United States Data Center Energy Usage Report. December 2024](https://eta-publications.lbl.gov/sites/default/files/2024-12/lbnl-2024-united-states-data-center-energy-usage-report_1.pdf)
- [U.S. Department of Energy. DOE Releases New Report Evaluating Increase in Electricity Demand from Data Centers. December 2024](https://www.energy.gov/articles/doe-releases-new-report-evaluating-increase-electricity-demand-data-centers)
- [U.S. Energy Information Administration. EIA forecasts strongest four-year growth in U.S. electricity demand since 2000, fueled by data centers. January 2026](https://www.eia.gov/pressroom/releases/press582.php)
- [U.S. Energy Information Administration. Annual Energy Outlook 2026. April 2026](https://www.eia.gov/outlooks/aeo/pdf/AEO_Narrative.pdf)
- [U.S. Energy Information Administration. Fossil generation could rise with faster-than-expected growth in data center power demand. March 2026](https://www.eia.gov/todayinenergy/detail.php?id=67344)
- [Lawrence Berkeley National Laboratory. Queued Up: 2025 Edition. December 2025](https://www.osti.gov/biblio/3008763)
- [Federal Energy Regulatory Commission. Improvements to Generator Interconnection Procedures and Agreements (Order No. 2023). September 2023](https://www.federalregister.gov/documents/2023/09/06/2023-16628/improvements-to-generator-interconnection-procedures-and-agreements)
- [U.S. Department of Energy, Office of Electricity. National Transmission Needs Study. Accessed July 2026](https://www.energy.gov/oe/national-transmission-needs-study)
- [North American Electric Reliability Corporation. 2025 Long-Term Reliability Assessment. January 2026](https://www.nerc.com/globalassets/our-work/assessments/nerc_ltra_2025.pdf)
- [U.S. Department of Energy. Report on Evaluating U.S. Grid Reliability and Security. July 2025](https://www.energy.gov/sites/default/files/2025-07/DOE%20Final%20EO%20Report%20%28FINAL%20JULY%207%29.pdf)
- [U.S. Energy Information Administration. Electric Power Monthly, Table 6.07.B, Capacity Factors for Utility Scale Generators Not Primarily Using Fossil Fuels. 2025 data](https://www.eia.gov/electricity/monthly/epm_table_grapher.php?t=epmt_6_07_b)
- [U.S. Energy Information Administration. Electric Power Monthly, Table 6.07.A, Capacity Factors for Utility Scale Generators Primarily Using Fossil Fuels. 2025 data](https://www.eia.gov/electricity/monthly/epm_table_grapher.php?t=table_6_07_a)
- [North American Electric Reliability Corporation. Characteristics and Risks of Emerging Large Loads. July 2025](https://www.nerc.com/globalassets/who-we-are/standing-committees/rstc/whitepaper-characteristics-and-risks-of-emerging-large-loads.pdf)
- [Federal Energy Regulatory Commission. PJM Co-location Proceeding, Docket Nos. EL25-49-000 et al. December 2025](https://www.ferc.gov/sites/default/files/2025-12/EL25-49%20PPT%20E-1%2012.17.25_0.pdf)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [Idaho National Laboratory / DOE. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)

## Related

- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects data-center power demand and advanced-nuclear deployment status as of July 2026. Demand projections are estimates that may be revised, and advanced-nuclear timelines depend on licensing and fuel-supply developments that are still evolving. Check back if the IEA updates its figures or if the HALEU supply picture changes.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state/

# Trusting a Remotely Operated Nuclear Reactor Safely

> Remote operation splits the operator from the core. Learn the two trust gaps this opens, verified commands and verified state, and how each is being addressed.

[Resources](https://rankshieldenergy.com/resources) / Autonomy & Part 57 Autonomy & Part 57

# Trusting a Remotely Operated Reactor: The Command and State Problem
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Remote operation splits the operator from the core: the people running the reactor are no longer standing next to it. That separation opens two distinct trust gaps. The command gap is whether the instruction the reactor carried out is the one the operator actually sent. The state gap is whether the condition the reactor reports back is its real condition. Verified commands and verified state are the two things an outside party has to be able to check, and neither is solved by trusting the network link. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended.
When a reactor is operated from outside the site boundary, the physics of the core do not change, but the path between the operator's intent and the reactor's behavior gets longer, and every link in that path is something a regulator, insurer, or grid operator now has to be able to trust. In July 2026, Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[1]](#src-1). That result shows the operating model is becoming real. It also sharpens the two questions that follow it: was the right instruction received, and is the reported condition true?
RankShield Energy is a pre-applicant with the NRC, engaged in early regulatory interaction and holding no license or approval. This article is educational. It defines remote operation as command and control from outside the site boundary, distinct from monitoring, then takes apart the command gap and the state gap in turn, compares them, reads the July 2026 demonstration honestly, and sets out where the regulation stands, against a current rule that assumes an operator at the controls and a proposed Part 57 that is not yet final [[8]](#src-8). The reactor's own safety systems and the human in the loop are one layer; independent confirmation of commands and state is a separate layer, and it is the one this post is about.
Key takeaways

- Remote operation is command and control from outside the site boundary, which is distinct from monitoring and opens two trust gaps.
- The command gap is proving the reactor carried out the instruction the operator actually sent, unaltered and in order.
- The state gap is proving the condition the reactor reports back is its real condition, not a stale or spoofed reading.
- Both gaps are verification problems: they are closed by evidence an outside party can check, not by trusting the link.
- Current rules require an operator at the controls; proposed Part 57 contemplates reduced staffing but is not final, and no facility is licensed to operate unattended.

## What does remote operation actually change?
Remote operation means issuing command and control from outside the site boundary, over a communications link, rather than from a control room on the plant. That is a narrower thing than it sounds, and the first useful move is to separate it from monitoring. A regulator can watch data leave a site without anyone off site being able to change what the reactor does. Human factors researchers working with the NRC draw exactly this line, treating offsite monitoring and remote operation as distinct activities with different demands on the people involved [[6]](#src-6). Monitoring observes; remote operation acts.
On-site operation keeps intent and action in one room. An operator moves a control, watches the instrument respond, and confirms both firsthand. Remote operation breaks that loop into pieces joined by a network: the instruction travels to the reactor, and the reactor's response travels back, and neither leg is something the operator witnesses directly. Oak Ridge described the shape of this well before it became topical, noting that remote and centralized control rooms change where operators sit relative to the plant they run [[2]](#src-2).
The engineered safety systems still act locally, and safety-significant actions keep a human in the loop; no facility today is licensed to operate unattended. Current rules assume presence, requiring a licensed operator to be at the controls [[7]](#src-7). What changes under remote operation is the basis for trusting the day-to-day operating picture. More of the operating case now rests on two flows of messages, the commands going out and the state coming back. For a consequential system, trusting those messages is not the same as verifying them, and it helps to keep remote operation distinct from the neighboring ideas of automation and autonomy, which a companion piece on [what those terms actually mean](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms) takes up. The next two sections take the outbound and inbound flows in turn.

## The command gap: how do you prove the reactor got the instruction the operator sent?
The command gap is the risk that the instruction the reactor acts on is not the instruction the operator meant to send. Closing it means making each command something the reactor can confirm as genuine before acting, and something an outside party can check afterward. In practice that has three parts. First, the command carries proof of who issued it, so the reactor can reject anything not from an authorized operator. Second, it is protected against alteration in transit, so a message changed on the way is detected rather than obeyed. Third, each command is recorded in order, so a replayed or reordered instruction cannot pass as fresh.
This is not a new class of problem. Computer security settled its shape years ago in the internet's attestation architecture, published as IETF RFC 9334, which formalizes the idea that a relying party should act on evidence it can appraise rather than on an unverified assertion [[9]](#src-9). Applied to a reactor, the operator proposes an action, but the reactor and any independent verifier act on a command whose origin and integrity can be confirmed.
Oak Ridge, studying the licensing implications of autonomous control, found that the reach of these questions goes well past staffing: it extends into manipulation of controls, licensed-operator provisions, technical specifications, cybersecurity, and required notifications, with the control room possibly not co-located with the plant [[3]](#src-3). Each of those touches the command path. In our own attestation engineering at RankShield, the recurring lesson is that the hard part is not signing a command but making the record of what was commanded checkable by someone who is not the operator, which is the same separation described in [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors). All of this is design intent, subject to analysis, testing, and NRC review; nothing here has been demonstrated to or accepted by the NRC.

## The state gap: how do you prove the reactor's reported condition is real?
The state gap is the mirror image of the command gap. Once a command has been carried out, the operator needs the reactor's actual condition, and outside the control room that condition arrives as reported data rather than direct observation. Verified state is the continuous, checkable confirmation that the condition the reactor reports is its real condition, and not a stale reading, a dropped update, or a value altered in transit.
The mechanics parallel verified commands. The reported state carries proof of where it came from, it is protected against alteration on the way back, and it is recorded so a regulator, insurer, or lender can inspect it later. The same attestation logic applies, in which a relying party appraises evidence about a system rather than taking the system's word for its own status [[9]](#src-9). There is a mature precedent for placing this kind of check outside the reporting party. International safeguards exist so an outside body can independently verify a facility's declarations through its own technical measures, rather than relying on an operator's assertion [[12]](#src-12). Safeguards address non-proliferation, not operational safety, so the analogy is structural rather than exact, but the structural point holds: for a claim that matters, the party confirming it sits outside the party making it.
The engineering preconditions are real. Turning a raw sensor stream into a record an outside party can trust involves instrumentation that survives long unattended operation and a defensible chain from sensor to signed statement, which is the sequence walked through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record). The point is durability of trust. A live dashboard shows what the operator's software chooses to show right now. Verified, recorded state tells an outside party, later, what the reactor actually reported, in a form that does not depend on the operator vouching for itself.

## How do the two gaps compare?
The two gaps are symmetric in structure and opposite in direction. One protects instructions traveling to the reactor; the other protects condition data traveling back. Laying them side by side makes the shared remedy visible: in both cases the fix is not trusting the link but producing a record an outside party can check. The appraise-the-evidence model of RFC 9334 is the common thread [[9]](#src-9).

The command gap and the state gap, compared across what each is, what can go wrong, and how it is addressed

Aspect
Command gap
State gap

What it is
Proving the reactor carried out the instruction the operator actually sent
Proving the condition the reactor reports back is its real condition

Direction of flow
Outbound: operator to reactor
Inbound: reactor to operator and outside parties

What could go wrong
An unauthorized, altered, replayed, or reordered instruction is obeyed as if genuine
A stale, dropped, spoofed, or altered reading is trusted as current truth

How it is addressed
Origin proof, tamper-evidence in transit, and ordered recording an outsider can check
Origin proof, tamper-evidence on the return path, and recording an outsider can inspect later

Who needs to check it
Regulator, insurer, lender, grid operator
Regulator, insurer, lender, grid operator

Reading the table across rather than down is the useful exercise. The failure modes differ, but the remedy is one idea applied twice: replace an act of trust with a piece of evidence. That is why command and state verification are usually built as one system rather than two, and why the honest measure of a remote-operation claim is not how good the dashboard looks but what an outside party can reconstruct without the operator's help. The proposed regulatory framework for this class of reactor contemplates exactly the reduced-presence models that make this evidence matter, which the next sections take up [[8]](#src-8).

## What did the July 2026 INL demonstration show, and what did it not?
Remote reactor control has moved from concept to demonstration. In July 2026, Idaho National Laboratory and university partners achieved remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout the test [[1]](#src-1). That is a national-laboratory demonstration of the operating model, run on a research reactor under laboratory conditions. It is not a demonstration of any commercial reactor's safety, and it is not RankShield Energy's result.
It helps to be precise about what a result like this establishes. It shows that operating a reactor across a network is feasible while local safety systems keep control, and it was performed by a national lab whose broader microreactor program, including the MARVEL test reactor, is aimed at exactly this kind of experiment [[14]](#src-14). What it does not establish is that the command and state flows have been independently verified in a form a buyer, regulator, or insurer could check for themselves. The demonstration proved the operating capability. It did not, and did not claim to, prove independent verification of the record.
That second piece is the open frontier, and the honest framing for every serious developer, including us, is design intent subject to testing and regulatory review. The digital-twin approaches that make autonomous control possible on the operations side are further along than the independent-verification approaches that would let an outsider confirm the result, an asymmetry examined in [digital-twin verification of remote operations](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations). Reading the demonstration as proof of a trustworthy remote reactor would overstate it; reading it as proof that the operating model is reachable is exactly right.

## Where does the regulation actually stand?
The regulatory picture is best stated as a gap between what the rules require today and what a proposed rule would allow. Today, a licensed operator must be present at the controls; the conditions of an operating license assume on-site, at-the-controls presence [[7]](#src-7). That baseline is backed by an oversight system built on human presence. The NRC stations resident inspectors at operating plants, at least two per site, whose stated role is to independently verify that requirements are being met [[10]](#src-10), inside a Reactor Oversight Process that combines inspection findings with performance indicators [[11]](#src-11).
Against that baseline, the NRC published a proposed rule in May 2026, a new 10 CFR Part 57, that would set licensing requirements for microreactors and reactors with comparable risk profiles, and that contemplates remote operation and reduced on-site staffing with human responsibility retained for safety-significant actions [[8]](#src-8). The agency's microreactor regulatory-activities pages place this rulemaking within a broader modernization effort for the reactor class [[13]](#src-13). The single most important fact about Part 57 is its status: it is proposed, its comment period has run, and no developer is licensed under it. A neutral reading of what it does and does not say is set out in [our explainer on proposed Part 57](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The direction of travel is clear, and so is the distance still to cover. Reduced presence is contemplated, not authorized. The oversight model that presence supports, independent verification by inspectors on site, does not vanish when staffing thins; it has to be reconstituted in another form. That is the regulatory reason command and state verification matters, rather than a purely technical one: as human presence is proposed to decrease, the mechanism that presence provided has to be replaced by something an outside party can still check.

## Isn't this a problem the reactor's own safety systems already solve?
A fair objection runs like this: the reactor's engineered safety systems act locally and independently of the network, so if a bad command arrives or a reading is wrong, the plant's own protection should hold regardless. Why layer verification on top of that?
The response is that the two do different jobs. Engineered safety systems keep the reactor inside safe physical limits; they are the reason a corrupted command should not be able to cause harm. Command and state verification is about trust in the operating record, which is a separate question the safety systems do not answer. An insurer underwriting the plant, a lender financing it, and a regulator overseeing it all need to know what was commanded and what the reactor reported, in a form they can check without taking the operator's word. Safety systems protect the reactor; verification protects the account of what happened. Both are needed, and neither substitutes for the other. Human factors work for the NRC on facilities without traditional main control rooms frames the core question precisely, as confirming that important human actions can be accurately and reliably performed under these new arrangements [[5]](#src-5).
The honest limitation is this. Independent verification of remote operation is, across the industry, less mature than the operating capability it is meant to check. Sandia, working for the NRC, has mapped the human-factors demands of automating microreactors, including models where one control room supervises several units, and that body of work describes requirements more than it describes finished solutions [[4]](#src-4). RankShield is no exception. We can describe the architecture, and we can point to the attestation engineering behind it, but describing an architecture is not the same as having demonstrated it under regulatory review, and we would rather say that plainly than blur it.

## Where does this leave RankShield Energy?
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. Verifier-operator separation, applied to both the command flow and the state flow, is the architecture we are building toward and the reason this site exists. It is not a certified capability, and we do not present it as one.
Stated as a position that can be argued with: a vendor cannot be its own independent verifier, and that stays true of us. It is why we treat the separation as structural rather than as a feature to be bolted on later. The tradeoff is real and worth naming. A separate verifier costs more to stand up, adds a party to coordinate with, and creates a body that can publicly contradict the operator. We think that last property is the point rather than a defect, because a verifier that can never disagree with you is not verifying anything. That is a design decision we have made and are willing to defend, including what it gives up.
Two things keep this honest. Remote and autonomous operation are demonstrated capabilities at the national-lab level, not settled commercial reality, and no facility today is licensed to operate unattended; safety-significant actions keep a human in the loop. And the independent-verification layer we care about is a direction of work, not a finished product. If you are evaluating developers on any of this, the questions worth asking, and worth turning back on us just as hard, are collected in [how to verify an autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely). The distinction between what has been demonstrated and what has been claimed is the whole of the argument, and it should be applied to us without sentiment.

## Frequently asked questions

### What are the two trust gaps in remote reactor operation?
They are the command gap and the state gap. The command gap is the risk that the instruction the reactor acts on is not the one the operator sent, whether through alteration, replay, or an unauthorized source. The state gap is the risk that the condition the reactor reports back is not its real condition, whether through a stale reading, a dropped update, or a value changed in transit. Both are verification problems rather than only engineering problems, because closing them means giving an outside party something it can check [[9]](#src-9). The reactor's own engineered safety systems and the human in the loop for safety-significant actions are a separate and additional layer.

### How is the command gap actually closed?
By making each command confirmable rather than merely trusted. The command carries proof of who issued it, so the reactor can reject anything not from an authorized operator; it is protected against alteration in transit; and it is recorded in order, so a replayed or reordered instruction cannot pass as fresh. This mirrors the internet's attestation architecture, in which a relying party acts on evidence it can appraise rather than on an unverified assertion [[9]](#src-9). The aim is a record of what was commanded that a party other than the operator can check afterward.

### Is a remotely operated reactor unmanned?
No. Remote operation moves some operators away from the site; it does not remove people from the safety picture. Safety-significant actions keep a human in the loop, and no facility today is licensed to operate unattended. Current rules require a licensed operator at the controls [[7]](#src-7), and the proposed Part 57 framework contemplates remote and reduced-staffing models with human oversight retained, a rule that is proposed rather than final [[8]](#src-8). RankShield Energy does not describe its work as unmanned or fully autonomous, and neither term should be read as a settled reality or as this company's claim.

### Has remote reactor operation actually been demonstrated?
Yes, at national-lab scale. In July 2026, Idaho National Laboratory and university partners demonstrated remote, real-time autonomous power control of a research reactor, with safety systems retaining control throughout [[1]](#src-1). That demonstrates the operating model on a research reactor under laboratory conditions. It is not a demonstration of a commercial reactor's safety, and it is not RankShield Energy's result. Independent verification of the command and state flows, in a form an outside party can check, remains an open area of work across the industry.

### Does RankShield Energy verify commands and state today?
No, not as a deployed or certified capability. We are a pre-applicant with the NRC holding no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. Verifier-operator separation across the command and state flows is the architecture we build toward and our reason for existing, but describing an architecture is not the same as having demonstrated it under regulatory review. The proposed framework this sits inside is itself still proposed and subject to change [[8]](#src-8), and we would rather say all of that plainly than let the distinction blur.

## Sources

- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [U.S. NRC and Idaho National Laboratory. Characterizing the Human Factors of Offsite Monitoring and Remote Operation for the Nuclear Domain. NPIC&HMIT, June 2025](https://inl.elsevierpure.com/en/publications/characterizing-the-human-factors-of-offsite-monitoring-and-remote/)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)

## Related

- [Automation, remote operation, and autonomy explained →](https://rankshieldenergy.com/resources/automation-remote-autonomous-reactor-terms)
- [Self-attestation versus independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of remote reactor operation and NRC rulemaking as of July 2026. Proposed rules for this class of reactor are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely/

# How to Verify an Autonomous Microreactor Is Running Safely

> An autonomous microreactor runs with fewer people on site. See how independent verification confirms it is operating safely, without taking a vendor's word.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# How to Verify an Autonomous Microreactor Is Operating Safely
Published July 23, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. You verify an autonomous microreactor the way you verify any critical system you cannot stand next to: an independent party, not the operator, continuously confirms what the reactor is doing and records that confirmation so someone else can check it later. Verification is a separate function from operation. For a reactor designed to run with fewer people on site, that function has to be continuous, independent, and hard to alter after the fact.
That sounds abstract until you look at what it replaces. Today the Nuclear Regulatory Commission keeps roughly 150 resident inspectors in the field, at least two at every plant, whose job is independently verifying that requirements are being met [[2]](#src-2), and federal regulation requires a licensed operator at the controls at all times [[5]](#src-5). A microreactor designed for reduced on-site staffing does not merely trim that. It removes the mechanism by which outsiders have historically known anything.
This guide walks through what oversight looks like now, what the national laboratories have found actually breaks under autonomy, why the verifying party cannot be the operating party, what has genuinely been demonstrated, and where the regulator is heading. RankShield Energy is a pre-applicant with the NRC, holding no license or approval [[29]](#src-29), and the last section applies every argument here to our own program.
Key takeaways

- Today's oversight rests on people being present: about 150 NRC resident inspectors, at least two per plant, plus a licensed operator required at the controls at all times.
- Autonomy does not remove the verification burden, it moves it from observing a plant to checking claims about a plant.
- A vendor cannot be its own verifier, which is why IAEA safeguards and the internet's attestation standards both put the checker outside the checked.
- Autonomous control has been demonstrated at national-lab scale; continuous independent verification of a fleet has not, because no commercial fleet exists.
- The NRC itself anticipates a smaller inspection footprint, while the GAO flags unresolved staffing gaps. That space is what verification has to fill.

## How the current reactor fleet is actually watched
Oversight of the operating US fleet rests on people being physically present. The Nuclear Regulatory Commission stations resident inspectors at every plant, describing their role as providing essential on-site verification of licensee activities through walkdowns, observing tests, and reviewing corrective action documents [[1]](#src-1). The agency employs roughly 150 of them, with at least two assigned to each plant, and their stated job is independently verifying that requirements are being met [[2]](#src-2).
That human layer sits inside a larger structure. The Reactor Oversight Process is risk-informed and tiered, built on safety cornerstones, NRC-developed inspection findings, licensee-reported performance indicators, a significance determination process, and an action matrix that escalates as performance degrades [[3]](#src-3). The Government Accountability Office has described the agency's safety assurance as resting on exactly this: monitoring and inspecting the activities with the greatest effect on safety [[4]](#src-4).
There is also a hard legal floor underneath all of it. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times, and a licensed operator or senior operator must be present at the controls at all times [[5]](#src-5). That is not a guideline or an industry practice. It is a condition of the license.
Read together, these establish what a microreactor fleet is actually proposing to change. Not just staffing economics, but the mechanism by which anyone outside the operating organization knows what a reactor is doing.

## What autonomy actually removes, according to the labs studying it
Oak Ridge National Laboratory examined this directly and enumerated what autonomous control disturbs: staffing, manipulation of controls, licensed operator requirements, technical specifications, cybersecurity, and event notifications, noting that a control room may not even be co-located with the plant [[6]](#src-6). As one ORNL researcher put it, current regulatory guidance was written when remote operation of nuclear reactors was not possible, so this is a new frontier [[7]](#src-7).
Sandia National Laboratories, working for the NRC, reached the operational version of the same conclusion: human operators may not be located on site and may instead monitor the facility from a remote location, and some designs contemplate one control room supervising multiple microreactors [[8]](#src-8).
The most useful framing comes from Brookhaven National Laboratory, in work performed for the NRC's Office of Nuclear Regulatory Research on facilities without main control rooms. Their point is precise: the safety question is not so much justifying why a design has no main control room, but rather verifying that important human actions can be accurately and reliably performed [[9]](#src-9).
That sentence is the whole problem restated by the regulator's own research arm. The burden does not disappear when the people leave. It moves, from observing a plant to verifying claims about a plant. And verifying a claim requires something the claim itself cannot supply.

## Why the verifier cannot be the vendor
A party that both operates a reactor and certifies its own status carries a conflict that no amount of engineering removes. The report may be perfectly accurate. But an outside party has no independent basis to know that, because the same organization produces the report and is judged by it.
This is not a novel observation, and nuclear already contains the precedent. The IAEA safeguards system exists precisely so that an outside body applies technical measures through which it can independently verify that facilities are not misused, rather than relying on an operator's assertion [[10]](#src-10). Safeguards address non-proliferation rather than operational safety, so the subject matter differs. The structure does not.
Computing settled the same question formally. The internet's remote attestation architecture, standardized as RFC 9334, splits the roles into an Attester that produces evidence, a Verifier that appraises it against policy, and a Relying Party that acts on the result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [[11]](#src-11). The design assumption is that the thing being checked does not get to be its own checker.
Which is why [self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors) are different products, not different words for the same product. A vendor dashboard shows what the operator's software chooses to display at the moment it chooses to display it. That is useful for running a plant. It is not evidence to anyone else.
The uncomfortable version, stated plainly: "trust us, the reactor is fine" may well be true, but truth an outsider cannot check is not the same as truth an outsider can rely on. For something with a reactor's consequences, that difference is the entire point.

## What replaces the inspector, function by function
It helps to stop treating this as one problem and break the resident inspector's job into what it actually delivered, then ask what has to supply each piece when the person is not there. The table below is our own mapping rather than a regulatory framework, offered as a way to structure the question.

What on-site presence provided, and what has to replace each function

Function of on-site presence
What must supply it without a person there
Why the operator alone cannot

Direct observation of plant condition
Continuous instrumented measurement of reactor state
Sensors report through the operator's own systems

Independent judgment about what was seen
Appraisal of measured state against design limits by a separate party
Self-appraisal is the conflict being solved

A witness who can be asked afterwards
A tamper-evident record a third party can examine later
Logs the operator can alter prove little

Escalation when something looks wrong
Divergence surfaced automatically and recorded either way
Undocumented judgment calls are unreviewable

The middle column is not speculative. ORNL's work on autonomous microreactor operation identifies the same requirements from the engineering side: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring [[12]](#src-12). Those are the preconditions for anyone, operator or verifier, to know anything at all.
The right-hand column is where [independent verification](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) earns its place. Every function in the left column that depended on the inspector being a party with no stake in the answer needs a replacement with the same property.

## Recording it so someone can check afterwards
Continuous appraisal solves the present tense. It does not by itself solve the past tense, which is what a regulator, insurer, lender, or grid operator actually asks about. Their question is rarely "what is the reactor doing right now." It is "what was it doing on the fourteenth, and how do I know."
That is a records problem with an established answer outside nuclear. RFC 9943 defines an append-only transparency service that registers signed statements and issues receipts, so that a third party can audit the record later [[13]](#src-13). RFC 9942 standardizes the receipts themselves as compact cryptographic proofs of inclusion and append-only consistency against a verifiable data structure [[14]](#src-14), which matters for remote sites where bandwidth is limited.
Signatures on records intended to outlive the equipment need to survive future cryptography as well. NIST approved three post-quantum standards in August 2024, including ML-DSA and SLH-DSA for digital signatures [[15]](#src-15), and the federal baseline for assuring integrity across acquired components sits in NIST SP 800-161r1 [[16]](#src-16).
None of this is exotic and none of it was invented for reactors. It is the ordinary machinery of making machine-generated claims checkable by someone who was not present, which is exactly what [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record) requires.
A distinction worth holding onto: tamper-evident is not tamper-proof. The property being sought is not that a record cannot be altered. It is that alteration cannot happen quietly.

## What has actually been demonstrated so far
The operating model is further along than most coverage suggests. In 2022 the Department of Energy reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted future heat pipe temperatures and then autonomously controlled the heat pipe on the MAGNET testbed [[17]](#src-17). That is closed-loop autonomy, demonstrated, not theorized.
INL's MARVEL project is explicitly intended to test systems for remote monitoring, develop autonomous control technologies for microreactors, and help develop regulatory approval processes for them [[18]](#src-18). In July 2026, INL and university partners went further and demonstrated remote, real-time autonomous power control of a research reactor, with the reactor's safety systems retaining control throughout [[19]](#src-19).
Two cautions belong with those results, and we would rather state them than let a reader over-read the paragraph above. These are national-laboratory demonstrations, not commercial operation, and none of them belongs to any vendor including us. And demonstrating that a reactor can be controlled autonomously is a different achievement from demonstrating that an independent party can continuously confirm what it did.
The second half is the thinner half. The instrumentation and control security guidance exists internationally [[20]](#src-20), and the IAEA has an active research project on computer security for small modular and microreactors that names autonomous and remote operations, digital twins, and centralised fleet management with reduced staffing as the conditions to be addressed [[21]](#src-21). But there is no operating fleet under continuous independent verification today, because there is no operating microreactor fleet.

## Where the regulator is heading, and what is still unsettled
The NRC has been circling this since at least 2020, when SECY-20-0093 flagged autonomous operation, remote operation, staffing, and oversight as open policy questions for microreactors [[22]](#src-22). More recently the agency has been planning for standardized, fleet-scale deployment [[23]](#src-23), which is the regulatory shape of many units per unit of attention.
The concrete vehicle is proposed 10 CFR Part 57, published in the Federal Register on May 1, 2026, which contemplates remote operation and reduced on-site staffing [[24]](#src-24), with companion draft guidance in NUREG-2271 aimed at rapid licensing and high-volume deployment [[25]](#src-25). Both are proposals. The comment period closed in June 2026, no developer is licensed under Part 57, and the text can still change. Anyone describing it as settled law is describing something that does not exist yet, which is why we cover [what proposed Part 57 actually says](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) separately.
The most telling signal is quieter. Under the ADVANCE Act, the NRC is directed to develop microreactor strategies across areas including staffing and operations, and oversight and inspections, and in December 2025 staff proposed operational-phase oversight built on innovative inspection methodologies and a scalable inspection footprint [[26]](#src-26). The regulator itself anticipates that the inspection footprint shrinks.
Meanwhile the GAO has repeatedly flagged that the NRC has not evaluated its efforts to address staffing gaps and lacks benchmarks for whether recruitment and retention are working [[27]](#src-27), and still lists licensing advanced reactors among its priority open recommendations [[28]](#src-28). Fewer inspectors per reactor is arriving whether or not the verification layer arrives with it. That gap is the thing worth designing against now.

## How we apply this to ourselves
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [[29]](#src-29). We have never operated a reactor, so nothing above is offered as operating experience.
What we do claim is narrower and, we think, more useful. Our working domain is the verification layer itself: independent appraisal, signing, and transparency logging of machine-generated claims. That is where our judgment comes from, and it is why we treat separation between the verifier and the operator as an architectural requirement rather than a feature. The tradeoff is real and worth naming, because a separate verifier costs more and adds a party to coordinate with. We think that cost is the point rather than an inefficiency to engineer away.
Our reactor safety characteristics are design intent, subject to analysis, testing, and regulatory review. Our verification approach is an architecture we apply, not a deployed or certified capability. If you are weighing developers, the same questions we have set out here apply to us, which is the premise of our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.
One last framing that may be useful when you read any developer's material, including this site. Ask whether a claim is about engineering or about evidence. Engineering claims describe what a machine is built to do, and they are settled by analysis, testing, and regulatory review over years. Evidence claims describe how anyone outside the operating organization would know the machine did it, and they are settled by who is positioned to check. Most of this industry, ourselves included, is further along on the first than the second. Noticing which kind of claim you are being offered is most of the work.

## Frequently asked questions

### Who verifies an autonomous microreactor if no one is on site?
An independent verifier: a party structurally separate from the operator that continuously appraises the reactor's reported state against what the design permits, and records the result so it can be checked later. This is different from the operator's own monitoring software. Today the equivalent function is largely carried by NRC resident inspectors, roughly 150 of them with at least two at each plant, whose stated role is independently verifying that requirements are being met [[2]](#src-2). Regulatory oversight remains with the NRC. Independent verification is a technical function that supports it rather than replacing it.

### Does the law currently require an operator to be physically present?
Yes. Under 10 CFR 50.54(m), a licensed senior operator must be in the control room at all times and a licensed operator or senior operator must be present at the controls at all times [[5]](#src-5). That is a condition of the license for the current fleet. Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors [[24]](#src-24), but it is a proposal published in May 2026 whose comment period has closed, it is not final, and no developer is licensed under it today.

### Has autonomous reactor control actually been demonstrated?
Yes, at national-laboratory scale. DOE reported in 2022 that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[17]](#src-17), and in July 2026 INL and university partners demonstrated remote, real-time autonomous power control of a research reactor with safety systems retaining control [[19]](#src-19). Both are demonstrations of the operating model. Neither is a demonstration of continuous independent verification of a commercial fleet, and neither belongs to a vendor.

### Is independent verification the same as NRC approval?
No. Independent verification is a technical function performed by a party separate from the operator. NRC approval is a regulatory determination made by the federal regulator. A developer can build a verification layer and still be, as RankShield Energy is, a pre-applicant holding no license or approval [[29]](#src-29). The two support each other but are not interchangeable, and no verification architecture substitutes for regulatory review.

### Why not just rely on the vendor's monitoring dashboard?
Because a dashboard answers a different question. It shows what the operator's software chooses to display, at the moment it chooses to display it, to the operator. That is genuinely useful for running a plant. It does not help an insurer, lender, regulator, or grid operator establish what happened last month, because the party producing the record is the party being evaluated by it. The distinction is not about vendor honesty. It is structural, and it is the same reason companies do not audit their own books.

## Sources

- [U.S. Nuclear Regulatory Commission. Resident Inspector Program. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description/resident-insp-program)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Nuclear: Remote-controlled reactors. April 2019](https://www.ornl.gov/news/nuclear-remote-controlled-reactors)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026](https://www.rfc-editor.org/info/rfc9943)
- [Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026](https://www.rfc-editor.org/info/rfc9942)
- [National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024](https://www.nist.gov/news-events/news/2024/08/announcing-approval-three-federal-information-processing-standards-fips)
- [National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Updated November 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory. MARVEL Project. Accessed July 2026](https://inl.gov/marvel/)
- [Idaho National Laboratory. Researchers achieve remote, autonomous power control of a research reactor in real time. July 2026](https://inl.gov/news-release/researchers-achieve-remote-autonomous-power-control-of-a-research-reactor-in-real-time/)
- [International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018](https://www.iaea.org/publications/11184/computer-security-of-instrumentation-and-control-systems-at-nuclear-facilities)
- [International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026](https://www.iaea.org/projects/crp/j02021)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment). April 2026](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [NRC Part 57 and autonomous operation →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor verification and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/walk-away-safety-explained/

# Walk-Away Safety Explained: How a Reactor Cools Itself

> Walk-away safety means a reactor shuts itself down and cools itself using physics alone, with no operator, no power, and no pumps. Here is how it works.

[Resources](https://rankshieldenergy.com/resources) / Reactor safety Reactor safety

# Walk-away safety, explained
Published July 21, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy
Walk-away safety is the claim that a reactor can lose electrical power, lose active cooling, and lose its operators at the same time, and still shut itself down and remove its own heat through natural physical processes rather than through equipment that has to work. It is a design approach rather than a property any reactor gets for free, and the NRC has a narrower and more useful term for the underlying idea: passive safety. This article explains what the claim actually requires, the physics it rests on, and the four tests that separate a rigorous walk-away claim from a loose one.
The phrase is used loosely because it is persuasive, and that is precisely the reason to be careful with it. The NRC describes passive safety as systems and design characteristics that perform a safety function using natural forces such as gravity, natural circulation, and conduction, without relying on electrical power or operator action [[1]](#src-1). That is a description of an approach a designer can take. It is not a certificate that any particular machine has achieved anything, and the gap between those two readings is where most misleading marketing lives.
The distinction that runs through this article is **designed** versus **demonstrated**. Every specific reactor has to show, through qualified analysis and testing under regulatory review, that its passive features do what its analysis predicts. RankShield Energy is a pre-applicant engaged in early interaction with the NRC and holds no license, permit, or design approval [[11]](#src-11). Nothing here should be read as a representation that any characteristic of our design has been demonstrated to or accepted by the regulator.
Key takeaways

- A meaningful walk-away claim covers the simultaneous loss of power, cooling, and operators, not a single component failure.
- The NRC term for the underlying idea is passive safety: safety functions performed by natural forces without electrical power or operator action.
- Small size helps because a smaller core produces less decay heat relative to the material and surface area available to carry it away.
- Negative temperature feedback is a design property, not a universal law. Each design has to show its own core actually behaves that way.
- Designed and demonstrated are different words. Analysis predicts; testing under regulatory review substantiates.
- Four tests: does the claim name the failure set, distinguish designed from demonstrated, state regulatory status precisely, and survive an outside check?

## What does walk-away safety actually mean?
It means one specific and demanding thing: the reactor loses its connection to the grid, its backup power does not start, its active cooling stops, and every operator leaves, all at the same time, and the reactor still shuts down and removes its decay heat without damage and without anyone intervening.
The test is defined by simultaneity. Any reactor design can handle one failure; defense in depth has been standard practice in this industry for decades. What makes the walk-away framing demanding is that the failures are stacked and the human response is removed. A claim that addresses a single pump failure, or a loss of offsite power with backup generators available, is describing something considerably easier and should not be presented in the same language.
The regulator has a narrower term for the underlying idea, and it is the one worth using. The NRC defines passive safety as systems and design characteristics that perform their safety function using natural forces such as gravity, natural circulation, and conduction, without relying on electrical power or operator action [[1]](#src-1). The IAEA describes the same reliance on passive systems and inherent characteristics across the small reactor field [[2]](#src-2). Walk-away safety is the popular restatement of that idea, and popular restatements lose precision.
The claim is also bounded in time in a way that gets skipped. Decay heat falls sharply in the hours after shutdown but does not go to zero, so the honest question is not only whether the reactor survives the first hour but what the heat removal path looks like over days. A rigorous claim states the duration it covers and the conditions assumed.
One more boundary matters. Walk-away safety is a claim about the reactor responding to loss of power, cooling, and staff. It is not a claim about security, sabotage, or the integrity of the control system, which are separate problem domains with their own regulatory treatment and their own evidence requirements. Treating a thermal-hydraulic argument as though it covered a cybersecurity question is a common and consequential category error. The class context for all of this is in our explainer on [what a nuclear microreactor is](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor).

## Why does the NRC call these features passive safety?
Because the regulator uses a narrower and more testable term than the marketing phrase. The NRC glossary defines passive safety as safety systems and design characteristics that perform their function using natural forces such as gravity, natural circulation, and conduction, without reliance on electrical power or operator action [[1]](#src-1).
Two things are worth extracting from that definition. It names the mechanisms rather than the outcome, which makes a claim checkable: you can ask which natural force is doing the work in a given sequence and what analysis supports it. And it is written as a description of design characteristics, not as an assurance about any specific plant. The regulator is defining a category of engineering approach, not certifying a machine.
The IAEA uses the concept in the same way when discussing small modular reactors, describing designs that rely on passive systems and inherent characteristics such as natural circulation, so that safety functions can be performed without external intervention [[2]](#src-2). The agency also frames this as a design approach adopted across the small reactor field rather than as a settled result [[3]](#src-3).
This is why every careful sentence in this article attributes the general concept to the NRC, the IAEA, or DOE rather than asserting that a particular reactor achieves it. The concept is well established and uncontroversial. The application of the concept to any one machine is the part that requires evidence, and that evidence is produced through analysis and testing under regulatory review rather than through description. When a developer states the concept and lets the reader infer the achievement, that inference is doing work the developer has not earned.

## Why does small size help?
Because the amount of heat a core keeps producing after shutdown scales with the power it was producing before, while the material and surface area available to absorb and shed that heat do not shrink at the same rate. A smaller reactor therefore has a more favorable ratio between the heat it must remove and the mass and area available to remove it.
Decay heat is the specific problem. When the chain reaction stops, the fission products in the fuel keep decaying and keep releasing energy for a long period afterward. In a large light-water plant the absolute quantity of that heat is very large, which is why the conventional safety architecture is built around powered pumps and the emergency electrical supply needed to run them. In the microreactor size class, which DOE describes as roughly one to twenty megawatts [[4]](#src-4), the absolute quantity is far smaller.
The IAEA makes the same point about the small reactor family, noting that reduced size and power allow greater reliance on passive systems and inherent characteristics for safety functions [[2]](#src-2). This is a genuine physical advantage and it is the reason the class can be designed the way it is.
It is not, however, a conclusion. A favorable ratio makes passive heat removal *plausible* for a given design. What turns plausibility into a safety case is the analysis that shows the specific geometry, materials, and heat path actually carry the heat under the specific sequences the regulator asks about, backed by testing that validates the models used. Size helps the argument. It does not make the argument.

## What makes a reactor slow itself down as it heats up?
A property called negative temperature feedback. In plain terms, a core with this property responds to rising temperature by slowing the fission rate, so an unplanned increase in power raises temperature, and the higher temperature pushes the reaction back down without anything being switched on.
The mechanism is physical rather than procedural. As fuel temperature rises, neutron absorption in the fuel changes in a way that reduces the number of neutrons available to sustain fission, and expansion of the core materials as they heat lets more neutrons escape. Both effects push in the same direction. The net result is a reactor whose power tends to self-limit rather than run away, which is why the IAEA and DOE both discuss inherent characteristics of this kind when describing advanced designs [[2]](#src-2) [[3]](#src-3).
This is where precision matters most, because the phrase is often stated as though it were a law of nature that applies to every reactor. It is not. Negative feedback is a design property that depends on core composition, geometry, materials, and operating temperature, and a design has to establish the sign and magnitude of its own feedback through analysis and confirm it through testing under regulatory review. We deliberately publish no reactivity coefficients, core geometry, or fuel loading details for our own design, because that class of technical data is subject to export control under 10 CFR Part 810.
The practical reading for a non-specialist: treat negative temperature feedback as a claim a developer must substantiate about a specific core, not as a category benefit that arrives with the word advanced.

## How does heat leave the core without pumps?
Through three natural mechanisms, usually working together: natural circulation, conduction, and thermal radiation. None requires electrical power, and none requires an operator to start it.
**Natural circulation** is buoyancy doing the work of a pump. Heated fluid becomes less dense and rises, cooler fluid falls to replace it, and a loop establishes itself driven purely by temperature difference and gravity. **Conduction** moves heat through solid material, out of the fuel, through the core structure, and into whatever surrounds it. **Thermal radiation** carries heat from hot surfaces to cooler ones with no medium required at all, and it becomes more effective as surface temperature rises, which is a useful property in exactly the situation where you need it. The NRC names gravity, natural circulation, and conduction explicitly in its definition of passive safety [[1]](#src-1), and the IAEA describes the same reliance in the small reactor context [[2]](#src-2).
The design consequence is that a rigorous safety case keeps the passive heat path independent of the equipment used in normal operation. Whether a design moves heat with a pump, a heat pipe, or natural circulation during normal running, the walk-away case has to be carried by a path that does not depend on any of that equipment continuing to function. If the passive path shares a component with the active path, the independence is nominal.
The ultimate heat sink is the part to ask about. Every one of these mechanisms ends by depositing heat somewhere outside the reactor, whether that is ambient air, ground, or a body of water. A claim that describes the path out of the core but never names where the heat finally goes, and whether that sink can be lost, is incomplete. For a microreactor sized in the range DOE describes [[4]](#src-4), the sink is often ambient air, which is attractive precisely because it is difficult to remove.

## What does the fuel contribute, and what does it not?
Fuel contributes a barrier, not an outcome. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic, with each particle carrying its own containment barrier around the fission products it produces [[5]](#src-5). Distributing that barrier across millions of particles rather than concentrating it in a single boundary is a real engineering property, and DOE presents it as a robust fuel form.
That is DOE characterizing a fuel concept, and the attribution matters. What a particular reactor achieves with TRISO depends on the fuel qualification data submitted for that design, the temperatures the design actually reaches in the sequences under review, and the regulator finding the supporting analysis adequate. Fuel qualification is its own substantial evidentiary program, not an inherited property of the fuel type.
It is also worth being clear about what fuel does not do. A robust fuel particle does not shut a reactor down, does not remove decay heat, and does not substitute for a heat removal path. It limits the consequences if temperatures rise. The shutdown mechanism, the heat path, and the fuel barrier are three separate elements of a safety case and a rigorous claim addresses all three rather than leaning on whichever is most quotable.
Absolute phrasing is the tell. When a claim about fuel is stated as though it removed the need for the rest of the safety case, the claim has outrun its evidence. The more useful framing is the one DOE uses: a fuel form with strong containment characteristics, supported by a specific body of qualification work [[5]](#src-5). Fuel availability is a separate constraint again, and [where HALEU comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel) governs whether any of this reaches a site.

## Designed is not demonstrated, and the difference is the whole argument
A design intent is what analysis predicts. A demonstration is what testing showed, under what conditions, reviewed by whom. Almost every misleading walk-away claim in circulation is a design intent written in the grammar of a demonstration.
The regulatory context makes the difference concrete. Today, assurance for the operating fleet rests substantially on people being present: federal regulation requires a licensed operator at the controls at all times [[8]](#src-8), and the NRC runs a risk-informed Reactor Oversight Process built on inspection findings and performance indicators [[9]](#src-9). Those mechanisms exist because a paper safety case is not by itself considered sufficient assurance about an operating plant.
For microreactors that architecture is being reworked rather than removed. The NRC published a proposed rule, 10 CFR Part 57, addressing licensing requirements for microreactors and other reactors with comparable risk profiles [[6]](#src-6), and in March 2026 published its risk-informed, technology-inclusive Part 53 framework for advanced reactors [[7]](#src-7). Part 57 is **proposed**, not final, it may change, and no developer is licensed under it. The federal microreactor program plan prepared by INL and GAIN for DOE sets out the research and demonstration work the class still requires [[10]](#src-10), which is a clearer statement of where the field stands than any vendor announcement.
Our position, stated so it can be argued with: a walk-away claim made by the party that would benefit from it is an assertion, whatever its technical merit, until someone with no stake in the answer can check it. That is the same reasoning behind [the difference between self-attestation and independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors), and it applies to reduced-staffing operation as directly as to safety analysis, which is the subject of our explainer on [what Part 57 proposes](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained). RankShield Energy is a pre-applicant with no license, permit, or design approval [[11]](#src-11), and we hold our own claims to this standard.

## Four tests to apply to any walk-away claim
These are the questions we would want asked of us, in the order they are most likely to be informative.
**One: does the claim name the failure set?** A meaningful walk-away claim covers the simultaneous loss of power, active cooling, and operators, and states the duration it covers. A claim that names no failure set is not a claim, it is a mood.
**Two: does it distinguish designed from demonstrated?** Look for the verb. Designed to, intended to, and analysis predicts are honest descriptions of design intent. Testing showed, validated against, and reviewed by are descriptions of evidence. A developer that never uses the first set is either not being careful or is counting on you not to notice.
**Three: is the regulatory status stated precisely?** Pre-applicant, applicant, and licensee are distinct. Proposed rules are proposals: Part 57 was published for comment in May 2026 and is not final [[6]](#src-6), and the NRC describes pre-application activities as early interaction preceding any application [[11]](#src-11). Vagueness here is rarely accidental.
**Four: what can an outside party check without the developer helping?** Regulator and laboratory documents are checkable by anyone. A slide is not. This is the test we consider load-bearing, and the extended version is in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) and in [how to verify an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).
**An honest limitation.** We cannot demonstrate our own passive safety performance to you through a blog post, and we are not going to try. The NRC glossary describes the general concept [[1]](#src-1); the specific behavior of any reactor is established through qualified analysis and testing under regulatory review, and we have not completed that process. We also deliberately publish no core geometry, fuel loading, enrichment specifics, or reactivity coefficients, because that data is subject to export control under 10 CFR Part 810. The cost of that decision is that this article stays at the level of concept and method. We think a reader is better served by an explicit boundary than by detail that reads as substantiation and is not.

## Frequently asked questions

### What does walk-away safe mean for a nuclear reactor?
It means the reactor can lose electrical power, active cooling, and its operators at the same time and still shut down and remove its decay heat through natural physical processes rather than through equipment that has to keep working. The demanding part is simultaneity: a claim about a single component failure is describing something much easier. The NRC term for the underlying idea is passive safety, defined as design characteristics that perform a safety function using natural forces such as gravity, natural circulation, and conduction, without electrical power or operator action [[1]](#src-1).

### Is passive safety the same as being completely safe?
No, and treating it that way is the most common error in this subject. Passive safety is a design approach recognized by the NRC [[1]](#src-1) and used widely across the small reactor field as described by the IAEA [[2]](#src-2). Applying the approach to a specific machine is a separate matter that has to be established through qualified analysis and testing under regulatory review. The honest formulation is that a reactor is designed to rely on passive features, with performance subject to that review, rather than that it is safe.

### How does a reactor remove heat without pumps?
Through natural circulation, conduction, and thermal radiation working together. Heated fluid rises and cooler fluid falls, establishing a loop driven by temperature difference and gravity; heat conducts out through solid structure; and hot surfaces radiate to cooler ones. The NRC names gravity, natural circulation, and conduction in its definition of passive safety [[1]](#src-1), and the IAEA describes the same reliance in small reactors [[2]](#src-2). The question worth asking of any design is where the heat finally goes and whether that ultimate heat sink can be lost.

### Why does a smaller reactor make passive cooling easier?
Because decay heat scales with the power the reactor was producing, while the structural mass and surface area available to absorb and shed that heat do not scale down as fast. A microreactor, at the roughly one to twenty megawatts DOE describes for the class [[4]](#src-4), has far less heat to remove in absolute terms than a large plant, and the IAEA notes that reduced size and power allow greater reliance on passive systems and inherent characteristics [[2]](#src-2). This makes passive heat removal plausible for a design. It does not by itself substantiate it.

### How do I tell a rigorous walk-away claim from marketing?
Four tests. Does the claim name the failure set, including simultaneous loss of power, cooling, and operators, and the duration covered? Does it distinguish what is designed from what has been demonstrated? Is the regulatory status stated precisely, given that proposed Part 57 was published for comment in May 2026 and is not final [[6]](#src-6) and that pre-application activity precedes any application [[11]](#src-11)? And can an outside party check the evidence without the developer helping [[10]](#src-10)? Absolute phrasing that removes the need for the rest of the safety case is the clearest warning sign.

## Sources

- [U.S. Nuclear Regulatory Commission. Glossary: Passive safety](https://www.nrc.gov/reading-rm/basic-ref/glossary/passive-safety.html)
- [International Atomic Energy Agency. Small Modular Reactors](https://www.iaea.org/topics/small-modular-reactors)
- [International Atomic Energy Agency. What are Small Modular Reactors (SMRs)?](https://www.iaea.org/newscenter/news/what-are-small-modular-reactors-smrs)
- [U.S. Department of Energy, Office of Nuclear Energy. What is a Nuclear Microreactor?](https://www.energy.gov/ne/articles/what-nuclear-microreactor)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [Idaho National Laboratory / GAIN. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). June 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [What is a nuclear microreactor? →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor technology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor/

# What Is a Nuclear Microreactor? A Complete 2026 Guide

> A nuclear microreactor is a factory-built reactor producing roughly 1 to 20 megawatts, per DOE, small enough to ship on a truck to where power is needed.

[Resources](https://rankshieldenergy.com/resources) / Reactor fundamentals Reactor fundamentals

# What is a nuclear microreactor?
Published July 21, 2026 · Updated July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy
A nuclear microreactor is a very small fission reactor that the U.S. Department of Energy describes as producing roughly one to twenty megawatts, small enough to be built in a factory and shipped to a site largely complete, and transportable by truck, rail, or ship. That is the whole definition. It says nothing about which coolant a design uses, what fuel it burns, or how it behaves when power is lost, because those are engineering choices made inside the envelope and they differ enormously between developers. This guide covers what the class is, how these machines work, how they differ from small modular reactors, why the category is drawing attention in 2026, and how to tell a substantiated microreactor claim from a loose one.
The reason the distinction matters is that the word microreactor is doing two jobs in public conversation at once. It is a category term about size, siting, and manufacturing, which is well defined and uncontroversial [[1]](#src-1). It is also, increasingly, a shorthand for a set of safety and autonomy claims that belong to individual designs and that each design has to substantiate on its own through analysis and testing under regulatory review. Those are not the same kind of statement, and conflating them is where most confusion starts.
So this guide keeps them apart. Where something is a settled description of the class, it is attributed to the DOE, the NRC, the IAEA, or a national laboratory. Where something is design intent that has not been demonstrated, it is labeled as such. RankShield Energy is a pre-applicant engaged in early interaction with the NRC and holds no license, permit, or design approval [[12]](#src-12), so the same standard is applied to us in the closing section.
Key takeaways

- DOE defines a microreactor by size and form: roughly one to twenty megawatts, factory built, and transportable.
- The definition covers manufacturing and siting. It does not by itself certify anything about how a specific reactor behaves in an accident.
- Microreactors are a subset of the small reactor family. The IAEA describes small modular reactors as up to about 300 megawatts of electricity per unit.
- Three things changed at once: demand for firm around-the-clock power, licensing modernization at the NRC, and a federal program to make HALEU fuel available.
- Autonomous control of a simulated microreactor has been demonstrated at national-laboratory scale. Commercial fleet operation has not, because no commercial fleet exists.
- The useful question to ask any developer is not what the reactor is designed to do, but what has been demonstrated, to whom, and under what review.

## What is a nuclear microreactor?
A nuclear microreactor is a very small fission reactor that the U.S. Department of Energy describes as generating roughly one to twenty megawatts, built in a factory rather than assembled in place, and small enough to be transported to a site by truck, rail, or ship [[1]](#src-1).
Three attributes carry the definition. It is **small**, measured in single or low double digit megawatts rather than hundreds or thousands. It is **factory fabricated**, which moves most assembly work off a construction site and into a controlled production environment where components can be inspected before shipment. And it is **transportable**, which is what allows a unit to be delivered to a load instead of requiring the load to be built beside a central station [[1]](#src-1).
Notice what the definition leaves out. It says nothing about coolant, fuel form, power conversion, siting rules, or accident behavior. Two machines can both be microreactors and share almost nothing else. One may be cooled by a liquid metal, another by a gas, another by heat pipes that move heat without a pump. They face the same regulator and the same physics, but their safety cases are separate documents built on separate evidence.
That gap between category and design is the single most useful thing to hold onto when reading about this technology. A statement about microreactors in general is usually a statement about size, manufacturing, and siting. A statement about what happens inside a specific reactor when power and cooling and staff are all lost at once is a statement about one design, and it has to be substantiated by that design through analysis and testing under regulatory review. The same discipline applies to every claim about [walk-away safety](https://rankshieldenergy.com/resources/walk-away-safety-explained) you will encounter.

## How small is a microreactor compared with a conventional plant?
Two to three orders of magnitude smaller in power output. A single large light-water unit at a conventional station produces around a thousand megawatts of electricity. A microreactor, at roughly one to twenty megawatts, sits in a different regime entirely [[1]](#src-1).
That difference is not simply a matter of scaling a familiar machine down. Below a certain size the engineering logic inverts. A conventional plant is built around large active systems, redundant pumps, and the emergency power needed to run them, because the amount of heat that has to be moved after shutdown is very large in absolute terms. A reactor producing a small fraction of that heat has correspondingly less to remove, and it can carry proportionally more structural material and surface area per unit of heat. That ratio is the reason designers in this class lean on natural processes rather than pumps, a point the IAEA makes about small reactors generally [[3]](#src-3).
Small size also changes the delivery model. A reactor that leaves a factory as a largely finished module can be manufactured under controlled conditions, quality checked before it ships, and installed on a prepared pad in a fraction of the time a conventional station takes to build [[1]](#src-1). For a data center, a remote community, an industrial process heat customer, or a defense installation, the practical appeal is a unit that arrives rather than a project that begins.
There is a corresponding trade. Small units produce less power each, so serving a large load means operating several of them, which multiplies the number of machines a regulator, an insurer, and an operator all have to keep track of. The industry answer is fleet operation with reduced on-site staffing, and that answer creates its own oversight problem rather than dissolving the original one.

## How does a microreactor actually work?
It works on the same principle as any fission reactor. Neutrons split heavy atoms such as uranium, the fission releases heat, and that heat is carried out of the core and either converted to electricity or used directly as process heat. What varies across designs is how the heat is carried and what the reactor does when the normal heat path stops working.
Most microreactor concepts avoid water as a coolant. Water-cooled reactors operate at high pressure, and much of the conventional safety case is built around keeping that pressure contained and replacing water that boils off. Designs cooled by liquid metals, gases, molten salts, or by heat pipes operate at low pressure by comparison, which removes an entire family of accident sequences and replaces it with a different set of engineering problems, including materials behavior at high temperature and the qualification data needed to support it.
The other common feature is a heavy reliance on passive design characteristics, meaning safety functions carried by natural forces such as gravity, natural circulation, and conduction rather than by powered equipment or operator action. DOE describes this reliance when characterizing the microreactor class [[1]](#src-1), and the IAEA describes the same approach across small reactors generally [[3]](#src-3). It is a design approach recognized by government and international bodies, not a property a reactor is granted by being small. Any specific machine still has to demonstrate that its passive features do what its analysis predicts, through qualified analysis and testing under regulatory review.
Many designs in this class also use TRISO fuel. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic that act as a containment barrier around each individual particle [[2]](#src-2). That is DOE characterizing a fuel concept, and it is worth citing precisely because it is the version of the claim that comes with public technical backing rather than a vendor brochure.

## What fuel do microreactors use, and what does TRISO actually do?
Most designs in the class use some form of high-assay low-enriched uranium, and many of them package it as TRISO. The NRC defines high-assay low-enriched uranium, or HALEU, as uranium enriched to between five and twenty percent in the fissile isotope, above the level used by the current commercial fleet and below the threshold that defines highly enriched material [[8]](#src-8).
The reason the class needs it is straightforward. A very small core has less room for fuel, so a higher fissile fraction is what allows a reactor of that size to sustain a chain reaction and to run for a long interval between refuelings. That is a general property of small cores, not a claim about any one design.
TRISO addresses a different problem. DOE describes TRISO particles as uranium kernels wrapped in successive layers of carbon and silicon carbide, so that each particle carries its own containment barrier around the fission products it produces [[2]](#src-2). The engineering appeal is that the barrier is distributed across millions of particles rather than concentrated in one boundary. DOE presents this as a robust fuel form, and that framing belongs to DOE. What any individual reactor achieves with it depends on the specific fuel qualification data submitted for that design and reviewed by the regulator.
Fuel is also where the schedule risk in this industry actually sits. The supply chain for HALEU is being stood up rather than drawn on, which is why DOE established a HALEU Availability Program to support the availability of that material for advanced reactor developers [[7]](#src-7). A developer with an elegant design and no path to qualified fuel does not have a product. We treat fuel availability as a gating question rather than a procurement detail, and it is worth reading [where HALEU actually comes from](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel) before evaluating any deployment timeline.

## How is a microreactor different from a small modular reactor?
A microreactor is a much smaller subset of the same family. The IAEA describes small modular reactors as advanced reactors producing up to about 300 megawatts of electricity per unit, roughly a third of the capacity of a traditional power reactor, built in modules in a factory setting [[3]](#src-3). Microreactors sit at the far low end of that spectrum, at roughly one to twenty megawatts [[1]](#src-1).
The difference is not only arithmetic. At SMR scale the machine is still a power station in the conventional sense: a fixed site, a substantial construction program, grid interconnection as the primary purpose, and a staffed control room. At microreactor scale the unit is closer to equipment. It is delivered, sited near a specific load, and in many concepts removed and returned rather than serviced in place [[1]](#src-1).
That shift changes which regulatory questions are hard. For a large plant, the demanding questions concern the accident analysis for a big core and the emergency planning zone around it. For a microreactor, the demanding questions concern transport, siting close to industrial or population loads, staffing levels, and how a regulator maintains oversight of many small units rather than a few large ones. The NRC has a dedicated body of work on microreactor-specific regulatory issues for exactly this reason [[4]](#src-4).
One practical consequence for readers: evidence does not transfer across the boundary. A demonstration involving an SMR does not substantiate a microreactor claim, and a licensing milestone reached by an SMR developer says nothing about where a microreactor developer stands. When a company cites progress in the broader advanced reactor sector as though it were its own, that is a category error worth catching.

## Why is this class drawing attention in 2026?
Three things moved at once: demand for firm around-the-clock power, licensing modernization at the NRC, and a federal effort to make advanced reactor fuel available. None of them alone would have been enough.
The demand side is the most visible. Large industrial and data center loads want power that is available continuously and that can be sited where the load is, and the interest in this reactor class follows from that requirement rather than from any claim about the price of electricity, which is outside the scope of this article.
The regulatory side is where the substantive change is. The NRC maintains an active program of microreactor-specific regulatory activities addressing factory fabrication, transport, and staffing [[4]](#src-4). In March 2026 the agency published its risk-informed, technology-inclusive framework for advanced reactors in the Federal Register, the rulemaking known as Part 53 [[6]](#src-6). In May 2026 it published a proposed rule, 10 CFR Part 57, addressing licensing requirements for microreactors and other reactors with comparable risk profiles [[5]](#src-5). Part 57 is a **proposed** rule. It is not final, it may change before it is, and no developer is licensed under it. Anything you read that treats Part 57 as settled law is wrong today, and the detail is worth understanding directly in our explainer on [what Part 57 proposes about remote and reduced-staffing operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained).
The fuel side is the third leg. DOE established the HALEU Availability Program to support availability of high-assay low-enriched uranium for advanced reactor developers [[7]](#src-7), and the NRC has published its own material on the licensing and regulatory treatment of HALEU [[8]](#src-8). Fuel that is being produced changes what a development schedule can honestly promise. Fuel that is planned does not.

## What has been demonstrated, and what is still design intent?
This is the question that separates a serious reading of the field from an enthusiastic one, and the honest answer is that real capability exists at national-laboratory scale while commercial operation does not yet exist at all.
On the demonstrated side: DOE reported that Idaho National Laboratory demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10). That is a genuine result, and it belongs to a national laboratory rather than to any vendor. INL also describes MARVEL as a microreactor project being developed at the laboratory to test microreactor applications and integration with end users [[9]](#src-9), which is a test platform rather than a commercial deployment.
On the still-open side: the microreactor program plan prepared by INL and GAIN for DOE lays out a coordinated federal program of research, development, and demonstration for this class [[11]](#src-11). A national program plan exists because the work is not finished. That is the correct way to read it, and it is more informative than any single vendor announcement.
**The counterargument worth taking seriously** is that this is how every new technology looks shortly before it works, and that demanding commercial operating history from a class of machine that has not yet been deployed is an unfalsifiable standard. That is fair as far as it goes. Our response is that the standard being asked for is not operating history, it is *evidence proportional to the claim*. A developer can substantiate a materials result, a fuel qualification result, or a control demonstration today without having operated anything commercially. What a developer cannot do is borrow the credibility of a laboratory result for a claim the laboratory did not make. The practical version of this problem is covered in [how you would verify an autonomous microreactor is operating safely](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely).

## How should you evaluate a microreactor claim?
Apply four tests, in this order, to any statement you encounter about any developer including us.
**One: is it a claim about the class or about the design?** Statements about size, factory fabrication, and transportability are class facts and are well documented [[1]](#src-1). Statements about how a specific machine behaves in an accident are design claims and require that design to produce evidence.
**Two: designed or demonstrated?** These are different words and the difference is not stylistic. Design intent describes what analysis predicts. Demonstration describes what testing showed, to whom, and under what review. Passive design characteristics are a recognized approach that DOE describes for this class [[1]](#src-1) and the IAEA describes for small reactors generally [[3]](#src-3), and every specific reactor still has to show that its own features perform through qualified analysis and testing under regulatory review.
**Three: what is the regulatory status, stated precisely?** Pre-applicant, applicant, and licensee are distinct positions. Proposed rules are proposals: Part 57 was published for comment in May 2026 and is not final [[5]](#src-5), and the NRC describes pre-application activities as early interaction that precedes any application [[12]](#src-12). A developer that blurs these is telling you something about its rigor.
**Four: who else can check it?** Ask what an outside party could establish without the developer participating. A federal program plan [[11]](#src-11) or a laboratory result [[10]](#src-10) is checkable. A brochure is not. The full version of this checklist is in our [guide to evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and it is written to be used against us as readily as against anyone else.
**An honest limitation of this article.** Because specific reactor technical data can be export controlled under 10 CFR Part 810, we deliberately keep our own design specifics off a public page. That is a decision with a real cost: this guide is less concrete about our machine than a reader would reasonably want, and we would rather state that plainly than let vague language stand in for detail we are not going to publish. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[12]](#src-12), and nothing here should be read as a representation that anything about our design has been demonstrated to or accepted by the NRC.

## Frequently asked questions

### What is a nuclear microreactor in simple terms?
It is a very small nuclear reactor that DOE describes as producing roughly one to twenty megawatts, built in a factory rather than assembled at the site, and transportable by truck, rail, or ship [[1]](#src-1). The definition is about size, manufacturing, and mobility. It does not by itself say anything about the coolant, the fuel, or how a particular machine behaves in an accident, because those are design choices that vary widely between developers and that each developer has to substantiate separately.

### Is a microreactor the same as a small modular reactor?
No. A microreactor is a much smaller subset of the same family. The IAEA describes small modular reactors as producing up to about 300 megawatts of electricity per unit, roughly a third of the capacity of a traditional power reactor [[3]](#src-3), while microreactors sit at roughly one to twenty megawatts [[1]](#src-1). The practical consequence is that evidence does not transfer across the boundary. A licensing milestone or demonstration achieved by an SMR developer does not substantiate a microreactor claim.

### What fuel do microreactors use?
Most designs use high-assay low-enriched uranium, which the NRC defines as uranium enriched to between five and twenty percent in the fissile isotope [[8]](#src-8), and many package it as TRISO fuel. DOE describes TRISO particles as uranium kernels encapsulated in layers of carbon and ceramic that act as a containment barrier around each particle [[2]](#src-2). Supply is a live constraint rather than a settled one, which is why DOE established a HALEU Availability Program to support fuel availability for advanced reactor developers [[7]](#src-7).

### Are microreactors approved by the NRC?
Not as a class, and no developer should be described as approved on the strength of the category. The NRC maintains an active program of microreactor-specific regulatory activities [[4]](#src-4), published its Part 53 framework for advanced reactors in March 2026 [[6]](#src-6), and published a proposed Part 57 rule for microreactor licensing in May 2026 [[5]](#src-5). Part 57 is proposed, not final. RankShield Energy is a pre-applicant engaged in early interaction with the NRC [[12]](#src-12) and holds no license, permit, or design approval.

### Has any microreactor actually been demonstrated?
Real work exists at national-laboratory scale, and commercial operation does not. DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [[10]](#src-10), and INL describes MARVEL as a microreactor project being developed at the laboratory to test applications and integration with end users [[9]](#src-9). The federal microreactor program plan prepared by INL and GAIN sets out the research and demonstration work still to be done [[11]](#src-11), which is the most honest summary of where the class stands.

## Sources

- [U.S. Department of Energy, Office of Nuclear Energy. What is a Nuclear Microreactor?](https://www.energy.gov/ne/articles/what-nuclear-microreactor)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [International Atomic Energy Agency. What are Small Modular Reactors (SMRs)?](https://www.iaea.org/newscenter/news/what-are-small-modular-reactors-smrs)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53). Federal Register, March 30, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Nuclear Regulatory Commission. High-Assay Low-Enriched Uranium (HALEU)](https://www.nrc.gov/materials/new-fuels/haleu)
- [Idaho National Laboratory. MARVEL Project](https://inl.gov/marvel/)
- [U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022](https://www.energy.gov/ne/articles/idaho-national-laboratory-demonstrates-first-digital-twin-simulated-microreactor)
- [Idaho National Laboratory / GAIN. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). June 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [Walk-away safety, explained →](https://rankshieldenergy.com/resources/walk-away-safety-explained)
- [Where HALEU comes from →](https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of microreactor technology and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/where-haleu-comes-from-advanced-reactor-fuel/

# Where HALEU Comes From: Fuel for Advanced Reactors

> HALEU is the fuel most advanced reactors need, and supply is still being stood up. Here is where it comes from and why it shapes deployment timelines.

[Resources](https://rankshieldenergy.com/resources) / Deployment Deployment

# Where HALEU Comes From: The Fuel Supply Behind Advanced Reactors
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Most advanced reactor designs need a fuel called high-assay low-enriched uranium, or HALEU: uranium enriched above the assay used by today's commercial fleet and below the line that separates low-enriched from highly enriched material. The physics of using it is well understood and has been studied for decades. The binding constraint is supply. Fuel belongs in every honest project schedule as a first-order input with named suppliers and named dates, not as a footnote to be resolved later.
The supply picture has three parts that are easy to run together and should not be. Federal auditors reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers [[10]](#src-10). Congress responded with a statutory program directing the Department of Energy to support availability of the material [[4]](#src-4). And DOE now runs a published process for allocating the limited quantities that exist to developers who apply for them [[5]](#src-5). An authorization, an allocation, and delivered material are three different things.
This article covers what HALEU is and how DOE defines it, why compact long-cycle designs need higher assay, where supply actually stands, the statutory basis for the availability program, what the allocation rounds reveal about demand, how domestic enrichment is scaling, why fabrication and qualification are separate bottlenecks from enrichment, and how to read fuel in a project schedule. RankShield Energy is a pre-applicant holding no license, permit, or design approval [[16]](#src-16), and the closing section applies all of it to us.
Key takeaways

- HALEU is uranium enriched above roughly 5 percent and below 20 percent, though DOE states the upper bound two different ways across its own pages.
- Higher assay is a packing solution: smaller cores running longer between refuelings need more fissile material in less volume.
- The physics is settled; supply is the constraint. GAO reported in 2022 that HALEU was not available at commercial scale from domestic suppliers.
- DOE allocation rounds are evidence of scarcity: an allocation process is what you build when demand exceeds what exists.
- Enrichment, fabrication, and qualification are three separate schedules, and a project is fuel-ready only when all three land.

## HALEU is uranium enriched above 5 percent, and DOE states the upper bound two different ways
High-assay low-enriched uranium is uranium whose uranium-235 content sits above the assay used by the existing commercial fleet and below the line that separates low-enriched from highly enriched material. DOE's explainer defines it as enriched to greater than 5 and less than 20 weight percent uranium-235, and notes that today's commercial light-water reactors run on uranium enriched up to about 5 percent [[1]](#src-1). DOE's HALEU frequently asked questions page uses that same greater-than-5-and-less-than-20 phrasing [[2]](#src-2).
DOE's HALEU Enrichment Services page describes the same material as enriched to between 5 and 19.75 percent [[3]](#src-3). Those two statements are not identical, and the difference is not a typographical accident. One states an open band up to a regulatory boundary. The other states a band that stops at a specific assay below that boundary.
We are flagging this because we ran the primary sources side by side rather than taking one page as the whole answer, and it is the kind of detail that gets lost when writers paraphrase a definition from memory. For a reader orienting to the topic, either phrasing is close enough to be useful. For a schedule assumption, a procurement document, or anything that will end up in front of a regulator, the two are not interchangeable, and the honest move is to cite the specific page you took the number from rather than presenting a single tidy figure as though DOE speaks with one voice on it.
The practical takeaway is small but real. When you see the HALEU band written a particular way in a vendor deck or a news article, check which federal page it traces to. Consistency between a claim and its source is the cheapest available signal of how carefully the rest of the document was assembled.

## Compact designs with long operating cycles need higher assay to carry enough fissile material
The reason so many advanced designs converge on HALEU is a packing problem rather than an exotic one. A smaller core has less room for fuel, and a core intended to run a long interval between refuelings has to hold enough fissile material at the start to sustain the chain reaction all the way to the end of that interval. Raising the assay is how designers get more uranium-235 into a given volume. DOE puts the consequence plainly: higher-assay fuel supports smaller plant designs, longer operating cycles, and higher efficiencies than the existing fleet achieves on conventional low-enriched fuel [[1]](#src-1).
That design logic is what produced the [microreactor class](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor) in the first place. GAO's technology spotlight describes nuclear microreactors as small, factory-fabricated units intended to be transportable and to operate for extended periods, and identifies the fuel they generally require as high-assay low-enriched uranium [[11]](#src-11). The fuel choice is not a preference bolted onto the concept. It is upstream of the concept.
DOE's microreactor program plan reflects the same ordering. The program is organized around technical areas that include fuel alongside the reactor technologies themselves, which is a signal that federal program managers treat fuel development as program-level work rather than as a downstream procurement task to be handled once a design is finished [[15]](#src-15).
The consequence for anyone reading design literature is that the assay decision drags a whole supply chain behind it. A design that needs HALEU does not simply need uranium. It needs enrichment capacity configured for that band, a fabricator able to make its specific fuel form, and a qualification record a regulator will accept. Each of those is a separate organization, a separate schedule, and a separate way for a project to slip.

## The binding constraint today is supply, and the federal government is the main route to material
The physics of using higher-assay fuel is well understood. The constraint is that there is not much HALEU available to buy. GAO reported in September 2022 that "The primary source of commercially available HALEU today is from Russia," and that the material "is not currently available at commercial scale from domestic suppliers" [[10]](#src-10). That report is now several years old and the domestic picture has moved since, which is exactly why the date matters when the sentence gets quoted. Read it as a description of the starting position rather than as a live snapshot.
GAO had flagged the broader vulnerability earlier still, finding in December 2020 that risks to the domestic uranium supply chain needed better planning and coordination across the agencies responsible for them [[12]](#src-12). The HALEU shortfall is a specific instance of a supply-chain problem that federal auditors had already named in general terms.
Today the practical route to material for most U.S. advanced reactor developers runs through the Department of Energy rather than through an open commercial market. DOE stood up an allocation process for distributing limited quantities of HALEU to developers [[5]](#src-5), which is the arrangement you build when demand exceeds what is available. Meanwhile domestic output remains modest in absolute terms: DOE-NE reported that cumulative U.S. HALEU production reached 900 kilograms by the end of June 2025 [[8]](#src-8).
It helps to see the whole chain at once, because the conversation usually collapses into enrichment alone when enrichment is only the first of several gates.

Stages a HALEU-fueled design has to clear, what each requires, and where each stood as of the cited sources

Stage
What it requires
Where it stands in the cited record

Enrichment above 5 percent
Operating enrichment capacity licensed and configured to produce assays above the roughly 5 percent used by the existing fleet
GAO reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers [[10]](#src-10). DOE-NE reported cumulative U.S. production of 900 kilograms by the end of June 2025 from a 16-centrifuge cascade in Piketon, Ohio [[8]](#src-8).

Access to material
A route to obtain quantities, which for most developers today runs through a federal program rather than an open commercial market
DOE established a published allocation process [[5]](#src-5) under the HALEU Availability Program [[4]](#src-4), and has announced conditional commitments in successive rounds [[6]](#src-6) [[7]](#src-7).

Fuel fabrication
Production lines able to turn enriched material into the specific fuel form a given design uses, at rate and to specification
DOE selected four companies for advanced nuclear fuel line pilot projects in September 2025 [[9]](#src-9), which is a signal that domestic fabrication capacity was still being stood up.

Fuel qualification
Irradiation testing and a documented performance dataset that a regulator can review for the form and conditions in question
The DOE Advanced Gas Reactor program was established to develop and qualify TRISO fuel and to produce that dataset [[14]](#src-14). DOE reports that the AGR-1 experiment reached 19 percent peak burnup with zero particle failures [[13]](#src-13).

Every row in that table is a separate industrial capability with its own lead time. A project is not fuel-ready when one of them clears. It is fuel-ready when all of them do, for its specific fuel form, on dates that line up.

## The HALEU Availability Program exists because Congress directed it
The federal effort here is not discretionary enthusiasm. DOE describes the HALEU Availability Program as established by section 2001(a)(1) of the Energy Act of 2020, with the purpose of supporting the availability of HALEU for civilian domestic demonstration and commercial use [[4]](#src-4).
Congress then attached a quantity and a schedule. DOE notes that section 3131(h) of the National Defense Authorization Act for Fiscal Year 2024 set a schedule under which the Department is to seek to make available 21 metric tons of HALEU [[4]](#src-4). That is a directive to seek to make material available, which is a meaningfully different thing from a delivered inventory, and the statutory language is worth reading in exactly those terms.
The program also has an operational face. DOE contracts for HALEU enrichment services as one of the mechanisms for building domestic capability [[3]](#src-3), and publishes the process by which available material is allocated to applicants [[5]](#src-5). Together those give the field something it did not have before: a defined, documented route to request material, with published criteria, rather than an informal queue.
The honest reading of a statutory program is that it tells you what the government has committed to attempt, on what timeline, and under what authority. It does not tell you that the material exists. Both facts can be true at once, and a project schedule that quietly converts the first into the second has introduced an assumption its own authors may not notice. When you see a developer point to the HALEU Availability Program as evidence that fuel is handled, the follow-up question is whether they are pointing at an authorization or at an allocation, because those are different objects.

## Two allocation rounds show demand running ahead of available material
The allocation record is the clearest public evidence of the imbalance, because it shows how many parties asked and how many were served. In April 2025 DOE announced conditional commitments in its initial round to TRISO-X, Kairos Power, Radiant Industries, Westinghouse and TerraPower, and reported that 15 companies had requested HALEU [[6]](#src-6). In August 2025 DOE announced a further round of conditional commitments to Antares Nuclear, Standard Nuclear, and Abilene Christian University together with Natura Resources [[7]](#src-7).
To be explicit about what that paragraph is and is not: it is factual reporting of two Department of Energy announcements. This article does not rank, score, rate, or compare any of the companies named, and nothing about appearing in a DOE round should be read here as an endorsement of a design, a schedule, or an organization. We name them because the composition of the rounds is public information that a reader evaluating the supply picture is entitled to have.
The structural signal is in the arithmetic rather than the names. An allocation process gets built when a resource is scarce enough that it has to be rationed, and DOE published one [[5]](#src-5). More companies requested material than received commitments in the initial round [[6]](#src-6). And the commitments themselves are conditional, which means conditions attach before material moves.
Read alongside the statutory target [[4]](#src-4), the rounds describe a federal program doing what it was directed to do, at a scale set by what is actually available rather than by what the field would like. That is not a criticism of the program. It is the reason fuel deserves a line on a project schedule instead of a footnote.

## Domestic enrichment is scaling up, and the published numbers show how early it is
The most concrete public marker of domestic progress is the Piketon, Ohio cascade. DOE-NE reported that cumulative U.S. HALEU production reached 900 kilograms by the end of June 2025, produced by Centrus from a 16-centrifuge cascade [[8]](#src-8). That is a real, verified, domestically produced quantity where a few years earlier there was effectively none.
Set that against projected need. DOE-NE has estimated that domestic HALEU demand could reach 50 metric tons per year by 2035 [[8]](#src-8). The two figures are not the same kind of measurement and should not be subtracted from one another. One is cumulative output through a date. The other is a projected annual requirement roughly a decade out. Stated in common units, 900 kilograms is 0.9 metric tons of cumulative production, against a projection of 50 metric tons required each year. What the pair describes is the distance between where domestic production had reached and where projected demand sits, and the number of doublings implied by closing it.
The scale-up mechanism is partly contractual. DOE procures HALEU enrichment services as one way of building the domestic capability the statute directs it to pursue [[3]](#src-3), under the availability program Congress established [[4]](#src-4). A 16-centrifuge cascade is a demonstration-scale machine, and moving from demonstration scale to the throughput implied by tens of metric tons per year is a capital, licensing, and construction problem rather than a scientific one.
None of this contradicts GAO's September 2022 finding about the starting position [[10]](#src-10). It refines it. The domestic capability that GAO reported as absent at commercial scale now exists at demonstration scale and is producing measurable output. Whether it arrives at commercial scale in time for any particular project is a schedule question, and the answer is specific to that project rather than general to the industry.

## Fabrication and qualification are separate bottlenecks from enrichment
Enriched uranium is not fuel. A reactor needs fuel elements in a specific geometry and chemical form, fabricated to specification, made on a line that can produce them at rate. That is a distinct industrial capability from enrichment, run by different organizations, and it can bind a schedule even when material is available. DOE selected four companies for advanced nuclear fuel line pilot projects in September 2025 [[9]](#src-9), which tells you domestic fabrication capacity for advanced fuel forms was still being established at that point.
Qualification is a third gate. For the TRISO fuel form, DOE describes a design in which a uranium kernel is surrounded by three layers of carbon and silicon carbide, so that each particle functions as its own containment system, and reports that the particles have been tested to 1,800 degrees Celsius with low fission product release [[13]](#src-13). DOE also reports that the AGR-1 experiment reached 19 percent peak burnup with zero particle failures [[13]](#src-13), results generated within the DOE Advanced Gas Reactor Fuel Development and Qualification Program, which was established to develop and qualify the fuel form and to build the performance dataset that supports it [[14]](#src-14).
Two qualifications on that paragraph, both of which matter. First, those are DOE's characterizations of a fuel form under test conditions, not a safety finding about any particular reactor. A robust fuel form is an input to a safety case, never a substitute for one, and the [passive safety claims](https://rankshieldenergy.com/resources/walk-away-safety-explained) that get made about advanced designs remain subject to analysis, testing, and NRC review for each specific design. Second, a qualification dataset covers the conditions it was generated under. A design operating outside that envelope inherits the testing burden rather than the conclusion.
This is also where the microreactor program plan's treatment of fuel as program-level work reads as sound program management rather than bureaucratic hedging [[15]](#src-15). Enrichment, fabrication, and qualification are three schedules that all have to land, and only one of them is the one everybody talks about.

## How to read fuel in a developer's schedule, including ours
Fuel is where optimistic schedules go to become real, so it is worth a short list of questions that separate a plan from an intention. Which specific fuel form does the design use? Has that form been fabricated at production rate by an identified supplier, or does it exist as a laboratory or pilot article? What qualification dataset covers it, and does the design operate inside the conditions that dataset actually spans? Is there an allocation, a conditional commitment, or a commercial contract, and which one? And what does the schedule do if fuel arrives late, since a design that has no answer there has embedded a single point of failure it has not disclosed.
Those questions belong next to the ones in our [vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they bear directly on the [speed-to-power case for data centers](https://rankshieldenergy.com/resources/speed-to-power-data-centers-firm-nuclear), because a fuel date that slips moves an energization date with it no matter how well the rest of the project is run. A developer who cannot separate an authorization from an allocation on their own schedule has not done this work.
Applied to us, unsentimentally. RankShield Energy is a pre-applicant engaged in early interaction with the U.S. Nuclear Regulatory Commission [[16]](#src-16). We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC. We have not secured HALEU supply, we hold no DOE allocation, and we are not named in any allocation round [[5]](#src-5). HALEU supply is a real constraint on our schedule exactly as it is for the rest of the field, and we would rather write that down than imply otherwise by omission.
Our position, stated so it can be argued with: fuel belongs in the schedule as a first-order input with named suppliers, named dates, and a stated fallback, not as an assumption in a footnote. That is a harder document to write and an easier one to check, which is the tradeoff we are choosing. If you want the regulatory half of the same picture, our explainer on [how NRC pre-application works](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) covers what a pre-applicant can and cannot claim.

## Frequently asked questions

### What exactly is HALEU?
High-assay low-enriched uranium is uranium with a higher uranium-235 content than the fuel used by today's commercial light-water reactors, which run on uranium enriched up to about 5 percent. DOE's explainer defines HALEU as enriched to greater than 5 and less than 20 weight percent uranium-235 [[1]](#src-1), and its frequently asked questions page uses the same phrasing [[2]](#src-2). Worth knowing: DOE's HALEU Enrichment Services page states the band as between 5 and 19.75 percent [[3]](#src-3). Both descriptions come from the Department of Energy, so cite the specific page you are relying on rather than treating one number as settled.

### Why do advanced reactors need higher-assay fuel?
It is a packing problem. A smaller core has less volume for fuel, and a longer interval between refuelings requires more fissile material loaded at the start. Higher assay is how designers fit enough uranium-235 into the space available. DOE states that higher-assay fuel supports smaller plant designs, longer operating cycles, and higher efficiencies [[1]](#src-1), and GAO's technology spotlight identifies HALEU as the fuel the microreactor class generally requires [[11]](#src-11). The fuel choice sits upstream of the design concept rather than downstream of it.

### Is there enough HALEU available today?
Not at commercial scale from domestic suppliers, on the public record. GAO reported in September 2022 that HALEU was not then available at commercial scale from domestic suppliers and that the primary source of commercially available material was Russia [[10]](#src-10); note the date, because the domestic picture has moved since. DOE-NE reported cumulative U.S. production of 900 kilograms by the end of June 2025 from a 16-centrifuge cascade, against a DOE-NE estimate that domestic demand could reach 50 metric tons per year by 2035 [[8]](#src-8). Those are different kinds of figure, one cumulative and one annual, and the gap between them is the reason a federal allocation process exists.

### What is the HALEU Availability Program?
It is the federal program DOE describes as established by section 2001(a)(1) of the Energy Act of 2020 to support the availability of HALEU for civilian domestic demonstration and commercial use, with section 3131(h) of the FY2024 National Defense Authorization Act setting a schedule under which the Department is to seek to make 21 metric tons available [[4]](#src-4). In practice it operates through enrichment services contracting [[3]](#src-3) and a published allocation process for distributing limited quantities to applicants [[5]](#src-5). A statutory directive to seek to make material available is not the same as material in hand, and it is worth keeping those separate when reading anyone's schedule.

### Does RankShield Energy have HALEU supply secured?
No. We have not secured HALEU supply, we hold no DOE allocation, and we are not named in any DOE allocation round [[5]](#src-5). RankShield Energy is a pre-applicant engaged in early interaction with the NRC, holding no license, permit, or design approval, with nothing about our design demonstrated to or accepted by the NRC [[16]](#src-16). Fuel supply is a genuine constraint on our schedule in the same way it is for other developers working in this class, and we would rather state that directly than let silence imply a position we have not earned.

## Sources

- [U.S. Department of Energy, Office of Nuclear Energy. What is High-Assay Low-Enriched Uranium (HALEU)?. December 2024](https://www.energy.gov/ne/articles/what-high-assay-low-enriched-uranium-haleu)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Frequently Asked Questions. Accessed July 2026](https://www.energy.gov/ne/haleu-frequently-asked-questions)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Enrichment Services. Accessed July 2026](https://www.energy.gov/ne/haleu-enrichment-services)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program. Accessed July 2026](https://www.energy.gov/ne/haleu-availability-program)
- [U.S. Department of Energy. High-Assay Low-Enriched Uranium (HALEU) Allocation Process. August 2025](https://www.energy.gov/documents/haleu-allocation-process-08282025)
- [U.S. Department of Energy. U.S. Department of Energy to Distribute First Amounts of HALEU to U.S. Advanced Reactor Developers. April 2025](https://www.energy.gov/articles/us-department-energy-distribute-first-amounts-haleu-us-advanced-reactor-developers)
- [U.S. Department of Energy. U.S. Department of Energy to Distribute Next Round of HALEU to U.S. Nuclear Industry. August 2025](https://www.energy.gov/articles/us-department-energy-distribute-next-round-haleu-us-nuclear-industry)
- [U.S. Department of Energy, Office of Nuclear Energy. Centrus Reaches 900 Kilogram Mark for HALEU Production. June 2025](https://www.energy.gov/ne/articles/centrus-reaches-900-kilogram-mark-haleu-production)
- [U.S. Department of Energy. Energy Department Selects Four Companies for Advanced Nuclear Fuel Line Pilot Projects. September 2025](https://www.energy.gov/articles/energy-department-selects-four-companies-advanced-nuclear-fuel-line-pilot-projects)
- [U.S. Government Accountability Office. Nuclear Energy Projects: DOE Should Institutionalize Oversight Plans for Demonstrations of New Reactor Types (GAO-22-105394). September 2022](https://www.gao.gov/assets/gao-22-105394.pdf)
- [U.S. Government Accountability Office. Science and Tech Spotlight: Nuclear Microreactors (GAO-20-380SP). February 2020](https://www.gao.gov/products/gao-20-380sp)
- [U.S. Government Accountability Office. Uranium Management: Actions to Mitigate Risks to Domestic Supply Chain Could Be Better Planned and Coordinated (GAO-21-28). December 2020](https://www.gao.gov/products/gao-21-28)
- [U.S. Department of Energy, Office of Nuclear Energy. TRISO Particles: The Most Robust Nuclear Fuel on Earth. Updated June 2023](https://www.energy.gov/ne/articles/triso-particles-most-robust-nuclear-fuel-earth)
- [Idaho National Laboratory. DOE Advanced Gas Reactor Fuel Development and Qualification Program (INL/MIS-23-75732). December 2023](https://www.osti.gov/biblio/2278790)
- [Idaho National Laboratory / U.S. Department of Energy. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [What is a nuclear microreactor? →](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)
- [How NRC pre-application works →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of HALEU supply and advanced-reactor fuel programs as of July 2026. This area is moving quickly. Check back if the Department of Energy or the NRC issues new allocations or guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor/

# Which NRC Regulations Apply to a Microreactor Today?

> A regulatory applicability analysis of the four NRC licensing pathways open to a microreactor developer, the guidance above them, and where the choices lie.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# Which Regulations Apply to a Microreactor? A Framework Applicability Analysis
Published August 11, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published August 11, 2026 Revised August 11, 2026 Status Regulatory applicability analysis, open for comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
A developer bringing a microreactor to the U.S. Nuclear Regulatory Commission today meets several licensing frameworks rather than one, together with a body of guidance that shapes an application without carrying the force of a rule. Two frameworks have been in force for decades, a third became effective in 2026, and a fourth exists as a proposed rule. No single published document maps which of these applies to a microreactor, and when. This paper builds that map. It is a regulatory applicability analysis: it describes the pathways at 10 CFR Parts 50, 52 and 53 and the proposed microreactor framework, the guidance architecture above them, the methodology layer beneath them, and the pre-application instruments that precede all of them. It then presents a decision map identifying, for each pathway, what it presumes about design maturity at the point of filing and the question a developer is actually deciding.
The map and the distinctions it draws are the contribution, not a recommendation. No pathway is recommended and none is ranked, because ranking requires weights that belong to a developer's business case rather than to the regulator's framework. The principal limitation is that a pathway determination is made on a specific docket against a specific design, so nothing here can be carried to a particular case without that review. A second limitation is authorship: RankShield Energy is a pre-applicant with an interest in the answer, and this paper describes frameworks rather than announcing a pathway it has selected.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses which published U.S. Nuclear Regulatory Commission licensing frameworks are available to a microreactor, what guidance sits above and beneath those frameworks, which pre-application instruments precede an application, and where a developer's actual choices lie. It draws on twenty primary sources spanning the regulator, the Government Accountability Office, the Department of Energy and a national laboratory, and the International Atomic Energy Agency. Where a document is characterized, it is cited and its status is stated: rule in force, proposed rule, draft guidance, interim staff guidance, staff paper, or research.
Several things are deliberately out of scope. The paper does not tell any party what a rule requires of it; it describes the regulator's published frameworks and leaves application to the reader and the reader's advisers. It contains no design detail for any RankShield Energy system: no geometry, no fuel description, no enrichment, no performance or lifetime figures. It contains no cost, fee, or economic analysis. It does not name, rank, or characterize other developers. It does not describe unattended or fully autonomous operation of a reactor; where operating-model provisions are mentioned, the operating model under discussion keeps a human in the loop for reactivity and safety actions. Where a guidance document's primary text sits outside the twenty cited sources, this paper names the document and describes its role in the architecture without attributing specific content to it and without citing a URL for it.
Several developments would change the analysis materially and should trigger a revision: a final microreactor licensing rule, or withdrawal or material amendment of the proposal; final rather than draft application guidance for that framework; issuance or revision of the guidance and interim staff guidance named in sections 3 and 4; a Commission decision adopting or rejecting positions analyzed in the staff papers cited here; or published agency direction on how the frameworks are expected to be applied to this reactor class. The decision map in section 7 is our reading of the cited record and is offered for disagreement.

A developer that has settled its reactor physics has not settled its regulatory question, because the U.S. Nuclear Regulatory Commission does not present a microreactor with one licensing framework. It presents several, of different ages and different legal statuses, with a layer of guidance above them that governs how an application is assembled and a layer of methodology beneath them that governs how the safety case is built. There is no single published map of which framework applies to a microreactor and when. This paper draws one.
The method is deliberately plain. Section 1 sets out why applicability is a live question rather than a formality, and what a late answer costs. Section 2 describes the four licensing pathways and states the status of each. Section 3 describes the guidance architecture that sits above the rules and explains why guidance is not requirement. Section 4 describes the methodology layer beneath them and what a developer commits to when it adopts one. Section 5 separates the pre-application instruments, which are routinely conflated. Section 6 examines the construction permit provision that most affects sequencing. Section 7 presents the decision map. Section 8 applies the analysis to RankShield Energy, including the parts we cannot answer.
Two framing points govern everything that follows. What is in force is identified as in force: the construction permit provision at 10 CFR 50.35 [[7]](#src-7), the license conditions at 10 CFR 50.54 [[8]](#src-8), and the risk-informed, technology-inclusive framework at 10 CFR Part 53, which was published as a final rule and is effective [[1]](#src-1). What is proposed is identified as proposed at every mention, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[2]](#src-2), whose companion application guidance is NUREG-2271 (draft guidance issued by the NRC staff for comment; staff guidance, not final) [[3]](#src-3). RankShield Energy is a pre-applicant engaged in early regulatory interaction and holds no NRC license, permit, or design approval [[5]](#src-5). Nothing in the design has been demonstrated to or accepted by the NRC, and this paper describes frameworks rather than announcing a pathway RankShield Energy has selected.
Key takeaways

- A microreactor developer today has three licensing pathways it can file under and a fourth it can read and comment on, and the frameworks differ less in stringency than in when they demand design maturity and what they let a developer reuse.
- Guidance, regulatory guides, and interim staff guidance are not requirements; departing from them is permitted and shifts the burden of demonstration onto the applicant rather than placing it out of compliance.
- The methodology layer, not the rule text, is where a risk-informed framework consumes a developer's early engineering budget, because the rules rely on an analysis the applicant supplies.
- A white paper seeks staff feedback and no approval; a topical report seeks staff review and approval of a discrete technical issue and produces something a later application can reference, and the two are routinely conflated.
- Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) does not settle which framework any specific applicant would be held to, and that determination is made on a docket against a specific design.

## 1. Why applicability is a real question
A developer approaching the U.S. Nuclear Regulatory Commission with a microreactor design does not meet a licensing framework. It meets several, stacked in layers, each carrying a different legal status. Two frameworks have been in force for decades. A third, 10 CFR Part 53, was published as a final rule in the Federal Register on March 30, 2026, at 91 FR 15696, and became effective on April 29, 2026 [[1]](#src-1). A fourth exists as proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[2]](#src-2). Above all of them sits a body of guidance, regulatory guides, and interim staff guidance that shapes how an application is assembled and reviewed without carrying the force of a rule [[3]](#src-3) [[9]](#src-9).
The reactor class itself is described in the public record well before any framework is chosen. The Government Accountability Office published a science and technology spotlight on nuclear microreactors that describes the class for a general technical audience [[17]](#src-17), and the Department of Energy, through Idaho National Laboratory, maintains a microreactor program plan describing federal research and demonstration activity supporting it [[18]](#src-18). Our explainer on [what a nuclear microreactor is](https://rankshieldenergy.com/resources/what-is-a-nuclear-microreactor) covers the class-level description. None of those documents is a licensing document, so none establishes which body of regulation a given machine will be licensed under.
Choosing late is expensive in a specific way. The content of an application is set by the framework it is filed under, and that content is in turn set by decisions frozen years earlier: what was analyzed, what was instrumented, how the safety case was constructed, and which methodology produced the classification of structures, systems, and components. A developer that defers the applicability question until the application is being drafted discovers that analysis it has already paid for was scoped to a different framework's expectations. The Government Accountability Office has reported that the NRC needed additional actions to prepare to license advanced reactors [[15]](#src-15) and maintains priority open recommendations for the agency [[16]](#src-16), so schedule risk sits on both sides of the table.
Two boundaries govern this paper. It describes the frameworks the regulator has published and the choices those frameworks leave open. It does not tell any party what a rule requires of that party, and a reader with a regulatory decision to make should work from the primary sources cited rather than from this summary of them. The second boundary is that this is a licensing map, not a complete map of federal obligation. Fuel availability is administered through a separate Department of Energy program [[19]](#src-19), international safeguards are an institutional arrangement in which an outside body verifies declarations rather than a licensing pathway [[20]](#src-20), and the statutory backdrop, including the ADVANCE Act, sits above the agency's rulemaking rather than inside it [[10]](#src-10).

## 2. The four licensing pathways and the status of each
The 10 CFR Part 50 pathway is the oldest and proceeds in two steps. A construction permit is issued following review of a preliminary safety analysis, construction proceeds, and an operating license is issued following review of a final safety analysis. The construction permit stage carries a provision at 10 CFR 50.35 addressing issuance of a construction permit where the applicant has not supplied all of the technical information otherwise required, subject to the conditions the rule states [[7]](#src-7). Conditions attaching to the license itself, including licensed-operator conditions, sit at 10 CFR 50.54 [[8]](#src-8); section 6 returns to the construction permit provision.
The 10 CFR Part 52 pathway rearranges the same review into instruments obtainable separately and then combined: an early site permit addressed to site suitability, a standard design approval or design certification addressed to a design, and a combined license that authorizes construction and conditions operation in one instrument. The Federal Register notice for the Part 53 final rule describes that rule as an additional framework rather than a replacement for Parts 50 and 52 [[1]](#src-1). The property that matters to a developer intending repeat deployment is that design review is separable from site review, which is why standardization arguments tend to be made in its vocabulary. Staff analysis of Nth-of-a-kind microreactor licensing and deployment considerations, which is staff analysis presented to the Commission rather than a Commission position, examines repeat deployment in that light [[12]](#src-12).
10 CFR Part 53 is final. The rule was published in the Federal Register on March 30, 2026, at 91 FR 15696, and became effective on April 29, 2026, under the title Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors [[1]](#src-1). Technology-inclusive means the requirements are written so as not to presuppose a particular reactor technology, which allows machines of different families to be reviewed against the same rule text. Risk-informed means the structure of the rule leans on an applicant's own risk analysis to establish what is safety significant, which moves work into the methodology layer of section 4. Being final and effective, this framework is available now, which distinguishes it from the fourth pathway.
The fourth pathway is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), published under the title Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles, at 91 FR 23628 [[2]](#src-2). Because it is a proposal, there is nothing in it to apply for, its text may change before any final rule issues, and the agency's public summary of microreactor regulatory activities is the practical place to watch for movement [[9]](#src-9). Our explainer on [the proposed microreactor rule](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) treats its operating-model provisions in detail.
Stated plainly, a developer today has three pathways it can file under and a fourth it can read, comment on, and design toward at its own risk.

## 3. The guidance architecture above the rules
Below the rule text and above the application sits the layer that does most of the day-to-day work: guidance. Guidance describes methods the NRC staff finds acceptable. It is not a requirement, and the distinction is not academic. An applicant that follows guidance obtains a review path the staff already understands. An applicant that departs from guidance is not out of compliance, because there was nothing there to comply with, but it assumes the burden of demonstrating that its alternative satisfies the underlying rule. The agency publishes guidance across topic areas, including digital instrumentation and controls for advanced reactors, which is guidance rather than rule text [[13]](#src-13).
Two guidance frameworks recur in advanced reactor licensing discussion: the advanced reactor content of application project, known as ARCAP, and the technology-inclusive content of application methodology, known as TICAP. Both are guidance rather than requirements, and both address what an application contains and how it is organized rather than what a reactor is required to achieve. This paper names them descriptively and does not attribute specific content to them, because their primary texts sit outside the twenty sources cited here; the agency's microreactor regulatory activities summary is the entry point the NRC itself maintains for that material [[9]](#src-9).
A further instrument in this layer is DANU-ISG-2022-01 (interim staff guidance, which is guidance and not a requirement), issued to describe a review roadmap for risk-informed, technology-inclusive advanced reactor applications in advance of, or in place of, a fully developed guidance document. Interim staff guidance is staff-level material: it describes how the staff currently intends to approach a class of application, and it establishes no obligation. For a developer the practical consequence is that a roadmap of this kind is the nearest available index of where review expectations are written down, while remaining guidance rather than rule text [[9]](#src-9).
The guidance associated with the fourth pathway is NUREG-2271 (draft guidance issued by the NRC staff for comment; staff guidance, not final), issued in April 2026 as guidelines for preparing and reviewing applications under the proposed framework [[3]](#src-3). Two consequences follow. Its content is provisional in the same sense that the rule it accompanies is provisional, since guidance written against proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) cannot be more settled than the proposal it accompanies. And the pairing itself is informative: the agency issued draft application guidance alongside the proposal rather than long after it, which gives a developer an early view of the content that would be expected if the proposal became final. Reading draft guidance early is useful. Treating it as settled would be a mistake, and the same caution applies to every document named in this section.

## 4. The methodology layer beneath the rules
Beneath the content question sits a methodology question, and it is the one that determines how much of a developer's engineering budget is spent before an application exists. A risk-informed framework requires an applicant to establish what is safety significant using an analysis of its own, and the rule does not perform that analysis [[1]](#src-1). The methodology layer is where that analysis is specified: how event sequences are selected, how they are quantified, how uncertainty is treated, and how the results are used to classify structures, systems, and components and to set the treatment each class receives. Three guidance documents recur in this layer. Their primary texts sit outside the twenty sources cited here, so this paper names them and describes their role in the architecture without attributing specific content to them.
The Licensing Modernization Project approach is the methodology most often named in this context, and the NRC endorsed a version of it in Regulatory Guide 1.233. That endorsement is guidance: it identifies an approach the staff finds acceptable, and it does not prohibit an alternative. Naming it precisely matters, because what a developer takes on when it adopts an approach of this kind is not a single document but a chain, running from a method for developing event sequences, through the targets against which those sequences are judged, to a classification scheme that falls out of the result. Each link in that chain is an engineering commitment with a cost and a schedule attached [[9]](#src-9).
A second guidance document, Regulatory Guide 1.232, addresses design criteria for advanced reactors, adapting criteria written for light-water plants into forms intended for other technologies. It is guidance. Its practical role is to give a developer a starting vocabulary of design criteria that a reviewer will recognize, which is worth more than it sounds when a review depends on both parties meaning the same thing by the same term. A third, Regulatory Guide 1.247, concerns endorsement of a probabilistic risk assessment standard for advanced non-light-water reactors, and is likewise guidance. Its significance is quality of analysis rather than scope of analysis: it bears on what makes a risk assessment adequate to be relied upon, which becomes load-bearing in a framework that uses the risk assessment to decide what matters.
What a developer chooses when it adopts this layer is a set of commitments it will be held to in review and a set of interfaces into its own engineering. It is choosing the vocabulary in which its safety case will be written, the analysis products it will have to produce and maintain under configuration control, and the review practice it will encounter. Departure remains available at every step; departure costs argument, and argument costs schedule. Staff analysis of policy and licensing considerations related to micro-reactors, which is staff analysis prepared for Commission consideration rather than an adopted requirement, canvassed questions of this type for the reactor class specifically [[11]](#src-11).

## 5. Pre-application instruments and what each is for
Before an application exists there is a set of interactions the agency has structured and published. The NRC describes a pre-application process for prospective new reactor applicants as general guidance [[4]](#src-4), and maintains a separate description of pre-application activities for advanced reactors [[5]](#src-5). The stated purpose of these activities is alignment: reducing the probability that an application arrives containing a surprise for either party. Pre-application interaction confers no approval of anything, and our explainer on [the pre-application process](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained) covers the mechanics at greater length.
The instruments are distinguishable and are frequently conflated. A letter of intent notifies the agency that a prospective applicant intends to engage and describes what it expects to submit. A project number is an administrative identifier the agency assigns so that correspondence with a pre-applicant can be tracked before any docket exists; it is a filing convenience rather than a status, and it is not a license, a permit, or an approval of any technical position. The agency's pre-application process page is where the mechanics of these steps are described [[4]](#src-4).
A regulatory engagement plan is the instrument that turns intent into a schedule. The NRC publishes a description of the regulatory engagement plan and its role in advanced reactor pre-application interaction [[6]](#src-6). In practice it is where a prospective applicant states the pathway it intends to use, the submittals it intends to make, and the sequence and timing of those submittals, so that agency staff and review resources can be planned against it. Its content is a statement of intent rather than a commitment enforceable as a license condition, and it is revised when the intent changes.
The distinction between a white paper and a topical report is the one most worth getting right, because the two documents look alike and do different work. A white paper is submitted to obtain staff feedback on an approach. It does not request approval, the staff response is feedback rather than a finding, and nothing in the exchange binds either party in a later review. A topical report is submitted to obtain staff review and approval of a discrete technical issue, and a favorable outcome is a safety evaluation that a subsequent application can reference. The consequence is asymmetric: a white paper is fast, inexpensive in review effort, and non-binding; a topical report is slower and heavier and produces something a later application can stand on. The agency describes both among the pre-application mechanics it publishes [[4]](#src-4) [[5]](#src-5). A readiness assessment is a third instrument, in which staff examine whether a planned submittal is complete enough to be accepted for review; it is a schedule instrument rather than a technical finding.

## 6. What a construction permit does and does not require
The construction permit provision at 10 CFR 50.35 is the sequencing instrument carried by the two-step pathway, and it is the provision most often misread [[7]](#src-7). The rule provides that the Commission may issue a construction permit where the applicant has not supplied all of the technical information otherwise required, subject to the conditions the rule states, and it further provides that a construction permit is not an approval of any design feature unless approval of that feature was specifically requested and granted [[7]](#src-7). Both halves of the provision matter, and they matter in opposite directions.
The permissive half addresses a real problem in early-unit deployment: a design is rarely complete at the moment construction has to begin if a schedule is to close at all. The provision allows a review to proceed on a preliminary safety analysis and remaining technical questions to be resolved before the operating stage, rather than requiring a complete design as a precondition of any authorization to build [[7]](#src-7). For a developer whose schedule risk is concentrated in construction rather than in operation, that is the property of the two-step pathway that no other pathway reproduces in the same form.
The restrictive half is what a developer with a standardization strategy should read closely. Because a construction permit does not approve a design feature unless approval of that feature was specifically requested, a permit obtained for one unit does not by itself carry design approvals forward to the next unit [[7]](#src-7). Carrying approvals forward is what the Part 52 instruments are structured to do [[1]](#src-1). Staff analysis of Nth-of-a-kind microreactor licensing and deployment considerations, which is staff analysis presented to the Commission rather than a Commission position, examines how repeat deployment accumulates justification across units rather than receiving it at the outset [[12]](#src-12).
The sequencing consequence is that a pathway choice determines when design maturity has to exist, not whether it has to exist. A pathway that permits an early authorization moves the maturity requirement later and buys schedule with it; a pathway built around design approval moves the maturity requirement earlier and buys reusability with it. Neither is inherently superior, and the trade depends on how many units a developer intends to build and how much confidence it has in a frozen design. Downstream of any of these choices, conditions attach to the license itself, including the licensed-operator conditions at 10 CFR 50.54 [[8]](#src-8), and an operating plant enters the Reactor Oversight Process, which is the agency's framework of inspection, performance indicators, significance determination, and assessment for operating reactors [[14]](#src-14). Our comparison of [oversight models for a deployed fleet](https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment) takes that downstream question up separately.

## 7. A decision map
The table below compresses section 2 into a single view and adds two columns the rule text does not supply: what each pathway presumes about design maturity at the point of filing, and the question a microreactor developer is actually deciding when it considers that pathway. Three cautions before reading it. The cells are qualitative, because the cited record supports nothing quantitative about pathway selection. The two analytical columns are our reading and not the regulator's. And the table maps choices rather than making one: nothing in it establishes which pathway suits any particular design, and that determination is made on a docket against a specific application.

Table 1. The four licensing pathways available to or proposed for a microreactor, with the status of each and two analytical columns. The status column reports the public record cited in this paper. The maturity and open-question columns are RankShield Energy analysis. This table is not a regulatory position, it has not been reviewed or accepted by the NRC, and nothing in it is required, endorsed, or approved by any agency.

Pathway
Status
What it is for
What it presumes about design maturity
Principal open question for a microreactor developer

10 CFR Part 50, two-step
In force
A construction permit on a preliminary safety analysis, then an operating license on a final safety analysis
Least at the permit stage; the rule addresses issuance where technical information is incomplete
Whether schedule bought at the permit stage is repaid at the operating stage, and what carries to the next unit

10 CFR Part 52 instruments
In force
Early site permit, standard design approval, design certification, and combined license, obtainable separately and combinable
Most, where a design approval or certification is sought; site and design questions are separable
Whether the unit count justifies front-loading a design review to obtain a reusable approval

10 CFR Part 53
Final rule, published March 30, 2026 at 91 FR 15696, effective April 29, 2026
A risk-informed, technology-inclusive framework for advanced reactors, alongside Parts 50 and 52
Analysis maturity rather than drawing maturity; the framework relies on the applicant's own risk analysis
Whether the methodology chain in section 4 is affordable at microreactor scale and how early it has to be committed

Proposed microreactor framework
Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it)
A licensing framework proposed for microreactors and other reactors with comparable risk profiles
Not determinable from a proposal; the companion application guidance is a draft issued for comment and not final
Whether to design toward a proposal that may change, and what to do if a schedule arrives before a final rule does

Two patterns run across the rows. Design maturity and reusability move together: every pathway that lets a developer file earlier gives it less that can be carried to the next unit, and every pathway that produces a reusable approval demands a more complete design before it will produce one. That trade appears in every row and is resolved by none of them. The second pattern is that analytical burden migrates rather than disappearing. A risk-informed framework moves work out of prescriptive compliance and into the applicant's own analysis, which is why the methodology layer described in section 4, and not the rule text, is where a developer's early spending concentrates.
What the table does not do is rank the pathways, and the omission is deliberate. Ranking requires a weighting across schedule risk, capital exposure, intended unit count, and confidence in a frozen design, and those weights belong to a developer's own business case rather than to the regulator's framework. A developer building a single demonstration unit and a developer intending a repeat-build fleet will read the same row differently, and both readings can be correct. A reader who wants the vendor-facing version of the same discipline can consult our note on [evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor). What the record does settle is that the choice has to be made explicitly, because it will otherwise be made implicitly by whatever the engineering organization happens to have produced by the time an application is drafted.

## 8. How RankShield Energy is approaching this
The standard this paper follows requires it to apply its own analysis to RankShield Energy and to state where we do not have a strong answer. The status, stated exactly. RankShield Energy is in pre-application engagement with the NRC and filed a letter of intent in August 2026. A project number has been requested and has not yet been assigned. RankShield Energy holds no NRC license, permit, or design approval, and nothing in the design has been demonstrated to or accepted by the NRC. Pre-application interaction confers no approval of anything [[5]](#src-5) [[4]](#src-4).
This paper does not announce a selected pathway, and that omission is the honest choice rather than a coy one. Three pathways are available to file under and a fourth is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[2]](#src-2). Announcing a selection before the analysis supporting it is complete would convert a working position into a public commitment, and a public commitment that later moves is exactly the kind of inconsistency that costs a pre-applicant credibility on a docket. What this paper does instead is publish the map, so that an eventual choice can be read against the reasoning rather than asserted without it.
The uncomfortable part is that the pathway question and the design question are coupled, and we do not yet hold all of the inputs. Our own emphasis is an assurance and verification layer, which is a component inside whatever oversight arrangement a licensed plant eventually has rather than a licensing pathway in its own right. If the eventual framework treats such a layer as an addition to be reviewed rather than a substitution for something already required, its licensing value is smaller than a developer would like it to be, and we hold no evidence either way. The draft application guidance that might bear on it is NUREG-2271 (draft guidance issued by the NRC staff for comment; staff guidance, not final), which is not a document to plan against as though it were settled [[3]](#src-3).
Two further dependencies sit outside anything a pathway choice settles. Fuel availability is administered through a separate Department of Energy program [[19]](#src-19), and safeguards are an institutional arrangement in which an outside body applies technical measures to verify declarations [[20]](#src-20). Neither is resolved by choosing a framework, and either can constrain a schedule that a framework choice appears to have freed. Agency readiness is a further variable a developer does not control and that has been examined externally [[15]](#src-15) [[16]](#src-16), and the agency's own summary of microreactor regulatory activity is where movement becomes visible [[9]](#src-9). What remains genuinely unsettled is recorded below and in our [open questions paper](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight). We would rather publish an incomplete map with the gaps marked than a complete-looking one with the gaps painted over.

## Frequently asked questions

### How many licensing frameworks can a microreactor actually use today?
Three are available to file under: the two-step construction permit and operating license pathway at 10 CFR Part 50, the instruments at 10 CFR Part 52, and the risk-informed, technology-inclusive framework at 10 CFR Part 53, which was published as a final rule on March 30, 2026 and became effective on April 29, 2026. A fourth framework exists as proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), so it can be read, commented on, and designed toward, but not filed under. Which of the three available frameworks suits a given design is determined on a docket rather than in a paper of this kind.

### Is guidance the same thing as a requirement?
No, and the difference has practical consequences. Guidance, regulatory guides, and interim staff guidance describe methods the NRC staff finds acceptable. Following them obtains a review path the staff already understands. Departing from them is permitted, and it shifts the burden onto the applicant to demonstrate that the alternative satisfies the underlying rule rather than placing the applicant out of compliance. Requirements live in the rule text and in conditions attached to a license.

### What is the difference between a white paper and a topical report?
A white paper is submitted to obtain staff feedback on an approach. It seeks no approval, the response is feedback rather than a finding, and it binds neither party in a later review. A topical report is submitted to obtain staff review and approval of a discrete technical issue, and a favorable outcome is a safety evaluation that a later application can reference. The trade is speed and cost against durability of the result.

### Does the proposed microreactor rule determine which framework applies?
No. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). A proposal contemplates a framework; it does not establish which framework any specific applicant would be held to, and the companion application guidance, NUREG-2271, is draft guidance issued by the NRC staff for comment and is not final. The determination for a specific design is made on a docket.

### What would change the analysis in this paper?
A final microreactor licensing rule, or withdrawal or material amendment of the proposal. Final rather than draft application guidance for that framework. Issuance or revision of the regulatory guides and interim staff guidance named in sections 3 and 4. A Commission decision adopting or rejecting positions analyzed in the staff papers cited here. Or published agency direction on how the existing frameworks are expected to be applied to this reactor class. Any of those would move cells in the decision map, and the map is versioned so that movement can be recorded.

## Sources

- [U.S. Nuclear Regulatory Commission. Risk-Informed, Technology-Inclusive Regulatory Framework for Advanced Reactors (10 CFR Part 53, final rule). Federal Register, March 30, 2026 (91 FR 15696); effective April 29, 2026](https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628); proposed rule, comment period closed June 15, 2026, not final](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. Guidelines for Preparing and Reviewing Applications Under 10 CFR Part 57 (NUREG-2271, Draft for Comment), April 2026; draft staff guidance issued for comment, not final, accompanying a proposed rule that is not final](https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr2271/index.html)
- [U.S. Nuclear Regulatory Commission. Pre-application Process (general guidance). Accessed August 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/pre-app-process)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed August 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)
- [U.S. Nuclear Regulatory Commission. Regulatory Engagement Plan. Accessed August 2026](https://www.nrc.gov/reactors/new-reactors/advanced/new-app/general-guidance/engagement)
- [U.S. Government Publishing Office. 10 CFR 50.35, Issuance of construction permits. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-35.xml)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities.html)
- [U.S. Nuclear Regulatory Commission. About the ADVANCE Act. Accessed August 2026](https://www.nrc.gov/about-nrc/governing-laws/advance-act/about-advance-act)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors (staff paper, not a Commission position). October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations (staff paper, not a Commission position). June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Digital Instrumentation and Controls guidance for advanced reactors (guidance, not rule text). Accessed August 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/guidance/digital-instrumentation-and-control.html)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed August 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description.html)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [U.S. Government Accountability Office. Priority Open Recommendations: Nuclear Regulatory Commission (GAO-26-109004). June 2026](https://www.gao.gov/products/gao-26-109004)
- [U.S. Government Accountability Office. Science and Tech Spotlight: Nuclear Microreactors (GAO-20-380SP). February 2020](https://www.gao.gov/products/gao-20-380sp)
- [Idaho National Laboratory for the U.S. Department of Energy. A Microreactor Program Plan for the Department of Energy (INL/EXT-20-58919 Rev. 4). May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [U.S. Department of Energy, Office of Nuclear Energy. HALEU Availability Program. Accessed August 2026](https://www.energy.gov/ne/haleu-availability-program)
- [International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed August 2026](https://www.iaea.org/topics/basics-of-iaea-safeguards)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Whether the proposal becomes a rule.** Whether proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) is finalised, materially amended, or withdrawn, and on what schedule [[2]](#src-2) [[9]](#src-9). Unresolved because a comment period closing is not a rulemaking outcome. Resolver: the NRC, through rulemaking.
- **OQ-2. Interaction between the frameworks.** How an applicant that has invested in the risk-informed, technology-inclusive framework at 10 CFR Part 53 [[1]](#src-1) would carry that work across if a microreactor-specific framework later becomes available. Unresolved because the cited record describes the frameworks separately rather than describing migration between them. Resolver: the NRC, through rulemaking and guidance.
- **OQ-3. Guidance maturity.** When application guidance for the proposed framework moves from draft to final, given that NUREG-2271 (draft guidance issued by the NRC staff for comment; staff guidance, not final) is what a developer would otherwise plan against [[3]](#src-3). Unresolved because guidance for a proposal cannot settle ahead of the proposal. Resolver: the NRC staff.
- **OQ-4. Methodology cost at small scale.** Whether the methodology chain described in section 4 scales down economically to a reactor of this class, or whether the analysis burden is close to invariant with size. Unresolved because staff analysis of policy and licensing considerations related to micro-reactors canvassed the questions without settling the cost of answering them [[11]](#src-11). Resolver: applicants and the NRC, demonstrated on dockets.
- **OQ-5. Reuse across units.** What actually carries from one unit to the next under each pathway, given that a construction permit is not an approval of a design feature unless approval was specifically requested [[7]](#src-7) and that staff analysis of Nth-of-a-kind licensing and deployment considerations, which is staff analysis rather than a Commission position, treats justification as accumulating across units [[12]](#src-12). Resolver: the NRC, on specific dockets.
- **OQ-6. Digital review expectations.** How the guidance layer for digital instrumentation and controls in advanced reactors, which is guidance rather than rule text [[13]](#src-13), interacts with a framework choice, and whether that interaction changes the pathway calculation for a design with a substantial digital content. Resolver: the NRC, through review practice.
- **OQ-7. Agency capacity as a pathway variable.** Whether review capacity differs materially between pathways in a way a developer should account for, given that the Government Accountability Office has reported preparation gaps for advanced reactor licensing [[15]](#src-15) and maintains priority open recommendations [[16]](#src-16). Unresolved because the cited record addresses readiness in aggregate rather than by pathway. Resolver: the NRC, with Government Accountability Office scrutiny.
- **OQ-8. We cannot answer this one.** Which framework RankShield Energy will file under, and whether the framework we would prefer will exist when we need it. We have filed a letter of intent and requested a project number that has not yet been assigned [[4]](#src-4) [[5]](#src-5), we hold no NRC license, permit, or design approval, and the determination depends on a rulemaking outcome we do not control and on a design maturity assessment we have not completed. Publishing a selection now would be a claim rather than an answer. Resolver: the NRC for the framework, RankShield Energy for the filing, and neither of us alone.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [The NRC pre-application process explained →](https://rankshieldenergy.com/resources/nrc-pre-application-process-explained)
- [Oversight models for fleet-scale microreactor deployment →](https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment)
- [Open questions in autonomous microreactor oversight →](https://rankshieldenergy.com/resources/open-questions-autonomous-microreactor-oversight)
- [How to evaluate a microreactor vendor →](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of NRC advanced reactor and microreactor rulemaking and the published guidance record as of August 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/resources/who-inspects-a-reactor-built-in-a-factory/

# Who Inspects a Nuclear Reactor Built in a Factory?

> An analysis of how a factory-built reactor is verified before shipment and how provenance is established when the unit is received at its operating site.

[Resources](https://rankshieldenergy.com/resources) / Technical papers Technical papers

# Who Inspects a Reactor Built in a Factory? Verification of Off-Site Fabrication
Published September 1, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. Technical paper · document control
Document type Technical paper Version 1.0 Published September 1, 2026 Revised September 1, 2026 Status Verification analysis of off-site fabrication, open for comment Regulatory status RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission. RankShield Energy holds no NRC license, permit, or design approval. No RankShield Energy design, product, or facility, and no safety, performance, or operational characteristic of one, has been demonstrated to or accepted by the NRC. Descriptions of design behavior are design intent and are subject to analysis, testing, and regulatory review.

## Abstract
Factory fabrication is one of three defining features of the microreactor class in the Department of Energy program plan, and the premise moves construction of the reactor off the site it will operate on. The oversight instruments most discussed attach to an operating site. The build phase therefore carries the least site-attached oversight and the most consequence, and it is the phase in which a downstream party has the least direct evidence. This paper examines the instrument the framework in force provides for verifying off-site construction, the inspections, tests, analyses, and acceptance criteria required in a manufacturing license application by 10 CFR 52.158, and observes that the microreactor rule now proposed sets that instrument aside.
Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contains a manufacturing-license subpart covering fabrication, factory fuel loading, transport, and site acceptance. The NRC gives its reasons and invites comment on streamlined constructs. This paper answers that invitation structurally: it decomposes the verification functions the existing construct performs in an off-site build, identifies which remain load-bearing when a whole reactor rather than a module is built off site, and sets out what a records-based construct would have to supply in their place. The principal limitation is authorship. RankShield Energy does not manufacture reactors, and the argument is an architecture argument rather than a manufacturing one.

This paper is technical analysis prepared for a professional audience. It is not legal, regulatory, engineering, or investment advice. It does not interpret regulatory requirements on behalf of any third party. Where this paper describes a proposed rule, the rule is not final and may change. Readers responsible for regulatory decisions should rely on the primary sources cited rather than on this summary of them.

## Scope and limitations
This paper addresses how a reactor manufactured away from its operating site is verified, which published instruments reach the manufacturing facility, what the proposed microreactor framework would do differently, how transport sits between the two quality assurance boundaries, and what a records-based verification construct would have to provide to serve the functions the existing construct serves. It draws on primary sources spanning the regulator, the Government Accountability Office, the NRC Office of the Inspector General, the Department of Energy and five national laboratories, and the standards bodies. The audit finding recorded in section 4 is a 2012 finding and is labeled as such there. Where a document is characterized, it is cited and its status is stated: rule in force, proposed rule, staff paper, contractor report, or audit finding.
Several things are deliberately out of scope. The paper does not tell any party what a rule requires of it. It contains no design detail for any RankShield Energy system: no geometry, no fuel description, no enrichment figure, no performance or lifetime figures. It contains no cost or economic analysis. It does not name, rank, or characterize other developers. It does not describe unattended operation of a reactor. It does not quote from the body of any staff paper, inspection manual chapter, or program plan document whose full text sits outside the verified source set; those documents are named by title and date and described in terms their titles and the agency's own summary pages support. It draws no conclusion about the diligence of any agency, office, or vendor from the dated facts recorded in section 4.
Several developments would change the analysis materially and should trigger a revision: a final microreactor licensing rule, or withdrawal or material amendment of the proposal; a published agency position on what a streamlined construct for verifying off-site manufacture would consist of; a final rule following the NRC's proposed rule on package certification requirements (a proposed rule published in the Federal Register on July 27, 2026; a proposed rule that is not final); new national-laboratory results that change the transport dose or criticality picture; or any agency statement addressing the evidentiary status of machine-generated manufacturing records. Amendment of the licensing and oversight rules through the NRC's proposed rule modernizing reactor licensing, safety oversight, and siting practices (a proposed rule published in the Federal Register on July 16, 2026 at 91 FR 44560; not final), which touches 10 CFR Parts 2, 50, 51, 52, 53, 54, 71 and 100 [[39]](#src-39), would also bear on it. The decomposition in section 7 is our reading of the cited record and is offered for disagreement rather than for adoption.

A microreactor is defined in the public record partly by where it is built. The Department of Energy program plan lists factory fabrication as one of three defining features of the class [[31]](#src-31). That premise moves the construction of a reactor off the site it will operate on and into a facility the site licensee does not run, that a downstream party cannot walk through, and that the regulator reaches by a route different from the one it uses at a construction site. The question this paper asks is narrow and practical: who verifies that build, and what does a party who was not present get to rely on afterwards?
The method is a decomposition rather than a survey. Section 1 sets out why the build phase is structurally different from the operating phase. Section 2 describes the instrument the framework in force provides for it, the manufacturing license at 10 CFR Part 52 Subpart F [[1]](#src-1). Section 3 describes what inspections, tests, analyses, and acceptance criteria actually do, because the machinery is more specific than the acronym suggests [[4]](#src-4) [[5]](#src-5). Section 4 describes how the regulator reaches a factory today, through the vendor inspection program [[10]](#src-10). Section 5 sets out what the proposed microreactor framework would do and what it sets aside. Section 6 treats transport as a custody interval [[20]](#src-20). Section 7 is the contribution. Section 8 applies the analysis to RankShield Energy.
Two framing rules govern what follows. Anything in force is identified as in force, and anything proposed is identified as proposed at every mention, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) [[19]](#src-19). Staff papers are staff analysis rather than Commission positions and are identified as such wherever they are named. RankShield Energy is a pre-applicant in early regulatory interaction with the NRC, holds no NRC license, permit, or design approval, and does not operate a manufacturing facility. The analysis in section 7 is offered as a contribution to an open regulatory question the agency has itself put out for comment. It is not a proposal this paper claims the agency should adopt, and it is not a description of a product.
Key takeaways

- The build phase of a factory-fabricated reactor carries the least site-attached oversight and the most consequence, and an Oak Ridge National Laboratory contractor report states that factory fueling and assembly, multi-site operation, and the associated transportation have not been demonstrated under Nuclear Regulatory Commission rules and regulations.
- The framework in force already contains an instrument aimed at off-site construction: a manufacturing license application must contain inspections, tests, analyses, and acceptance criteria sufficient to assure that the reactor has been manufactured in conformity with the manufacturing license, so that construct is not confined to combined licenses.
- Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) contains a manufacturing-license subpart covering fabrication, factory fuel loading, transport, and site acceptance, and the NRC states that it did not pursue a combined license approach because those inspection and acceptance requirements were designed for light water reactors and the associated closure hearing could extend the licensing timeline.
- Transport is a custody interval in which the unit sits outside the manufacturing facility's quality assurance boundary and is not yet inside the site's, and the proposed rule would require verification of the condition of shipped items on receipt without specifying what that verification rests on.
- Nothing in 10 CFR Part 21, Appendix B to 10 CFR Part 50, 10 CFR Part 52, or the proposed microreactor framework references machine-verifiable attestation, and a developer arguing for a records-based construct has an obvious interest in preferring one.

## 1. The phase with the least oversight
Oversight of a power reactor in the United States is usually discussed in terms that presume a site: a licensee, a fixed location, and a regulator with a physical route to it. The rule governing inspection during construction is written around a licensee that notifies the Commission as it completes acceptance criteria at the place the plant is being built [[4]](#src-4). Our starting observation is that the microreactor premise breaks that presumption, and breaks it at the phase where the material condition of the machine is established. When the reactor is built where it will run, site-attached oversight and construction oversight are the same thing. When the reactor arrives on a truck, they are not.
The premise is explicit in the federal record. The Department of Energy program plan, prepared through Idaho National Laboratory, lists factory fabrication as one of three defining features of the class and states that the majority of components of a microreactor are anticipated to be fully assembled in a central factory and shipped out to the locations of operation [[31]](#src-31). A Pacific Northwest National Laboratory report prepared under a prototype microreactor transportation safety program describes microreactors as factory-fabricated and designed to be easily transportable by truck, rail, vessel, or air [[24]](#src-24). An Idaho National Laboratory assessment published in Nuclear Technology examined factory fabrication considerations for the class directly [[29]](#src-29), and an earlier laboratory regulatory and licensing strategy for microreactor technology set out the regulatory questions the class raises [[33]](#src-33).
Oak Ridge National Laboratory, in a contractor report supporting the development of guidance for microreactor manufacturing licenses, states the position plainly: factory fueling and assembly, multi-site operation, and the associated transportation of advanced nuclear systems present both new opportunities and challenges, and these areas have not been demonstrated under Nuclear Regulatory Commission rules and regulations [[30]](#src-30). That is the honest frame for this paper, and it is a contractor to the regulator saying it. Off-site construction itself is not novel to the agency: Brookhaven National Laboratory assessed modular construction for safety-related structures at advanced nuclear power plants for the NRC in 1997 [[32]](#src-32). What changes is the fraction of the plant that moves off site, and with it the fraction of the verification record that has to travel.
Statute has recognized the sequencing problem. The ADVANCE Act directs microreactor strategies in eight areas, among them oversight and inspections and the transportation of fueled microreactors, as the agency records on its microreactor regulatory activities page [[15]](#src-15). The build phase is where the material condition of the reactor is established, and it is the phase in which a downstream party, whether a site licensee, a lender's technical adviser, an insurer, or a host community, has the least direct evidence. Our companion analysis of [oversight models for fleet-scale deployment](https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment) treats the operating end of the same problem. This paper treats the build end.

## 2. The instrument that exists: the manufacturing license
The framework in force does contain an instrument built for this situation. 10 CFR Part 52 Subpart F provides for a manufacturing license [[1]](#src-1). Under 10 CFR 52.151 the license authorizes the manufacture of nuclear power reactors to be installed at sites not identified in the manufacturing license application [[2]](#src-2). That is precisely the factory case. The instrument is bounded. 10 CFR 52.153 provides that a reactor manufactured under a manufacturing license may only be transported to and installed at a site for which either a construction permit under Part 50 or a combined license under Subpart C of Part 52 has been issued [[1]](#src-1). A manufacturing license does not create a place to put the reactor.
The application content is where the verification intent shows. 10 CFR 52.157 requires design information sufficient to permit the Commission to judge the applicant's proposed means of assuring that the manufacturing conforms to the design, and sufficient to permit the preparation of acceptance and inspection requirements by the NRC [[1]](#src-1). Those two clauses state the whole verification problem in a sentence: a means of assurance held by the applicant, and a basis on which the regulator can write its own inspection requirements. 10 CFR 52.158 then requires the application to contain inspections, tests, analyses, and acceptance criteria sufficient to assure that the reactor has been manufactured in conformity with the manufacturing license [[1]](#src-1).
The license itself carries terms. 10 CFR 52.167(b) provides that a manufacturing license specifies terms and conditions, technical specifications, site parameters, design characteristics, and interface requirements [[3]](#src-3). 10 CFR 52.167(c)(2) reaches into the commercial layer: the holder is required to write NRC-approved shipping requirements into the transport contract [[3]](#src-3). That provision is unusual and worth noticing. The rule anticipates that the custody chain runs through an agreement with a carrier, and it places a regulatory requirement inside a private contract. It is one of the few points in the framework where a document rather than an inspection is the control.
Two further provisions bear on the fleet case. Under 10 CFR 52.171(a)(2) a design modification imposed by the Commission will be applied to all reactors manufactured under the license, including those that have already been transported and sited [[1]](#src-1). That is a configuration-management obligation reaching units the manufacturer no longer holds. 10 CFR 52.173 runs a manufacturing license for five to fifteen years and provides that manufacture may not be initiated less than three years before expiry [[1]](#src-1). On the historical record, the NRC historian writes that the Offshore Power Systems production facility in Jacksonville needed an NRC manufacturing license, that the NRC did not issue a license until 1982, and that Westinghouse formally abandoned the enterprise in 1984 [[38]](#src-38). This paper does not characterize how many manufacturing licenses have been issued under Subpart F. Our survey of [which regulations apply to a microreactor](https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor) places Subpart F among the available pathways.

## 3. What the existing verification construct actually does
The acronym is used loosely, so it is worth stating what the machinery is. Inspections, tests, analyses, and acceptance criteria are commitments carried in a license application: an activity to be performed, and a criterion the result has to meet. The NRC's own description explains that they are sourced either from a certified design or written for a specific site, that the agency reviews closure notifications, and that inspection manual chapter 2503 is the vehicle through which the associated inspections are carried out [[5]](#src-5). A point commonly gotten wrong deserves emphasis here: these criteria are required in a manufacturing license application by 10 CFR 52.158, not in a combined license alone [[1]](#src-1). The instrument for verifying off-site construction already sits inside the manufacturing pathway.
10 CFR 52.99 supplies the reporting machinery. Under paragraph (c)(1) the licensee submits closure notifications as acceptance criteria are met. Under paragraph (c)(3) the licensee notifies the Commission of uncompleted criteria no later than 225 days before the scheduled date for initial loading of fuel. Paragraph (b) provides that the licensee may proceed at its own risk with construction activity, which places the schedule consequence of a disputed finding on the licensee rather than on the regulator [[4]](#src-4). The corresponding provision governing issuance of combined licenses sits at 10 CFR 52.97 [[6]](#src-6).
The most interesting provision for the purposes of this paper is the post-closure notification at 10 CFR 52.99(c)(2) [[4]](#src-4). That duty was established by a final rule published in the Federal Register on August 28, 2012 at 77 FR 51880, which set out a requirement to report information that materially alters a previously submitted closure notification [[9]](#src-9). The acknowledgment embedded in that rulemaking is worth naming: a closed acceptance criterion can be invalidated by information that arrives afterwards. That is not a defect in the instrument, it is a configuration-management property. A verification record that cannot be superseded is a record that will eventually be wrong, and any construct proposed in place of this one has to inherit the property rather than drop it.
The construct is also younger than it looks, which matters when judging an alternative against it. The Government Accountability Office reported in 2007 that the NRC was continuing to develop several components of the process, such as the final closeout review for ensuring all criteria are met, and had just begun staffing the construction inspection program [[8]](#src-8). Measuring a records-based alternative against an idealised version of a construct that took years to mature would be unfair to the alternative. Our paper on [evidentiary standards for machine-generated reactor records](https://rankshieldenergy.com/resources/evidentiary-standards-machine-generated-reactor-records) takes up the separate question of what makes such a record usable as evidence at all.

## 4. How the regulator reaches a factory today
Between the rule text and the factory floor sits the vendor inspection program. The NRC describes it directly: vendor inspections are conducted at vendor shops principally to examine whether the vendor has been complying with Appendix B to Title 10, Part 50, as required by procurement contracts with licensees [[10]](#src-10). The legal shape of that sentence matters. The quality requirement travels to the vendor through a procurement contract rather than through a license, because the vendor is not a licensee. The Appendix B criteria themselves apply quality assurance to design, fabrication, construction, and testing [[14]](#src-14), so the substantive coverage of the factory phase is present; what differs is the instrument through which it is enforced.
The enforcement instruments follow from that shape. The NRC states that notices of nonconformance or notices of violation are issued to vendors for failures to meet quality commitments or the requirements of 10 CFR Part 21 [[10]](#src-10). Part 21 places a duty on suppliers of basic components to notify the Commission immediately of defects that could create a substantial safety hazard [[13]](#src-13). And the agency states the allocation of responsibility plainly: licensees are ultimately responsible for vendor oversight [[10]](#src-10). In the factory-fabricated case that allocation deserves examination, because the party held responsible for overseeing a manufacture may be a site licensee that was not yet a licensee while the manufacture was under way.
Two dated facts belong in the record, stated without insinuation. Take them in date order. The NRC Office of the Inspector General audited the process for inspections, tests, analyses, and acceptance criteria in 2012 (a 2012 finding of the NRC Office of the Inspector General), and one finding in that audit was titled to the effect that a formal strategy for inspection of components at modular assembly facilities would strengthen the inspection program [[7]](#src-7). The background to that finding records that vendor inspections are performed as part of the inspection effort in particular because a key characteristic of the then-current approach to new reactor construction is the use of modular assemblies, constructed offsite and shipped to the construction site for installation [[7]](#src-7).
The second dated fact concerns the public record of results. The NRC's published vendor inspection program plan page lists revision 30, dated July 2024, describes the plan as updated every six months, and records annual self-assessments through fiscal year 2024 [[11]](#src-11). The agency page collecting vendor inspection findings related to acceptance criteria, which posts summary letters covering vendors supporting the Vogtle and Summer projects, carries a most recent posted letter dated October 12, 2018 [[12]](#src-12). This paper draws no conclusion from either fact about the diligence of the agency or of any vendor. Both are stated because omitting them would be selecting the evidence. What they establish is narrower: the public, per-item record of factory inspection findings available to a party outside the transaction is thin, and it is thin at the point where the factory-fabricated premise puts the most weight.

## 5. What the proposed microreactor framework would do, and what it sets aside
Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) would build its own manufacturing pathway [[19]](#src-19). Its Subpart D is titled Manufacturing Licenses, and the proposed scope provision at 57.145 covers manufacture at a manufacturing facility, fuel loading into manufactured reactors there, and transportation of manufactured reactors. Across its 139 pages manufacturing license appears 183 times and manufactured reactor 147 times.
Several provisions of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) carry verification content [[19]](#src-19). Proposed 57.160(d)(1) would require a description of the codes and standards used in procurement, fabrication, and assembly. Proposed 57.160(d)(3) would require "a description of the tests and inspections to be performed during the manufacturing and fabrication process, including components, as well as an assembled manufactured reactor." Proposed 57.160(e)(1) would require information on shipping preparation, the conduct of shipping, and verification on receipt. Proposed 57.197(f) would address required receipt inspections and verification that interface requirements between the reactor and the balance of the plant have been met.
Against that, ITAAC appears four times in the 139 pages of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). The NRC states its reasoning: "The NRC didn't pursue amending part 52 or implementing a combined license approach in this proposed rule because the requirements for inspections, tests, analyses, and acceptance criteria (ITAAC) were designed for light water reactors (LWRs) (required by the Atomic Energy Act of 1954, as amended (AEA)) and the associated hearing on ITAAC closure could extend the licensing timeline." [[19]](#src-19) Both reasons are legitimate. Acceptance criteria built around light water systems do not transfer cleanly to other technologies.
The agency also invites challenge to its own premise. Question Q12-1 of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) asks whether the conclusion that the existing pathways would impose unnecessary burden and extend review timelines for microreactors is accurate and sufficiently supported, and Q12-2 asks what alternatives, "e.g., targeted modifications to part 52, streamlined ITAAC constructs, or scoped use of part 53 elements", the NRC should evaluate [[19]](#src-19). That second question is the reason this paper exists. Setting an instrument aside because it was built for a different technology and carries a hearing is a reason to replace its functions, not a finding that its functions are unnecessary. Our explainer on [the proposed microreactor framework](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained) covers the operating-model provisions in the same proposal.

## 6. Transport as an evidence gap
Between the factory and the site the unit is in transport, and transport is governed by 10 CFR Part 71 [[20]](#src-20). The external radiation standard at 10 CFR 71.47(b)(3) sets a limit measured at two meters from the vehicle for exclusive-use shipments [[21]](#src-21). For a fueled microreactor that limit is a live engineering constraint rather than a formality. A Pacific Northwest National Laboratory report prepared for the NRC states in its abstract that microreactors may be challenged to meet the current 10 mrem/hr limit at 2 meters from the vehicle in 10 CFR 71.47(b) [[23]](#src-23).
The NRC's proposed rule on package certification requirements (a proposed rule published in the Federal Register on July 27, 2026; a proposed rule that is not final) addresses the point directly. That proposal states that shipment of a fueled microreactor on accelerated timelines with "less than one-year of cooling" means "external radiation levels during transport could exceed the 0.1 millisievert per hour (mSv/h) (10 millirem per hour (mrem/h)) at 2 meters (m) from the vehicle radiation level limit currently specified in Sec. 71.47(b)(3)" [[22]](#src-22). It proposes an alternative radiation standard for certain exclusive-use Type B shipments and risk-informed alternatives under 10 CFR 71.41 [[22]](#src-22).
The supporting technical record is being assembled. The Pacific Northwest National Laboratory dose assessment is the technical basis for the transport dose question [[23]](#src-23), and the companion prototype microreactor transportation safety program report records that designs often assume the unit can be transported containing either unirradiated or irradiated fuel [[24]](#src-24). Argonne National Laboratory has published a microreactor core transportation cask model description supporting a criticality safety validation basis assessment [[25]](#src-25), and Sandia National Laboratories has published a qualification framework for the safe transportation of microreactors [[26]](#src-26).
The verification point is separate from the dose point. Transport is a custody interval during which the unit is outside the manufacturing facility's quality assurance boundary and is not yet inside the site's. The framework in force reaches that interval through the shipping requirements 10 CFR 52.167(c)(2) obliges the license holder to write into the transport contract [[3]](#src-3). Under the proposal, 57.160(e)(1) of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) would require information on "the procedures governing the preparation of the manufactured reactor for shipping to the site where it is to be operated, the conduct of shipping, and the verification of the condition of the shipped items upon receipt at the site" [[19]](#src-19). That provision names the verification without naming what it rests on. A receipt inspection can establish that a sealed unit arrived with its seals intact. It cannot, by itself, establish what was inside the seals when they were applied, and that is a records question rather than an inspection question.

## 7. What a records-based construct would have to provide
If the existing construct is set aside for a factory-built reactor, the functions it performs do not disappear. Six are separable because the rule text separates them: a criterion fixed before the work and reviewed in the application [[1]](#src-1); a determination made by an identified party and reported [[4]](#src-4); a result a third party can examine without repeating the work [[5]](#src-5); a commitment binding to the reactor manufactured under the license rather than to a design in the abstract [[1]](#src-1); a finding that can be superseded when later information invalidates it, as the post-closure duty and the fleet-modification provision each express [[4]](#src-4) [[9]](#src-9); and a record that reaches a party who was not present.
One feature of the proposal sharpens the fourth. Proposed 57.197 of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) would include requirements applying to portions of a manufactured reactor, in recognition that activities under a manufacturing license may occur at different fabrication facilities [[19]](#src-19). A single unit's provenance can therefore run through more than one plant, an argument for binding the record to the unit rather than the facility. The closest regulatory slots such a record could occupy are proposed 57.160(e)(1) and proposed 57.197(f), both of which describe a verification without specifying its evidentiary basis. Table 1 sets each function against what the existing construct supplies and what a substitute would need. The center column is drawn from the cited rule text; the right column is RankShield Energy analysis, offered for disagreement.

Table 1. Verification functions performed in an off-site build under the framework in force, and what a records-based construct would have to supply for each. The center column reports the cited rule text and the agency's description of it. The right column is RankShield Energy analysis. This table is not a regulatory position, it has not been reviewed or accepted by the NRC, and nothing in it is required, endorsed, or approved by any agency.

Verification function
What the existing construct supplies
What a records-based construct would have to supply

Criterion fixed before the work
Acceptance criteria are contained in the license application and reviewed there, so the criterion precedes the activity that tests it (10 CFR 52.158)
A criterion committed and published before fabrication begins, bound so that a later reading of the record cannot silently alter what was promised

Identified determining party
The licensee performs the inspection, test, or analysis, determines that the criterion is met, and notifies the Commission (10 CFR 52.99(c)(1))
A named accountable party for each determination, distinguishable in the record from the party that performed the underlying work

Checkable without repetition
A closure notification is a document the agency reviews rather than a test it repeats, with inspection sampled separately
A record whose integrity a reviewer can check computationally, without re-performing the fabrication test and without access to the factory

Binding to the physical unit
Criteria in a manufacturing license application attach to the reactor manufactured under that license (10 CFR 52.158)
An identifier bound to the individual unit and carried with it, so that a record cannot be transferred between units of the same design

Revision when later information arrives
The post-closure notification duty (10 CFR 52.99(c)(2)) and the fleet-modification provision reaching sited units (10 CFR 52.171(a)(2))
An append-only history in which a superseding finding is added and the earlier record remains visible, rather than an editable record of current state

Availability to an absent party
Notifications are submitted to the Commission and enter the public docket
A proof a party with no relationship to the manufacturer can check offline, at a time of its choosing, without the manufacturer's cooperation

Mechanisms in the standards record map onto those requirements. They are candidates, not anything the agency has adopted or referenced. IETF RFC 9334 supplies a vocabulary of attestation roles: who produces evidence, who appraises it, and who relies on the result [[34]](#src-34). IETF RFC 9943 supplies an append-only model in which statements about an artifact are registered and can be superseded but not silently removed [[35]](#src-35). IETF RFC 9942 supplies a receipt a verifier can check without contacting the party that issued it [[36]](#src-36). NIST FIPS 204 supplies a signature standard [[37]](#src-37).
Two limits belong with it. Nothing in 10 CFR Part 21 [[13]](#src-13), Appendix B to 10 CFR Part 50 [[14]](#src-14), 10 CFR Part 52 [[1]](#src-1), or the proposed microreactor framework [[19]](#src-19) references machine-verifiable attestation, and this paper does not suggest that any of them implies it. The exposure is one the agency already names: its material on counterfeit, fraudulent, and suspect items states that vendors, suppliers and nuclear power plants must verify the quality of items destined for safety-related functions, and that verification includes extensive inspections combined with rigorous performance testing [[27]](#src-27). NIST SP 800-161r1 frames the same exposure for systems whose components may be counterfeit or poorly manufactured [[28]](#src-28). Our [reference architecture for independent verification](https://rankshieldenergy.com/resources/reference-architecture-independent-verification-reactor-state) covers the operating-phase version.

## 8. Applying this to RankShield Energy
The standard this paper follows requires it to apply its own analysis to RankShield Energy. The accurate statement is short. RankShield Energy does not operate a manufacturing facility. It has not applied for a manufacturing license under 10 CFR Part 52 Subpart F [[1]](#src-1), nor under the framework the NRC has proposed for microreactors. It has not qualified a supply chain against Appendix B to 10 CFR Part 50 [[14]](#src-14). It has never shipped a reactor. It is a pre-applicant in early regulatory interaction with the NRC, holds no NRC license, permit, or design approval, and nothing in the design has been demonstrated to or accepted by the agency.
Our experience is in attestation and verification engineering and in navigating pre-application, not in nuclear manufacturing, and that distinction governs how section 7 should be read. The decomposition there is an architecture argument: it asks what a verification record has to do and answers in terms of properties a record can be made to have. It is not a manufacturing argument. It does not address whether a factory can hold a tolerance, how a welding procedure is qualified, what a receiving inspection can physically detect, or how many units a supply chain can deliver before a quality escape becomes probable. Those are the questions a manufacturer would be answering, and we are not answering them.
There is also an incentive problem, and it belongs in the paper rather than in a reader's margin. A developer whose competence is in records has an obvious interest in a regulatory construct that runs on records. That interest does not make the argument wrong, but it means the argument should not be weighed by who is making it. The test we would ask a reviewer to apply is whether the six functions in section 7 are correctly decomposed from the cited rule text, and whether any function has been dropped. If a function is missing, a construct built on the list is incomplete regardless of who proposed it.
Two things we do not know bound the argument. We do not know what evidentiary weight a cryptographic manufacturing record would carry in an NRC proceeding; the question is untested. And we do not know which streamlined construct the agency will adopt after comment, if it adopts one, because Q12-2 of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) is an invitation rather than a signal [[19]](#src-19). Staff analysis has canvassed adjacent questions without settling them: SECY-20-0093 on policy and licensing considerations related to micro-reactors [[17]](#src-17) and SECY-25-0052 on nth-of-a-kind licensing and deployment considerations (a staff paper, which is staff analysis and not a Commission position) [[18]](#src-18). Our guide to [evaluating a microreactor vendor](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor) sets out questions a buyer can ask, and these are ones we would expect to be asked of us.

## Frequently asked questions

### Who actually inspects a reactor while it is being built in a factory?
Under the framework in force, a manufacturing license application has to contain inspections, tests, analyses, and acceptance criteria sufficient to assure that the reactor has been manufactured in conformity with the manufacturing license, and 10 CFR 52.157 requires the applicant to describe its proposed means of assuring that manufacturing conforms to the design and to give the NRC enough to prepare acceptance and inspection requirements. Alongside that, the NRC conducts sampled inspections at vendor shops to examine compliance with Appendix B to 10 CFR Part 50, and it states that licensees are ultimately responsible for vendor oversight. The vendor is not a licensee, so the quality requirement reaches it through a procurement contract rather than through a license.

### Does the proposed microreactor rule remove the ITAAC construct?
No, and it should not be overstated. The instrument in question is proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it). It does not amend 10 CFR Part 52 and it abolishes nothing. It proposes a separate framework whose manufacturing subpart does not use that construct, and the NRC explains that it did not pursue a combined license approach because those requirements were designed for light water reactors and the associated closure hearing could extend the licensing timeline. The agency invites comment on streamlined constructs in its question Q12-2, so the matter is open rather than settled.

### Are inspections, tests, analyses, and acceptance criteria a combined-license feature?
No. 10 CFR 52.158 requires a manufacturing license application to contain inspections, tests, analyses, and acceptance criteria sufficient to assure that the reactor has been manufactured in conformity with the manufacturing license. This is commonly misstated. The reporting machinery at 10 CFR 52.99, which includes closure notifications, the post-closure notification duty, and the 225-day notification for uncompleted criteria, is what most readers picture when they hear the acronym, and that machinery is written around inspection during construction.

### What happens to verification while the unit is in transport?
Transport is governed by 10 CFR Part 71, and the external radiation standard at 10 CFR 71.47(b)(3) is the provision a fueled microreactor shipment is most likely to press against. A Pacific Northwest National Laboratory assessment prepared for the NRC states that microreactors may be challenged to meet that limit. For verification specifically, transport is a custody interval in which the unit sits outside the manufacturing facility's quality assurance boundary and is not yet inside the site's. Proposed provisions of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) would require verification of the condition of shipped items on receipt at the site without specifying what that verification rests on.

### What would change the analysis in this paper?
A final microreactor licensing rule, or withdrawal or material amendment of the proposal. A published agency position on what a streamlined construct for verifying off-site manufacture would consist of. A final rule following the NRC's proposed rule on package certification requirements (a proposed rule published in the Federal Register on July 27, 2026; a proposed rule that is not final). New national-laboratory results on microreactor transport that change the dose or criticality picture. Or any agency statement addressing the evidentiary status of machine-generated manufacturing records, on which the cited record is silent. Any of those would move the decomposition in section 7, and the paper is versioned so that movement can be recorded.

## Sources

- [U.S. National Archives, eCFR. 10 CFR Part 52 Subpart F, Manufacturing Licenses (sections 52.151, 52.153, 52.157, 52.158, 52.171, 52.173). Current edition, accessed September 2026](https://www.ecfr.gov/current/title-10/chapter-I/part-52/subpart-F)
- [U.S. Government Publishing Office. 10 CFR 52.151, Scope of subpart. CFR 2025, title 10, volume 2](https://www.govinfo.gov/content/pkg/CFR-2025-title10-vol2/pdf/CFR-2025-title10-vol2-sec52-151.pdf)
- [U.S. Government Publishing Office. 10 CFR 52.167, Issuance of manufacturing license. CFR 2025, title 10, volume 2](https://www.govinfo.gov/content/pkg/CFR-2025-title10-vol2/pdf/CFR-2025-title10-vol2-sec52-167.pdf)
- [U.S. Government Publishing Office. 10 CFR 52.99, Inspection during construction; schedules and notifications. CFR 2025, title 10, volume 2](https://www.govinfo.gov/content/pkg/CFR-2025-title10-vol2/pdf/CFR-2025-title10-vol2-sec52-99.pdf)
- [U.S. Nuclear Regulatory Commission. Inspections, Tests, Analyses, and Acceptance Criteria (ITAAC). Page last reviewed August 27, 2026](https://www.nrc.gov/reactors/new-reactors/how-we-regulate/oversight/itaac)
- [U.S. National Archives, eCFR. 10 CFR 52.97, Issuance of combined licenses. Last amended 91 FR 20067, April 15, 2026](https://www.ecfr.gov/current/title-10/chapter-I/part-52/subpart-C/section-52.97)
- [U.S. Nuclear Regulatory Commission, Office of the Inspector General. Audit of NRC's Inspections, Tests, Analyses, and Acceptance Criteria (ITAAC) Process, OIG-12-A-16 (an audit finding dated July 12, 2012)](https://oversight.gov/sites/default/files/documents/reports/2021-11/ML12194A434.pdf)
- [U.S. Government Accountability Office. GAO-07-1129. September 2007](https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-1129/pdf/GAOREPORTS-GAO-07-1129.pdf)
- [U.S. Nuclear Regulatory Commission. Requirements for Maintenance of Inspections, Tests, Analyses, and Acceptance Criteria. Final rule, 77 FR 51880, August 28, 2012. The source credit for 10 CFR 52.99 reads 77 FR 51892, August 28, 2012](https://www.federalregister.gov/documents/2012/08/28/2012-21207/requirements-for-maintenance-of-inspections-tests-analyses-and-acceptance-criteria)
- [U.S. Nuclear Regulatory Commission. Vendor Quality Assurance (QA) Inspections. Page last reviewed August 27, 2026](https://www.nrc.gov/reactors/new-reactors/how-we-regulate/oversight/quality-assurance/vendor-insp)
- [U.S. Nuclear Regulatory Commission. Vendor Inspection Program (VIP) Plan (program page; revision 30, July 2024). Page last reviewed August 27, 2026](https://www.nrc.gov/reactors/new-reactors/oversight/quality-assurance/vendor-insp/vendor-insp-prog-plan.html)
- [U.S. Nuclear Regulatory Commission. ITAAC Related Vendor Inspection Findings. Page last reviewed August 27, 2026](https://www.nrc.gov/reactors/new-reactors/how-we-regulate/oversight/quality-assurance/vendor-insp/itaac-vendor-insp-findings)
- [U.S. Government Publishing Office. 10 CFR Part 21, Reporting of Defects and Noncompliance. CFR 2025, title 10, volume 1](https://www.govinfo.gov/content/pkg/CFR-2025-title10-vol1/pdf/CFR-2025-title10-vol1-part21.pdf)
- [U.S. Government Publishing Office. Appendix B to 10 CFR Part 50, Quality Assurance Criteria for Nuclear Power Plants and Fuel Reprocessing Plants. CFR 2025, title 10, volume 1](https://www.govinfo.gov/content/pkg/CFR-2025-title10-vol1/pdf/CFR-2025-title10-vol1-part50-appB.pdf)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Page last reviewed August 11, 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-24-0008, Micro-Reactor Licensing and Deployment Considerations: Fuel Loading and Operational Testing at a Factory, ADAMS ML23207A252 (staff paper, staff analysis and not a Commission position). Released February 8, 2024](https://www.nrc.gov/docs/ML2320/ML23207A252.html)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093, Policy and Licensing Considerations Related to Micro-Reactors, ADAMS ML20254A363 (staff paper, staff analysis and not a Commission position). Released October 23, 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052, Nth-of-a-Kind Microreactor Licensing and Deployment Considerations, ADAMS ML24309A266 (staff paper, staff analysis and not a Commission position). Released July 3, 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628), Docket NRC-2025-0379; proposed rule, comment period closed June 15, 2026, not final](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. National Archives, eCFR. 10 CFR Part 71, Packaging and Transportation of Radioactive Material. Current edition, accessed September 2026](https://www.ecfr.gov/current/title-10/chapter-I/part-71)
- [U.S. National Archives, eCFR. 10 CFR 71.47, External radiation standards for all packages. Current edition, accessed September 2026](https://www.ecfr.gov/current/title-10/chapter-I/part-71/subpart-E/section-71.47)
- [U.S. Nuclear Regulatory Commission. Modernizing Package Certification Requirements. Federal Register, July 27, 2026 (91 FR 46869), Docket NRC-2025-1667; proposed rule, not final](https://www.federalregister.gov/documents/2026/07/27/2026-15117/modernizing-package-certification-requirements)
- [Pacific Northwest National Laboratory for the U.S. Nuclear Regulatory Commission. Microreactor Incident-Free Transportation Radiation Dose Assessment, PNNL-38760 (contractor report). December 31, 2025](https://www.osti.gov/biblio/3019896)
- [Pacific Northwest National Laboratory. Final Prototype Microreactor Transportation Safety Program, PNNL-38272 (laboratory report). September 22, 2025](https://www.osti.gov/biblio/3364616)
- [Argonne National Laboratory. Microreactor Core Transportation Cask Model Description for Criticality Safety Validation Basis Assessment (Rev. 2), ANL/NSE-25/97-Rev2 (laboratory report). May 29, 2026](https://www.osti.gov/biblio/3367712)
- [Sandia National Laboratories. A qualification framework for the safe transportation of microreactors, SAND2025-07256C (laboratory conference paper). June 2025](https://www.osti.gov/biblio/3369103)
- [U.S. Nuclear Regulatory Commission. Counterfeit, Fraudulent, and Suspect Items. Page last reviewed August 27, 2026](https://www.nrc.gov/about-nrc/cfsi)
- [National Institute of Standards and Technology. Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, SP 800-161r1. May 2022, updated November 1, 2024](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)
- [Abou-Jaoude et al., Idaho National Laboratory and Munro and Associates. Assessment of Factory Fabrication Considerations for Nuclear Microreactors. Nuclear Technology, June 12, 2023](https://www.osti.gov/biblio/1984731)
- [Oak Ridge National Laboratory. Mid-Year Progress Update on ORNL Support for Developing the Guidance for Microreactor Manufacturing Licenses, ORNL/LTR-2022/405 (contractor report). April 2022](https://www.osti.gov/biblio/1887694)
- [Idaho National Laboratory for the U.S. Department of Energy. A Microreactor Program Plan for The Department of Energy, INL/EXT-20-58919 Rev. 4. May 2025](https://gain.inl.gov/content/uploads/4/2025/06/Microreactor-Program-Plan_INL-EXT-20-58919-Rev-4.pdf)
- [Brookhaven National Laboratory for the U.S. Nuclear Regulatory Commission. Assessment of modular construction for safety-related structures at advanced nuclear power plants, NUREG/CR-6486 (contractor report). March 1997](https://www.osti.gov/biblio/464149)
- [Idaho National Laboratory. Regulatory and Licensing Strategy for Microreactor Technology, INL/EXT-18-51111-Rev000 (laboratory report). August 2018](https://www.osti.gov/biblio/1565916)
- [Internet Engineering Task Force. RFC 9334, Remote ATtestation procedureS (RATS) Architecture (Informational). January 2023](https://www.rfc-editor.org/rfc/rfc9334.html)
- [Internet Engineering Task Force. RFC 9943, An Architecture for Trustworthy and Transparent Digital Supply Chains (Standards Track). June 2026](https://www.rfc-editor.org/rfc/rfc9943.html)
- [Internet Engineering Task Force. RFC 9942, CBOR Object Signing and Encryption (COSE) Receipts (Standards Track). June 2026](https://www.rfc-editor.org/rfc/rfc9942.html)
- [National Institute of Standards and Technology. FIPS 204, Module-Lattice-Based Digital Signature Standard. August 13, 2024](https://csrc.nist.gov/pubs/fips/204/final)
- [Wellock, T., U.S. Nuclear Regulatory Commission historian. Floating Nuclear Power Plants: Waves of Uncertainty (Part II). Page last reviewed August 11, 2026](https://www.nrc.gov/reading-rm/basic-ref/students/history-101/waves-of-uncertainty)
- [U.S. Nuclear Regulatory Commission. Modernizing Reactor Licensing, Safety Oversight, and Siting Practices. Federal Register, July 16, 2026 (91 FR 44560); proposed rule, not final](https://www.federalregister.gov/documents/2026/07/16/2026-14341/modernizing-reactor-licensing-safety-oversight-and-siting-practices)

## Open questions
Questions this paper does not resolve, including those we cannot answer from the current record.

- **OQ-1. Which streamlined construct the agency adopts.** What construct, if any, the NRC adopts after comment in place of inspections, tests, analyses, and acceptance criteria for a factory-built reactor, given that Q12-2 of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) invites comment on the question [[19]](#src-19). Staff analysis has addressed factory fuel loading and operational testing at a factory in SECY-24-0008 (a staff paper, which is staff analysis and not a Commission position) [[16]](#src-16) without settling the verification construct. Unresolved because a comment period closing is not a rulemaking outcome. Resolver: the NRC, through rulemaking.
- **OQ-2. Whether a factory quality assurance program can substitute for an independent determination.** Whether a program meeting the Appendix B criteria [[14]](#src-14), enforced through procurement contracts and reached by sampled vendor inspection [[10]](#src-10), can stand in for a per-unit determination reported to the regulator, and under what conditions. Unresolved because the cited record describes the two mechanisms separately rather than treating either as a substitute for the other. Resolver: the NRC, through rulemaking and review practice.
- **OQ-3. Who bears the inspection cost at nth-of-a-kind rates.** How the cost of factory inspection is allocated when units are produced in series rather than singly, given that staff analysis of nth-of-a-kind microreactor licensing and deployment considerations canvasses the deployment question (a staff paper, which is staff analysis and not a Commission position) [[18]](#src-18) and that the agency's microreactor regulatory activities page records the statutory direction to develop oversight and inspection strategies [[15]](#src-15). Resolver: the NRC, with congressional appropriators.
- **OQ-4. Discharging the fleet-modification obligation across sited units.** How the obligation at 10 CFR 52.171(a)(2), under which a Commission-imposed design modification is applied to all reactors manufactured under the license including those already transported and sited [[1]](#src-1), is discharged when the units are numerous, remote, and held by different licensees. Unresolved because the provision states the obligation without describing a mechanism at fleet scale. Resolver: the NRC and manufacturing license holders, on specific dockets.
- **OQ-5. Whether a receipt inspection at a thinly staffed site can be meaningful.** What a receipt inspection under proposed 57.160(e)(1) and proposed 57.197(f) of proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) can establish at a site whose staff have limited reactor construction experience [[19]](#src-19), given that the corresponding provision in the framework in force reaches the shipment through a transport contract rather than through a site inspection [[3]](#src-3). Resolver: the NRC, through guidance and review practice.
- **OQ-6. Whether transport custody belongs to the manufacturer's boundary or the site's.** Whether the transport interval should be treated as part of the manufacturing licensee's quality assurance boundary or the receiving site's, given that Part 71 governs the package [[20]](#src-20), that laboratory work assumes the unit may travel with unirradiated or irradiated fuel [[24]](#src-24), and that cask and qualification work is still being published [[25]](#src-25) [[26]](#src-26). The question is not confined to domestic movement: Proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it) would at 57.197(e) permit removal from the place of manufacture for export under 10 CFR Part 110, which the rule notes differs from 10 CFR 52.153 [[19]](#src-19). Resolver: the NRC, through rulemaking.
- **OQ-7. Whether the public per-item record of factory findings is intended to grow.** Whether the public posting of vendor inspection findings related to acceptance criteria [[12]](#src-12), alongside the published program plan and its self-assessment cadence [[11]](#src-11), is expected to expand for factory-fabricated units, and whether a party outside the transaction is intended to be able to rely on it. Unresolved because the cited pages describe a program rather than a disclosure policy. Resolver: the NRC.
- **OQ-8. We cannot answer this one.** What evidentiary weight a cryptographic manufacturing record would carry in an NRC proceeding. The mechanisms exist as published standards [[35]](#src-35) [[36]](#src-36), and the supply-chain exposure they address is recognized in federal guidance [[28]](#src-28), but the question is untested: we have found nothing in the cited record that establishes how such a record would be weighed, and we are not in a position to assert an answer. Resolver: the NRC and, ultimately, an adjudicatory record.

This paper reflects the state of the cited record as of its revision date. Regulatory proposals, national-laboratory results, and standards referenced here are subject to change. Section references to proposed rules should be re-checked against the current docket before use.

## Related

- [Evidentiary standards for machine-generated reactor records →](https://rankshieldenergy.com/resources/evidentiary-standards-machine-generated-reactor-records)
- [Oversight models for fleet-scale microreactor deployment →](https://rankshieldenergy.com/resources/oversight-models-fleet-scale-microreactor-deployment)
- [Which regulations apply to a microreactor →](https://rankshieldenergy.com/resources/which-regulations-apply-to-a-microreactor)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This paper reflects the state of the NRC manufacturing, construction-inspection, vendor inspection, and transport record as of September 2026. Proposed requirements, including proposed 10 CFR Part 57 (a proposed rule published in the Federal Register on May 1, 2026, with the comment period closed on June 15, 2026; not final, and no developer is licensed under it), may change before any final rule issues. Re-check the docket before relying on any section reference here.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/safety/

# Safety

> The HELIX safety case: passive shutdown by negative temperature feedback, walk-away decay-heat removal by natural-draft air cooling and radiation with no pumps of any kind, no water and no high pressure, and a verification layer held physically outside the safety boundary that can never command it.

The safety case

# Nothing in the safety case moves, and nothing is powered.
**The HELIX safety concept does not depend on a pump, a valve, an operator, or a network, and there is no pump anywhere in the reactor to begin with.** Reactivity self-limits on the core's own physics, shutdown is fail-safe on loss of power, and decay heat removes itself by natural-draft air cooling and radiation. The verification layer that makes the reactor checkable is deliberately held outside this boundary, across a hardware one-way path, and can never command a safety function. This page states each of those claims plainly and then states what still has to be proven before any of them is credited.
A modern microreactor safety case is judged on one question: what happens when everything that can be lost is lost, no grid, no operators, no cooling, no controls, and no way to intervene. HELIX is designed so that the answer to that question is set by physics and geometry rather than by equipment that has to work. The sections below walk each layer of that answer, from the reaction itself out to the boundary that keeps the verification layer honest.

## How does HELIX shut itself down?
Shutdown happens twice over, once by physics and once by mechanism, and the physics comes first. HELIX is designed for a strongly negative temperature coefficient of reactivity: as the core temperature rises, reactivity falls, so power is self-limiting before any control system is asked to act. This is the same feedback that makes a well-designed reactor inherently stable rather than something that has to be actively held in check.
On top of that physics sit sixteen boron-carbide control drums and one diverse central shutdown rod. Their defining property is that they fail into safety. On any loss of power they rotate or drop their absorbing element into the core under spring return and gravity, needing no generator, no operator command, and no software decision. Our screening shows their combined worth exceeds any credible excess reactivity with margin, and the core remains subcritical even under the conservative assumption that the single most effective drum is stuck out. Those numbers are unqualified screening results and are treated as design inputs, not credited safety analysis, but the architecture they describe is deliberate: the mechanism is a backstop to the feedback, not a substitute for it.

## What happens in a total loss of power and cooling?
This is the scenario that defines a walk-away-safe reactor, and it is where the sealed heat pipes and the low-pressure design earn their place. After a trip, the core still produces decay heat, and in HELIX that heat leaves by natural-draft air cooling and thermal radiation alone. The monolith conducts its heat outward, ambient air rises past the module in a chimney flow driven by nothing but temperature difference, RVACS-style, and the balance radiates away. Nothing has to start, nothing has to be switched, and no operator has to be present.
The consequence is the sentence the whole design is built to earn: a complete loss of power and cooling in HELIX is an availability event, not a safety event. The plant stops making electricity; it does not approach fuel damage. The module's large thermal inertia and the low power density buy time measured in the terms that matter for emergency planning. The heat-transport decision, sodium heat pipes versus an EM-pumped pool, is now made, and it made the safety case even simpler: heat pipes won, so there is no pump of any kind in the reactor. With no pumps there is no loss-of-flow accident class at all, and the safety case never credits a pump for the plainest possible reason, none exists.

## Why is there no water and no high pressure?
The primary coolant is low-pressure liquid sodium, and there is no water in the primary system. That single choice removes an entire family of accidents. There is no high-pressure blowdown, because there is no high pressure to release. There is no loss-of-coolant accident of the light-water kind, because the coolant is not a pressurized fluid flashing to steam. And because the power-conversion side is a dry supercritical-CO2 Brayton cycle rather than a steam plant, there is no energetic sodium-water reaction interface anywhere on the site. Sodium does react with water and air, which is a real engineering constraint we design the sealed boundary and inert cover gas around, but the site is deliberately built so that the aggressive counterpart, water, is never present in the same place as the sodium.
Defense in depth, stated as five independent barriers
Each barrier holds on its own. A release requires all of them to fail at once, and the first two are physics, not equipment.
01

**The fuel kernel**
Each TRISO particle is its own containment. Silicon-carbide layers retain fission products to temperatures far above any operating or accident condition. The first barrier is inside the fuel, before any engineered system.

02

**Negative temperature feedback**
If the core heats, the reaction slows. Power and temperature are self-limiting on physics alone, screened at roughly -6 to -8 pcm/K, before a single control action is taken.

03

**Fail-safe shutdown**
Sixteen control drums and a diverse rod insert on loss of power by spring and gravity. No generator, no operator, no software. Screened shutdown worth far exceeds any credible excess reactivity, even with one drum assumed stuck.

04

**Passive decay-heat removal**
After a trip, decay heat leaves by natural-draft air cooling and radiation alone. Nothing is pumped, nothing is powered, no valve moves and no action is required.

05

**Low-pressure sealed boundary**
The primary is low-pressure sodium with zero water. There is no stored pressure energy to drive a blowdown and no loss-of-coolant accident of the light-water kind.

## Where does the verification layer sit, and why can it never cause harm?
HELIX is instrumented for protection by an independent digital-safety platform on an NRC-approved technology lineage, providing deterministic, analyzable trip logic. The RankShield attestation layer, the thing that makes each reactor independently checkable, is deliberately not part of that platform. It observes reactor integrity from outside the safety boundary, across a hardware one-way path: a physical data diode that lets information flow out to be attested and, by the construction of the wiring itself, cannot carry a command back in toward any safety system.
This is a boundary enforced by physics, not by policy. The attestation layer can prove a module's state to an operator, an insurer, or a regulator; it cannot rotate a control drum, override a trip, or touch a protective function, because there is no wire on which such a command could travel. The layer is classified non-safety and observe-only for exactly this reason, which is also what lets it ride on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists; the network only makes that safety checkable.

## What is proven, and what is still owed?
Every claim on this page is a design intent supported by unqualified reactor-physics screening, produced outside a nuclear quality-assurance program. It is not credited safety analysis and it is not field data. No microreactor of this class has yet operated at its rated life, and we will not describe screening as if it were a demonstrated result. The honest path to crediting these claims is defined: a stood-up NQA-1 quality program, structural and thermal finite-element analysis of the failure boundary, independent physics validation with independent codes and ultimately test data, and NRC review, under the proposed 10 CFR Part 57 microreactor framework once it is final, with Part 53 as the backup pathway. The safety architecture is designed to make that path shorter, because the hardest cases are answered by physics that does not need to be qualified so much as confirmed.
[See the validation program and the failure campaign →](https://rankshieldenergy.com/testing)
[See the licensing pathway →](https://rankshieldenergy.com/licensing)



---

## Page: https://rankshieldenergy.com/specs/

# Specifications & Drawings

> HELIX design-of-record specification and dimensioned engineering drawings, module elevation and core cross-section. All figures are design targets; pre-application.

Design of record · targets held to an honest ceiling

# Specification & engineering drawings.
The HELIX module and core at design-of-record fidelity. Every value is computed, not measured in the field. Dimensions on the drawings are representative of the current design basis and will be superseded by qualified design documents.

Figure 1 · Module elevation, not to scale · design targets

Figure 2 · Core cross-section, control drums, fuel channels, diverse rod

## Specification sheet
Module output | 4.40 MWe at the cycle (11.0 MWth, 40% net dry sCO₂). Delivered at the meter is lower and site-specific once dry-cooler fans, house load and ambient derate are taken off; the configurator computes it per site
Site output | Number-up, 1 to 20+ identical modules; roughly 4–100 MWe (design target)
Configuration | Identical factory-sealed modules with N+1 reserve per site
Package | 1.80 m core; 2.70 m pressure-boundary OD (casing stack not yet fixed)
Heat transport | 421 sealed sodium heat pipes; no pumps (EM-pumped pool evaluated, not selected)
Fuel | UCO-TRISO, 19.75 wt% HALEU, graphite-moderated; inside the NRC-accepted EPRI-AR-1(NP)-A particle envelope
Heat-pipe wick | Composite: 14.7 µm surface pore, 48 arteries; 1.52× margin on peak duty (entrainment-limited)
Reflector | BeO, 0.40 m radial
Control | 16 B4C control drums + 1 diverse shutdown rod
Reactivity feedback | −6 to −8 pcm/K (screening)
Core life | 6.67 full-power yr at the current design point; bounded 6.67–6.91 pending the energy-per-fission normalisation (screening; unqualified)
Cooling | Fully dry, forced-draft dry coolers; zero cooling water
Power conversion | Dry sCO₂ Brayton, air-cooled, on skids outside the sealed module
Thermal storage | Molten-nitrate-salt buffer (peak-shave + trip bridge)
Safety I&C | FPGA deterministic (NRC-approved platform lineage)
Attestation | Non-safety, observe-only, behind a hardware one-way path
Transport | Factory-sealed. Outbound at 2.70 m OD is oversize and permittable. Road-legal is 2.60 m and costs core life. Whether a unit travels on ordinary roads or needs superload permitting is an open question, and the shield architecture inside the envelope is not yet fixed
Core return | Ship the irradiated core, not the module, in a Type B cask. Estimated 72 t, a superload. No certified cask is presently dimensioned for a 1.80 m core

All values are pre-QAPD screening resulargets. Heat transport is sealed sodium heat pipes; an EM-pumped sodium pool was evaluated and not selected. Physics figures are unqualified screening, pre-QAPD.



---

## Page: https://rankshieldenergy.com/technology/

# Technology

> How the HELIX microreactor works: a graphite-moderated UCO-TRISO core at 19.75% HALEU, sealed sodium heat pipes with no pumps of any kind, fully-dry cooling, passive walk-away safety, and a sealed transportable module. Every subsystem chosen for physics, supply, and licensing, not novelty.

The reactor · design of record

# How the HELIX microreactor works.
**HELIX is a sealed, transportable microreactor built around choices we can defend on physics, supply chain, and licensing, not on novelty.** It uses a graphite-moderated core of UCO-TRISO fuel at 19.75% HALEU, moves heat with sealed sodium heat pipes and no pumps of any kind, rejects that heat to dry air with zero cooling water, and shuts itself down on its own physics. This page walks the reactor from the fuel kernel outward, and states plainly why each subsystem was chosen and where it still has to be proven.
Most advanced-reactor concepts try to win on a single exotic idea. We took the opposite discipline. Every HELIX subsystem was pushed to its honest engineering ceiling, screened in our own reactor-physics simulations, and then checked against one hard filter: can the materials actually be bought, and can the design actually be licensed. Where a more glamorous choice failed that filter, we took the buildable one. What follows is the result of that filtering, subsystem by subsystem.

## What is the HELIX core made of?
The core is a nuclear-graphite monolith drilled with channels that hold UCO-TRISO fuel compacts. The fuel is uranium oxycarbide enriched to 19.75%, which is high-assay low-enriched uranium (HALEU), the highest enrichment allowed below the 20% line that triggers a different security category. TRISO stands for tri-structural isotropic: each microscopic fuel kernel is wrapped in layers of carbon and silicon carbide that form an individual pressure vessel around it. A single fuel compact contains thousands of these kernels, and the silicon-carbide layer retains fission products to temperatures far above anything the reactor reaches in normal operation or in a loss-of-cooling event.
This is the single most important materials choice in the design. TRISO is not a laboratory curiosity; it is the fuel form the US Department of Energy has invested in for a decade, it has NRC licensing precedent, and it is purchasable today from more than one qualified American fabricator. Choosing it means the fuel supply is a procurement question, not a research program. It also means the first and most robust barrier against a radiological release is built into the fuel itself, before any engineered system is credited.

## How does HELIX control the reaction?
Reactivity is held by sixteen boron-carbide control drums arranged around the core and one diverse central shutdown rod. A control drum is a cylinder with a neutron absorber on one face; rotating it toward or away from the core raises or lowers reactivity smoothly, with no fast-moving parts inside the pressure boundary. The drums fail safe: on any loss of power they rotate their absorbing face inward under spring return, driving the core subcritical without a generator, an operator, or a line of software.
Underneath that engineered control sits the physics that actually keeps the reactor stable. HELIX is designed for a strongly negative temperature coefficient of reactivity, screened in the range of roughly negative six to negative eight pcm per kelvin. In plain terms: if the core heats up, the reaction naturally slows down. Power and temperature are self-limiting before any control system has to act. Our screening shows the combined worth of the drums and the diverse rod exceeds any credible excess reactivity with margin to spare, and the core stays subcritical even if the single most effective drum is assumed stuck. Those are screening results, unqualified and pre-QAPD, and they are inputs to the design rather than credited safety analysis, but they are the reason the control system is a backstop to the physics, not the other way around.

## How does heat leave the core?
Heat leaves the core through sealed sodium heat pipes run through the graphite monolith, carrying it at roughly 650 degrees Celsius with no water anywhere in the primary system. Sodium is an excellent heat-transfer fluid at near-atmospheric pressure, which is the whole point: because the working fluid is not pressurized, there is no stored pressure energy waiting to drive a blowdown, and there is no loss-of-coolant accident of the kind that dominates light-water-reactor safety analysis. After a shutdown, decay heat leaves by natural-draft air cooling and radiation, with nothing powered and nothing pumped.
This decision was, until recently, genuinely open on this page, and we will state plainly how it closed. Two heat-transport architectures went through final evaluation: sealed sodium heat pipes, which have no moving parts and no pumping at all, versus an electromagnetically-pumped sodium pool, which uses a pump with no moving mechanical parts. The heat pipes won, and they won on physics and install engineering, not on preference: the pumped pool lost on installed weight, on commissioning complexity, and on the value of having zero pumps of any kind. The safety invariant is now simpler than the one we used to defend. There is no pump anywhere in the reactor, so there is no loss-of-flow accident class, and the safety case never credits a pump for the plainest possible reason: none exists. Shutdown cooling is carried by natural-draft air cooling and radiation alone.

## Why does HELIX carry a beryllium-oxide reflector?
The core is ringed by a beryllium-oxide radial reflector, 0.40 m thick, and this is the one materials choice where we accepted a constrained supply chain because the physics demanded it. BeO is a superb neutron reflector, and in a core small enough to travel on a truck, that reflection is what makes a multi-year sealed life reachable at all: every screening result we publish, criticality, shutdown worth, and lifetime, is computed with this reflector in place. We state the costs as plainly as the benefit. Beryllium oxide is toxic to machine, expensive, and supply-limited, and the module's BeO inventory is a flagged cost item in our own engineering register. A split reflector, BeO on the inner band with nuclear graphite on the outer band, is under study to cut that inventory without giving back the neutron economy, and if it screens well it will be adopted through the same labeled process as every other change to the design basis.
The pressure vessel is a 50 mm wall around the graphite monolith, and we have not yet fixed its material. We are explicit about why that matters rather than quietly naming an alloy: the maximum operating temperature in our design basis sits near the boundary where code-qualified austenitic grades give way to a nickel-base alloy under ASME Section III Division 5, and the vessel's own operating temperature is not yet a recorded quantity in that basis. Until it is, the Division 5 code case cannot honestly be called closed. Regulatory Guide 1.87 governs that acceptance, and resolving it is a named item on our licensing path rather than an assumption buried in a spec table. The preference is a known, code-covered material with a deep supplier base over a bespoke alloy that would need its own qualification campaign, but preference is not qualification and we do not present it as one.

## How is the electricity actually made, and where does the waste heat go?
Heat from the heat pipes crosses an intermediate heat exchanger and drives a dry supercritical-CO2 Brayton cycle, air-cooled and targeting roughly 40 percent net conversion, so a module at 11.0 MWth delivers 4.40 MWe net. Choosing a dry cycle means there is no steam plant on site and therefore no energetic sodium-water interface to engineer around. Critically, the conversion machinery rides on bolt-on skids outside the sealed reactor module and can be serviced or upgraded without ever opening the module.
All of the reactor's waste heat is rejected to forced-draft dry coolers with variable-speed fans. There is no cooling tower and no evaporative water loss, which means zero cooling-water draw against whatever community or facility hosts the plant. For a microreactor meant to sit beside a data center, an industrial site, or a town, removing the water fight is not a minor convenience; it removes one of the most reliable reasons a thermal plant gets blocked in local permitting.

## How does a HELIX site fit together?
A molten-salt thermal buffer sits between the reactor and the load. It lets each module run flat at its most efficient operating point while stored heat follows demand swings and bridges short transients. The reactor never chases load; the buffer does. A site numbers up identical factory-sealed modules rated 4.40 MWe at the cycle, one module for a hotel or a campus, twenty-plus for a hyperscale site, held to an N+1 reserve margin so a single module outage never takes the site down. Delivered output per module is lower and site-specific; the configurator computes it. Sealed does not mean single-use. The module is sealed in the field and never opened on site, but core exchange lands on a roughly 6 to 7 year cadence and each swapped core returns to the factory to be defueled, recharged and refurbished, so the modules are multi-year while the site runs indefinitely on rolling factory recharge. We are explicit about the unfinished part of that: the irradiated core ships in a Type B cask rather than the whole module, that package is not yet licensed, and at an estimated 72 tonnes it is a superload rather than a routine move. Outbound, the fresh module at 2.70 m is oversize and permittable; road-legal is 2.60 m and costs core life, and which of those a unit needs is a question our envelope work has not closed.
The six decisions that define HELIX
Each row is a place we chose the buildable, licensable, purchasable option over the more novel one. The design is the sum of these filters.
Fuel form not: Metallic or oxide pin fuel | **UCO-TRISO at 19.75% HALEU.** TRISO is the only advanced fuel form that is both NRC-precedented and purchasable from multiple US fabricators today. Each kernel is its own containment; fission products stay inside the particle to well above any credible operating temperature.
Moderator not: Hydride or unmoderated fast spectrum | **Nuclear graphite monolith.** Graphite gives a thermal spectrum that pairs with TRISO, a large heat capacity that slows every transient, and a supply chain with several qualified vendors. It carries the negative temperature feedback the safety case is built on.
Heat transport not: High-pressure helium, water, or an EM-pumped sodium pool | **Sealed sodium heat pipes.** Sodium moves heat at near-atmospheric pressure, so there is no stored pressure energy to drive a blowdown and no loss-of-coolant accident of the light-water kind. Sealing it in heat pipes removes the last pump from the reactor entirely; the EM-pumped pool alternative lost on installed weight, commissioning complexity, and the value of having zero pumps.
Reflector not: Graphite-only reflector | **Beryllium oxide, 0.40 m radial.** BeO's neutron reflection is what keeps a truckable ~1.7 m core critical for a multi-year sealed life; the frozen design basis and all of our screening physics carry it. Its mass, cost, and supply are honestly flagged constraints, and a split reflector with a graphite outer band is under study to cut the BeO inventory.
Heat rejection not: Evaporative cooling tower | **Fully dry forced-draft coolers.** A microreactor sited next to a data center or a community cannot compete for water. Dry cooling draws zero water and removes the single most common local-permitting fight over a thermal plant.
Power conversion not: Steam Rankine | **Dry supercritical-CO2 Brayton.** A dry sCO2 Brayton cycle, air-cooled and targeting roughly 40% net conversion, avoids a steam plant entirely, so there is no energetic sodium-water interface anywhere on site. It rides on bolt-on skids outside the sealed module, so the conversion side can be serviced or upgraded without ever opening the reactor.

## What is proven, and what is still owed?
Everything above is a design of record supported by our own continuous-energy Monte Carlo screening in OpenMC with ENDF/B-VII.1 cross-sections. That screening is unqualified and produced outside a nuclear quality-assurance program, so it informs design decisions and is never credited in a safety case. The qualified path is defined and honestly owed: a stood-up NQA-1 quality program, independent physics validation with independent codes and ultimately test data, NRC licensing, under the proposed 10 CFR Part 57 microreactor framework once it is final, with Part 53 as the backup, and validated demand before any hardware is committed. We publish the targets and label the screening as screening because a reactor whose whole promise is that you can check it cannot afford to blur the line between what is designed and what is proven.
[See the full specification and dimensioned engineering drawings →](https://rankshieldenergy.com/specs)
[Read how the safety case works →](https://rankshieldenergy.com/safety)



---

## Page: https://rankshieldenergy.com/testing/

# Testing & Scenarios

> The HELIX validation program: continuous-energy reactor-physics screening in OpenMC, a six-family register of real-life scenarios from nominal to chaotic failure, and the destructive-boundary campaign, all honestly labeled as unqualified pre-QAPD screening rather than credited analysis.

Validation program · unqualified screening, pre-QAPD

# We test the design against reality before we build it.
**HELIX is screened in our own reactor-physics simulations and stress-tested against a structured register of real-life scenarios, nominal, harsh, chaotic, production, grid, and long-run.** Every result on this page is an unqualified screening analysis: an input to design, not credited safety analysis and not field data. The qualified-lane program that will supersede it is defined and honestly owed. What follows is exactly what we have run, what it showed, and what it deliberately does not yet prove.
There is a temptation, in a pre-application program, to show only the numbers that flatter the design. We do the opposite, because the entire premise of RankShield is that our claims are checkable. So this page separates three things that are often blurred together: physics we have actually screened, the full register of real-world conditions the design is being tested against, and the destructive-boundary work that still requires tools we are standing up. Reading it should leave you knowing precisely how far along the validation is.

## What reactor physics have we actually run?
The screening uses OpenMC, an open-source continuous-energy Monte Carlo neutron-transport code from the same national-laboratory ecosystem that qualified codes come from, with ENDF/B-VII.1 nuclear data, run locally on the design of record. Monte Carlo transport is the reference-class method for this work: it tracks individual neutron histories through the real geometry and materials rather than approximating them. The table below is the current state of that screening. Every row is a design input, pre-QAPD, and will be superseded by qualified analyses once the quality program is stood up.
Criticality & core sizing | Continuous-energy Monte Carlo (OpenMC, ENDF/B-VII.1) Design of record resized to reach criticality with a beginning-of-life excess-reactivity bank.
Reactivity-limited lifetime | Depletion, full-power 6.67 full-power years at the current design point, re-derived from a depletion run at the matched double-heterogeneity bias. Bounded 6.67 to 6.91 pending the energy-per-fission normalisation. A worse number than we held a week earlier, reported because it is what the evidence supports.
Temperature feedback | Multi-temperature k-eff Strongly negative coefficient (-6 to -8 pcm/K), self-stabilizing.
Shutdown margin | Drum + diverse-rod worth Combined worth far exceeds any credible excess reactivity, with ample margin under a stuck-drum assumption.
Post-trip xenon | Xenon transient depletion No xenon dead-time at this power density; a tripped module can restart immediately.

The most consequential finding is the least glamorous one. Depletion screening, plus scaling from our validated larger-core run, puts the module's reactivity-limited life at roughly four to five full-power years as modeled, and likely five to seven once known model conservatisms come out, the homogenization bias and the erbium banking not yet applied, with an engineering path toward eight. That number, not power or efficiency, is the binding design constraint, and it is the reason the site architecture is built around staggered sealed-core swaps and rolling factory recharge rather than a single long-lived unit: the modules are multi-year, but the site runs indefinitely. We would rather design honestly around a screened lifetime than advertise a sealed life the physics does not support.

## How do we test against real-world conditions?
Reactor physics tells you whether the core works. It does not tell you what happens on a 49-degree afternoon when the dry coolers are fouled with dust, or when the grid browns out while a neighboring generator is still spinning down. For that we maintain a register of six scenario families that together cover the conditions a deployed reactor actually meets, from ordinary operation to deliberately chaotic failure. Each scenario is mapped to the analytical tool that is meant to prove it, and we are explicit about which of those tools is already running and which is owed.
A · Nominal
Steady full power over the swap interval; daily AI-load swing (the reactor never chases load, storage absorbs it); seasonal ambient sweep; startup and shutdown margins.

B · Harsh environment
Hot-day derate (45 to 50 °C); frozen-sodium cold start; dust, salt, and smoke cooler fouling; seismic; flood; grid-outage islanding.

C · Chaotic / failure
Single worst-position channel failure; cascade (2 tolerated, 3 forces shutdown, more is beyond design basis); module trip with survivors carrying the site for months; xenon restart; stuck drum; station-blackout walk-away; conversion-island failure.

D · Production & logistics
Fabrication-defect containment (block segmentation, 100% acceptance test); weld-yield Monte Carlo; transport damage to a sealed module (attested custody, site acceptance); vendor-failure supply strategy.

E · Grid & electromagnetic
Frequency ride-through; brownout with slow generators (storage bridge, then fast islanding, then fail-safe drum insert); EMI and RFI (self-generated and host-facility); GMD and EMP for defense sites; timing-attack on the attestation layer.

F · Long-run internals & siting
Sodium void reactivity sign (decision-gating); tritium permeation; Na-24 activation dose fields; absorber swelling; graphite dust; state nuclear-law siting screen.

Two design principles show up repeatedly across these families. First, the reactor never chases load: the molten-salt thermal buffer absorbs demand swings so the core runs flat, which turns a whole class of grid-following transients into storage problems rather than reactor problems. Second, failure is designed to degrade gracefully: a number-up site carries an N+1 reserve module so the survivors carry the load for months if one module trips, and the cascade logic tolerates two simultaneous channel failures, forces an orderly shutdown at three, and treats anything beyond that as outside the design basis rather than pretending it is handled.

## What does the failure campaign still owe?
Screening establishes the reactivity and lifetime envelope. It does not establish the destructive boundary, the maximum-power-to-failure case, cascade thermal-stress, and seismic response, because those are structural and thermal problems, not neutronics problems. Answering them requires finite-element analysis, which we are standing up using MOOSE-class multiphysics tools from the same national-laboratory ecosystem as our neutronics. Until that stand-up is complete and validated, we make no claim of demonstrated structural or thermal-mechanical performance, and the failure campaign is explicitly incomplete.
The gates that remain before any hardware are the same ones stated across this site, and the validation program is where several of them are earned: a stood-up NQA-1 quality program so that analysis can be credited at all, independent physics validation with independent codes and ultimately test data, the finite-element failure campaign, NRC licensing under the proposed Part 57 microreactor framework once it is final or under Part 53 as the backup, and validated demand. None of the screening on this page shortcuts those gates. It exists to make sure that when we walk through them, the design already knows where its limits are.
Honesty statement
Everything on this page is unqualified screening produced outside a quality-assurance program. It informs design decisions and is never credited in a safety case. It is superseded by qualified analyses once the QA program is stood up.
RankShield Energy · HELIX · pre-application



---

## Page: https://rankshieldenergy.com/verify/

# Verify this site

> Recompute the SHA-256 of any page on this site in your own browser and compare it to the hash we published. Tamper-evidence you can check yourself, with its limits stated plainly.

Check us

# Verify this site.
We argue that a reactor should be checkable rather than taken on trust. It would be strange to ask that of a reactor and not of our own website. Every page here publishes a hash. This is where you check one.
Content integrity check
Page path Recompute hash and compare Ready.
Published - Recomputed - Build -
This proves the text you were served matches the hash published for this build. It is
tamper-evidence, not a signature and not an independent witness, and we do not present it as one.
The manifest is at [/transparency.json](https://rankshieldenergy.com/transparency.json).

## What this checks
Every build writes a clean Markdown twin of every page, hashes each one with SHA-256, and publishes the result at [/transparency.json](https://rankshieldenergy.com/transparency.json). The tool above refetches a twin in your browser, recomputes the hash with WebCrypto, and compares. Nothing is sent anywhere; the computation happens on your machine.

## What this does not check
This is tamper-evidence, not a signature and not an independent witness. The manifest and the page are served from the same origin, so an operator able to change one could change both. What it rules out is a page being altered after publication without the published hash moving with it. That is a real and narrow guarantee, and it is the only one we claim here.
The module-level attestation described on the [technology](https://rankshieldenergy.com/technology/) and [safety](https://rankshieldenergy.com/safety/) pages is a different and far stronger construction: post-quantum signed telemetry, an append-only log, independent off-site co-signers. It is a design target for the reactor, not something running on this website today, and we label it that way everywhere it appears.

## Do it yourself
The tool is a convenience, not the mechanism. Any page path with a.md extension returns its twin, and /transparency.json lists the expected hash for each route:
curl -s https://rankshieldenergy.com/technology.md | shasum -a 256
curl -s https://rankshieldenergy.com/transparency.json | grep -A2 '"/technology/"' If those two agree, the page you read is the page we published.

## The other machine surfaces
The same discipline applies to what we hand to AI systems. Each of these is generated from one configuration file at build time, so none of them can quietly disagree with the pages:

- [/llms.txt](https://rankshieldenergy.com/llms.txt), a ranked index with the key facts and the honesty rails.
- [/llms-full.txt](https://rankshieldenergy.com/llms-full.txt), the full text of every page in a single fetch.
- [/AGENTS.md](https://rankshieldenergy.com/AGENTS.md), how to cite us accurately and what not to claim on our behalf.
- [/ai-content-index.json](https://rankshieldenergy.com/ai-content-index.json), the same map as JSON.
