Reactivity Control. Heat Removal. Containment. Everything Else Is Commentary.
Intended audience: Advanced reactor engineers, licensing leads, QA managers, and technical founders building a design and licensing basis before it becomes an application — regardless of whether that application will be filed under Part 50, Part 52, Part 53, or the proposed Part 57.

Executive Summary
Every nuclear reactor design, no matter the coolant, fuel form, or licensing pathway, has to answer three questions to the NRC's satisfaction: can you control reactivity, can you remove heat, and can you keep the radionuclides where they belong. The NRC doesn't organize its regulations under one tidy heading called “the three safety functions.” But trace the General Design Criteria in Appendix A to Part 50, the accident analysis requirements that carry into Part 52, and the safety-function-based SSC classification methodology in Part 53's Subpart C, and the architecture is unmistakable. This piece walks through the regulatory basis for each function, the type of design and analysis reviewers expect to see, and where recent advanced reactor designs are genuinely raising the bar: diverse and redundant reactivity control, passive decay heat removal, and functional containment. The pathway you pick changes the packaging, and it changes the bill. Doing the harder analytical work to prove a design is safer is usually what makes it cheaper to build.
Why Three Functions, Not Fifty Requirements
New entrants to licensing sometimes treat the General Design Criteria, the Standard Review Plan (NUREG-0800), and the accident analysis chapters of an FSAR as fifty-plus unrelated boxes to check. They aren't. Every one of them traces back to a small number of physical outcomes the NRC and DOE need assured, in this order of consequence: don't let the chain reaction run away, don't let the fuel overheat after it stops, and don't let what's radioactive get out. Reactivity control, heat removal, containment.
This isn't a Gibboney Nuclear framing exercise. It shows up explicitly in NRC staff training material on safety function-based SSC classification, it's baked into the structure of Appendix A to Part 50, and it's formalized in Part 53's design and analysis requirements. If you're building a design and licensing basis and you can't map every safety-related structure, system, and component back to one of these three functions, that's a gap a reviewer will find before you do.
There's a scope-control reason to hold this line as tightly as the NRC does. A design summary can talk about anything: efficiency gains, siting flexibility, fuel cycle economics, whatever helps sell the technology. A licensing basis can't. Every page you put in front of NRC staff that isn't tied back to controlling reactivity, removing heat, or containing radionuclides is a page they're entitled to ask questions about, and questions cost fee-basis review hours you're paying for by the hour. The applicants who keep their licensing basis scoped to the three functions aren't being minimalist for its own sake. They're not paying NRC staff to debate features that were never going to affect the safety case in the first place. That's what actually separates a design summary from a licensing basis.
The Pathway Changes the Packaging. The Analysis Changes the Bill.
Whichever pathway you file under changes how and when you demonstrate these three functions. It also changes what the demonstration costs you to build, and that's worth separating from the licensing conversation entirely.
The traditional, deterministic route to satisfying GDC 26 and GDC 34 is redundancy: a second train of the same pump, the same valve, the same control logic, sitting in a separate room so a single failure doesn't take out both. That's a legitimate way to meet the single-failure criterion, and it's expensive, because you're paying to build, qualify, and maintain two, or three, complete copies of the same hardware.
A risk-informed, performance-based approach, the kind Part 53 and the NEI 18-04 methodology are built around, lets you make a different argument: instead of a second identical train, you credit a genuinely diverse means of accomplishing the same safety function, one that doesn't share the failure mechanisms, environment, or common-cause vulnerabilities of the first. A gravity-fed reserve shutdown system isn't vulnerable to the same failure mode as a stuck control rod. A passive, natural-circulation heat removal path doesn't share a failure mode with an actively pumped one. Defense-in-depth built on real diversity can satisfy a reviewer in ways that a second copy of the same train can't improve on, and without the capital cost of building it.
That trade only works if you do the harder analytical work up front: probabilistic risk assessment, licensing basis event selection, and a defense-in-depth adequacy evaluation that can withstand NRC scrutiny. It's a genuinely more rigorous case to build. It's also, in the graded QA and SSC classification work we do with clients, routinely the difference between a safety-related SSC list sized for a traditional large LWR and one reduced by as much as half. Arguing that your design is safer, with real analysis behind it, is very often what makes it cheaper to build.
Function One: Reactivity Control
Regulatory basis.
Appendix A to Part 50 devotes four General Design Criteria specifically to this function: GDC 25 (protection system requirements for reactivity control malfunctions), GDC 26 (reactivity control system redundancy and capability), GDC 27 (combined reactivity control systems capability), and GDC 28 (reactivity limits). Part 53's Subpart C carries the same expectation forward in technology-inclusive language, requiring applicants to demonstrate adequate control of reactivity across the licensing basis events they identify.
What the analysis looks like.
For a light water reactor, this has historically meant a control rod ejection or rod withdrawal accident analysis, demonstrating adequate shutdown margin assuming the single most reactive control rod fails to insert, the classic GDC 26 “stuck rod” criterion. For any design, the reviewer wants to see reactivity feedback coefficients (temperature, void, power) that support inherent shutdown behavior, kinetics analysis showing the core stays within fuel design limits during anticipated operational occurrences, and a demonstration that no single failure defeats your ability to reach and hold a safe shutdown condition.
Where it's advancing.
The meaningful recent progress isn't a new control rod design or material. It's how much weight inherent physics is being allowed to carry alongside it. Large light water reactors have historically satisfied the diversity behind GDC 26 and GDC 27 by building a whole second system: control rods as the primary means, and a boric acid injection system, a standby liquid control system in a BWR, emergency boration in a PWR, as an entirely separate, diverse means of getting negative reactivity into the core if the rods don't do the job. That's real diversity, but it's also tanks, pumps, and injection lines that have to be built, qualified, and maintained. High-temperature gas-cooled and pebble-bed designs are increasingly making the same diversity argument without a second engineered system at all: pair a primary control rod system with a core whose graphite moderator gives it a strongly negative temperature coefficient by design, reactivity drops as fuel temperature rises, with no signal, no active system, and no operator action involved, and the inherent feedback itself becomes the diverse means. It doesn't share the failure modes of the control rods, and unlike a boron injection system, there's no separate hardware to build and credit.
Reactivity control shows up in less obvious places, too. TerraPower's Natrium design physically decouples the energy island, where the turbine, generator, and molten salt thermal storage live, from the nuclear island. In a conventional LWR, a turbine trip is a reactivity event: losing the steam load suddenly changes pressure and temperature in a system that's directly coupled to the reactor, and the plant has to insert negative reactivity fast enough to keep up. Decoupling the two islands means a turbine trip on the energy side doesn't propagate back into the reactor's thermal-hydraulics the same way, which is a reactivity control argument as much as it is anything to do with the plant's power conversion design.
Function Two: Fission and Decay Heat Removal
Regulatory basis.
GDC 34 (residual heat removal) and GDC 38 (containment heat removal) are the anchor criteria in Appendix A to Part 50. Part 53 carries the same requirement forward as a design and analysis obligation: the applicant must demonstrate adequate heat removal capability across normal operation, anticipated operational occurrences, and design basis events, without relying on a single point of failure.
What the analysis looks like.
This is thermal-hydraulic analysis of the plant's response after shutdown, when the chain reaction has stopped but the fuel is still generating decay heat that has to go somewhere. Reviewers want a station blackout and loss-of-ultimate-heat-sink analysis, a demonstration that the design meets the single-failure criterion for whatever system is credited with heat removal, and a defined coping period during which the plant reaches and maintains safe shutdown conditions without offsite power or, increasingly, without operator action at all.
Where it's advancing.
This is where advanced reactor designs are making the most publicly visible progress, because a longer unassisted coping period is a genuinely strong safety case. GE Hitachi's BWRX-300 uses an isolation condenser system built on natural circulation and gravity-driven flow, with heat exchangers submerged in seismically qualified pools, and the company states the design can maintain safe shutdown for seven days without AC power or operator action. TerraPower's Natrium design uses its molten salt storage tanks as the heat sink for decay heat removal, giving the plant substantial passive thermal capacity that doesn't depend on pumps or offsite power. NuScale's integral design goes further on the mechanical side, eliminating reactor coolant pumps entirely in favor of natural circulation during normal operation as well as accident conditions.
This is also where the “walk-away safe” and “meltdown-proof” marketing claims you'll see from advanced reactor developers actually trace back to. Stripped of the marketing language, the underlying engineering argument is a heat removal margin argument: if passive systems can remove decay heat fast enough, indefinitely, to keep the fuel below damage thresholds with no operator action and no power, then the reactor genuinely cannot reach a temperature high enough to melt down under the accident scenarios the design basis considers. You can't melt down if the reactor can't get hot enough. That's a real, analyzable engineering claim, not just a slogan. It's also worth being precise about it: the claim holds for the accident scenarios the analysis actually covers, and “meltdown-proof” is doing a lot of marketing work that “passive heat removal keeps peak fuel temperature below the damage threshold across the design basis” does more carefully.
Function Three: Containment of Radionuclides
Regulatory basis.
This is the largest cluster of General Design Criteria: GDC 16 (containment design), and GDC 50 through 57, covering containment design basis, fracture prevention, leak rate testing, penetrations, and isolation. Dose limits that containment performance is ultimately measured against sit in Part 20 and in the site criteria of Part 100. For non-light water reactors under Part 52 or Part 53, this is where “functional containment” comes in: SECY-18-0096 established functional containment performance criteria, and Regulatory Guide 1.233 endorses NEI 18-04 as an acceptable methodology for demonstrating it.
What the analysis looks like.
For a large light water reactor, this is the world of leak rate testing under Appendix J, isolation valve qualification, and dose consequence analysis at the exclusion area boundary assuming a design basis loss of coolant accident. For a design without a traditional pressure-retaining structure, the analysis shifts to a mechanistic source term evaluation: identifying every credible barrier to radionuclide release, fuel particle coatings, coolant chemistry, confinement structures, and demonstrating through best-estimate analysis (not the older, more conservative deterministic assumptions) that the combined performance of those barriers keeps onsite and offsite doses within Part 20 and Part 100 limits.
Where it's advancing.
Functional containment is a real shift, but it's not a shift from many barriers down to one. Traditional LWR containment was never really "one steel and concrete structure doing all the work" either: the licensing basis already credits the fuel pellet matrix, the cladding, and the reactor pressure vessel and primary system boundary as barriers in their own right, with the containment building as the last one in the chain. TRISO fuel makes the same defense-in-depth argument with a different set of layers. The particle's ceramic coating, a porous buffer layer followed by pyrolytic carbon and silicon carbide layers, is itself a multi-layer barrier at the particle level. The graphite matrix that binds the particles into a pebble or compact is another. The coolant chemistry is another still: Flibe molten salt chemically retains a meaningful fraction of the fission products that do escape a particle. Kairos Power's KP-FHR design, which has already earned NRC construction permits for the Hermes and Hermes 2 test and demonstration reactors, is a clean public example of building that case: the combined performance of the particle layers, the graphite matrix, and the coolant is evaluated through a mechanistic source term methodology under the NEI 18-04 framework, reviewed against the functional containment performance criteria SECY-18-0096 established, rather than against one structure's pressure rating. The barriers are different. The number of them isn't.
A Fourth Requirement That Is An Honorable Mention: Shielding
Shielding deserves a mention here precisely because it isn't one of the three design safety functions, and it's worth being clear about why. Containment governs what happens to radionuclides during accidents and off-normal conditions. Shielding governs occupational and public radiation exposure during normal operation, and the requirements sit in 10 CFR Part 20, Standards for Protection Against Radiation, which sets dose limits for both workers and the general public. Unlike the three functions, shielding doesn't trace back to a General Design Criterion, because it was never a reactor-specific requirement to begin with. It doesn't care which licensing pathway a power reactor files under, Part 50, Part 52, Part 53, or the proposed Part 57, and it doesn't care whether you're licensing a power reactor at all. The same Part 20 dose limits apply to subcritical accelerators, fusion devices, reprocessing and enrichment facilities, essentially anything licensed to work with radioactive material. Reactivity control, heat removal, and containment are what a reactor specifically has to prove. Radiation protection is what the entire industry has to prove, reactor or not.
Biological shielding is almost always passive, concrete, steel, water, or some combination, and once it's installed and verified, the ongoing concern is aging management, not redesign. There isn't much frontier here the way there is with reactivity control, heat removal, or containment. The physics is well understood: reduced dose is a function of shielding material, time, and distance, the same ALARA triad it's always been. What has actually changed is manufacturing, not physics. New materials and additive manufacturing methods let you get a tighter, more conformal fit around complex geometries than you could machine or cast previously. That's a real improvement, but it doesn't change the verification requirement. Whatever method builds the shield, you still have to confirm there are no voids and no streaming paths before you credit it, because a shield with a gap in it isn't a shield.
The Practical Implication
Whichever pathway you're filing under, the safety function architecture doesn't change, only when and how you're required to demonstrate it.
Build your SSC classification around these three functions from day one, not after the FSAR outline is due. A structure, system, or component is safety-related because of which function it supports. If you can't answer that question for every item on your SSC list, that's not a hole in your classification basis, a hole would be a safety function with no SSC behind it. It's the opposite problem: an SSC that made the list to protect a design engineer's attachment to a feature, not because the physics required it. That's not conservatism. It's extraneous scope, and it invites NRC scrutiny into a part of the design that never needed to be there.
Let your QA program trace back to the same three functions. Grading isn't about doing less everywhere. It's about spending rigor where safety significance actually lives. The procedures and design controls behind reactivity control, heat removal, and containment carry the most rigor because failure there has consequences the rest of the plant doesn't. Everything else gets proportionate treatment, not because it doesn't matter to the goals of the plant or investment protection, but because it isn't carrying a safety function.
Don't wait for the FSAR to write the design and analysis safety requirements. Reactivity feedback, source term, and coping-time analyses are core physics and engineering work that should inform your design long before it's a licensing document. Retrofitting the safety requirements to a frozen design is where avoidable rework gets locked in.
Part 57, if it applies to your design, changes the packaging, not the burden. Eligibility-gated and front-loaded, it may offer speed and repeatability for designs that satisfy its entry criteria and business models built around fleet deployment. It does not relax what you have to demonstrate about reactivity control, heat removal, or containment of each unit.
This is the work Gibboney Nuclear does with developers moving from concept into licensable, financeable design: translating first-of-a-kind physics into a design and licensing basis architecture that a reviewer, an investor, and a constructor can all follow back to the same three functions.
Different pathway. Different paperwork. Different bill. Same three questions the reactor has to answer.
Frequently Asked Questions
Q: Do all three safety functions apply to every reactor type, including non-light water designs?
A: Yes. The functions are technology-inclusive by nature, they describe physical outcomes, not specific hardware. What changes by technology is how you demonstrate each one: a sodium-cooled fast reactor and a high-temperature gas-cooled reactor satisfy GDC 34's heat removal intent through very different engineering, but both have to satisfy it.
Q: Does the proposed Part 57 change which safety functions I need to demonstrate?
A: No. Part 57 is a licensing pathway, not a safety basis approach. If your design and business model fit its eligibility criteria, it may offer a more standardized, potentially faster route to a license. It does not reduce what has to be shown about reactivity control, heat removal, or containment.
Q: If risk-informed licensing requires more analysis, how does it end up costing less?
A: Because the analysis replaces hardware, not the other way around. A deterministic design satisfies redundancy requirements by building multiple copies of the same system. A risk-informed design can satisfy the same requirement by demonstrating that a genuinely diverse system, one immune to the same common-cause failures, provides equivalent or better protection. The upfront cost is a more rigorous PRA and defense-in-depth case. The downstream savings are in the capital-intensive hardware you no longer have to build, qualify, and maintain.
Q: What's the difference between a safety function and a safety-related SSC?
A: A safety function is the physical outcome (control reactivity, remove heat, contain radionuclides). A safety-related SSC is the specific structure, system, or component your design credits to accomplish one or more of those functions. Classification methodology, under Part 50's traditional approach or Part 53's risk-informed approach, is the process of mapping SSCs to functions and assigning performance metrics accordingly.
Q: How is functional containment different from a traditional containment building?
A: Traditional containment is a single pressure-retaining structure, engineered and tested to hold in a design basis release. Functional containment credits a set of barriers, potentially including fuel form, coolant chemistry, and confinement structures, whose combined, analytically demonstrated performance meets the same dose-based acceptance criteria. It's endorsed under Regulatory Guide 1.233 for non-light water reactors reviewed via NEI 18-04.
Q: Why isn't shielding one of the three safety functions?
A: Because it answers a different question. The three functions are about preventing and mitigating accidents. Shielding, under 10 CFR Part 20, is about managing normal-operation radiation exposure to workers and the public. It matters just as much for a license application, it's just a separate, and considerably more mature, body of analysis.
Sarah Gibboney is the Founder and CEO of Gibboney Nuclear, PLLC. She has spent 17 years continuously in the nuclear industry, primarily on the applicant and developer side of the table, with regulatory strategy, licensing, and QA work supporting advanced reactor and fuel cycle companies. Gibboney Nuclear helps developers move from concept to a licensable, financeable, and buildable design.




Comments