Proposed Nuclear Security Regulations 2023
Canada Gazette, Part I, Volume 156, Number 46: Nuclear Security Regulations, 2023
The Canadian Nuclear Safety Commission proposes to repeal the current Nuclear Security Regulations and replace them with the Nuclear Security Regulations, 2023, shifting to a performance- and risk‑based approach and adding explicit cybersecurity and sensitive‑information protections. Practical effects include mandatory threat and risk assessments (every 5 years with annual review), updated security‑screening rules (site access validity extended to 10 years; credit checks for enhanced clearances), new requirements for drills/exercises and private security at non‑HSS, and a 60‑day public comment period starting on publication.
- Published
- November 12, 2022
- Department
- Unavailable
- Section
- REGULATORY IMPACT ANALYSIS STATEMENT
- Comment deadline
- January 11, 2023
- Effective date
- Unavailable
- Publication part
- Part I
Summary
Summary#
The Canadian Nuclear Safety Commission (CNSC) is proposing to repeal the current Nuclear Security Regulations and replace them with the Nuclear Security Regulations, 2023. The proposal would move the rules from specific, prescriptive requirements to a more flexible, performance- and risk‑based approach and add new requirements for cybersecurity, protection of sensitive information and updated security screening. The CNSC estimates the net present‑value cost of the proposal at about $13.34 million over 10 years, while noting some safety and security benefits are hard to put a dollar value on.
What it does#
- Replaces the existing, prescriptive rules with the proposed Nuclear Security Regulations, 2023 that focus on performance outcomes and a risk‑informed approach.
- Adds new explicit cybersecurity requirements and rules to protect sensitive information. The CNSC estimates the cybersecurity and information protection cost at $13.35 million (present value).
- Requires regular threat and risk assessments (TRAs) — at least every 5 years with an annual review or sooner if threats change.
- Updates security screening rules:
- Extends routine site access validity from 5 years to 10 years (this change is estimated to save $6.59 million present value).
- Requires credit checks for people with enhanced clearances.
- Creates clearer tiers of control for nuclear material:
- Category I material must be kept in an “inner area”; Category II in a “protected area”; Category III in a protected area or other controlled area.
- Strengthens rules for on‑site and off‑site response forces, drills and exercises (including transport exercises).
- Sets new requirements for private security personnel at non‑high‑security sites (training, provincial standards).
- Simplifies structure and removes an outdated schedule of named facilities so the rules apply by facility type instead of by name.
- Proposal includes new administrative penalties for failing to meet these requirements.
- The CNSC ran a public consultation process and is offering a 60‑day comment period on the proposal.
Who's affected#
- Operators of large nuclear power plants and other high‑security sites (HSS).
- These typically already meet many security standards but would see requirements formalized and reorganized.
- Operators of smaller or non‑high‑security facilities (non‑HSS), such as research reactors, fuel fabrication facilities and nuclear substance processing facilities.
- Non‑HSS are likely to see proportionally larger new costs because some security and cybersecurity measures are new for them.
- Security staff and contractors (nuclear security officers, central alarm station operators, private security guards).
- Organizations that transport nuclear material (some new exercise and planning requirements).
- Developers and supporters of small modular reactors (SMR proponents).
- The rules aim to be less prescriptive so they can better fit new SMR designs.
- The general public (indirectly), because the changes are intended to reduce the risk of theft, sabotage or cyber incidents involving nuclear material.
If it is unclear: the proposal affects anyone who holds a CNSC licence for activities listed in the Regulations. The RIAS does not list every company by name, though the CNSC consulted utilities and SMR proponents during development.
Why it matters#
- Modern threats have changed since the old rules were last updated. The proposal explicitly adds cyber threats and protections for digital information. That aims to reduce the chance of disruptive or dangerous incidents caused by hacking.
- The move to performance‑based rules is intended to allow newer reactor designs (including SMRs) to meet security goals without forcing them into rules made for large plants. That could make new technology easier to deploy while keeping safety goals.
- There are direct costs and savings. The CNSC estimates total monetized benefits of $7.42 million (mainly from longer site‑access validity) and total monetized costs of $20.77 million, giving a net present‑value cost of about $13.34 million over 10 years. Many important benefits—like reduced risk to public health and the environment—are not fully monetized and are considered qualitative.
- Implementation timing matters: security requirements for high‑security sites would come into force about one year after the regulations are registered, and for non‑high‑security sites about two years after registration. That gives operators time to plan upgrades.
- The proposal also updates screening standards to match current federal practice and aims to align Canada’s rules with international guidance (IAEA) and Canada’s commitments on SMRs.
If you work at or live near a facility that handles nuclear material, or follow energy and cyber security issues, these proposed rules are worth watching while the CNSC takes comments during the consultation period.
Key topics
Source: Canada Gazette