PARLIAMENT QUESTION: THIRD-PARTY SECURITY AUDITS OF NUCLEAR POWER PLANTS
Issued by Department of Atomic Energy
Read or download the official PDF of this gazette notification issued by the Department of Atomic Energy on 12th August 2026. Classified under Press Release.
Executive Summary & Key Takeaways
Executive Summary This report outlines the comprehensive security frameworks, audits, and emergency preparedness protocols implemented at Indian nuclear power plants (NPPs). It details the roles of internal, regulatory, and external agencies in maintaining physical and cybersecurity, highlighting recent emergency exercises conducted at Kudankulam and Kalpakkam. The document confirms that all security systems are regularly upgraded to comply with findings from periodic assessments.
Key Points / Main Content
Security Assessments and Oversight
- Periodic security assessments are conducted internally, by the Atomic Energy Regulatory Board (AERB), and by external government agencies at all sites, including Kudankulam.
- The AERB performs specific regulatory inspections regarding the nuclear security of all operating plants.
- All audit observations are reviewed and monitored to ensure necessary upgrades are carried out for full compliance.
Physical and Electronic Security Infrastructure
- Operating NPPs utilize state-of-the-art electronic surveillance as an integral part of their infrastructure.
- Key systems include Perimeter Intrusion Detection Systems, Access Control Systems, X-Ray baggage inspection, and CCTV monitoring.
Cybersecurity Protocols
- Cybersecurity is managed through continuous monitoring and surveillance to detect and respond to threats.
- Preventive measures involve regular security audits, vulnerability assessments, incident response mechanisms, and capacity-building programs.
- CERT-in provides national-level support by issuing alerts on emerging threats and coordinating responses through the National Cyber Coordination Centre (NCCC).
Emergency Preparedness and Training
- Regulatory-approved Emergency Preparedness Plans (EPPs) are mandatory at all NPP sites.
- Training exercises are conducted at fixed intervals: Table Top exercises every two years, Integrated Command, Control & Response (ICCR) exercises every three years, and Mock Exercises as per the NDMA schedule.
- Recent milestones include the Kudankulam ICCR exercise on 15 April 2025 and the Kalpakkam offsite exercise on 17 July 2026.
Impact Analysis
Nuclear Power Plant (NPP) Authorities Impact They are responsible for maintaining high-level physical and cyber infrastructure and ensuring site-specific safety compliance. Action Required Must implement and maintain electronic security systems, facilitate periodic audits, and conduct emergency exercises at the stipulated frequencies.
Atomic Energy Regulatory Board (AERB) Impact Serves as the primary regulatory body overseeing the safety and security standards of all nuclear installations. Action Required Conduct periodic regulatory inspections and review/approve Emergency Preparedness Plans (EPPs) for all sites.
CERT-in and National Cyber Coordination Centre (NCCC) Impact These agencies act as the national facilitators for cybersecurity posture and threat mitigation. Action Required Issue timely alerts and advisories on emerging vulnerabilities and coordinate incident response for affected nuclear organizations.
Local and District Administration Impact Involved in the execution of off-site emergency preparedness and large-scale response exercises. Action Required Participate in ICCR and mock exercises to validate and improve coordinated emergency response plans.