K07 · evidence-bundled critical-infrastructure assurance

K07 Primary-Source Reviews

Direct answer

K07 reviewed selected official nuclear, engineering, OT, supply-chain, procurement, software, hardware, and Machine Intelligence risk sources at a point in time while preserving unresolved applicability and authority.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

K07 primary-source review groups

REVIEWED_POINT_IN_TIME

NRC advanced-reactor and cyber-security sources

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • Part 53 is an official optional technology-inclusive framework for advanced-reactor licensing.
  • RG 5.71 Revision 1 is official NRC cyber-security program guidance for nuclear power reactors.

Unavailable or unresolved

  • No public source review decides applicability to a named datacenter or reactor.
  • No source creates private operational or counter-UAS authority.
REVIEWED_POINT_IN_TIME

DOE Cyber-Informed Engineering

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • DOE describes CIE as integrating cybersecurity into engineering conception, design, development, and operation.
  • The method emphasizes design and engineering controls against high-consequence cyber-enabled outcomes.

Unavailable or unresolved

  • A CIE or CCE workshop is not a facility certification.
  • Site findings require authorized facility evidence.
REVIEWED_POINT_IN_TIME

NIST operational-technology security

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • SP 800-82 Revision 3 remains the final OT security publication at the K07 cutoff.
  • NIST initiated a Revision 4 pre-draft process in January 2026.

Unavailable or unresolved

  • The Revision 4 pre-draft notice is not a final control baseline.
  • NIST guidance does not decide NRC, NERC, contract, or facility applicability by itself.
REVIEWED_POINT_IN_TIME

NIST, NTIA, and CISA supply-chain assurance

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • NIST publishes multilevel C-SCRM guidance and a final 2026 supplier due-diligence quick-start guide.
  • NTIA and CISA publish software and hardware bill-of-materials transparency guidance.

Unavailable or unresolved

  • Bills of materials do not prove absence of defects, compromise, counterfeit components, or installed-state equivalence.
  • Contract-specific completeness and data rights remain unresolved until acquisition.
REVIEWED_POINT_IN_TIME

Digital-twin and AI-system assurance

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • NIST IR 8356 addresses digital-twin cyber-security and trust considerations.
  • SP 800-218A adds AI-model-specific secure development practices.
  • NIST is developing a critical-infrastructure AI RMF profile.

Unavailable or unresolved

  • The critical-infrastructure profile is not final at the cutoff.
  • A digital twin is not presumed faithful to a site outside its validated range.
REVIEWED_POINT_IN_TIME

Federal performance and quality acquisition

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Supported propositions

  • FAR 37.602 emphasizes required results and measurable performance standards in performance work statements.
  • FAR Part 46 addresses inspection, quality control, evidence, nonconformance, and acceptance.

Unavailable or unresolved

  • The public work packages are not solicitations or contract awards.
  • Agency-specific clauses, security requirements, data rights and acquisition authority remain unresolved.

Currentness boundary

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Official publication status does not decide applicability, compliance, licensing, contract interpretation, operational authority, or later currentness.