[
  {
    "assumptions": [
      "Existing reactor license basis and physical protection program remain authoritative for the nuclear facility.",
      "Datacenter ownership or power purchase does not transfer licensee authority.",
      "Shared power, communications, cooling, timing, maintenance, or emergency services create cross-domain dependencies."
    ],
    "classification": "NON-CERTIFYING REFERENCE PATTERN",
    "context": "A datacenter is adjacent to or supplied by an operating legacy nuclear station through a behind-the-meter or closely coupled arrangement.",
    "controlIds": [
      "GOV-01",
      "GOV-02",
      "ARC-01",
      "ARC-02",
      "ARC-03",
      "OT-01",
      "OT-02",
      "PWR-01",
      "REC-01",
      "EVD-01"
    ],
    "directAnswer": "Treat the licensed nuclear plant, grid interconnection, datacenter, shared services, and contractual boundaries as one consequence network while preserving separate authorities and deterministic safety boundaries.",
    "id": "FP-K06-001",
    "name": "Existing nuclear-plant colocation",
    "nonClaims": [
      "Not a license amendment",
      "Not a FERC, NRC, NERC, or state-jurisdiction determination",
      "Not proof that colocation is approved or operating"
    ],
    "priorityHazards": [
      "load rejection and grid transient",
      "IT-to-OT or management-plane pivot",
      "shared maintenance credential compromise",
      "common-cause cooling or substation failure",
      "misclassified ownership and incident authority"
    ],
    "requiredEvidence": [
      "license and ownership boundary map",
      "single-line power and protection diagrams",
      "data-flow and trust-boundary inventory",
      "shared-service failure analysis",
      "joint incident command and restoration evidence"
    ],
    "slug": "existing-plant-colocation",
    "tailoringQuestions": [
      "Which assets remain inside the nuclear licensee's protected and cyber-security programs?",
      "Which power and network paths are shared or mutually dependent?",
      "Who may order isolation, load shedding, shutdown, restoration, and evidence release?",
      "What grid services are still required when the datacenter is described as behind the meter?"
    ],
    "workPackageIds": [
      "WP-K06-01",
      "WP-K06-02",
      "WP-K06-03",
      "WP-K06-04",
      "WP-K06-07",
      "WP-K06-08"
    ]
  },
  {
    "assumptions": [
      "The final Part 53 framework exists, but facility elections and license-specific requirements are not assumed.",
      "Passive safety can reduce some consequences but does not eliminate sabotage, cyber, insider, supply-chain, or grid hazards.",
      "Digital design decisions can become licensing-basis evidence and must be controlled from concept through operation."
    ],
    "classification": "NON-CERTIFYING REFERENCE PATTERN",
    "context": "A new advanced reactor under a Part 53 licensing path supplies a high-consequence compute campus.",
    "controlIds": [
      "GOV-01",
      "GOV-03",
      "ARC-01",
      "ARC-03",
      "ID-01",
      "SUP-01",
      "SUP-02",
      "OT-01",
      "AUT-01",
      "EVD-02"
    ],
    "directAnswer": "Use security-by-design, technology-inclusive licensing evidence, consequence analysis, and selected Part 73 pathways from the beginning; never infer election, applicability, or approval from the existence of the final rule.",
    "id": "FP-K06-002",
    "name": "Part 53 advanced-reactor campus",
    "nonClaims": [
      "Not a Part 53 application",
      "Not an NRC approval",
      "Not a conclusion that armed responders or other safeguards may be removed"
    ],
    "priorityHazards": [
      "security claims unsupported by design evidence",
      "digital I&C common-cause failure",
      "remote fleet-management compromise",
      "supply-chain and firmware substitution",
      "authority drift between applicant, licensee, vendor, and datacenter operator"
    ],
    "requiredEvidence": [
      "licensing-path and election record",
      "security-by-design traceability",
      "high-consequence event analysis",
      "digital asset and support-system inventory",
      "independent verification plan and change control"
    ],
    "slug": "part-53-advanced-reactor",
    "tailoringQuestions": [
      "Which Part 73 provisions are elected or imposed?",
      "Which claims depend on passive safety and what defeats them?",
      "How are vendor, fleet, and remote-service privileges bounded?",
      "What evidence is required at each licensing and deployment milestone?"
    ],
    "workPackageIds": [
      "WP-K06-01",
      "WP-K06-02",
      "WP-K06-03",
      "WP-K06-04",
      "WP-K06-06",
      "WP-K06-08",
      "WP-K06-09"
    ]
  },
  {
    "assumptions": [
      "Remote siting increases response, maintenance, and supply-chain latency.",
      "Autonomous operation and remote supervision increase management-plane and communications dependence.",
      "Passive and physical safety functions must remain independent of datacenter availability."
    ],
    "classification": "NON-CERTIFYING REFERENCE PATTERN",
    "context": "A remote or islanded compute campus uses one or more microreactors and may have limited grid, communications, logistics, or public-safety support.",
    "controlIds": [
      "GOV-02",
      "ARC-02",
      "ID-01",
      "ID-02",
      "OT-02",
      "AUT-01",
      "AUT-02",
      "PHY-01",
      "PWR-01",
      "REC-01"
    ],
    "directAnswer": "Design for degraded communications, sparse local support, independent safe-state behavior, delayed external response, protected fuel and maintenance chains, and verifiable restoration without assuming autonomous force authority.",
    "id": "FP-K06-003",
    "name": "Isolated microreactor campus",
    "nonClaims": [
      "Not proof that zero staffing is lawful or safe",
      "Not private counter-UAS or lethal-force authority",
      "Not a generic microreactor security plan"
    ],
    "priorityHazards": [
      "communications partition",
      "remote credential or fleet-control compromise",
      "fuel and transport security",
      "extended cooling or maintenance outage",
      "unauthorized autonomous physical response"
    ],
    "requiredEvidence": [
      "islanding and black-start test",
      "communications-loss safe-state test",
      "remote-access and workload-identity proof",
      "physical delay and authorized-response analysis",
      "spares, fuel, and recovery logistics plan"
    ],
    "slug": "isolated-microreactor-campus",
    "tailoringQuestions": [
      "How long can the campus remain safe and functional without external communications?",
      "Which actions remain locally authorized during partition?",
      "How are captured or tampered edge devices revoked?",
      "What is the credible arrival time and authority of external responders?"
    ],
    "workPackageIds": [
      "WP-K06-01",
      "WP-K06-02",
      "WP-K06-03",
      "WP-K06-05",
      "WP-K06-06",
      "WP-K06-07",
      "WP-K06-10"
    ]
  },
  {
    "assumptions": [
      "Absence of a reactor removes nuclear-specific licensing but not cyber-physical consequence.",
      "Grid, generators, storage, cooling, water, telecom, and cloud dependencies remain operational attack surfaces.",
      "Service criticality and data/model authority require explicit mission and recovery evidence."
    ],
    "classification": "NON-CERTIFYING REFERENCE PATTERN",
    "context": "A datacenter supports national security, public safety, finance, healthcare, communications, model training, or other high-consequence services without colocated nuclear generation.",
    "controlIds": [
      "GOV-01",
      "ARC-01",
      "ID-01",
      "SUP-01",
      "CLG-01",
      "AUT-01",
      "PWR-01",
      "REC-01",
      "EVD-01",
      "OPS-01"
    ],
    "directAnswer": "Apply the same consequence, autonomy, evidence, recovery, power, cooling, management-plane, and physical-protection discipline even when nuclear licensing does not apply.",
    "id": "FP-K06-004",
    "name": "Non-nuclear high-consequence datacenter",
    "nonClaims": [
      "Not a nuclear-control mapping",
      "Not proof of critical-infrastructure designation",
      "Not a certification or service-level guarantee"
    ],
    "priorityHazards": [
      "multi-utility outage",
      "cooling and water failure",
      "management-plane takeover",
      "model, data, or firmware compromise",
      "recovery from corrupted backups"
    ],
    "requiredEvidence": [
      "mission impact analysis",
      "power and cooling dependency map",
      "identity and management-plane assurance",
      "clean-room recovery exercise",
      "supplier and external-service continuity evidence"
    ],
    "slug": "non-nuclear-high-consequence-datacenter",
    "tailoringQuestions": [
      "Which services create life, safety, national-security, or systemic consequences?",
      "What is the maximum tolerable data, model, and service loss?",
      "Which external utilities or cloud dependencies can defeat local resilience?",
      "What evidence proves restoration is clean rather than merely available?"
    ],
    "workPackageIds": [
      "WP-K06-01",
      "WP-K06-03",
      "WP-K06-04",
      "WP-K06-05",
      "WP-K06-06",
      "WP-K06-07",
      "WP-K06-08"
    ]
  }
]
