Comment on FR Doc # 2026-12989, NRC-2025-1303-0001, from Anonymous
Anonymous AnonymousSupportOther
Summary: The commenter advocates for the NRC to replace prescriptive testing periodicities with a risk-informed, performance-based approach. They argue that allowing licensees to establish testing frequencies based on equipment performance history and reliability data reduces administrative burden and improves security effectiveness.
The NRC should remove prescriptive testing periodicities from regulations and associated guidance and instead adopt a risk-informed, performance-based approach that allows licensees to establish testing frequencies based on equipment performance history, operating experience, vendor recommendations, reliability data, and corrective action program insights.
The current use of fixed testing intervals, such as every 7 days, does not appear to have a clearly documented technical, reliability, or risk-informed basis. While periodic testing is an important component of maintaining equipment reliability, the frequency of testing should be driven by demonstrated equipment performance and the security significance of the function being tested rather than by an arbitrary calendar interval.
A risk-informed maintenance and testing program would utilize actual performance data, including:
•Historical equipment reliability and failure rates.
•Preventive and predictive maintenance results.
•Corrective action program trends.
•Manufacturer and vendor recommendations.
•Environmental and operating conditions.
•Security significance of the equipment function.
•Equipment age and lifecycle considerations.
This approach is consistent with modern reliability-centered maintenance principles and places resources where they provide the greatest security benefit.
From a security effectiveness perspective, the objective is not to perform a test every prescribed number of days. The objective is to ensure that detection, assessment, communication, delay, and response capabilities remain available and effective. Proposed performance-based security requirements in 10 CFR 73.100 already focus on maintaining effective security functions and establishing inspection, testing, and calibration intervals that are "necessary and sufficient" to achieve those objectives, rather than prescribing specific frequencies.
A prescriptive testing frequency may create two undesirable outcomes:
1.Over-testing highly reliable equipment, increasing administrative burden, equipment wear, and resource expenditure without a corresponding security benefit.
2.Under-testing degraded or higher-risk equipment, because compliance is measured by meeting a fixed interval rather than by actual equipment performance.
A risk-informed program allows licensees to increase testing frequencies when performance data indicates degradation and reduce testing frequencies when equipment demonstrates sustained reliability. This provides a more defensible and technically supported approach than applying the same testing interval regardless of equipment type, environment, or performance history.
Additionally, security effectiveness is ultimately demonstrated through the performance evaluation program, drills, exercises, inspections, and corrective action processes. If equipment reliability is inadequate, deficiencies will be identified through actual performance testing and operational use. As such, equipment testing frequency should be treated as a licensee-managed reliability strategy rather than a prescriptive regulatory requirement.
The NRC has already recognized the value of performance-based approaches in other security areas by proposing reductions in prescriptive frequencies where operating experience demonstrates limited value and where performance outcomes can be evaluated through other means. For example, proposed changes within the Modernizing Security Requirements initiative reduce certain audit and testing burdens based on operating experience and demonstrated effectiveness.
A more risk-informed regulatory framework would therefore require that security systems be tested at intervals sufficient to demonstrate reliability and effectiveness, while allowing licensees flexibility to establish and adjust those intervals using performance data, vendor recommendations, and risk significance. This approach maintains security effectiveness, improves resource utilization, and aligns with the NRC's stated objective of reducing unnecessary regulatory burden while focusing on demonstrated performance and outcomes.