Examine India's nuclear power expansion strategy through foreign collaboration. What are the security and strategic risks associated with such partnerships?

Q. Examine India's nuclear power expansion strategy through foreign collaboration. What are the security and strategic risks associated with such partnerships? (15 marks, 250-350 words)

India's Nuclear Energy Mission targets 100 GW by 2047, up from a present base of about 8,180 MW [1]. Since imported light water reactors (LWRs) supplement the indigenous PHWR-based three-stage programme, foreign collaboration is central to this leap — but it embeds security and strategic vulnerabilities alongside capacity gains.

Strategy: the foreign-collaboration leg of expansion - Russian partnership at Kudankulam is the anchor: KKNPP 1&2 (2×1000 MW) are operational, while Units 3&4 and 5&6 are under construction in cooperation with the Russian Federation [2]. - Vendor diversification is being pursued — Jaitapur (France) and Kovvada (USA) proposals remain under discussion [3]. - Technology infusion: post-NSG-waiver access to fuel and large-capacity reactors compresses build timelines that indigenous capacity alone could not deliver, complementing the ₹20,000 crore SMR mission for five indigenous reactors by 2033 [1]. - Domestic industrial linkage: balance-of-plant and EPC packages are tendered to Indian private firms, widening the vendor chain.

Security and strategic risks - Cyber and supply-chain exposure: the 2019 KKNPP malware infection of the administrative network — probed by CERT-In and DAE's CISAG [4] — and the 2026 reports of engineering drawings leaking from a contractor's server show that third-party IT, not the air-gapped reactor systems, is the weak link. - Regulatory gap in vendor oversight: compliance burdens under Section 70A and the IT (Information Security Practices for Protected Systems) Rules, 2018 rest on the operator, while contractors handle sensitive design data [5]. - Legal-commercial friction: the operator's right of recourse against suppliers under the Civil Liability for Nuclear Damage Act, 2010 [6] has deterred foreign vendors and delayed Jaitapur and Kovvada [3]. - Strategic dependence: concentration on a single supplier for reactors, fuel and spares exposes projects to sanctions and geopolitical shifts.

Foreign collaboration is thus indispensable but insufficient by itself. The way forward lies in diversified partnerships, accelerated indigenous SMRs, mandatory NCIIPC-supervised cyber audits and data-classification clauses in every EPC contract — so that energy security under the net-zero-2070 pledge is not purchased at the cost of strategic autonomy.

(~325 words)

Sources: 1. PIB — "Nuclear Mission" in Union Budget 2025-26: 100 GW by 2047, SMR programme — capacity target, present installed base, ₹20,000 crore SMR outlay 2. PIB — Parliament Question: Kudankulam Nuclear Power Project — KKNPP units operational/under construction with Russian cooperation 3. PIB — Parliament Question: Impact of Indo-US Nuclear Agreement — Jaitapur (France) and Kovvada (USA) proposals; liability-related delays 4. PIB — Cyber attack on KKNPP — 2019 malware on the administrative network; CERT-In and CISAG investigation 5. NCIIPC, Government of India — Section 70A IT Act mandate, Protected Systems, IT (Information Security Practices and Procedures for Protected Systems) Rules, 2018 6. The Civil Liability for Nuclear Damage Act, 2010 (PRS Legislative Research) — operator's right of recourse against suppliers