RECOMMENDATION

Capitalize on the upcoming revision of Information Circular 225

This recommendation is relevant to
  • Securing Materials Against Theft
  • Supporting Global Efforts Against Theft
  • Protecting Facilities Against Sabotage
All countries should capitalize on the opportunity presented by the revision of international physical protection guidance with the following actions:
  • Contribute to the revision process of INFCIRC/225/ Rev.5 with specific input on how to strengthen provisions regarding insider threat mitigation, cybersecurity systems, continuous threat assessment, and emerging technologies
  • Host regional discussions that enable dialogue between nuclear security professionals about significant nuclear security gaps in daily facility operation and elevate lessons learned into the INFCIRC/225/Rev.5 revision process
  • Engage regulators, especially those involved in approving new reactor designs, in the INFCIRC/225/ Rev.5 revision process
  • Implement more stringent nuclear security regulations than INFCIRC/225/Rev.5 calls for, based on regular threat assessments and the principle of continuous improvement.

What the Data Show

The International Atomic Energy Agency has not updated its benchmark guidance for nuclear security in 15 years, leaving growing gaps in its coverage of insider threats, cybersecurity, and emerging technologies. The revision of this guidance, initiated in 2024, presents an opportunity for countries to provide input on the development of new best practices addressing modern threats.
Data Highlights
  • Thirty-two countries and Taiwan with nuclear facilities have no insider threat awareness program, an issue inadequately covered by INFCIRC/225/Rev.5.
  • Only 11 countries and Taiwan require cybersecurity assessments to be conducted at least annually.
  • Nineteen countries lack basic requirements for assessments of cybersecurity measures, although six have implemented such requirements since 2023 (Belgium, Chile, Indonesia, Slovenia, the United Arab Emirates, and Uzbekistan).
Data Details

International Atomic Energy Agency (IAEA) Information Circular 225 Revision 5 (INFCIRC/225/Rev.5) guides governments on establishing and maintaining a national physical protection program. Last updated in 2011, it is the internationally recognized benchmark for preventing theft of nuclear materials and sabotage to nuclear facilities; its recommendations are directly incorporated into many states’ domestic laws and bilateral agreements, and 39 countries have made a clear political commitment to using INFCIRC/225/Rev.5 as the baseline for their national nuclear security implementation.

However, today’s threat environment is fundamentally different from the 2011 environment reflected in INFCIRC/225/Rev.5. In 2016, six countries with nuclear facilities or weapons-usable nuclear materials experienced armed conflict or explosions within 10 miles of their nuclear facilities. By 2026, that number more than tripled to 23. Cyber capabilities, uncrewed aerial vehicles, and artificial intelligence tools have matured into widely available commercial technologies that pose major challenges to national nuclear security regimes, but INFCIRC/225/Rev.5 does not recognize emerging technologies as a threat vector. Uncrewed aerial vehicles (UAVs), for example, now frequently integrate other developing technologies, such as artificial intelligence and fiber-optic control systems, which render traditional response strategies ineffective.

The consequences of outdated guidance are measurable. The areas where INFCIRC/225/Rev.5 guidance is less comprehensive correspond with gaps in nuclear security that the 2026 NTI Index identifies. Thirty-three countries and areas with nuclear facilities have no insider threat awareness program, an issue inadequately covered by INFCIRC/225/Rev.5. Similarly, INFCIRC/225/Rev.5 offers limited specifics on cybersecurity and the concept of continuous improvement in contrast to detailed physical protection guidance, and 19 countries lack basic requirements for assessments of cybersecurity measures. Countermeasures to protect nuclear facilities from emerging technologies, including UAVs, are entirely absent from INFCIRC/225/Rev.5 and other IAEA nuclear security guidance. Standards for addressing these emerging threats need to be developed. These are not intentional gaps—they reflect the limits of guidance written 15 years ago.

The stakes are rising as nuclear energy is poised to change and expand in ways that existing guidance does not anticipate. Dozens of new reactor designs are progressing through licensing processes in several countries, including small modular reactors, microreactors, and floating reactors designed for colocation at industrial facilities and data centers, deployment in remote areas, and other locations substantially different from currently operating reactors. The novel conditions introduced by these designs and deployment scenarios require new guidance that reflects the full range of contexts in which nuclear facilities may operate.

The next iteration of INFCIRC/225—Rev.6—is now under development. This process offers a direct channel for states to shape the content and ambition of global nuclear security guidance for the future.

See how your country can act on this recommendation

Actions to take

Capitalize on the upcoming revision of Information Circular 225

  • Contribute to the revision process of INFCIRC/225/Rev.5 through participation in the IAEA Nuclear Security Guidance Committee, and provide specific input on how to strengthen provisions regarding insider threat mitigation, cybersecurity systems, continuous threat assessment, and emerging technologies (done)

Close

O
Q
Y