Showing posts with label NRC. Show all posts
Showing posts with label NRC. Show all posts

Saturday, July 4, 2026

OMB Approves NRC NEPA NPRM

 On Thursday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the Nuclear Regulatory Agency (NRC) on “Implementation of the National Environmental Policy Act [NRC-2025-0478]”. The NPRM was submitted to OIRA on March 20th, 2026. 

According to the 2026 Unified Agenda entry for this rulemaking: 

“This rulemaking would revise the U.S. Nuclear Regulatory Commission’s regulations to (1) streamline implementation of the National Environmental Policy Act (NEPA), (2) alleviate unnecessary regulatory burdens, and (3) expand flexibilities for applicants and licensees while complying with environmental requirements. The revisions are necessitated by and consistent with the U.S. Council on Environmental Quality's recision of its NEPA implementing regulations, Executive Order (EO) 14300 [link added], Ordering the Reform of the Nuclear Regulatory Commission,” and EO 14154 [link added], Unleashing American Energy.”” 

I would expect to see this NPRM published in the Federal Register in the next week or so. I do not expect that I will cover this rulemaking in any detail. At the very least, though, I would mention its publication in the appropriate Short Takes Post. 

Thursday, June 11, 2026

OMB Approves NRC Security Update NPRM

Yesterday, OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking from the Nuclear Regulatory Commission (NRC) on “Modernizing Security Requirements [NRC-2025-1303]”. The NPRM was submitted to OIRA on May 18th,2026.  

This rulemaking was not listed in the Spring 2025 Unified Agenda. Fortunately, the NRC docket number (NRC-2025-1303) is listed in the Notice. According to that docket: 

“Consistent with Executive Order 14300 [link added], “Ordering the Reform of the Nuclear Regulatory Commission,” the NRC is conducting a review and wholesale revision of its regulations. This initiative aims to modernize security requirements to enhance efficiency.” 

Section 5(g) of EO 14300 requires the NRC to: “Revise the Reactor Oversight Process and reactor security rules [emphasis added] and requirements to reduce unnecessary burdens and be responsive to credible risks.” 

I do not typically cover NRC security regulations in this blog. I would expect to announce the publication of this NPRM in the appropriate Short Takes post. 

Thursday, February 19, 2026

NRC Sends Foreign Ownership Direct Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a direct final rule from the Nuclear Regulatory Commission (NRC) on “Exceptions from Foreign Ownership, Control, or Domination [NRC-2024-0218]”. This rulemaking is supporting the requirements of §301 of the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024 (Division B of PL 118-67, 138 STAT. 1465).

The Spring 2025 Unified Agenda entry for this rulemaking notes:

“This rulemaking would amend the NRC’s regulations to comply with Section 301 of the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024, which has designated certain exclusions from the foreign ownership, control, or domination provision set forth in the Atomic Energy Act of 1954, as amended. This rulemaking would affect applicants and licensees of commercial nuclear power reactor or non-power production or utilization facilities that are owned, controlled, or dominated by a foreign entity.”

I am not expanding coverage of this blog to include the NRC; really, I am not. This rulemaking just caught my interest. I do not expect that there will be any detailed coverage of this rule here, but I will almost certainly mention its publication in the Federal Register in the appropriate Short Take post.

Wednesday, February 18, 2026

NRC Sends Modernizing Security for Nuclear Materials NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the Nuclear Regulatory Commission (NRC) on “Modernizing Requirements Relating to Physical Protection of Category 1 and Category 2 Quantities of Radioactive Material [NRC-2025-1238]”. This rulemaking was not listed in the Spring 2025 Unified Agenda.

The rulemaking would appear to be targeting amendments to 10 USC Part 37, Physical protection of category 1 and category 2 quantities of radioactive material. This Part was included as one of the recent regulatory revisions published on December 3rd, 2025, where the NRC placed portions of regulations under a new sunset provision (in this case sunsetting on January 8th, 2027), so this rulemaking should also serve as the first 5 year extension of that sunset.

According to an NRC memo on FY 2026 regulatory priorities:

“This initiative aims to modernize the NRC's regulations by removing unnecessary requirements relating to physical protection and security of category 1 and category 2 quantities of radioactive material, while maintaining safety and security. The NRC anticipates the proposed rule to be published in March 2026.”

According to that memo, the listed regulatory efforts (including this rulemaking) are being proposed in response to EO 14300, Ordering the Reform of the Nuclear Regulatory Commission. It also notes that the proposed rulemakings “are deregulatory and are expected to result in cost savings to both NRC and Industry stakeholders”.

This rulemaking is generally outside of the scope of this blog, but it deserves mention as it deals with chemical security in the most extreme case.

Monday, September 29, 2025

OMB Approves NRC Sunset Rule Final Rule

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a direct final rule from the Nuclear Regulatory Commission (NRC) on “The Sunset Rule [NRC-2025-0479]”. The rule was submitted to OIRA on August 4th, 2025.

According to the entry for this rulemaking in the Spring 2025 Unified Agenda:

“This rulemaking would amend covered NRC regulations to insert conditional sunset dates under Executive Order 14270 [link added], Zero-Based Regulatory Budgeting to Unleash American Energy. The EO directs the NRC to issue a sunset rule to the extent consistent with applicable law and provides an exemption from the EO for regulatory permitting regimes authorized by statute.”

The NRC rulemaking listing for this rule reports that this final rule will affect Parts “1, 2, 4, 5, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 19, 20, 21, 25, 26, 30, 31, 32, 33, 34, 35, 36, 37, 39, 40, 50, 51, 52, 53, 54, 55, 60, 61, 62, 63, 70, 71, 72, 73, 74, 75, 76, 81, 95, 100, 110, 140, 150, 160, 170, 171” of 10 CFR Chapter 1.

I do not normally cover NRC regulations, and I do not expect to cover this rulemaking in any depth, but I do think that the scope of what this direct final rule will potentially affect is worth looking at. For example, the above list of affected sections covers the following facility security regulations:

Part 11 - Criteria And Procedures for Determining Eligibility for Access to or Control Over Special Nuclear Material,

Part 37 - Physical Protection of Category 1 and Category 2 Quantities of Radioactive Material,

Part 73 - Physical Protection of Plants and Materials.

This rulemaking will probably be published this week. Again, I will probably not cover this direct final rule in any detail, but I will announce its publication in the appropriate “Short Takes” post.

Thursday, May 17, 2018

NRC Withdraws Cybersecurity Rulemaking


Yesterday the Nuclear Regulatory Commission (NRC) published a notice in the Federal Register (83 FR 22413-22414) announcing that they were discontinuing their rulemaking activities on “Cyber Security for Byproduct Materials Licensees” (RIN 3150-1756). This rulemaking first appeared in the Unified Agenda during the Obama Administration in the long-term actions section. It was moved to the Active Agenda in the Spring of 2017 and then back to the long-term actions in the most recent agenda.

Background


The Byproduct Materials Cyber Security Working Group was formed in 2013 to look into the potential need for a cybersecurity rulemaking for facilities that stored Category 1 or Category 2 quantities of radioactive material (does not include the radioactive material contained in any fuel assembly, subassembly, fuel rod, or fuel pellet; see 10 CFR 37.5).

The working group identified four sets of digital assets that the NRC should evaluate with respect to cyber threat protection:

• Digital/microprocessor-based systems and devices that support the physical security of the licensee's facilities. These include access control systems, physical intrusion detection and alarm systems, video camera monitoring systems, digital video recorders, door alarms, motion sensors, keycard readers, and biometric scanners;

• Equipment and devices with software-based control, operation, and automation features, such as panoramic irradiators and gamma knives;

• Computers and systems used to maintain source inventories, audit data, and records necessary for compliance with security requirements and regulations; and

Digital technology used to support incident response communications and coordination such as digital packet radio systems, digital repeater stations, and digital trunk radio systems.

The most recent, publicly-available document (Update to the U.S. Nuclear Regulatory Commission Cyber Security Roadmap, ML15201A509, 2-28-17) noted that (pg 7):

“The working group plans to complete its evaluation of the [180] questionnaire [sent to all NRC and Agreement State licensees that possess Categories 1 and 2 quantities of radioactive Materials] responses, its consequence analysis, and any follow-up communication with stakeholders in early 2017. As a result, the working group intends to develop recommendations for a path forward by spring/summer 2017.”

Question: Why does the NRC still use antiquated on-line tools to provide access to public documents? Why can I not provide a link to the document listed above? The NRC does not provide links to their documents.

NRC Conclusion


The NRC staff completed its evaluation in October 2017 and concluded that:

“The NRC staff concluded that byproduct materials licensees that possess risk-significant quantities of radioactive material do not rely solely on digital assets to ensure safety or physical protection. Rather, these licensees generally use a combination of measures, such as doors, locks, barriers, human resources, and operational processes, to ensure security, which reflects a defense-in-depth approach to physical protection and safety. As a result, the staff concluded that a compromise of any of the digital assets identified in the January 6, 2016, Commission memorandum would not result in a direct dispersal of risk-significant quantities of radioactive material, or exposure of individuals to radiation, without a concurrent and targeted breach of the physical protection measures in force for these licensees.”

Based upon that recommendation, the NRC is discontinuing rulemaking activity to develop cyber security requirements for byproduct materials licensees possessing risk-significant quantities of radioactive materials.

Commentary


Since I have not seen (and probably never will see for legitimate security reasons) the final NRC staff report, it is hard to draw any hard conclusions about the decision reached by the NRC.

Having said that, I see little in the language in this announcement that provides me with any level of comfort that the Commission took a hard look at anything beyond the immediate security of these materials. There is no language that would indicate that operational security (the security of the devices that manipulate or move the covered materials) has been adequately addressed.

Additionally, since these materials are ideally suited to employment in weapons of mass confusion (radiologically enhanced improvised explosive devices), I am also concerned about the security of information systems that deal with the ordering and shipping of these commercial products. The diverted delivery of legitimate shipments via electronic changes in orders or shipping documents provide a legitimate scenario for terrorists to acquire the material necessary to build a radiological dispersion device (‘dirty bomb’).

Again, the NRC and its staff may very well have looked at these potential vulnerabilities, but there is nothing in this announcement that provides any indication that this is so. Perhaps this is something that Congress out to take a look at.

Saturday, October 31, 2015

NRC Publishes Cybersecurity Event Reporting Final Rule

The Nuclear Regulatory Commission published in Final Rule in Monday’s Federal Register (80 FR 67264-67277; available on-line today) concerning Cyber Security Event Notifications. The rule codifies certain reporting activities associated with cybersecurity events contained in security advisories issued by the NRC.

The rule makes modifications to three sections of 10 USC Part 73 (§73.8, §73.22, and §73.54) and adds a new section (§73.77; Cyber Security Event Notifications). For readers of this blog, the items of specific interest will be found in the changes to §73.54 (Protection of digital computer and communication systems and networks) and the new §73.77.

Protecting Cyber Assets

Section 73.54 provides a great deal of detail about the requirements that a regulated facility needs to undertake to protect cyber systems associated with {§73.54(a)(1)}:

• Safety-related and important-to safety functions;
• Security functions;
• Emergency preparedness functions, including offsite communications; and
• Support systems and equipment which, if compromised, would adversely impact safety, security, or emergency preparedness functions

Paragraph (d) of the current §73.54 outlines the licensee actions that are required for the security program set forth in the section. They include:

• Ensure that appropriate facility personnel, including contractors, are aware of cyber security requirements and receive the training necessary to perform their assigned duties and responsibilities.
• Evaluate and manage cyber risks.
• Ensure that modifications to assets, identified by paragraph (b)(1) of this section, are evaluated before implementation to ensure that the cyber security performance objectives identified in paragraph (a)(1) of this section are maintained.

The new final rule adds a fourth required action: “Conduct cyber security event notifications in accordance with the provisions of §73.77.”

Event Notification

The NRC safety regulations contain a whole host of requirements for notification activities that must be under taken by licensees (see §73.71 for example). The new §73.77 adds a new set of notification requirements and classifies them generally by how soon notification is required after the event is detected. There are four operational time limit are:

• One hour;
• Four hour;
• Eight hour; and
• 24 hour

The one hour time limit is reserved for cyber attacks that: “that adversely impacted safety-related or important-to-safety functions, security functions, or emergency preparedness functions (including offsite communications); or that compromised support systems and equipment resulting in adverse impacts to safety, security, or emergency preparedness functions within the scope of § 73.54” {new §73.77(a)(1)}. In other words there was an actual impact on safety, security or emergency preparedness.

There are three categories of events under the four hour reporting standard. First is an attack that could have resulted in a situation that would have required a one-hour report if it had been successful. The second is the discovery of a “suspected or actual cyber attack initiated by personnel with physical or electronic access to digital computer and communication systems and networks within the scope of §73.54” {§73.77(a)(2)(ii)}; essentially a breach of the cyber perimeter. The third is a generic catch all that requires a report of any cyber related situation that resulted in a notification of law enforcement.

The eight hour category is the last one that requires actual telephonic communications with the NRC. It is reserved for information “regarding observed behavior, activities, or statements that may indicate intelligence gathering or pre-operational planning related to a cyber attack against digital computer and communication systems and networks within the scope of §73.54” {§73.77(a)(3)}.

The ’24 hour’ category that I’ve listed here is not actually a requirement to ‘communicate’ with the NRC in any direct way. It is a requirement to record the event in the “corrective action program (CAP)”. This is an NRC inspect able document maintained under §73.55(b)(10) that the facility uses to “track, trend, correct and prevent recurrence of failures and deficiencies in the physical protection program”. Under the new §73.77(b) the facility will now also record “vulnerabilities, weaknesses, failures, and deficiencies in their § 73.54 cyber security program” as well as documenting any of the notifications made under the provisions outlined above.

The remainder of the new §73.77 outlines how the facility is to report the incidents described above to the NRC and how a follow-up written report will be prepared and submitted.

Effective Date

This rule becomes effective on December 2nd, 2015. The NRC will begin enforcement of the rule on May 2nd, 2016.

Commentary

Few readers (I know there are some, bear with me) of this blog are intimately involved in the operation of nuclear power plants or maintenance of the security apparat that protects them. I am certainly not planning on becoming a subject matter expert on the topic. This rulemaking is important, however, because it outlines a cybersecurity event notification process that can serve as a model in developing a regulatory scheme for control systems in other critical infrastructure sectors.

Before we go any further, let me remind folks that the NRC already has a regulatory process that is set up to take security reports from the regulated community, digest those reports and communicate the essential information to other facilities in that regulated community so that they can modify their on-going processes at a higher level of safety and security. Lacking that sort of information digestion and communication, there is absolutely no reason to require timely reporting of cybersecurity incidents, or any sort of security incidents for that matter.

The important thing for other regulators to take from this rulemaking is the way that the NRC prioritized reporting requirements; events that had cyber physical impacts, events that could have had cyber physical impacts, and events that demonstrate penetration of the cyber perimeter. This categorization should be able to withstand numerous changes in technology and be adaptable to any industry that has the potential for cyber physical impacts outside of the facility boundary.

The other important take away from this rulemaking is that the NRC had already established a workable definition of the critical control systems at their regulated facilities; safety functions, security functions, emergency response functions and systems that directly support those functions. Again, those functions could be easily translated into any regulated industry that has the potential for cyber physical impacts outside of the company fence line. With minor adaptations they could even be modified to apply to mobile control systems (auto, planes and ships) and even medical devices.


There is much that is still missing from this rulemaking, which is arguably part of the most proactive security program functioning in this country outside of the military. The NRC rules are still missing a cyber forensics component, for example. But the NRC is actually trying to codify a proactive cyber incident reporting program and that is a very important part of any cybersecurity program, a part that should be looked at very carefully by other critical infrastructure regulatory agencies.

Monday, August 10, 2015

OMB Approves CG Oil Spill Reporting ICR

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the reinstatement of a Coast Guard information collection request (ICR) supporting both the reporting of oil or hazardous substance discharge, and reporting of suspicious maritime activity.

Lapsed ICR

Apparently the Coast Guard inadvertently allowed this ICR to lapse in February of 2012. Both the 60-day and the 30-day ICR notices in the Federal Register from earlier this year reported that the ICR was a renewal. And there is nothing in the Supporting Statement [.DOC download link] submitted to OIRA that indicates that the CG was aware that the ICR had expired.

Change in Burden Estimates

The table below shows the differences in the burden estimates between the previously approved ICR and the lasted version.

Burden Estimate
10-31-2011
08-07-2015
Responses
147,178
39,286
Hours
12,098
3,144
Change in Burden Estimate

The CG explained the drastic reduction in the number of responses this way in their submission document to OIRA:

“The change in burden is an ADJUSTMENT due to a change (i.e., decrease) in the number of NRC reports received by the Coast Guard.  It is unknown why we have seen a large decrease in the number of annual responses.  The reporting requirements, and the methodology for calculating burden, remain unchanged.  Additionally, the Coast Guard has revised the methods for submitting a report by eliminating the online option.  The upkeep of that method proved too costly.”

There was a reduction in burden estimate between the 2011 ICR and the ICR approved in 2008, but that change was only about 7%, not the almost 73% decrease reported in the latest CG data. Such a large decrease in reported spills means that either industry has made tremendous strides in reducing the number of spills that it is experiencing or there has been a decrease in the rate of reporting of spills that are occurring. More than likely it is some combination of the two.

Cybersecurity Issue

The CG did report on programmatic change that may have an impact on the reporting rate. In the quote above the CG noted that it had eliminated the online reporting option for this ICR. The reason for that change was described in a little more detail earlier in the submission document:

“The NRC online submission option was eliminated in February 2014 following a security breach.  The online submission website was built in the 1990s, and does not meet modern security standards.  At this time, the NRC does not have the funds necessary to build a modern, functional, and secure site.”

A footnote to that statement notes that in the last full year of on-line reporting those reports only accounted for about 10% of the NRC reports submitted.

Commentary

A drastic change (and a 74% reduction in spills is nothing short of miraculous if true) in spill reporting numbers must be investigated. It is not acceptable to dismiss a 74% reduction in spill reports with just the brief comment that: “It is unknown why we have seen a large decrease in the number of annual responses.”

Now I understand that OIRA is an administrative body that would have nothing to do with the actual investigation of why there is such a drastic change in spill reporting. So may be the Coast Guard is actually conducting such an investigation and just did not feel that it was necessary to mention that investigation in their submission data to OIRA. I am surprised, however, that OIRA accepted this dramatic change in reporting burden without more justification.

Likewise, I am concerned that OIRA did not demand at least a cursory explanation of why the Coast Guard had allowed this ICR to lapse for almost two years before submitting this ICR revision. The NRC is a vital part of a major environmental response program and while this ICR does not actually effect the operation of that program failure to keep the ICR up to date reflects poorly on the management of the program and begs the question of what other programmatic issues exist.

Finally I sympathize with the Coast Guard discovering security issues with an on-line reporting program designed in the 90’s. Cutting off that reporting process due to lack of funds does seem very short sighted. Looking at the last two Coast Guard authorization bills (and Committee Reports supporting those bills) I have seen nothing that would indicate that Congress has been informed of this problem. If they have been informed and they have been ignoring the problem this is a political problem that should be addressed. If they have not been repeatedly made aware of this problem than shame on the Coast Guard and the Secretary of DHS.


Sunday, June 8, 2014

RegInfo Website Down

It seems that the Federal government is having problems maintaining its web sites. I reported earlier on the National Response Center reporting page being down. I tweeted Friday morning that the OMB’s RegInfo page had disappeared; well as of Friday afternoon that page has reappeared with a notice that it was ‘currently undergoing system maintenance’ and it is still in that status now.

Web page updates don’t normally take this long. Something else is obviously going on and we just are not being told what. Three common reasons that government that government agencies don’t tell the whole story about problems that they are having are:

• Gross incompetence;
• Criminal malfeasance; or
• National security.

Of course, ‘national security’ is frequently used as an excuse to cover the first two reasons because the agency typically doesn’t have to explain to the public what is really going on in that case. And if they tap dance ‘national security’ well enough, Congress will usually give them a pass as well.

So, I’ll ask the nasty question that probably won’t be answered, were they hacked? And I don’t mean a petty little ‘we were there’ defacement attack that seems to be the hallmark of a couple of international cyber-warrior groups. I’m talking about the serious, ‘I have access to your secure databases’ type of access.

Now neither of these sites deals in any way with national security issues or directly affects any safety or welfare issues, so this probably would not (if it is actually happening, something that I am only loosely conjecturing) rise to a level that would require a public response or retaliation. But, it would provide a pretty serious black eye for our cybersecurity programs at the Federal level; particularly if it were accompanied by back channel communications essentially saying: “Keep your nose out of our business or this will happen in more serious places.”

Of course, that would provide an even better reason not to discuss the situation publicly; the public would demand a response and our cybersecurity posture is just not up to defending against a State level attack.

Of course, it could still be gross incompetence or criminal malfeasance. There has certainly been plenty enough of that going around to explain pretty much any agency failure.

NOTE: As of 05:00 CDT 06-09-14 the RegInfo site is up.

Friday, February 7, 2014

NRC to Look at PLCs

Today the Nuclear Regulatory Commission (NRC) published a notice in the Federal Register (79 FR 7406) acknowledging that it had received a petition for rulemaking under 10 CFR 2.802(c) {NOTE: The notice mistakenly lists 10 USC 2.802(c)} that requests that the NRC “NRC require ‘new-design programmable logic computers’ to be installed in the control systems of nuclear power plants to block malware attacks on their industrial control systems of those facilities”.


The notice explains that since the petition was received in proper form that the NRC will officially consider it. The NRC is not requesting public comments on the petition or the topic at this time. A docket has been established on the Federal eRulemaking Portal (www.Regulations.gov; Docket # NRC-2013-0214) that will be used to make information about this petition available.

Sunday, May 19, 2013

NRC Publishes Transportation Security Rule


The Nuclear Regulatory Agency (NRC) published a final rule in Monday’s Federal Register (78 FR 29519-29557; available on-line yesterday) regarding the Physical Protection of Irradiated Reactor Fuel in Transit. This is the first major revision of the provisions of 10 CFR 73.37 since it was established in 1980. Section 73.37, Requirements for physical protection of irradiated reactor fuel in transit, is being revised and §73.38 is being added.

I certainly don’t intend to expand the general coverage of this blog to nuclear security matters, but I do think that a brief look at the security measures required for transportation of nuclear fuel provides a look at how involved transportation security measures can be. I’ll leave for another day the discussion of the relative security risks associated with a small (101 gram) shipment of nuclear fuel and a 40,000 lb tank wagon shipment of a toxic inhalation hazard (TIH) chemical.

Purpose of Regulations

Section 73.37(a) sets forth the security performance objectives that each licensee that transports or causes to be transported more than 100 grams of irradiated reactor fuel will achieve. These objectives are twofold:

• Minimize the potential for theft, diversion, or radiological sabotage of spent nuclear fuel shipments; and
• Facilitate the location and recovery of spent nuclear fuel shipments that may have come under the control of unauthorized persons.

To achieve these objectives requires the use of physical protective systems that:

• Provide for early detection and assessment of attempts to gain unauthorized access to, or control over, spent nuclear fuel shipments;
• Delay and impede attempts at theft, diversion, or radiological sabotage of spent nuclear fuel shipments; and
• Provide for notification to the appropriate response forces of any attempts at theft, diversion, or radiological sabotage of a spent nuclear fuel shipment.

Required Security Measures

Security measures required by this final rule include:

• Preplan and coordinate spent nuclear fuel shipments;
• Advance notifications;
• Transportation physical protection program; and
• Contingency and response procedures.

The NRC requires the submission of detailed preplan; including route, safe havens, and local law enforcement coordination; which must be approved by the NRC before it can be implemented. These requirements apply to all shipments by road, rail, or US waterways.

Additional specific requirements are provided for shipments by road. These include:

• Provisions for armed escorts;
• Redundant 2-way communications capabilities;
• Vehicle immobilization devices;
• Continuous and active telemetric position monitoring;

Background Checks

The final rule adds a new §73.38, Personnel access authorization requirements for irradiated reactor fuel in transit. This requires the establishment of an access authorization program. The program will apply not only to personnel with unaccompanied access to spent nuclear fuel in transit but also personnel who:

• Could adversely impact the safety, security, or emergency response to spent nuclear fuel in transit;
• Are responsible for implementing a licensee's physical protection program;
• Have access to spent nuclear fuel shipment information; or
• Is the access authorization program reviewing official.

As one would expect the access authorization program must include provisions for completing background checks on covered individuals. The checks will include:

• Personal history disclosure;
• Criminal history;
• Verification of true identity;
• Employment history;
• Credit history;
• Character and reputation; and
• Determination of trustworthiness and reliability.

Interestingly, there is no specific requirement to vet an individual for terrorist ties through the Terrorism Screening Database (TSDB) or any other specific terrorism related list.

Regulatory Detail

All of the above requirements are spelled out in great regulatory detail.

Clearly the NRC and its regulated community take security much more seriously than does PHMSA and/or TSA. Certainly the security of nuclear materials is a serious matter, but these rules apply to shipments as small as 101 grams, or about a ¼ of a pound. How much of this is based upon a realistic threat assessment and how much of this is based upon a knee-jerk fear of radioactive materials is not clear.

Friday, June 3, 2011

NRC Facilities Exempt from CFATS

As I noted yesterday DHS and the Nuclear Regulatory Commission (NRC) have signed an memorandum of understanding (MOU) that addresses the provisions of the §550 CFATS authorization language that exempts from CFATS coverage “any facility subject to regulation by the Nuclear Regulatory Commission”. It clarifies the ‘subject to regulation’ wording, establishes procedures for DHS and NRC to evaluate the status of individual facilities, and provides for changes to that status brought about by changes at the facility.

Subject to Regulation

Section 4b of the MOU provides the definition of the Section 550 exemption language as agreed to by DHS and NRC. That definition has three core ideas. First it clarifies that the exemption may apply to just part of a facility. Next it requires that NRC or an Agreement State (a State that has reached an agreement with the NRC to enforce NRC regulations) “imposes significant security requirements that protect an NRC-licensed or Agreement-State-licensed material”. Finally it requires that “the licensee has implemented security requirements” for the definition to apply.

Section 5a addresses the issue of facilities that may only be partially exempt from CFATS coverage. It specifically notes that: “DHS and the NRC acknowledge that a facility that is subject to NRC regulations could contain areas that are not subject to NRC regulations and that such areas, as determined by the parties under Section 6(b) of this MOU, may be subject to DHS regulations under CFATS.”

Section 5c provides that the NRC will provide DHS with a list of facilities that NRC believes are covered, or partially covered by the NRC CFATS exemption. For partially covered facilities it specifies that “the NRC will provide DHS with sufficient information to identify any area within the facility that should not be subject to the exemption from the CFATS rule”. Once DHS and NRC staffs agree on a list of exempted facilities, DHS will notify facilities of their exemption or the limits of their exemption from the CFATS requirements.

Yesterday’s publication of the Federal Register notice marked the end of the 60-day period that NRC was allotted in the MOU to provide the list of covered facilities to DHS. There is nothing in the MOU that indicates when we might expect to see DHS provide facilities with their notification of exemption. Hopefully ISCE will provide a date by which covered facilities would expect to have received their notification. That would be the only way that facilities not covered by the NRC exemption might know that they have fallen outside of that process.

Dual Coverage Facilities

The NRC will provide DHS a list of facilities that might contain areas not exempted from CFATS coverage. I would expect that DHS would use that list to specifically notify those facilities that areas of their facility are not exempt and for those facilities to submit a Top Screen for those areas if they have covered COI at or above the screening threshold quantity set for those COI.

Once DHS makes a determination that an ‘uncovered’ portion of an NRC regulated facility is a high-risk chemical facility the life for the security management team at that facility is bound to get interesting. Since it would not be unexpected for there to be conflicting security requirements under CFATS and NRC regulations, §7a provides that “DHS and the NRC may jointly establish implementing agreements specific to the responsibilities and authorities of their respective agencies at any facility subject to both DHS and NRC regulation, as well as information-sharing protocols, or similar agreements with respect to such a facility”.

Public Information

I want to congratulate the NRC for making this MOU public in this manner. We had been led to believe that the discussions between the Coast Guard and ISCD on the limits of the MTSA exemption to CFATS were more advanced than those with the NRC. That would be expected since ISCD and the CG both work for the DHS Secretary. When that MOU is finally signed, I would hope that DHS follows the example set by the NRC in publishing the details of that MOU.

Thursday, June 2, 2011

NRC Notice of NRC-DHS MOU on CFATS

Today the Nuclear Regulatory Commission (NRC) published a notice in the Federal Register (76 FR 31997) about the existence of a memorandum of understanding (MOU) between the NRC and DHS on issues related to the Chemical Facility Anti-Terrorism Standards (CFATS). According to the Notice:

Chemical Facility Security, NRC, NRC-DHS MOU
“The MOU delineates clear lines of responsibility between the parties, based on their legal authorities, for the security of high-risk chemical facilities subject to DHS regulation and for the security of chemicals at facilities subject to NRC regulation. The MOU describes the parties’ relationship in identifying which facilities are subject to NRC regulation and thus are, in whole or in part, exempt from the chemical facility security regulations issued by DHS.”
A copy of the MOU is available at http://pbadupws.nrc.gov/docs/ML1027/ML102720798.pdf.

I’ll have more information after I have a chance to do a detailed review of the MOU.

Tuesday, March 22, 2011

NRC Briefing on Fujushima

Yesterday afternoon a Nuclear Regulatory Commission (NRC) meeting-notice was posted on the Federal Register ‘pre-view’ web site about a public briefing on the “NRC Response to Recent Nuclear Events in Japan”. While that subject is not of direct concern to the chemical security community (though everyone should have some concerns about the issue) I am mentioning this here because of some administrative problems this notice underlines in the communications tools available to the Federal Government.

The problem with this notice is that it was posted to the preview site at 4:15 pm EDT yesterday for actual publication in the Federal Register scheduled for March 23rd. Now that isn’t too unusual until you consider when the public meeting is (actually was) scheduled; March 21, 2011 at 9:00 a.m. EDT. In other words the public notice was ‘published’ (still not yet legally published, but actually published) seven hours after the start of the meeting.

Now, I don’t think that the NRC was attempting to hide anything, and I even think that I briefly saw a clip from this briefing on the late news last night (it was short, and it was late, and I wasn’t completely awake), but this isn’t what we really want to see when dealing with critical information like this. We want to see as much advance notice as is practical.

I do have two questions. The notice states that the NRC voted on 3-15-11 to hold the meeting without giving the ‘required’ one-week notice; I understand and approve of that. But why wasn’t the notice given to the Federal Register folks until Monday afternoon? And then why was the announcement delayed until Thursday instead of on Tuesday? I would have been able to type up the meeting notice provided on the 15th and it could have been to the Federal Register folks on the 15th, 16th, 17th or 18th and still provided some public notice of the meeting.

I suspect that it was held up for bureaucratic reasons, waiting for release authority before it was sent out. If that’s the case, then someone needs to answer for that delay because this long a delay for the release of time sensitive information is inexcusable. If there was some other reason, legitimate or otherwise, that also needs to be shared.

The government has a responsibility to provide timely information to the public and notice of public meetings is one important type of timely information. When circumstances limit the time available for providing notice, extraordinary efforts must be taken to provide as much notice as possible. Finally, there is never any excuse for providing notice of a meeting after the meeting is over.
 
/* Use this with templates/template-twocol.html */