BlackLeafwatch the watchmen
NRC cybersecurity inspection program for operating nuclear power plants

NRC Calls Its Cyber Inspection Program 'Robust.' Its Audit Disagrees

Summary

An inspector general audit of the program that checks whether America's 55 nuclear power plants are protected against cyberattack calls that program 'robust and adaptive' -- then documents unclear guidance, undefined refresher training, and inspectors who couldn't reliably log the hours they spent doing the work. The same audit shows the program shrinking: a 2025 executive order aimed at cutting regulatory burden is taking NRC's annual cybersecurity inspections from 27 down to 19, even as the agency fields just 24 qualified inspectors, a third of them with under a year of experience.

By Marcus Aurelius · July 20, 2026

Every nuclear power plant in the country is required to protect its digital systems against cyberattack -- a rule on the books since 2009, verified in person by the Nuclear Regulatory Commission, the federal agency licensed to decide whether a reactor may keep running. The 's own Inspector General, its statutory internal watchdog, just finished a year-long performance audit of that inspection program and delivered a verdict that reads, on its face, as reassurance: the program is "robust and adaptive to evolving cyber threats." A skeptical reader's next question is the obvious one -- robust and adaptive by what test? The same report answers it four different ways, and none of the four answers is reassuring.

A finding, and the four findings underneath it

The defines "robust" as a program built on qualified inspectors, efficient processes, and sufficient resources, and "adaptive" as one that keeps up with a changing threat picture. Having granted the 's cybersecurity inspection program both labels in the abstract, the audit then spends 20 pages on what it calls "operational inefficiencies": guidance that inspectors and licensees interpret differently -- driving a share of the 339 performance deficiencies inspectors have logged against 73 different security controls since 2022; refresher-training requirements the 's own qualification program never wrote down; a document-request process so repetitive that 9 of 11 surveyed licensees called it redundant; and inspectors whose logged hours, in the 's own sample, didn't match the work.

Qualified cyber inspectors
24
8 of them have under a year of cybersecurity-inspection experience
Annual inspections, new schedule
19/yr
down from 27/yr under the prior cycle -- a 30% cut
Deficiencies found since 2022
339
across 73 different cybersecurity controls, two full inspection cycles
Annual Cybersecurity Inspections, Before and After Re-Baselining
NRC's shift from a 2-year to a 3-year inspection cycle, ordered under Executive Order 14300
Under the prior 2-year cycle (2022-2025)
27
Under the new 3-year cycle (from 2026)
19
Source: NRC OIG, Report OIG-NRC-26-A-03, p.6-7
View data as table
OIG's own before/after figures for the schedule change ordered in response to Executive Order 14300 (May 2025).
Under the prior 2-year cycle (2022-2025)27The number of cybersecurity baseline inspections the NRC conducted annually across its licensed plants before the 2026 schedule change
Under the new 3-year cycle (from 2026)19The re-baselined annual total, with inspection teams also shrinking from two contractors to one

The watch gets thinner as the workload doesn't

In May 2025, Executive Order 14300 directed the to cut what it called unnecessary regulatory burden. The agency's answer, for cybersecurity, is to inspect less often: a shift from a two-year to a three-year cycle that takes the number of annual cybersecurity inspections from 27 down to 19, and shrinks each inspection team from two contractors to one. That change is defensible on its own terms -- an agency is allowed to decide 94 reactors don't need checking as frequently. What the same audit makes harder to defend is doing it with the bench the found: 24 qualified cybersecurity inspectors nationwide, averaging three years of experience, eight of them with less than one year on the job. The qualification program requires exactly one inspection every three years and one annual meeting to stay current -- optional beyond that, and the annual meeting itself isn't even recorded for anyone who misses it.

How Much Warning Licensees Got Before Cybersecurity Inspections
OIG's review of 109 initial information requests issued for baseline cybersecurity inspections
Issued fewer than the standard 120 days ahead
64%
Didn't give licensees the full 36-day response window
46%
Source: NRC OIG, Report OIG-NRC-26-A-03, p.16
View data as table
Both figures are drawn from the same 109-RFI sample the OIG reviewed; they describe two different timing problems, not a single split that sums to 100%.
Issued fewer than the standard 120 days ahead64%Share of the 109 initial RFIs the OIG analyzed that missed the standard lead time set for the first information request
Didn't give licensees the full 36-day response window46%13 of those RFIs asked for a response within 20 days; some gave as little as 8 days

Hours that don't add up

A full on-site cybersecurity inspection is built to take two inspectors about 35 hours each -- 70 hours combined, spread over a five-day site visit, per the 's own Inspection Procedure 71130.10. The pulled the agency's internal time-and-labor system and checked that estimate against what inspectors actually logged between January 2022 and June 2025. It found eight inspectors across three regions charging cybersecurity-oversight work to the wrong indirect billing code, and one full inspection that logged just 14 hours of the estimated 70 -- a gap the traced to an inspector who had booked 29 of those hours under an unrelated code instead. The 's fee structure charges licensees for exactly these hours, and the law requires the agency to recover its budget authority through them; the did check for over- or under-billed licensees and found none in the cases it reviewed. What the miscoding does confirm is that the same system meant to tell the agency how much cybersecurity oversight actually costs cannot currently be trusted to say so.

  • The 's own headline finding calls the program "robust and adaptive," then documents four operational gaps underneath that label -- unclear guidance, undefined refresher training, redundant inspection paperwork, and unreliable hour-tracking. All nine of the audit's recommendations aim at closing those four gaps, not at the robust/adaptive verdict itself.
  • is cutting annual cybersecurity inspections from 27 to 19 -- a 30% reduction -- and shrinking each inspection team from two contractors to one, under an executive order directing the agency to reduce regulatory burden, even as its own audit finds the inspector bench thin: 24 qualified inspectors, a third with under a year of experience.
  • 46% of the 109 initial information requests the reviewed didn't give licensees the standard 36-day response window -- 13 gave less than 20 days, some as little as 8 -- while 64% were issued later than the standard 120-day lead time the 's own guidance sets.
  • Eight inspectors across three regions mis-logged their cybersecurity oversight hours to the wrong billing code, and one inspection reported 14 of an estimated 70 hours -- a gap the traced to hours booked under a different code entirely. confirmed no licensee was over- or under-billed as a result, but the audit found the underlying time data itself cannot be relied on for budgeting.

Figures are drawn from the U.S. Nuclear Regulatory Commission Office of Inspector General's performance audit, Report No. --26-A-03, Audit of the U.S. Nuclear Regulatory Commission's Cybersecurity Inspection Program for Operating Nuclear Power Plants (issued June 4, 2026), read in full via direct PDF fetch from oversight.gov, with an existing Wayback capture confirmed live on a single probe. The report's listing is independently corroborated on the 's own report index at nrcoig.oversight.gov, on a separate page, distinguished during research from a similarly-titled but unrelated 2019 report at a different URL on the same site. A blind adversarial verifier, working from the primary documents alone with no access to this draft, independently checked every itemized fact; see verification.json.

The 30% inspection-schedule cut, the one-third share of inspectors with under a year of experience, and the 56-hour gap between the estimated and logged hours on the underreported inspection are this outlet's own arithmetic on the source document's own itemized figures (methods and caveats in analysis.json). None of these comparisons appear pre-computed in the source document itself.

Sources(2) ▾
  • U.S. Nuclear Regulatory Commission, Office of the Inspector General, Audit of the U.S. Nuclear Regulatory Commission's Cybersecurity Inspection Program for Operating Nuclear Power Plants (OIG-NRC-26-A-03) (2026-06-04)The 's own performance audit is the sole source for every finding: the 55-plant/94-reactor scope, the 24-inspector qualified workforce and its experience distribution, the 70-hour/63-77-hour inspection resource estimates, the 27-to-19 annual-inspection cut under re-baselining, the 339 performance deficiencies across 73 controls, the RFI-timeline findings from the 109-RFI sample, the HCM Cloud time-and-labor miscoding findings, the 9 recommendations, and the audit's own scope/methodology. oversight.gov · original document
  • Nuclear Regulatory Commission / Defense Nuclear Facilities Safety Board OIG (oversight.gov subdomain), Audit of the U.S. Nuclear Regulatory Commission's (NRC) Cybersecurity Inspection Program for Operating Nuclear Power Plants (report listing) (2026-06-04)The 's own report-listing page independently corroborates report number --26-A-03, the June 4, 2026 issue date, the audit title, the 9-recommendation count, and the same finding summary quoted in the report itself -- confirming the PDF is not a stray or superseded draft. nrcoig.oversight.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account