RECOMMENDATION

Strengthen regulatory bodies and technical institutions to sustain nuclear security regimes

This recommendation is relevant to
  • Securing Materials Against Theft
  • Protecting Facilities Against Sabotage
Countries and areas with weapons-usable nuclear materials or nuclear facilities should take the following actions to sustain their nuclear security regimes:
  • Conduct a national needs assessment to inform the development of indigenous technical support organizations or Nuclear Security Support Centers that ensure access to the expertise necessary to translate an accurate threat picture into effective security regulations
  • Require a process to regularly update the design basis threat (DBT) in use that includes cyber and insider threats and draws on technical expertise from support organizations to identify and assess emerging and rapidly evolving threats
  • Establish regulatory requirements for tests and assessments of security systems conducted by a competent authority, including force-on force exercises, designed with realistic threat considerations
  • Mandate regular cybersecurity system tests informed by input from a technical support organization in coordination with the national regulator and based on a current understanding of threat vectors and the tactics, techniques, and procedures adversaries may use
  • Develop institutions that can conduct research and strategic planning on cybersecurity in coordination with nuclear regulatory authorities, translating technical expertise into regulations and guidance.

What the Data Show

Progress has stalled on developing technical support institutions, requiring threat-based testing, regularly updating design basis threat, and building cybersecurity capacity among regulatory bodies and technical support organizations in countries and areas with weapons-usable nuclear materials and nuclear facilities.
Data Highlights

Among the 50 countries and areas with weapons-usable nuclear material or nuclear facilities:

  • Forty countries and Taiwan have established institutions to provide nuclear security technical support to their regulatory bodies.
  • Fourteen countries do not have technical cybersecurity institutions with a nuclear security role.
  • Only 16 countries require personnel with security responsibilities to undergo additional training or certification.
  • Just 12 countries require both realistic threat-based evaluations and regular force-on-force exercises to assess nuclear security systems’ effectiveness. Since 2020, Finland and France are the only countries that have strengthened their regulations to include these requirements.
  • Thirteen countries and Taiwan do not require use of a regularly updated DBT.
  • Five countries that require a regularly updated DBT do not explicitly include cyber threats in the threat assessment process (Algeria, Kazakhstan, Morocco, Peru, and Turkey). Just two countries have added these requirements since 2023 (Armenia and Ukraine).
Data Details

Sustaining a nuclear security regime requires governments to follow a cycle of continuous improvement by developing human resources, maintaining equipment, fostering a robust security culture, and strengthening regulatory oversight. Technical expertise is necessary to effectively execute the processes that support these functions, through regularly reassessing threats, testing security measures, and acting on findings to strengthen their requirements. The institutions and frameworks that support this continuous process are the tools governments need to sustain regimes capable of addressing modern, emerging threats.

The 2026 NTI Index finds that 41 of the 50 countries and areas with weapons-usable nuclear material or nuclear facilities have institutions that provide nuclear security technical support to regulatory bodies—a necessary foundation—but that number has plateaued since the 2020 NTI Index. Amid escalating cyber threats to nuclear facilities, progress is also stalled on the number of countries and areas that have indigenous technical cybersecurity institutions to translate national cyber strategies into specific guidance. Fourteen countries are still without this support—a figure that has not changed since the 2023 NTI Index.

Simply having support institutions does not mean countries and areas are capturing their benefits to strengthen nuclear security implementation. Harnessing the capabilities of technical support organizations requires national legal frameworks—including requirements for regular updates to the DBT, threat-based testing of security systems, security culture programs, and training and certification of security personnel—that give oversight authorities the mandate to fully use them.

At the core of every nuclear security regime is the DBT: the profile of adversary tactics, capabilities, and motivations that security systems are designed to protect against. A well-developed DBT requires input from regulatory bodies, intelligence and security services, technical and legal experts, facility operators, law enforcement, and other stakeholders. Dedicated technical support organizations are an asset for both their expertise and stakeholder coordination capabilities. DBTs should inform testing requirements, security system design, regulatory guidance, and force-on-force exercises. Developing security plans without a DBT creates reliance on a prescriptive list of measures that may not effectively deter the full scope of potential threats.

Unfortunately, 13 countries and Taiwan do not require a regularly updated DBT. Among the 36 countries that do require a regularly updated DBT, 5 (Algeria, Kazakhstan, Morocco, Peru, and Turkey) do not explicitly include cyber threats in the threat assessment process. In a rapidly evolving threat environment defined by drone strikes, sophisticated cyberattacks, terrorist risks, and insider threats, a DBT that is outdated, incomplete, or absent creates a compounding failure where security systems are designed and tested against threats that no longer represent the actual risk environment.

Without robust mechanisms to assess the effectiveness of security measures, even well-resourced regulatory institutions cannot guarantee that nuclear security keeps pace with an evolving threat environment. Technical support organizations have the unique expertise to translate threat assessments into testing and assessment requirements, validating whether physical protection and cybersecurity systems can realistically mitigate or defeat credible threats. But just 12 countries require both realistic threat-based evaluations and regular force-on-force exercises to assess nuclear security systems’ effectiveness—and no country or area has added this requirement since the 2023 NTI Index.

Sustaining a nuclear security regime is a permanent responsibility for all governments. Developing institutions that can support continuous improvement and the legal and regulatory frameworks that give them a mandate to do so is the foundation of upholding this responsibility.

See how your country can act on this recommendation

Actions to take

Strengthen regulatory bodies and technical institutions to sustain nuclear security regimes

  • Require the use of a Design Basis Threat that must be regularly updated (done)
  • Establish regulatory requirements for tests and assessments of security systems conducted by a competent authority, including force-on force exercises, designed with realistic threat considerations (done)
  • Create a Nuclear Security Support Center (NSSC) or a non-NSSC institution that demonstrates core nuclear security sustainability competencies
  • Develop institutions that can conduct research and strategic planning on cybersecurity in coordination with nuclear regulatory authorities, translating technical expertise into regulations and guidance (done)
  • Require personnel with security responsibilities to undergo additional training or certification that builds upon existing training for non-security personnel

Close

O
Q
Y