K07 · evidence-bundled critical-infrastructure assurance
K07 Primary-Source Reviews
Direct answer
K07 reviewed selected official nuclear, engineering, OT, supply-chain, procurement, software, hardware, and Machine Intelligence risk sources at a point in time while preserving unresolved applicability and authority.
K07 primary-source review groups
NRC advanced-reactor and cyber-security sources
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- Part 53 is an official optional technology-inclusive framework for advanced-reactor licensing.
- RG 5.71 Revision 1 is official NRC cyber-security program guidance for nuclear power reactors.
Unavailable or unresolved
- No public source review decides applicability to a named datacenter or reactor.
- No source creates private operational or counter-UAS authority.
DOE Cyber-Informed Engineering
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- DOE describes CIE as integrating cybersecurity into engineering conception, design, development, and operation.
- The method emphasizes design and engineering controls against high-consequence cyber-enabled outcomes.
Unavailable or unresolved
- A CIE or CCE workshop is not a facility certification.
- Site findings require authorized facility evidence.
NIST operational-technology security
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- SP 800-82 Revision 3 remains the final OT security publication at the K07 cutoff.
- NIST initiated a Revision 4 pre-draft process in January 2026.
Unavailable or unresolved
- The Revision 4 pre-draft notice is not a final control baseline.
- NIST guidance does not decide NRC, NERC, contract, or facility applicability by itself.
NIST, NTIA, and CISA supply-chain assurance
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- NIST publishes multilevel C-SCRM guidance and a final 2026 supplier due-diligence quick-start guide.
- NTIA and CISA publish software and hardware bill-of-materials transparency guidance.
Unavailable or unresolved
- Bills of materials do not prove absence of defects, compromise, counterfeit components, or installed-state equivalence.
- Contract-specific completeness and data rights remain unresolved until acquisition.
Digital-twin and AI-system assurance
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- NIST IR 8356 addresses digital-twin cyber-security and trust considerations.
- SP 800-218A adds AI-model-specific secure development practices.
- NIST is developing a critical-infrastructure AI RMF profile.
Unavailable or unresolved
- The critical-infrastructure profile is not final at the cutoff.
- A digital twin is not presumed faithful to a site outside its validated range.
Federal performance and quality acquisition
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Supported propositions
- FAR 37.602 emphasizes required results and measurable performance standards in performance work statements.
- FAR Part 46 addresses inspection, quality control, evidence, nonconformance, and acceptance.
Unavailable or unresolved
- The public work packages are not solicitations or contract awards.
- Agency-specific clauses, security requirements, data rights and acquisition authority remain unresolved.
Currentness boundary
Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Official publication status does not decide applicability, compliance, licensing, contract interpretation, operational authority, or later currentness.