# Fleet-Scale Verification: One Operator

> When one operator oversees many microreactors, verification has to scale too. See what changes and why independent confirmation matters more at fleet scale.

[Resources](https://rankshieldenergy.com/resources) / Verification & trust Verification & trust

# Fleet-Scale Verification: One Operator, Many Reactors
Published July 24, 2026 · By [Jamie Kloncz](https://rankshieldenergy.com/authors/jamie-kloncz), Founder, RankShield Energy

HELIX microreactor, concept render. RankShield Energy is at the pre-application stage; this depicts a design under development, not an operating facility. A single reactor can be watched. A fleet cannot be watched the same way. When one operating organization oversees many microreactors across many sites, human attention becomes the scarce resource, and verification does not scale linearly with the fleet. The cost that grows fastest is not checking each unit. It is reconciling them, and that is the part of the problem nobody has solved yet.
This is worth working through now because the regulatory direction points at it. The NRC's proposed Part 57 rule contemplates remote operation and reduced on-site staffing for microreactors [[1]](#src-1), and NRC staff have examined licensing and deployment beyond the first unit of a design, including standardization of operational programs [[2]](#src-2). Sandia National Laboratories, working for the NRC, has described designs in which one control room supervises multiple microreactors [[10]](#src-10). None of that is settled law. Part 57 is proposed rather than final, its comment period closed in June 2026, and no developer is licensed under it.
What follows is about the structural problem rather than any product: what changes when one organization oversees many units, why verification does not simply multiply, why the failure mode is quiet, the three properties fleet verification has to have, what the NRC's own oversight direction implies, what the national laboratories have described, what the rules require today, and where the field honestly stands. RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval, we operate no fleet, and we have never operated a reactor. The last section applies the argument to us.
Key takeaways

- At fleet scale, attention per reactor falls by design, so more of the safety story has to be carried by evidence rather than by presence.
- Verification does not multiply. The dominant cost is reconciliation: deciding whether one unit behaving differently is a sensor, maintenance, real divergence, or nothing.
- The failure mode is quiet. Small anomalies across many units are what human attention handles worst, so differences stop being investigated because they usually amount to nothing.
- Fleet verification has to be per-unit, comparable across units, and checkable by someone outside the operator. Two out of three is not verification.
- Proposed Part 57 contemplates remote and reduced-staffing operation, but it is not final, the comment period closed in June 2026, and it grants no approval today.
- Honest status: no commercial microreactor fleet is operating, so fleet-scale independent verification exists nowhere, including here.

## What changes is that presence stops scaling
With one reactor, oversight can lean on proximity. People are on site, they know the plant, and their judgment fills gaps that instrumentation misses. That is not an informal arrangement. Federal regulation requires a licensed operator to be present at the controls at all times [[5]](#src-5), and the NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, describing their role as independently verifying that requirements are being met [[6]](#src-6).
Now put one operating organization in charge of many units across many sites. The staff-to-reactor ratio falls by design, because that ratio is part of why modular fleets are attractive in the first place. This is not a hypothetical operating model invented for an article. Sandia National Laboratories, working for the NRC on human factors for automating microreactors, described designs in which operators may monitor from a remote location and in which one control room supervises multiple microreactors [[10]](#src-10).
What replaces proximity is reporting. Each unit describes its own condition, and the operating organization assembles a picture from those descriptions. Many distributed industrial systems already work this way and work well. But the change is worth stating plainly, because it is easy to miss: a claim of safe operation stops resting on what an experienced person observed and starts resting on whether the reporting itself can be trusted. At fleet scale, trust in operations becomes trust in evidence, which is the same shift that makes [verifying a single autonomous microreactor](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely) a different exercise from watching a staffed plant.
The table below maps the oversight functions that presence quietly performed, what happens to each one across a fleet, and what has to take over. The last row is deliberately unresolved.

How single-unit oversight functions change at fleet scale. This mapping is ours, offered as a way to structure the question, not as a regulatory framework.

Oversight function
What it relied on with one reactor
What breaks across a fleet
What has to replace it

Noticing that something is off
A person present who knows the plant
Attention per unit falls as the unit count rises
Per-unit evidence that surfaces divergence before anyone has to notice it

Judging whether it matters
Local knowledge and shift-to-shift memory
Many other units compete for the same judgment
Records comparable across units, so a difference reads as a difference

Recording what happened
Logs kept and interpreted by the operator
Volume grows faster than the capacity to review it
Records signed and checkable later without the operator helping

Outside confirmation
Resident inspectors on site
Inspection presence does not scale one-to-one with sites
Evidence a regulator, insurer, or lender can appraise remotely

Escalating when performance degrades
An action matrix tied to a licensed operating plant
No fleet-level equivalent exists for microreactors today
An open question. Named here rather than answered.

## Verification does not multiply, because the real cost is reconciliation
Verifying twenty reactors is not twenty times verifying one. Handled unit by unit, it is worse than linear, and the reason is that the dominant cost is not checking. It is reconciliation.
Reconciliation is the work of deciding what a difference means. Unit seven is running slightly differently from the other nineteen. Is that a sensor drifting, a maintenance action nobody logged clearly, a real divergence in how that unit is behaving, or nothing at all? Answering that question requires comparing unit seven against its own history and against its siblings, then forming a judgment that is rarely clean. Each additional unit adds a check, but it also adds a new set of comparisons, and comparisons are where the hours go.
This is the claim in this article that we would most like people to argue with, because it cuts against how fleet oversight is usually sold. The pitch is normally aggregation: one screen, all units, green across the board. Aggregation does not remove reconciliation cost. It relocates it, and often it hides it, because a fleet rollup is precisely the presentation in which one divergent unit disappears into an average. A dashboard that is green because nineteen units are fine is not evidence about the twentieth.
The design consequence follows directly. If reconciliation is the expensive part, then the fleet has to emit evidence in a form that makes comparison cheap and divergence conspicuous, rather than leaving reconciliation as an exercise performed by whoever happens to be on shift. That is an argument about the shape of the record, not about how hard people are working, and it starts at the point where a sensor reading becomes something durable, which is the chain we walk through in [turning reactor state into an attestation record](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record).

## The failure mode is quiet, not dramatic
The way fleet oversight degrades is not a missed alarm during a crisis. It is a slow normalization in which small differences stop being investigated because they usually amount to nothing.
The mechanism is ordinary and well known outside nuclear. Sustained monitoring of mostly uneventful signals degrades human detection performance over time, which is why vigilance is treated as a design constraint rather than a matter of diligence. Add volume and the second effect arrives: when most flagged differences turn out to be benign, the flags themselves lose meaning, and the rational response of a competent person managing many units is to triage harder. Neither effect is a failure of character. Both are predictable properties of the task, and a fleet is a machine for producing exactly the input that triggers them, which is a high rate of small, mostly uninteresting variation spread across many units.
This is why human factors work in this area treats the human and automation interface as a safety-relevant question rather than a usability nicety, and why function allocation between people and machines is the framing rather than whether machines act at all [[10]](#src-10). Brookhaven National Laboratory, reviewing facilities without main control rooms for the NRC, put the safety question precisely: the issue is not so much justifying why a design has no main control room, but verifying that important human actions can be accurately and reliably performed [[11]](#src-11).
Apply that formulation to a fleet and it does real work. If one of the important human actions is investigating a divergence, then the reliability of that action is a safety question, and it is a question about workload and evidence quality rather than about competence. An organization can staff a fleet with excellent people and still build a system in which the twentieth anomaly of the week gets three seconds of attention. Designing against that means the evidence has to do more of the noticing.

## Fleet verification has to be per-unit, comparable, and externally checkable
Three properties have to hold at once. Any two without the third produces something that looks like verification and does not function as it.
**Per-unit.** Verification attaches to an individual reactor, not to a fleet average. A fleet-level summary that smooths individual behavior is a management view, and management views are useful, but averages are exactly where a single divergent unit becomes invisible. If the artifact cannot be pulled apart into one record per unit, it is not verification of any unit.
**Comparable across units.** If each reactor reports in its own idiosyncratic format, reconciliation stays manual and the cost of oversight grows with fleet size. Comparability is what allows an anomaly to stand out against its siblings rather than requiring a person to notice it unaided. This is also where standardization stops being a procurement convenience and becomes an oversight property.
**Checkable by someone outside the operator.** At single-reactor scale, a regulator can partly compensate for weak evidence with inspection. Across a distributed fleet that compensation does not scale either, which makes machine-checkable evidence more load-bearing rather than less. The architecture that formalizes this separation is settled outside nuclear: RFC 9334 defines an attester that produces evidence about its state, a verifier that appraises that evidence against a policy, and a relying party that acts on the verifier's result [[14]](#src-14). The point of the split is that the party with a stake in the answer is not the party producing it, which is the whole of [self-attestation versus independent verification](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors).
The obvious objection is that industrial fleets already run on remote monitoring platforms, and that a well-built one covers all three properties. Sometimes it covers the first two. The third is where these systems generally stop, because they are built to give the operating organization a better view of its own assets, which is a legitimate and different goal. The test that separates them is simple to state and uncomfortable to answer: what could a regulator, insurer, or lender establish about unit seven last month if the operator declined to help, or no longer existed? If the answer depends entirely on the operator's cooperation, the platform is operations tooling. It may be excellent operations tooling.

## The NRC's own oversight direction points at scale and standardization
The regulator has been working on this longer than the vendors have. SECY-20-0093, in October 2020, flagged autonomous operation, remote operation, staffing, and regulatory oversight as open policy questions specific to microreactors [[4]](#src-4). Those questions did not have clean answers inside a framework built for large light-water plants, and naming them was the useful act.
More recently the staff has been planning for repetition rather than for one-off projects. SECY-25-0052 addresses nth-of-a-kind microreactor licensing and deployment, including standardization of operational programs [[2]](#src-2). That is the regulatory shape of many similar units rather than a handful of bespoke ones, and standardization has a direct consequence for verification: units built and operated to a common program are units whose records can be compared. Separately, NRC staff have proposed operational-phase oversight built on a scalable inspection footprint [[3]](#src-3), which is the agency acknowledging in its own terms that inspection presence cannot grow one-for-one with sites.
Set that against what oversight rests on today. The Reactor Oversight Process is risk-informed and tiered, built on safety cornerstones, NRC-developed inspection findings, licensee-reported performance indicators, a significance determination process, and an action matrix that escalates as performance degrades [[7]](#src-7). The Government Accountability Office has described the agency's safety assurance as resting on exactly that, the monitoring and inspection of the activities with the greatest effect on safety [[8]](#src-8).
Two things follow. The first is that performance indicators reported by the licensee are already part of the structure, so the idea of an operator supplying evidence about itself is not foreign to nuclear oversight. The second is that the balance shifts. As inspection presence per unit thins, the licensee-reported share of the picture grows, and the quality of that reporting stops being an administrative matter. It is also worth noting that readiness is not assumed even by the agency's own overseers: GAO reported in July 2023 that the NRC needed to take additional actions to prepare to license advanced reactors [[9]](#src-9). That is a reason to design evidence carefully now, not a reason to wait.

## The national laboratories have already described the fleet operating model
This is not a scenario the industry invented for marketing. Sandia, working for the NRC, described designs where operators may not be located on site and where one control room supervises multiple microreactors [[10]](#src-10). That single clause carries most of the difficulty in this article, because supervising several units from one room changes what a supervisor can actually attend to.
Oak Ridge examined what autonomous control disturbs and found it reaches well past headcount, into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and event notifications, with the control room possibly not co-located with the plant [[12]](#src-12). Each of those is a place where fleet scale multiplies the question rather than repeating it. Technical specifications for one unit are a document. Technical specifications across a fleet, with per-unit deviations and per-unit histories, are a reconciliation problem.
Oak Ridge's work on concepts for autonomous operation of microreactors names the engineering preconditions plainly: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring and control [[13]](#src-13). None of those are trivial, and the third one changes character at fleet scale, since a common software stack across many units is efficient and is also a common surface. That tension is the subject of [microreactor cybersecurity](https://rankshieldenergy.com/resources/microreactor-cybersecurity-explained) and it is not resolved by verification alone.
Read together, the lab record supports a narrow and specific conclusion. The operating model of one organization supervising many remote units is described in the literature as a design direction being studied. It is not described as a validated arrangement with a settled oversight answer, and the Brookhaven framing about verifying that important human actions can be accurately and reliably performed [[11]](#src-11) is the standing test that a fleet architecture would have to meet.

## What the rules require today, and what is only proposed
The current baseline is unambiguous. The conditions of an operating license require a licensed operator to be present at the controls at all times [[5]](#src-5). Whatever a fleet architecture eventually looks like, that is the rule as it stands, and no fleet of microreactors is operating under any different arrangement in the United States today.
The proposed 10 CFR Part 57 framework contemplates remote operation and reduced on-site staffing for microreactors, published in the Federal Register on May 1, 2026 [[1]](#src-1). Three qualifications belong in the same breath every time it is mentioned. It is proposed and not final. Its comment period closed in June 2026. No developer is licensed under it, including us. A walkthrough of what the proposal actually says is in [our explainer on Part 57 and autonomous operation](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained), and the honest summary is that it sets a direction rather than granting a permission.
It is worth being explicit about what this article is not describing, because the vocabulary in this space runs ahead of the facts. Nothing here describes an unmanned plant, and nothing here describes fully autonomous operation in the sense of a reactor running without human involvement in safety-significant actions. No facility is licensed to operate that way. Human-in-the-loop for reactivity and safety actions is the assumption throughout, and a verification layer does not change it, because a verification layer produces evidence rather than control.
That distinction also answers a question we get asked in a different form: whether better evidence could substitute for the operator or the inspector. It could not, and the argument here does not require it to. The NRC's oversight of licensees stays with the NRC [[7]](#src-7). Independent verification is a technical function that supports regulatory oversight rather than replacing any part of it, and the reason to build it is that the mechanisms outsiders have historically relied on to know anything at all get thinner as unit counts rise.

## Where this actually stands, including where we stand
Nobody is running a commercial microreactor fleet, so nobody is running fleet-scale independent verification. That is the whole status, and it is worth saying without softening. Any vendor presenting fleet verification as a proven, deployed capability is describing an intention. The regulatory framework that would allow the operating model is proposed and not final [[1]](#src-1), and the national-lab work referenced throughout this article consists of research and demonstrations by the laboratories, which belong to those institutions and are not evidence about any vendor's product, ours included.
RankShield Energy is a pre-applicant with the NRC [[15]](#src-15). We hold no license, permit, or design approval. We operate no fleet, and we have never operated a reactor. Nothing about our design has been demonstrated to or accepted by the NRC. Our working expertise is on the verification side rather than the operating side: independent verifiers, signing, transparency logs, and the question of what an outside party can check without cooperation from the party being checked.
Here is a concrete decision from that work, stated with what it costs. We design toward per-unit signed records rather than fleet rollups, even though rollups are cheaper to produce, easier to store, and far more pleasant to demonstrate. The tradeoff is real. Per-unit records mean more artifacts, more storage, more surface to keep consistent, and a system that surfaces more differences to a human than a smoothed fleet view would. We accept that because a rollup answers a question about the fleet, and the question that matters in an incident is about one unit. We would rather explain the extra noise than explain, later, why the divergent unit was inside an average.
The honest limitation is that our own architecture is subject to the same test we just applied to everyone else. A verification layer built and run by the party being verified is self-attestation with better engineering, which is why verifier and operator separation has to be structural rather than added later, and why we think a party that can publicly contradict us is a feature rather than a defect. We are not there. If you are evaluating developers on any of this, the questions are in our [microreactor vendor evaluation guide](https://rankshieldenergy.com/resources/how-to-evaluate-a-microreactor-vendor), and they should be applied to us as unsentimentally as to anyone else.

## Frequently asked questions

### Does proposed NRC Part 57 allow one operator to run many reactors?
Not today, and the proposal itself grants nothing. Proposed Part 57 contemplates remote operation and reduced on-site staffing for microreactors, which points toward fleet-style oversight [[1]](#src-1), but it was published on May 1, 2026, its comment period closed in June 2026, it is not final, and no developer is licensed under it. Meanwhile the operative rule still requires a licensed operator at the controls at all times [[5]](#src-5). Contemplating an operating model is also not the same as approving a staffing arrangement, which would be evaluated for a specific design under review. Treat it as regulatory direction rather than present permission.

### Why is verifying a fleet harder than verifying one reactor twenty times?
Because the expensive part is reconciliation, not checking. With many units, the work is deciding what a difference means: whether one unit behaving slightly differently is a drifting sensor, an unlogged maintenance action, a genuine divergence, or nothing. Most of those turn out to be benign, and that is exactly the condition under which anomalies stop being investigated. Human detection performance degrades against high-volume, mostly uneventful variation, so the fleet has to produce evidence that makes comparison cheap and divergence conspicuous rather than leaving reconciliation to whoever is on shift.

### What does fleet-scale verification actually have to produce?
Three properties at once. Per-unit records, because a fleet average is where a single divergent unit disappears. Comparability across units, because idiosyncratic per-unit reporting keeps reconciliation manual and makes oversight cost grow with fleet size. And checkability by a party outside the operator, because inspection presence does not scale one-for-one with sites. The third property has a standard form outside nuclear: RFC 9334 separates the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [[14]](#src-14). Two out of three produces something that resembles verification without functioning as it.

### Is anyone operating a microreactor fleet under independent verification today?
No. No commercial microreactor fleet is operating at all, so fleet-scale independent verification does not exist in practice. What exists is a regulatory proposal that contemplates the operating model and is not final [[1]](#src-1), national-lab research describing designs in which one control room supervises multiple microreactors [[10]](#src-10), and a set of engineering preconditions the labs have named rather than closed [[13]](#src-13). RankShield Energy is a pre-applicant that operates no fleet and has never operated a reactor [[15]](#src-15).

### What should a buyer ask a vendor about fleet operations?
Ask how evidence from each unit is produced, whether it is directly comparable across units, and who confirms it besides the operator. Then ask the harder version: if one unit diverges, who is alerted, what record is created, and could an outside party reconstruct that sequence afterward without the vendor's help. Answers that describe a monitoring dashboard are describing operations, which is necessary but is the operator grading its own work. Today that outside confirmation is supplied largely by people, with roughly 150 NRC resident inspectors in the field whose stated role is independently verifying that requirements are being met [[6]](#src-6). A fleet answer has to say what supplies it when presence per unit falls.

## Sources

- [U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)](https://www.federalregister.gov/documents/2026/05/01/2026-08550/licensing-requirements-for-microreactors-and-other-reactors-with-comparable-risk-profiles)
- [U.S. Nuclear Regulatory Commission. SECY-25-0052: Nth-of-a-Kind Microreactor Licensing and Deployment Considerations. June 2025](https://www.nrc.gov/docs/ML2430/ML24309A266.html)
- [U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026](https://www.nrc.gov/reactors/new-reactors/advanced/modernizing/microreactors/reg-activities)
- [U.S. Nuclear Regulatory Commission. SECY-20-0093: Policy and Licensing Considerations Related to Micro-Reactors. October 2020](https://www.nrc.gov/docs/ML2025/ML20254A363.html)
- [U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition](https://www.govinfo.gov/content/pkg/CFR-2024-title10-vol1/xml/CFR-2024-title10-vol1-sec50-54.xml)
- [U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026](https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/resident-inspectors-bg)
- [U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026](https://www.nrc.gov/reactors/operating/oversight/rop-description)
- [U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025](https://www.gao.gov/products/gao-25-107807)
- [U.S. Government Accountability Office. Nuclear Power: NRC Needs to Take Additional Actions to Prepare to License Advanced Reactors (GAO-23-105997). July 2023](https://www.gao.gov/products/gao-23-105997)
- [Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020](https://www.osti.gov/biblio/1763526)
- [Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025](https://www.osti.gov/biblio/2529385)
- [Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018](https://www.osti.gov/biblio/1492160)
- [Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019](https://www.osti.gov/biblio/1615811)
- [Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023](https://www.rfc-editor.org/info/rfc9334/)
- [U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026](https://www.nrc.gov/reactors/new-reactors/advanced/who-were-working-with/pre-application-activities)

## Related

- [How to verify an autonomous microreactor →](https://rankshieldenergy.com/resources/verify-autonomous-microreactor-operating-safely)
- [Self-attestation vs independent verification →](https://rankshieldenergy.com/resources/self-attestation-vs-independent-verification-reactors)
- [Part 57 and autonomous operation, explained →](https://rankshieldenergy.com/resources/nrc-part-57-autonomous-operation-explained)
- [Trusting a remotely operated reactor's command state →](https://rankshieldenergy.com/resources/trusting-remotely-operated-reactor-command-state)
- [Turning reactor state into an attestation record →](https://rankshieldenergy.com/resources/reactor-state-sensors-attestation-record)
- [Digital twins and remote reactor verification →](https://rankshieldenergy.com/resources/digital-twin-verification-remote-reactor-operations)

Written by
Jamie Kloncz
Founder, RankShield Energy
Jamie leads the HELIX microreactor pre-application program and RankShield Energy's verification-first approach to advanced-reactor operations. [More about the author](https://rankshieldenergy.com/authors/jamie-kloncz)

*This guide reflects the state of NRC microreactor rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. Check back if the rule is finalized or the NRC issues new guidance.*
**About this article.** RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.

A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application
