Verification & trust
Self-Attestation vs Independent Verification for Autonomous Reactors

Self-attestation is a reactor reporting on itself: the operator runs the reactor and also produces the account of how it is behaving. Independent verification adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer. Both can be accurate. Only one is checkable by anyone else.
The distinction sounds academic until presence is removed. Today the NRC keeps roughly 150 resident inspectors in the field, at least two per plant, whose stated role is independently verifying that requirements are being met [1]. A design premised on reduced on-site staffing removes that layer, and what replaces it determines whether an outside party can establish anything at all.
This article sets out the difference, three structural tests that separate the two models, how two adjacent fields already solved the same problem, what independence has to mean concretely, and why autonomy converts this from good practice into a requirement. RankShield Energy is a pre-applicant holding no license or approval [20], and the last section applies the argument to us.
Key takeaways
- Self-attestation is the operator vouching for itself; independent verification adds a party with no stake in the answer.
- The useful test: if the operator went silent, what could an outsider still establish about last month?
- Independence is structural and testable: who signs, who can alter it, and what an outsider can check unaided.
- IAEA safeguards and the internet's attestation standards both solved this by putting the checker outside the checked.
- As on-site presence thins, more of the safety story rests on self-report, which makes independent confirmation more load-bearing, not less.
The distinction, stated as plainly as possible
Self-attestation is a system reporting on itself. The operator runs the reactor and also produces the account of how the reactor is behaving. Independent verification adds a second party that appraises that account against evidence and records the result, where that party has no stake in the answer.
Both can be accurate. The difference is not honesty, and framing it as a trust problem about vendors misses the point. The difference is what an outside party is able to establish for themselves.
A useful test: if the operating organization went silent tomorrow, what would a regulator, insurer, or lender still be able to determine about what the reactor did last month? Under self-attestation the answer is roughly nothing, because every artifact traces back to the party being evaluated. Under independent verification the answer is bounded but real.
That gap is the entire subject of this article, and it becomes load-bearing precisely when people stop being physically present.
One clarification before going further, because it is the most common misreading of this argument. Nothing here implies that operators are untrustworthy or that vendor engineering is weak. The claim is narrower and structural: a party cannot supply the independence of its own account, however competent or honest it is. That is a property of the arrangement rather than a judgment about the people inside it.
Why self-monitoring is necessary but never sufficient
Nothing here argues against operator monitoring. A reactor cannot be run without it, and a vendor with excellent internal instrumentation is in better shape than one without. Self-monitoring detects the large majority of problems, and it detects them fastest.
What it cannot do, by construction, is catch the class of problem where the reporting path itself is the thing that is wrong. If a model is miscalibrated, a sensor drifts, or a reporting chain is compromised, the dashboard can look healthy while the underlying picture is not. There is no second party positioned to notice the discrepancy, because the only observer is the one being observed.
This is not a hypothetical failure mode invented for marketing purposes. It is the ordinary reason auditors exist in every other high-consequence domain, and the reason no serious institution accepts a self-certified financial statement as equivalent to an audited one.
Nuclear has historically solved it with people. The NRC keeps roughly 150 resident inspectors in the field, at least two at every plant, and describes their function as independently verifying that requirements are being met [1]. That word "independently" is doing specific work in that sentence. The inspector is not a better observer than the operator. The inspector is a differently positioned one.
Three tests that separate the two models
Independence is not a matter of intentions, and it cannot be established by assertion. It is structural, and it can be tested with three questions that a buyer can ask in a meeting.
| Test | Self-attestation | Independent verification |
|---|---|---|
| Who signs the record? | The operator, or its software | A party separate from operations |
| Who can alter or withdraw it? | The same party that produced it | No one silently; changes are detectable |
| What can an outsider check unaided? | Only what the operator chooses to show | The signature, the log, and the inclusion proof |
| Failure mode | Undetectable divergence between claim and reality | Detectable, with a record of when detection occurred |
The second row is where most systems marketed as verification actually fail. Logs that the operator can rewrite are not evidence, however well formatted. The property that matters is not that a record cannot be changed, but that it cannot be changed quietly.
The third row is the one buyers should press hardest, because it is answerable with a demonstration rather than a description. Ask what an outside party can check without the vendor participating. If the answer requires the vendor to hand something over or vouch for something, the separation is nominal.
How other high-consequence fields already solved this
Nuclear contains the precedent already, in a different problem domain. The IAEA safeguards system exists so that an outside body applies technical measures through which it can independently verify that facilities are not misused, rather than relying on a state or operator assertion [2]. Safeguards address non-proliferation rather than operational safety, so do not overread the analogy. But the structural insight is identical: for a claim that matters enough, the verifying party is placed outside the party being verified.
Computing formalized the same split and standardized it. RFC 9334 defines an architecture with an Attester that produces evidence, a Verifier that appraises it against an appraisal policy, and a Relying Party that acts on the Verifier's result, built on the premise that one end of a communication needs to know whether the other end is in an intended operating state [3].
The reason that architecture exists is worth noting: the industry that most wanted self-attestation to be sufficient concluded, after trying, that it was not. Remote attestation was developed precisely because a machine's own claim about its state is not usable by a party that has reason to care.
So the model this article argues for is not novel and we are not claiming to have invented it. It is a settled pattern in two adjacent fields, and the contribution is applying it to reactor operations, which is what verifying an autonomous microreactor actually requires.
What independence has to mean in practice
Vendors will describe many things as independent. Four properties are worth insisting on, because each closes a specific loophole.
Separation of function. The party appraising reactor state is not the party operating the reactor. Not a different team inside the same organization with the same incentives, and not a subsidiary whose budget depends on favorable results.
Completeness of the record. Disagreement is recorded as faithfully as agreement. A system that only writes a record when everything matches is not verifying, it is publishing.
Durability. The record survives the equipment and the vendor. This is why signature choices matter for records intended to outlive a reactor design cycle, and why NIST approving post-quantum signature standards in August 2024 is relevant to a nuclear conversation at all [4].
Checkability without cooperation. A third party can verify the record later without asking the operator for help. That is exactly what an append-only transparency service with issued receipts provides [5], using receipts standardized as compact cryptographic proofs of inclusion and consistency [6]. Assurance over the components involved sits under established federal supply-chain guidance [7].
Why autonomy moves this from good practice to necessity
For a staffed plant, weak evidence is partly compensated by presence. An inspector on site can form a judgment that instrumentation missed, inside an oversight process built on inspection findings and performance indicators [8]. The GAO has described NRC safety assurance as resting on exactly that monitoring and inspection of the most safety-significant activities [9].
Remove or thin that presence and the compensation goes with it. Proposed Part 57 contemplates remote operation and reduced on-site staffing [10], against a current requirement that a licensed operator be present at the controls at all times [11]. NRC staff have separately proposed operational-phase oversight built on a scalable inspection footprint [12].
The national laboratories have been explicit about what this disturbs. Oak Ridge found autonomous control reaches past staffing into manipulation of controls, licensed operator provisions, technical specifications, cybersecurity, and notifications, with the control room possibly not co-located with the plant [13]. Sandia, working for the NRC, described designs where one control room supervises multiple microreactors [14]. Brookhaven, also for the NRC, framed the safety question for facilities without main control rooms as verifying that important human actions can be accurately and reliably performed [15].
Put together: as presence decreases, the share of the safety story carried by self-report increases. Independent verification is what stops that curve from ending somewhere uncomfortable, and it is why the fleet-scale version of this problem is harder still.
There is a fair objection to all of this, and it deserves a direct answer rather than being skipped. Independent verification adds cost, adds a party, and adds latency to a system that already carries heavy regulatory overhead. For a single well-run reactor with inspectors on site, a reasonable person can argue the marginal benefit is small relative to that burden.
We think that argument is correct for exactly the case it describes, and stops being correct as soon as the model changes. The value of independence scales with two things: how consequential the claim is, and how difficult it is for an outsider to check by other means. A staffed plant with regular inspection scores low on the second. A remotely operated unit inspected on a scalable footprint scores high on both. So the cost stays roughly constant while the benefit grows, which is the opposite of the usual argument for skipping an audit layer.
The other consideration is timing. Verification designed after deployment tends to be verification bolted on, and bolted-on evidence is the kind an outside party has least reason to trust, because the system was not built to produce it. Doing it late is not merely more expensive. It produces a weaker artifact.
What this looks like applied to reactor state
Concretely, the chain has four steps. Reactor state is measured. An independent party appraises the measurements against what the operator reports and what the design permits. The appraisal is signed and written to an append-only log that returns a receipt. Later, a third party checks the receipt and the signature without needing the operator's cooperation. That is the sequence we walk through in turning reactor state into an attestation record.
The engineering preconditions are not trivial and the labs have named them: sensor and instrumentation technologies capable of long-term unattended operation, complete system state awareness, and cybersecurity appropriate to remote monitoring [16]. Guidance on protecting reactor instrumentation and control across its life cycle exists internationally [17], and the IAEA has an active research project on computer security for small modular and microreactors that names autonomous and remote operations and centralised fleet management with reduced staffing as the conditions to address [18].
Capability on the operations side is real and demonstrated. DOE reported that INL demonstrated a digital twin of a simulated microreactor that predicted heat pipe temperatures and then autonomously controlled the heat pipe [19]. The verification side is where the field is thinner, which is the honest asymmetry in this whole discussion.
Where we actually are, including us
No commercial microreactor fleet operates today, so no fleet operates under continuous independent verification either. Proposed Part 57 is a proposal whose comment period has closed and under which no developer is licensed [10]. Anyone presenting independent verification of reactor state as a deployed, proven capability is describing an intention.
RankShield Energy is a pre-applicant with the NRC. We hold no license, permit, or design approval, and nothing about our design has been demonstrated to or accepted by the NRC [20]. Verifier-operator separation is the architecture we build toward and the reason this site exists. It is not a certified capability, and we do not present it as one.
Our position, stated so it can be argued with: a vendor cannot be its own independent verifier, and this remains true of us. It is why we treat the separation as structural rather than as a feature to be added later, and the tradeoff is genuine. A separate verifier costs more, adds a party to coordinate with, and creates a body that can contradict us in public. We think that last property is the point rather than a defect.
If you are evaluating developers on this, the questions are in our vendor evaluation guide, and they should be applied to us as unsentimentally as to anyone else.
Frequently asked questions
Is a vendor monitoring its own reactor the same as independent verification?
No. Monitoring is the operator observing its own plant, which is necessary for running it. Independent verification adds a party structurally separate from the operator that appraises those reports and records the result. The difference is not about vendor honesty. It is that under self-attestation every artifact traces back to the party being evaluated, so an outside reviewer has nothing to rely on that does not depend on that party. Nuclear has traditionally supplied this separation with resident inspectors whose stated role is independently verifying that requirements are being met [1].
What makes verification genuinely independent?
Four properties, each closing a loophole. Separation of function, meaning the appraising party is not the operating party and not a team with the same incentives. Completeness, meaning disagreement is recorded as faithfully as agreement. Durability, meaning the record outlives the equipment and the vendor. And checkability without cooperation, meaning a third party can verify the record later without asking the operator for anything. If any one is missing, independence is nominal rather than structural.
Has any other industry actually solved this?
Two have, in different ways. IAEA safeguards place verification with an outside body that applies its own technical measures rather than relying on operator assertion [2]. Computing standardized it in RFC 9334, separating the attester that produces evidence from the verifier that appraises it and the relying party that acts on the result [3]. Notably, remote attestation was developed because the industry that most wanted self-attestation to be sufficient found that it was not.
Why does autonomy make this more important rather than less?
Because presence was silently doing part of the work. With staff and inspectors on site, weak evidence is partly compensated by human judgment inside an inspection-based oversight process [8]. Proposed Part 57 contemplates remote operation and reduced staffing [10], and NRC staff have proposed a scalable inspection footprint for operational oversight [12]. As presence decreases, the share of the safety story resting on self-report increases, which makes independent confirmation more load-bearing, not less.
Does RankShield Energy have independent verification today?
No, not as a deployed or certified capability. We are a pre-applicant with the NRC holding no license, permit, or design approval [20]. Verifier-operator separation is the architecture we build toward and our reason for existing, but describing an architecture is not the same as having demonstrated it under regulatory review. We would rather say that plainly than let the distinction blur, since the distinction is the entire argument we are making.
Sources
- U.S. Nuclear Regulatory Commission. Backgrounder on NRC Resident Inspectors Program. Accessed July 2026
- International Atomic Energy Agency. Basics of IAEA Safeguards. Accessed July 2026
- Internet Engineering Task Force. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. January 2023
- National Institute of Standards and Technology. Announcing Approval of Three FIPS for Post-Quantum Cryptography. August 2024
- Internet Engineering Task Force. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains (SCITT). June 2026
- Internet Engineering Task Force. RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts. 2026
- National Institute of Standards and Technology. SP 800-161r1, Cybersecurity Supply Chain Risk Management Practices. Updated November 2024
- U.S. Nuclear Regulatory Commission. Reactor Oversight Process Framework. Accessed July 2026
- U.S. Government Accountability Office. Nuclear Power: NRC Relies on Information From its Reactor Oversight Process to Ensure Safety (GAO-25-107807). September 2025
- U.S. Nuclear Regulatory Commission. Licensing Requirements for Microreactors and Other Reactors With Comparable Risk Profiles (proposed 10 CFR Part 57). Federal Register, May 1, 2026 (91 FR 23628)
- U.S. Government Publishing Office. 10 CFR 50.54(m), Conditions of licenses. 2024 CFR edition
- U.S. Nuclear Regulatory Commission. Microreactors: Regulatory Activities. Updated May 2026
- Oak Ridge National Laboratory. Licensing Challenges Associated with Autonomous Control (ORNL/SPR-2018/1071). December 2018
- Sandia National Laboratories. Human Factors Considerations for Automating Microreactors (SAND-2020-5635). June 2020
- Brookhaven National Laboratory for the U.S. NRC. Review of Reactor Facilities without Main Control Rooms (BNL-227637-2025-INRE). February 2025
- Oak Ridge National Laboratory. Concepts for Autonomous Operation of Microreactors (ORNL/TM-2019/1305). September 2019
- International Atomic Energy Agency. Computer Security of Instrumentation and Control Systems at Nuclear Facilities (Nuclear Security Series No. 33-T). 2018
- International Atomic Energy Agency. Enhancing Computer Security of Small Modular Reactors and Microreactors (CRP J02021). Accessed July 2026
- U.S. Department of Energy, Office of Nuclear Energy. Idaho National Laboratory Demonstrates First Digital Twin of a Simulated Microreactor. July 2022
- U.S. Nuclear Regulatory Commission. Pre-Application Activities for Advanced Reactors. Accessed July 2026
This guide reflects the state of reactor verification concepts and NRC rulemaking as of July 2026. Proposed rules such as 10 CFR Part 57 are not final and may change. This area is evolving rapidly; check back if the rule is finalized or if the NRC issues new guidance.
About this article. RankShield Energy is a pre-applicant engaged in early regulatory interaction with the U.S. Nuclear Regulatory Commission (NRC). Nothing here should be read as a representation that any RankShield Energy design, product, or facility is NRC-approved, licensed, or certified, or that any safety, performance, or operational characteristic has been demonstrated or accepted by the NRC. Descriptions of reactor and system behavior reflect design intent and are subject to analysis, testing, and regulatory review. This article is for general educational purposes and is not engineering, legal, regulatory, or investment advice.
A note on how we write about our own reactor
HELIX is in pre-application development. Where this article touches our design, every figure is a design target and every physics result is unqualified screening, labeled as such. We cite authoritative sources (NRC, DOE, IAEA, national laboratories) and never invent statistics.
RankShield Energy · HELIX · pre-application