# Complete written NRC cyber-event follow-up after telephonic notification

> Use 10 CFR 73.77 - Cyber security event notifications to review this narrow operational decision without extending the source beyond its stated scope.

- Canonical URL: https://update.dsesecurity.com/updates/complete-written-nrc-cyber-event-follow-up-after-telephonic-notification/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-27T12:11:36+00:00
- Modified: 2026-08-27T13:06:59+00:00
- Last reviewed by DSE: 2026-08-26
- Resource type: Playbook
- DSE priority: Advisory
- Topics: Access Control, Cybersecurity, Video Surveillance
- Reading time: 3 minutes

## What you need to know

Use 10 CFR 73.77 - Cyber security event notifications to review this narrow operational decision without extending the source beyond its stated scope.

## Potentially affected

Teams, systems, services, or facilities within the stated scope of 10 CFR 73.77 - Cyber security event notifications

## DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

## Article

Keep this document to one review outcome: Complete written NRC cyber-event follow-up after telephonic notification. Only the official source and traced locations below supply facts. Confirm applicability before acting.

## Source fact:

The official [10 CFR 73.77 – Cyber security event notifications](https://www.ecfr.gov/current/title-10/section-73.77) from U.S. Nuclear Regulatory Commission via eCFR supports the following bounded statements:

- Under 10 CFR 73, if the licensee subsequently retracts a telephonic notification made under this section as not meeting the threshold of a reportable event after it has submitted a written security follow-up report required by this paragraph, then the licensee must submit a revised written security follow-up report in accordance with this paragraph. The research record locates this support at 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)).

- Under 10 CFR 73, each licensee making an initial telephonic notification of security events to the NRC according to the provisions of paragraphs (a)(1), (a)(2)(i), and (a)(2)(ii) of this section must also submit a written security follow-up report to the NRC within 60 days of the telephonic notification in accordance with section 73.4. The research record locates this support at 10 CFR 73.77(d) (eCFR anchor p-73.77(d)).

Keep the evidence boundary at these traced claims. They support a review of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths; they do not support conclusions outside the source’s stated conditions.

## What the source does not establish

NRC regulation for covered licensees and event categories; classification, timing, protected details, parallel reporting, records, and current NRC guidance require qualified review. It does not establish a deployment’s current state, authorize a production change, prove compliance, or show that identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel are healthy. Documented options are review inputs, not universal mandates.

## Applicability questions

- For source statement 1 at 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)), which observable configuration, record, or test can confirm applicability here?

- For source statement 2 at 10 CFR 73.77(d) (eCFR anchor p-73.77(d)), which observable configuration, record, or test can confirm applicability here?

- Which owner can attest to the recorded state of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, including exceptions?

- What baseline for identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel must accompany the source-specific observation?

- Which success, stop, and escalation criteria are written before testing begins?

## DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of access control, video, intrusion detection, communications, supporting facilities, operators, and documented response paths, observed and expected states, owner, and reason for deviation.

Do not move from citation to production in one step. Pilot the decision where practical, observe agreed signals, retain a reversal point, and verify identity, Windows DNS where used, time, networks, power, life-safety systems, vendors, and monitoring personnel. Handle credentials, keys, recovery data, and personal information through approved secure channels.

## Verification and evidence

Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations 10 CFR 73.77(d)(10) (eCFR anchor p-73.77(d)(10)); 10 CFR 73.77(d) (eCFR anchor p-73.77(d)). Favor asset and firmware inventories, configuration exports, event tests, inspections, alarm response records, and maintenance findings, linked to stable identifiers, time, and operator.

Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.

## Official references

- [10 CFR 73.77 – Cyber security event notifications](https://www.ecfr.gov/current/title-10/section-73.77) — U.S. Nuclear Regulatory Commission via eCFR

## Primary reference

- Name: 10 CFR 73.77 - Cyber security event notifications
- Authority: www.ecfr.gov
- URL: https://www.ecfr.gov/current/title-10/section-73.77
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Complete written NRC cyber-event follow-up after telephonic notification,” DSE Security, https://update.dsesecurity.com/updates/complete-written-nrc-cyber-event-follow-up-after-telephonic-notification/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
