Comment on FR Doc # 2026-12989, NRC-2025-1303-0001, from Anonymous
Anonymous AnonymousOpposeOther
Summary: The commenter opposes the proposed changes to the access authorization program, specifically arguing against the removal of prescriptive identity verification requirements, the elimination of periodic credit history checks, and the extension of audit intervals. They argue that these changes weaken insider threat protections and reduce necessary oversight of nuclear power plant security.
Access authorization program changes:
Disagree with the proposed change to 73.56(d)(3) to remove “prescriptive requirements for the verification of true identity.” The most minimal effort a utility has to expend on an individual is to look at a valid state issued driver’s license or other form of acceptable ID like a passport - similar ID verification requirements apply to purchasing liquor or cigarettes, financing a car or home purchase, voting in an election, or applying for a job in the U.S. This is especially true for visitors under escort who are not subject to fingerprinting or the increased scrutiny that comes with unescorted plant access. Many of us remember 9/11, the rollout of the REAL ID standard has been a welcomed, if not timely, improvement in uniform identity verification in the U.S. A REAL ID should be the only state issued ID that is acceptable for entry into a nuclear power plant. Guidance is unnecessary. If TSA requires a REAL ID to fly on a plane in the U.S. then that ID should be perfectly fine for entry into a nuclear power plant, whether it is operating, in outage, or under construction.
The proposed revision to 73.56(i)(1)(v) to eliminate periodic credit history checks is a bad idea. The NRC basis offered in the proposed rule is that operating experience has shown that re-evaluations of credit history add little value. Please provide the data to support the assertion. I could find no NRC published statistics on the access authorization program. Divorce, illness and resultant medical bills, gambling addiction, impacts of a natural disaster on one’s home, the loss of a job of a spouse, the death of a family member, and excessive spending with associated increases in debt service/leverage can all create substantial financial hardship and life altering stress. Financial leverage is one of the most easily identifiable changes in an individual’s life that predicts instability and presents a real vulnerability for exploitation by an adversary. Any basic insider threat training covers this topic. An insider threat is the biggest threat a plant can have. Not performing periodic low cost credit history checks weakens the insider threat program. This proposal is unwise and potentially dangerous.
The regulatory analysis demonstrates significant benefits to plants that enroll in continuous government monitoring such as the FBI Rap Back program with relief from performing more frequent periodic background investigations. Relying on the self reporting of legal actions is not comparable to continuous monitoring programs. This change should be mandated on licensees because it is more effective than self reporting or infrequent fingerprinting/criminal history checks performed every few years and which offer only a snap shot in time. Continuous monitoring saves money and is superior to the current approach. It is illogical to suggest that adoption of continuous monitoring be optional. It saves money and is more effective. It must be mandated.
Extending audit intervals in 73.56(n) for the access authorization programs is a terrible idea. The NRC has already implemented significant reductions in its inspection programs across the board in 2025 and 2026. Roughly a 50 percent reduction in inspection hours for all inspections along with significantly paring back the minimal required inspection elements to be completed at inspection. As a result, the NRC will apply fewer inspection hours when it conducts inspections, which will result in reduced oversight. Now the agency is proposing to relieve licensees from performing internal audits until just before the 3 year NRC inspection — that is what changing the licensee auditing period from every 2 years to every 3 years means. Licensees have received a lot of credit, and reasonably so, for internally identifying problems, logging them into a CAP, and correcting deficiencies independent of NRC oversight. Reducing external and internal program oversight weakens the access authorization program. This proposed change is not in the best interests of safety and security.