10 C.F.R. § 73.55
(b)
General performance objective and requirements.
(1)
The licensee shall establish and maintain a physical protection program, to include a security organization, which will have as its objective to provide high assurance that activities involving special nuclear material are not inimical to the common defense and security and do not constitute an unreasonable risk to the public health and safety.
(2)
To satisfy the general performance objective of
paragraph (b)(1) of this section, the physical protection program must protect against the design basis threat of radiological sabotage as stated in
§ 73.1.
(3)
The physical protection program must be designed to prevent significant core damage and spent fuel sabotage. Specifically, the program must:
(i)
Ensure that the capabilities to detect, assess, interdict, and neutralize threats up to and including the design basis threat of radiological sabotage as stated in
§ 73.1, are maintained at all times.
(ii)
Provide defense-in-depth through the integration of systems, technologies, programs, equipment, supporting processes, and implementing procedures as needed to ensure the effectiveness of the physical protection program.
(4)
The licensee shall analyze and identify site-specific conditions, including target sets, that may affect the specific measures needed to implement the requirements of this section and shall account for these conditions in the design of the physical protection program.
(5)
Upon the request of an authorized representative of the Commission, the licensee shall demonstrate the ability to meet Commission requirements through the implementation of the physical protection program, including the ability of armed and unarmed personnel to perform assigned duties and responsibilities required by the security plans and licensee procedures.
(6)
The licensee shall establish, maintain, and implement a performance evaluation program in accordance with appendix B to this part, to demonstrate and assess the effectiveness of armed responders and armed security officers to implement the licensee's protective strategy.
(7)
The licensee shall establish, maintain, and implement an access authorization program in accordance with
§ 73.56 and shall describe the program in the Physical Security Plan.
(8)
The licensee shall establish, maintain, and implement a cyber security program in accordance with
§ 73.54 or
§ 73.110, as applicable.
(9)
The licensee shall establish, maintain, and implement an insider mitigation program and shall describe the program in the Physical Security Plan.
(i)
The insider mitigation program must monitor the initial and continuing trustworthiness and reliability of individuals granted or retaining unescorted access authorization to a protected or vital area, and implement defense-in-depth methodologies to minimize the potential for an insider to adversely affect, either directly or indirectly, the licensee's capability to prevent significant core damage and spent fuel sabotage.
(ii)
The insider mitigation program must contain elements from:
(A)
The access authorization program described in
§ 73.56;
(B)
The fitness-for-duty program described in
part 26 of this chapter;
(D)
The physical protection program described in this section.
(10)
The licensee shall use the site corrective action program to track, trend, correct and prevent recurrence of failures and deficiencies in the physical protection program.
(11)
Implementation of security plans and associated procedures must be coordinated with other onsite plans and procedures to preclude conflict during both normal and emergency conditions.
(12)
(i)
The licensee must ensure that the firearms background check requirements of
§ 73.17 of this part are met for all members of the security organization whose official duties require access to covered weapons or who inventory enhanced weapons.
(ii)
The provisions of this paragraph are only applicable to licensees subject to this section that are also subject to the firearms background check provisions of
§ 73.17 of this part.
(c)
Security plans.
(1)
Licensee security plans must describe:
(i)
How the licensee will implement requirements of this section through the establishment and maintenance of a security organization, the use of security equipment and technology, the training and qualification of security personnel, the implementation of predetermined response plans and strategies, and the protection of digital computer and communication systems and networks.
(ii)
Site-specific conditions that affect how the licensee implements Commission requirements.
(2)
Protection of security plans. The licensee shall protect the security plans and other security-related information against unauthorized disclosure in accordance with the requirements of
§ 73.21.
(3)
Physical Security Plan. The licensee shall establish, maintain, and implement a Physical Security Plan which describes how the performance objective and requirements set forth in this section will be implemented.
(4)
Training and Qualification Plan. The licensee shall establish, maintain, and implement, and follow a Training and Qualification Plan that describes how the criteria set forth in appendix B, section VI, to this part, “Nuclear Power Reactor Training and Qualification Plan for Personnel Performing Security Program Duties,” will be implemented.
(5)
Safeguards Contingency Plan. The licensee shall establish, maintain, and implement a Safeguards Contingency Plan that describes how the criteria set forth in appendix C, section II, to this part, “Nuclear Power Plant Safeguards Contingency Plans,” will be implemented.
(6)
Cyber Security Plan. The licensee shall establish, maintain, and implement a Cyber Security Plan that describes how the criteria set forth in
§ 73.54 or
§ 73.110, as applicable, will be implemented.
(7)
Security implementing procedures.
(i)
The licensee shall have a management system to provide for the development, implementation, revision, and oversight of security procedures that implement Commission requirements and the security plans.
(ii)
Implementing procedures must document the structure of the security organization and detail the types of duties, responsibilities, actions, and decisions to be performed or made by each position of the security organization.
(iii)
The licensee shall—
(A)
Provide a process for the written approval of implementing procedures and revisions by the individual with overall responsibility for the security program.
(B)
Ensure that revisions to security implementing procedures satisfy the requirements of this section.
(iv)
Implementing procedures need not be submitted to the Commission for approval, but are subject to inspection by the Commission.
(k)
Response requirements.
(1)
The licensee shall establish and maintain, at all times, properly trained, qualified and equipped personnel required to interdict and neutralize threats up to and including the design basis threat of radiological sabotage as defined in
§ 73.1, to prevent significant core damage and spent fuel sabotage.
(2)
The licensee shall ensure that all firearms, ammunition, and equipment necessary to implement the site security plans and protective strategy are in sufficient supply, are in working condition, and are readily available for use.
(3)
The licensee shall train each armed member of the security organization to prevent or impede attempted acts of radiological sabotage by using force sufficient to counter the force directed at that person, including the use of deadly force when the armed member of the security organization has a reasonable belief that the use of deadly force is necessary in self-defense or in the defense of others, or any other circumstances as authorized by applicable State or Federal law.
(4)
The licensee shall provide armed response personnel consisting of armed responders which may be augmented with armed security officers to carry out armed response duties within predetermined time lines specified by the site protective strategy.
(5)
Armed responders.
(i)
The licensee shall determine the minimum number of armed responders necessary to satisfy the design requirements of
§ 73.55(b) and implement the protective strategy. The licensee shall document this number in the security plans.
(ii)
The number of armed responders shall not be less than ten (10).
(iii)
Armed responders shall be available at all times inside the protected area and may not be assigned other duties or responsibilities that could interfere with their assigned response duties.
(6)
Armed security officers.
(i)
Armed security officers, designated to strengthen onsite response capabilities, shall be onsite and available at all times to carry out their assigned response duties.
(ii)
The minimum number of armed security officers designated to strengthen onsite response capabilities must be documented in the security plans.
(7)
The licensee shall have procedures to reconstitute the documented number of available armed response personnel required to implement the protective strategy.
(8)
Protective strategy. The licensee shall establish, maintain, and implement a written protective strategy in accordance with the requirements of this section and
part 73, appendix C, Section II. Upon receipt of an alarm or other indication of a threat, the licensee shall:
(i)
Determine the existence and level of a threat in accordance with pre-established assessment methodologies and procedures.
(ii)
Initiate response actions to interdict and neutralize threats in accordance with the requirements of
part 73, appendix C, section II, the safeguards contingency plan, and the licensee's response strategy.
(iii)
Notify law enforcement agencies (local, State, and Federal law enforcement agencies (LLEA)), in accordance with site procedures.
(9)
Law enforcement liaison. To the extent practicable, licensees shall document and maintain current agreements with applicable law enforcement agencies to include estimated response times and capabilities.
(10)
Heightened security. Licensees shall establish, maintain, and implement a threat warning system which identifies specific graduated protective measures and actions to be taken to increase licensee preparedness against a heightened security threat.
(i)
Licensees shall ensure that the specific protective measures and actions identified for each threat level are consistent with the security plans and other emergency plans and procedures.
(ii)
Upon notification by an authorized representative of the Commission, licensees shall implement the specific threat level indicated by the Commission representative.
(m)
Security program reviews.
(1)
As a minimum the licensee shall review each element of the physical protection program at least every 24 months. Reviews shall be conducted:
(i)
Within 12 months following initial implementation of the physical protection program or a change to personnel, procedures, equipment, or facilities that potentially could adversely affect security.
(ii)
As necessary based upon site-specific analyses, assessments, or other performance indicators.
(iii)
By individuals independent of those personnel responsible for program management and any individual who has direct responsibility for implementing the onsite physical protection program.
(2)
Reviews of the security program must include, but not limited to, an audit of the effectiveness of the physical security program, security plans, implementing procedures, cyber security programs, safety/security interface activities, the testing, maintenance, and calibration program, and response commitments by local, State, and Federal law enforcement authorities.
(3)
The results and recommendations of the onsite physical protection program reviews, management's findings regarding program effectiveness, and any actions taken as a result of recommendations from prior program reviews, must be documented in a report to the licensee's plant manager and to corporate management at least one level higher than that having responsibility for day-to-day plant operations. These reports must be maintained in an auditable form and available for inspection.
(4)
Findings from onsite physical protection program reviews must be entered into the site corrective action program.
(n)
Maintenance, testing, and calibration.
(1)
The licensee shall—
(i)
Establish, maintain, and implement a maintenance, testing and calibration program to ensure that security systems and equipment, including secondary and uninterruptible power supplies, are tested for operability and performance at predetermined intervals, maintained in operable condition, and are capable of performing their intended functions.
(ii)
Describe the maintenance, testing and calibration program in the physical security plan. Implementing procedures must specify operational and technical details required to perform maintenance, testing, and calibration activities to include, but not limited to, purpose of activity, actions to be taken, acceptance criteria, and the intervals or frequency at which the activity will be performed.
(iii)
Identify in procedures the criteria for determining when problems, failures, deficiencies, and other findings are documented in the site corrective action program for resolution.
(iv)
Ensure that information documented in the site corrective action program is written in a manner that does not constitute safeguards information as defined in
10 CFR 73.21.
(v)
Implement compensatory measures that ensure the effectiveness of the onsite physical protection program when there is a failure or degraded operation of security-related components or equipment.
(2)
The licensee shall test each intrusion alarm for operability at the beginning and end of any period that it is used for security, or if the period of continuous use exceeds seven (7) days. The intrusion alarm must be tested at least once every seven (7) days.
(3)
Intrusion detection and access control equipment must be performance tested in accordance with the security plans and implementing procedures.
(4)
Equipment required for communications onsite must be tested for operability not less frequently than once at the beginning of each security personnel work shift.
(5)
Communication systems between the alarm stations and each control room, and between the alarm stations and local law enforcement agencies, to include backup communication equipment, must be tested for operability at least once each day.
(6)
Search equipment must be tested for operability at least once each day and tested for performance at least once during each seven (7) day period.
(7)
A program for testing or verifying the operability of devices or equipment located in hazardous areas must be specified in the implementing procedures and must define alternate measures to be taken to ensure the timely completion of testing or maintenance when the hazardous condition or other restrictions are no longer applicable.
(8)
Security equipment or systems shall be tested in accordance with the site maintenance, testing and calibration procedures before being placed back in service after each repair or inoperable state.
(q)
Records.
(1)
The Commission may inspect, copy, retain, and remove all reports, records, and documents required to be kept by Commission regulations, orders, or license conditions, whether the reports, records, and documents are kept by the licensee or a contractor.
(2)
The licensee shall maintain all records required to be kept by Commission regulations, orders, or license conditions, until the Commission terminates the license for which the records were developed, and shall maintain superseded portions of these records for at least three (3) years after the record is superseded, unless otherwise specified by the Commission.
(3)
If a contracted security force is used to implement the onsite physical protection program, the licensee's written agreement with the contractor must be retained by the licensee as a record for the duration of the contract.
(4)
Review and audit reports must be maintained and available for inspection, for a period of three (3) years.
Notes, amendments, and revision history
Amendments
[74 FR 13971, Mar. 27, 2009, as amended at 77 FR 39909, July 6, 2012; 88 FR 15891, Mar. 14, 2023; 91 FR 15870, Mar. 30, 2026]
Source
Source: 88 FR 15881, Mar. 14, 2023, unless otherwise noted.
Authority
Authority: Atomic Energy Act of 1954, secs. 53, 147, 149, 161, 161A, 170D, 170E, 170H, 170I, 223, 229, 234, 1701 (42 U.S.C. 2073, 2167, 2169, 2201, 2201a, 2210d, 2210e, 2210h, 2210i, 2273, 2278a, 2282, 2297f); Energy Reorganization Act of 1974, secs. 201, 202 (42 U.S.C. 5841, 5842); Nuclear Waste Policy Act of 1982, secs. 135, 141 (42 U.S.C. 10155, 10161); 44 U.S.C. 3504 note. Section 73.37(b)(2) also issued under Sec. 301, Public Law 96-295, 94 Stat. 789 (42 U.S.C. 5841 note).
Source
Source: 38 FR 35430, Dec. 28, 1973, unless otherwise noted.
Amendments
[74 FR 13971, Mar. 27, 2009, as amended at 77 FR 39909, July 6, 2012; 88 FR 15891, Mar. 14, 2023; 91 FR 15870, Mar. 30, 2026]