Space Nuclear Power Systems
Two entirely different technologies travel under the single heading of nuclear power in space, and confusing them is the most common error in the subject. A radioisotope power system produces heat from the spontaneous decay of a radioactive isotope. Nothing starts that decay, nothing regulates it, and nothing stops it. The heat appears the moment the fuel is made and continues at a rate fixed by the isotope's half-life until the fuel is gone. A fission reactor, by contrast, sustains a neutron chain reaction that engineers start, control, and shut down deliberately. Before its first startup a space reactor is nearly inert and can be handled with modest precautions; after operation it contains an intense inventory of fission products that did not exist before.
The two differ by orders of magnitude in power. A flight radioisotope generator delivers something between forty and three hundred watts of electricity. The fission reactors under development for lunar and Martian surface use are sized at tens of kilowatts, and the concepts studied for nuclear electric propulsion reach into megawatts. They also differ almost completely in engineering. A radioisotope generator has no control system, no coolant loop that must be started, and no criticality safety case in the ordinary sense; its entire safety argument rests on containing the fuel through any conceivable launch accident. A reactor needs reactivity control, a means of moving heat out of a hot core, radiation shielding, and a licensing case that treats it as a nuclear installation that happens to be flying.
What unites them is the reason engineers accept the cost and the scrutiny. Sunlight is the default spacecraft power source and an excellent one near Earth, but it weakens with the square of distance from the Sun, so an array that supplies a kilowatt in Earth orbit supplies roughly forty watts at Saturn and about one watt at Neptune. It disappears entirely on the shadowed floor of a polar lunar crater, through the fourteen-Earth-day lunar night, and in a Martian global dust storm. Nuclear sources are indifferent to all of this: they deliver the same power at midnight as at noon, at Pluto as at Mars, and they do it for decades.
This article treats the electrical power systems themselves: the fuels, the conversion of heat into electricity, the waste heat that conversion leaves behind, the flight record of space reactors, and the launch approval and international framework that constrain the whole enterprise.
Decay Heat Versus a Chain Reaction
An unstable nucleus decays on its own schedule. Temperature, pressure, and neighboring material make no practical difference, so the decay rate of a fixed quantity of a pure isotope follows a single exponential set by the half-life, and the thermal power available at any future date can be calculated years before launch. A radioisotope power system is therefore a heat source with no throttle and no off switch, and the consequence runs in both directions. It cannot fail to produce power, which is why radioisotope generators have never caused a mission to go dark. It also cannot be turned down, so the heat must be removed continuously from the day of fueling, through integration and the launch campaign, whether or not the spacecraft wants it.
A fission chain reaction is the opposite in every respect. Each fission releases neutrons that may induce further fissions, and whether the population grows, holds steady, or dies away depends on the geometry, the fuel enrichment, the presence of neutron absorbers, and the presence of reflecting material around the core. All of those are engineering variables. A space reactor is deliberately built to be subcritical during launch, so that even a catastrophic failure of the launch vehicle cannot start it, and it is brought to criticality only after it has reached its operating destination. Once running it can be held at a chosen power level, ramped, and shut down.
The safety consequences follow directly. Fresh reactor fuel is far less radiologically hazardous than an equivalent mass of radioisotope fuel: uranium-235 has a half-life measured in hundreds of millions of years, so its specific activity is very low, and a never-started reactor released by a launch failure would be a chemical and security concern rather than a major radiological one. Plutonium-238 is the reverse, intensely active by design and hazardous from the day it is separated. The two technologies therefore have almost disjoint safety literatures: for radioisotope systems the argument is about containing an already-hot source through fire, impact, and reentry; for reactors it is mostly about guaranteeing that the core cannot go critical before it is supposed to.
Plutonium-238 and Why That Isotope
Only a handful of isotopes are practical as spacecraft heat sources, and the selection criteria are unforgiving. The isotope must have a high specific thermal power, so that useful heat comes from a small mass. It must have a half-life long enough to outlast the mission but short enough to be energetic, which in practice means decades rather than centuries or years. It must decay in a way that produces little penetrating radiation, so that shielding does not dominate the mass. It must be chemically stable in a form that will not vaporize, burn, or disperse if the container is breached. And it must be producible in kilogram quantities.
Plutonium-238 satisfies all five better than any alternative. Its half-life is 87.7 years, so a generator loses less than one percent of its heat per year from decay alone and a twenty-year mission still has roughly eighty-five percent of its original thermal source. Its specific power is about 0.57 watts per gram of the pure isotope, which is high enough that a few kilograms produce kilowatts of heat. It decays almost entirely by alpha emission, and alpha particles are stopped by the fuel itself and its cladding, so the external dose rate is modest and the shielding requirement is small. Flight fuel is not the metal but plutonium dioxide, a refractory ceramic with a very high melting point that resists vaporization and does not readily form respirable aerosols when fractured. Fragments of a broken ceramic pellet tend to be large particles that fall out of the air rather than fine dust that travels.
The alternatives lose on one criterion or another. Strontium-90, used by the Soviet Union in terrestrial and marine generators, is a beta emitter whose decay chain produces energetic gamma radiation, requiring shielding that no spacecraft can afford. Polonium-210 has extraordinary specific power but a half-life of only 138 days, which suits a lunar-night survival heater and nothing longer. Americium-241, far more available than plutonium-238 because it accumulates in separated civil plutonium, has been developed by the European Space Agency as a deliberate compromise: its specific power is roughly a quarter that of plutonium-238 and it needs more shielding, but it can be obtained without a dedicated production campaign.
The General Purpose Heat Source Module
United States radioisotope generators since the 1980s have been built around a common, standardized heat source rather than a bespoke fuel arrangement for each generator. The General Purpose Heat Source module is a rectangular brick containing four plutonium dioxide fuel pellets and producing roughly 250 watts of heat when fresh. Generators are assembled by stacking modules: eight of them give about two kilowatts of heat, eighteen give about 4,400 watts. The standardization matters more than it may appear. It means the containment and safety case is qualified once, for the module, and inherited by every generator that uses it, rather than being reargued for each new design.
The module is a nested set of barriers, each addressing a different accident. Each fuel pellet is sealed in a welded capsule of iridium alloy, chosen because it is chemically compatible with plutonium dioxide at high temperature, resists oxidation, and is remarkably ductile, so that it deforms rather than cracking under impact. Each clad pellet pair sits inside a graphite impact shell that absorbs the energy of a high-velocity ground strike. The shells are separated and supported by carbon-bonded carbon fiber insulation, which is a poor conductor and keeps the iridium within its ductile temperature range during reentry heating. The whole assembly is enclosed in an aeroshell of fine weave pierced fabric, a three-dimensionally woven carbon-carbon composite developed for reentry vehicle nose tips, which ablates in a controlled way and holds the module together through atmospheric entry.
The design philosophy differs from most aerospace practice and is worth stating plainly. The generator housing is not a containment barrier; it is expected to be destroyed in a severe accident. Containment sits at the fuel-pellet level, so that the outcome of a launch vehicle explosion, a fall from altitude, and an impact on rock is a scattering of intact clad pellets rather than a release. Qualification testing reflects this: modules are subjected to solid propellant fires, fragment impacts, explosive overpressure, and high-velocity projectile strikes, and the criterion is that the cladding retains the fuel.
Thermoelectric Conversion and Its Materials
Every radioisotope generator flown to date converts heat to electricity by the Seebeck effect. A junction between two dissimilar conductors held at different temperatures develops a voltage. Wire many such junctions in series, place the hot ends against the heat source and the cold ends against a radiating surface, and the assembly becomes a solid-state heat engine with no moving parts, no working fluid, and no bearings, seals, or valves to wear out. Orientation and vibration do not matter, and there is nothing to start and nothing to lubricate.
Performance is governed by the thermoelectric figure of merit of the materials, which combines a large Seebeck coefficient, high electrical conductivity, and low thermal conductivity. Those requirements pull against each other in most solids, which is why good thermoelectric materials are rare and practical efficiencies remain low. Two material systems have carried essentially all of the flight history.
Silicon-Germanium
Silicon-germanium alloys operate at high temperature, with hot junctions above 1,000 degrees Celsius, and they retain their properties in vacuum. The General Purpose Heat Source radioisotope thermoelectric generator, or GPHS-RTG, used several hundred silicon-germanium unicouples arranged around a stack of eighteen heat source modules. It converted about 4,400 watts of decay heat into roughly 300 watts of electricity at the beginning of a mission, in a package of about 57 kilograms. This generator powered Galileo at Jupiter, Ulysses over the solar poles, Cassini at Saturn, and New Horizons past Pluto and into the Kuiper Belt. Its weakness is that the silicon-germanium legs sublime slowly at operating temperature and the design requires a vacuum inside the housing, which makes it unsuitable for a planetary surface with an atmosphere.
Lead Telluride and TAGS
Lead telluride and the related alloy known as TAGS, a compound of tellurium, antimony, germanium, and silver, operate at considerably lower hot-junction temperatures. Their figure of merit is competitive in that lower range, and crucially they tolerate operation in a gas atmosphere rather than requiring hard vacuum. That property is what made a Mars surface generator possible. The penalty is a smaller temperature difference across the couple and therefore a lower Carnot ceiling, which shows up directly as reduced efficiency.
The Multi-Mission Radioisotope Thermoelectric Generator
The Multi-Mission Radioisotope Thermoelectric Generator, universally abbreviated MMRTG, is the current United States flight unit and the first designed from the outset to work either in vacuum or in a planetary atmosphere. It stacks eight General Purpose Heat Source modules, containing about 4.8 kilograms of plutonium dioxide, which supply roughly 2,000 watts of heat. Lead telluride and TAGS couples convert that to about 110 watts of electricity at the start of a mission. The generator masses about 45 kilograms, giving a specific power near 2.8 watts per kilogram, and it carries prominent external fins because on a planetary surface it must reject heat by convection to the local atmosphere as well as by radiation.
The MMRTG has flown on the Curiosity rover, which landed on Mars in 2012, and on Perseverance, launched in July 2020, and it is the baseline power source for the Dragonfly rotorcraft intended for Titan. Its design life is at least fourteen years of operation at the specified minimum output. That number deserves attention, because it is not a reliability figure in the usual sense. It is a guarantee about the shape of the decline curve. NASA does not promise that the generator will still be working after fourteen years in the way one promises that a bearing will not have seized; it promises that the physics of decay and the measured degradation of the couples will leave a specified power at that date.
For rover missions the MMRTG changes the operating concept in a way solar power cannot match. Its output is continuous, so the rover charges a lithium-ion battery around the clock and draws on the battery for the high-current activities of driving, drilling, and communicating. Dust accumulation on a solar array, the failure mode that ended the Spirit, Opportunity, and InSight missions, has no analogue, seasonal and latitude constraints largely vanish, and the waste heat is piped through a fluid loop to keep the rover's electronics warm through the Martian night.
Efficiency, Waste Heat, and the Thermal Design Consequence
The honest efficiency figure for a flight thermoelectric generator is a few percent. The GPHS-RTG converted about 300 watts out of 4,400, near 6.8 percent. The MMRTG converts about 110 watts out of 2,000, near 5.5 percent. Earlier units were no better: the SNAP-27 generators left on the Moon by the Apollo missions produced about 73 watts from about 1,480 watts of heat, close to 4.9 percent. More than 94 percent of the energy the plutonium releases never becomes electricity.
The immediate consequence is that a radioisotope generator is, from the spacecraft's point of view, primarily a heater. A single MMRTG dumps roughly 1,900 watts of heat that must go somewhere, and Cassini, carrying three GPHS-RTGs, rejected more than thirteen kilowatts continuously. In a vehicle whose total electrical load is a few hundred watts, this dwarfs every other thermal source aboard, and it cannot be scheduled. It is present during ground processing, when the spacecraft sits in a clean room with no radiators deployed and needs auxiliary cooling carts; inside the payload fairing during ascent, where fairing air conditioning must carry it away; and in cruise, where it sets the size of the radiators.
Good designs turn some of this into an asset. Waste heat is routed deliberately to propellant tanks that must not freeze, to battery bays, and to instrument electronics, displacing electrical survival heaters that would otherwise consume a significant fraction of the scarce electrical output. The Mars Science Laboratory rover uses a pumped fluid loop that collects heat at the generator and distributes it to the rover body, reversing its function to reject heat during the warm part of the Martian day. The thermal designer's task on a radioisotope spacecraft is therefore not primarily to conserve heat, as it is on a solar-powered deep-space probe, but to manage a large, constant, and immovable surplus.
Degradation and the Falling Power Budget
Radioisotope generator output declines from two independent causes that compound. The first is fuel decay, which is exactly predictable: with an 87.7-year half-life, the thermal source falls by about 0.787 percent per year, every year, forever. The second is degradation of the thermoelectric couples themselves. At operating temperature the leg materials sublime slowly, dopants diffuse, hot-side and cold-side bonds coarsen, and the sublimated material can deposit where it creates parasitic thermal or electrical paths. Interface resistance grows. The result is that the conversion efficiency falls on top of the falling heat input.
The Voyager spacecraft provide the cleanest long-baseline evidence, because they have been reporting since 1977. By 2000, decay alone should have removed about 16.6 percent of the original output, leaving roughly 83 percent. The generators were in fact delivering about 67 percent. The gap, roughly sixteen percentage points accumulated over twenty-three years, is couple degradation. Early in a mission this second mechanism generally dominates, because sub-one-percent annual decay is small compared with the initial settling of the thermoelectric materials.
What matters operationally is that the decline is known in advance, so mission planning treats the power budget as a schedule rather than a number. Instruments and heaters are grouped into tiers, and the operations plan specifies which tier is shed at which date, years before the shedding occurs. On the Voyagers this has become an explicit end-of-mission strategy, with loads progressively switched off as the available power, falling by a few watts each year, crosses successive thresholds. The design rule generalizes: a radioisotope mission is sized not by its beginning-of-life power but by whether a defensible, degraded science plan still closes at end of life.
The electrical interface inherits the same problem. Because the source impedance and open-circuit voltage of a thermoelectric string both drift with age and with hot-side and cold-side temperature, the power conditioning electronics must hold regulation across a slowly moving operating point, and shunt regulators or maximum-power-point-tracking converters must be specified against the end-of-life condition rather than the delivery condition.
Dynamic Conversion and the Stirling Question
A free-piston Stirling engine converts heat to mechanical work at efficiencies far beyond anything a thermoelectric couple achieves, and it has no crankshaft, no rotating seals, and no lubricant. A displacer and a power piston oscillate on gas or flexure bearings inside a hermetically sealed volume of helium; the power piston carries a magnet assembly that moves through a coil, so the output emerges directly as alternating current from a linear alternator, with no mechanical contact between moving and stationary parts once the machine is running.
The Advanced Stirling Radioisotope Generator, developed for NASA in the 2000s, was designed to produce about 140 watts of electricity from only two General Purpose Heat Source modules, at a conversion efficiency near 26 percent, in a package of about 32 kilograms. That is roughly the MMRTG's electrical output from a quarter of the plutonium, which given the supply constraint described below would change how many missions the national stockpile can support.
NASA nevertheless terminated the Lockheed Martin flight development contract in late 2013, after costs rose above $260 million, roughly $110 million beyond the original estimate, and redirected funds toward plutonium-238 production and existing MMRTG units. Convertor testing continued at NASA Glenn Research Center afterward, and some units showed power fluctuations early in their runs, a reminder that a machine with moving parts has failure modes a thermoelectric couple does not possess.
This is the recurring pattern in radioisotope power. Dynamic conversion has repeatedly won the efficiency argument and repeatedly lost the programmatic one, because the missions that need radioisotope power are precisely the missions that cannot be repaired, that last for decades, and that carry a single power source with no alternative. A thermoelectric generator's degradation is gradual, monotonic, and predictable, so a partial failure still leaves a working spacecraft. A Stirling convertor that seizes, or whose piston drifts into a stroke limit, could remove a large fraction of the spacecraft's power in an instant. Designers respond with multiple convertors in opposed pairs and fault-tolerant controllers, but the argument then becomes one about the reliability of a complex system rather than about thermodynamic efficiency, and complexity has historically lost. The lesson is general: for a system that cannot be serviced and has no redundant path, predictability of degradation can be worth more than a factor of four in efficiency.
Radioisotope Heater Units
Not every nuclear source aboard a spacecraft makes electricity. A radioisotope heater unit is a small package of plutonium dioxide that produces about one watt of heat and nothing else. A one-watt unit masses roughly 40 grams complete with its cladding and aeroshell, from a fuel charge of a few grams. It is bolted near a component that must not get cold, and it works forever without a wire, a switch, or a milliwatt of electrical power.
The trade this represents is stark. Keeping a mechanism above its survival temperature with an electrical heater costs one watt of electrical power for one watt of heat, and that watt has to come from a generator producing perhaps a hundred, through a harness that adds mass and a switch that can fail. A heater unit delivers the same watt with no electrical cost, no control loop, and no failure mode.
They have been used generously. Cassini carried 82 of them and its Huygens probe carried 35, keeping the probe's electronics alive through the descent to Titan's surface at about minus 180 degrees Celsius. Mars Pathfinder and the Mars Exploration Rovers used them to keep battery and electronics enclosures warm through Martian nights. Their safety analysis is much simpler than a generator's, because the inventory in each unit is small, but the same containment philosophy applies: the fuel is clad in a platinum-rhodium alloy and enclosed in graphite shells so that it survives launch failure and reentry intact.
The Plutonium-238 Supply Constraint
Plutonium-238 does not occur in nature and is not a byproduct of ordinary power reactor operation in usable form. It is made by irradiating neptunium-237, itself recovered from spent fuel reprocessing, in a reactor and then chemically separating the product. That means every gram traces back to a deliberate, expensive production campaign in a small number of facilities.
The United States stopped bulk production when the Savannah River Site reactors closed in 1988. For the following two decades the program relied on existing inventory and on purchases from Russia, buying roughly 16.5 kilograms from the Mayak Production Association in the early 1990s. Those purchases ended, and by the late 2000s the remaining stock was a recognized constraint on the outer planets program rather than a background detail.
Production restarted at Oak Ridge National Laboratory. The High Flux Isotope Reactor produced plutonium-238 in 2013 for the first time in twenty-five years, and in December 2015 the laboratory announced a demonstration quantity of about 50 grams. Automating the pellet pressing and target fabrication steps raised throughput to something on the order of 400 grams per year by 2019, and the Department of Energy set a goal of about 1.5 kilograms per year. For context, a single MMRTG contains about 4.8 kilograms of plutonium dioxide; a full-rate production line therefore supplies a generator every few years, not several per year. New material is also blended with older inventory, because plutonium that has sat for decades has decayed and accumulated impurities.
The practical effect is that the power source is a programmatic constraint before it is a technical one. Fuel availability, not generator manufacturing capacity, sets how many radioisotope missions can fly in a decade. This is the strongest argument for dynamic conversion and for the European work on americium-241, and it is also part of the argument for fission: a reactor's uranium fuel presents no comparable bottleneck.
Fission Reactors in Flight: The Historical Record
Space reactors have flown, but rarely, and almost all of the flight experience is more than three decades old.
SNAP-10A
The United States has launched exactly one nuclear reactor into space. SNAP-10A, part of the Systems for Nuclear Auxiliary Power program, reached orbit in 1965 and was intended to deliver about 500 watts of electricity for a year using a compact uranium-zirconium-hydride core, a sodium-potassium coolant loop, and silicon-germanium thermoelectric conversion. It operated for 43 days and then shut down. The cause was not nuclear: a voltage regulator elsewhere in the host spacecraft failed and issued a spurious command that drove the reflectors to the shutdown position. The reactor itself performed as designed, and it remains in a high orbit where it will stay for centuries.
The Soviet RORSAT Reactors
The Soviet Union flew reactors routinely. Thirty-one BES-5 units, known by the name Buk, powered radar ocean reconnaissance satellites between 1967 and 1988. These were thermoelectric systems producing a few kilowatts of electricity, cooled by liquid sodium-potassium, and they operated in low orbits because a side-looking radar needs to be close to its targets. Because a low orbit decays, the operational concept required the reactor to be separated at end of mission and boosted to a higher disposal orbit where it would remain long enough for the fission products to decay.
That plan failed on Kosmos 954. The satellite did not complete its boost, and in January 1978 it reentered over northwestern Canada, scattering debris across the Northwest Territories. The joint Canadian and American recovery effort, Operation Morning Light, searched the impact area over months and located dozens of radioactive fragments. The event drove the international legal work that produced the United Nations principles described below, and it is the reason the disposal orbit requirement now appears in an instrument of international law rather than only in an engineering procedure. Some Buk satellites also released droplets of sodium-potassium coolant during separation, and these frozen droplets remain a recognized population of orbital debris.
TOPAZ
The Soviet TOPAZ reactors took a different conversion approach, using thermionic converters in which electrons boil off a hot emitter and are collected across a small gap, eliminating the intermediate thermoelectric stage. Two units flew in 1987, aboard Kosmos 1818 and Kosmos 1867, producing on the order of five kilowatts of electricity, which makes them the most powerful nuclear systems yet operated in space. After the dissolution of the Soviet Union the United States purchased TOPAZ-II hardware and tested it on the ground, but never flew a unit.
Kilopower and the KRUSTY Demonstration
Modern American work on space fission restarted with the Kilopower project, which deliberately aimed low in power and simple in architecture. The target was a reactor in the range of one to ten kilowatts of electricity, built from as few components as possible, with a core that regulates itself.
The demonstration unit, named KRUSTY for Kilopower Reactor Using Stirling Technology, was tested at the Nevada National Security Site from November 2017 through March 2018, culminating in a 28-hour full-power run on March 20, 2018. Its core was a single solid casting of uranium alloyed with about seven percent molybdenum by weight, using uranium enriched to roughly 93 percent in uranium-235; the one-kilowatt prototype core contained about 28 kilograms of uranium-235. Reactivity control was a single central rod of boron carbide withdrawn to start the reactor. Heat left the core through passive sodium heat pipes, which contain no pump and move heat by evaporation at the hot end and condensation at the cold end, operating between roughly 400 and 700 degrees Celsius with the core near 600. Free-piston Stirling convertors turned that heat into electricity, and the test reached about 5.5 kilowatts of fission power with peak temperatures near 850 degrees Celsius.
The most instructive result was not the power level but the behavior during deliberately induced upsets. A solid monolithic core has a strongly negative temperature coefficient of reactivity: as the metal heats it expands, neutron leakage rises, and reactivity falls. The KRUSTY tests demonstrated that this feedback is strong enough to make the reactor load-following without any active control action. Stopping a Stirling convertor removed a heat sink, the core temperature rose, reactivity dropped, and the fission power fell to match the reduced load, all without a command. A reactor that settles itself in response to load changes is a very different proposition from one that needs a fast control system, and it is precisely what a remote, unattended surface power plant requires.
Fission Surface Power and Current Programs
The successor activity, Fission Surface Power, targets a system delivering at least 40 kilowatts of electricity for ten years on the lunar surface, with constraints that reflect the realities of getting it there: a mass under about 6,000 kilograms, a form factor that fits a lander, an output of roughly 120 volts direct current, and a radiation limit at the base of less than five rem per year at one kilometer from the reactor. In June 2022 NASA and the Department of Energy awarded three twelve-month design contracts of about five million dollars each, to Lockheed Martin, Westinghouse, and IX, a joint venture of Intuitive Machines and X-energy. NASA Glenn Research Center manages the effort.
The motivating case is arithmetic about the lunar night. At most sites on the Moon darkness lasts roughly fourteen Earth days, and the energy storage mass needed to carry a base through that on batteries alone is prohibitive by a wide margin. Even the favored polar sites, where crater rims receive near-continuous illumination, offer sunlight that is low-elevation and easily blocked, and the permanently shadowed regions holding the water ice of interest receive none at all.
Activity accelerated after 2025. A United States executive order directed priority to placing nuclear reactors on the lunar surface, and in January 2026 the Department of Energy and NASA signed a memorandum of understanding to develop a lunar surface reactor, with agency statements describing a fission surface power system on the order of 100 kilowatts of electricity and a target of 2030. NASA has also described Space Reactor-1 Freedom, an interplanetary demonstration of nuclear electric propulsion, stating a 20-kilowatt closed Brayton cycle conversion system driving a 12-kilowatt Hall thruster, a launch target in late 2028, and a Mars-bound trajectory carrying a payload of small rotorcraft derived from the Ingenuity helicopter. These are stated plans and schedules rather than accomplished flights, and the history of space reactor programs counsels caution about both.
Reactor Subsystem Engineering
A space reactor is not a heat source but a complete power plant, and most of its mass sits in subsystems that have nothing to do with fission.
Reactivity Control
Terrestrial power reactors control reactivity mainly with absorber rods inserted into the core and with soluble poison in the coolant. Space reactors, with small cores and high neutron leakage, more often control reactivity from outside. Rotating control drums surround the core; each drum carries a neutron-reflecting material such as beryllium oxide over most of its circumference and an absorbing material such as boron carbide over the remainder. Rotating the absorber face toward the core increases leakage and absorption and reduces reactivity; rotating the reflector face inward does the opposite. This arrangement has real advantages: the drives sit outside the core in a less hostile environment, a single drum failure changes reactivity only modestly, and the launch configuration can be made deeply subcritical by pointing every absorber inward. KRUSTY used a simpler central absorber rod, appropriate to a ground demonstration, while flight surface power concepts generally use drums.
The control electronics must be radiation-tolerant enough to sit near a reactor, capable of autonomous startup and shutdown across a light-time delay of minutes to tens of minutes, and designed to fail into a safe state. The strong negative temperature feedback of a solid metallic core, demonstrated by KRUSTY, makes much of the moment-to-moment regulation inherent rather than commanded, which reduces those demands considerably.
Heat Rejection
Heat rejection usually dominates the mass budget, for a thermodynamic reason. Space has no convective or conductive sink, so every joule of rejected heat must leave by radiation, and radiated power scales with the fourth power of absolute temperature: a radiator at 800 kelvin rejects roughly sixteen times as much power per unit area as one at 400 kelvin. The reject temperature is set by the cold end of the conversion cycle, and raising it lowers cycle efficiency, so radiator sizing and conversion efficiency trade directly against one another. For a 40-kilowatt-electric surface reactor at 25 percent conversion efficiency, roughly 120 kilowatts must be radiated away, and the radiator becomes the largest single structure in the system.
Conversion efficiency therefore matters twice: it sets how much reactor power is needed, and, more importantly, how much waste heat must be thrown away. This is why dynamic conversion is more attractive for reactors than for radioisotope sources despite the reliability concerns. At megawatt scale a thermoelectric system's radiator becomes impossible.
Power Conversion
Three conversion approaches compete, and the choice tracks power level. Thermoelectric conversion has no moving parts and is the natural choice at low power, but its few percent efficiency makes the radiator prohibitive above a few kilowatts. Free-piston Stirling conversion reaches efficiencies in the twenties to low thirties and suits the one-to-tens-of-kilowatts range, at the cost of moving parts and a machine that must be built in redundant pairs to be trustworthy. Closed Brayton cycle conversion uses a turbine, compressor, and alternator on a common shaft with an inert gas working fluid, typically a helium-xenon mixture; it scales gracefully to hundreds of kilowatts and beyond, but it is genuine rotating turbomachinery running for years without maintenance, with gas bearings and a rotor that must survive launch loads.
Shielding
Shielding a reactor on all sides is out of the question on mass grounds. Instead space reactors use a shadow shield: a truncated cone of shielding material placed between the reactor and the payload, sized so that the geometric shadow it casts encloses the spacecraft or the habitat. Radiation escapes freely in every other direction, which in vacuum is harmless. Neutrons are attenuated by hydrogen-rich material, typically lithium hydride, and gamma radiation by high-atomic-number material, typically tungsten or depleted uranium, so a practical shield is layered.
The shadow shield drives system architecture more than any other single component. It rewards putting distance between the reactor and everything else, because the dose falls with the square of separation while the shield mass grows with the cone's cross-section, so a long boom buys shielding cheaply. It constrains attitude and layout, because anything that must be protected has to stay inside the shadow, and a deployable that swings outside it accumulates dose. On a surface installation regolith is free shielding, so concepts frequently place the reactor in a pit or berm hundreds of meters to a kilometer from the habitat and rely on distance and terrain for the rest.
Electronics Inside a Radiation Field of Their Own Making
A consequence that is easy to overlook is that a reactor-powered spacecraft carries electronics in a radiation environment created by its own power source. The natural space environment already imposes total ionizing dose, displacement damage, and single-event effects, and radiation-hardened parts are selected against a mission dose budget accumulated over years. A reactor adds a second, continuous, and directional source at close range.
The character of the added environment differs from the natural one in ways that matter. Reactor neutrons cause displacement damage in silicon and, more severely, in the compound semiconductors used for optoelectronics and high-frequency devices; the natural environment is dominated instead by trapped protons and heavy ions. Optocouplers, laser diodes, image sensors, and bipolar devices with lightly doped bases are especially sensitive to displacement damage, and a part qualified against a total ionizing dose specification may still fail against a neutron fluence. Gamma radiation from fission products contributes total ionizing dose steadily rather than in the episodic bursts that solar particle events produce, which changes how enhanced low dose rate sensitivity in bipolar linear devices must be evaluated. The reactor's field is also always on and always from the same direction, so shielding placement is a fixed geometric problem rather than an omnidirectional one.
Scientific payloads suffer most. A gamma-ray spectrometer or a neutron detector placed on a reactor-powered vehicle is trying to measure exactly the signal its power source produces, and the background may exceed the signal by orders of magnitude. Missions in this situation resort to boom-mounting instruments far from the source, to shielding the detector against the reactor direction specifically, and to characterizing the source spectrum precisely enough to subtract it. Even radioisotope-powered spacecraft face a modest version of the problem: neutrons from spontaneous fission and from alpha reactions with light-element impurities in the plutonium fuel create a measurable background, which is one reason flight plutonium dioxide is made with oxygen enriched in oxygen-16 to suppress alpha-neutron reactions on the heavier oxygen isotopes. The practical response is to treat the source-generated environment as a line item in the radiation budget from the start and to fix instrument accommodation early, because retrofitting shielding late in a program is expensive in mass and rarely sufficient.
Nuclear Electric Propulsion
The application that motivates megawatt-class reactor work is propulsion rather than housekeeping power. In nuclear electric propulsion, the reactor makes electricity and the electricity drives ion or Hall thrusters. The attraction is specific impulse: electric thrusters achieve a few thousand seconds against roughly 450 seconds for the best cryogenic chemical stages, which translates into a large reduction in propellant mass for a given change in velocity. The limitation is thrust, which is proportional to available electrical power, so a mission that needs to accelerate a substantial vehicle on a useful timescale needs power measured in hundreds of kilowatts or megawatts, far beyond what solar arrays can provide beyond Mars.
The engineering obstacle is the one already described: waste heat. A megawatt-electric system at 25 percent conversion efficiency must reject three megawatts, and the radiator required is enormous. Every serious study of nuclear electric propulsion becomes a study of radiators, conversion cycle temperatures, and the specific mass of the power plant in kilograms per kilowatt, because that single figure of merit determines whether the concept beats chemical propulsion at all. Project Prometheus and its Jupiter Icy Moons Orbiter, studied in the early 2000s and cancelled in 2005, foundered on exactly this cost and mass problem. It is nonetheless the reason reactor work continues at scales far above what any surface base needs.
Launch Safety Analysis and Governance
No other spacecraft subsystem is subject to a comparable approval process. In the United States, a mission carrying a space nuclear system requires a nuclear safety analysis and an authorization that reaches outside the sponsoring agency.
The Safety Analysis
The technical core is a probabilistic risk assessment covering the full accident space of the launch: pad explosions, propellant fires, vehicle breakup at altitude, fragment and blast impact on the generator, reentry from suborbital and orbital trajectories, ground and water impact, and long-term environmental transport of any released material. Each accident scenario is assigned a probability and a source term, the resulting doses to individuals and populations are estimated, and the results are documented in a Safety Analysis Report. This work is performed by the Department of Energy laboratories that build the hardware, and it draws on the fire, impact, and reentry testing described earlier. Separately, the National Environmental Policy Act requires an environmental impact statement for such missions, which places the same analysis before the public and invites comment. Both the Cassini and Mars Science Laboratory launches went through this process, and Cassini's drew organized public opposition, litigation, and sustained press attention.
The Approval Path
For decades the governing policy was Presidential Directive/National Security Council Memorandum 25, under which an Interagency Nuclear Safety Review Panel evaluated the Safety Analysis Report and the launch required approval at the level of the Office of Science and Technology Policy or the President. In August 2019, National Security Presidential Memorandum 20 replaced that with a tiered, risk-informed approach. Missions are sorted into tiers by the quantity of radioactive material at risk, the technology involved, and the estimated radiological consequences, with the lowest tier defined by an inventory below a stated multiple of the international A2 reference value. Lower-tier missions can be authorized by the head of the sponsoring agency after a radiological safety review; higher tiers require review by an Interagency Nuclear Safety Review Board, which issues a Safety Evaluation Report, and the highest reaches the President. The intent was to make routine, low-inventory missions tractable without diluting the scrutiny applied to a large reactor or a multi-generator flagship.
International Principles
The governing international instrument is the set of Principles Relevant to the Use of Nuclear Power Sources in Outer Space, adopted by the United Nations General Assembly as resolution 47/68 on 14 December 1992, after fourteen years of negotiation in the Legal Subcommittee of the Committee on the Peaceful Uses of Outer Space. The negotiation was slow precisely because the substantive principle, the guidelines and criteria for safe use, had to accommodate both American radioisotope practice and Soviet reactor practice.
The principles require that a thorough safety assessment, including probabilistic risk analysis, be performed and made public before launch. They restrict nuclear reactors to interplanetary missions, to sufficiently high orbits, or to low Earth orbits provided the reactor is boosted to a sufficiently high orbit after its operational phase. A sufficiently high orbit is defined functionally rather than by an altitude: it is one whose lifetime is long enough for fission products to decay to approximately the activity of the actinides, while keeping collision risk to other missions to a minimum, and the definition explicitly requires that fragments of a destroyed reactor also attain that decay time before reentering. They specify that reactors use only highly enriched uranium-235 as fuel. They require states to notify the Secretary-General and concerned states when a malfunction creates a risk of reentry of radioactive material, to provide the information needed for emergency response, and to render assistance. And they affirm that states bear international responsibility for national activities involving nuclear power sources in space and are liable for damage, with compensation including the costs of search, recovery, and cleanup.
The connection to Kosmos 954 is direct: the notification, assistance, and cleanup-cost provisions are the codified lessons of that event, and Canada's claim against the Soviet Union for recovery costs was settled before the principles were adopted. A complementary technical document, the Safety Framework for Nuclear Power Source Applications in Outer Space, was developed jointly by the Committee's Scientific and Technical Subcommittee and the International Atomic Energy Agency and adopted in 2009. It is guidance rather than law, and it addresses what governments and organizations should do to establish safety programs, rather than prescribing hardware requirements.
Neither instrument was written with commercial operators or routine lunar surface reactors in mind, and the unresolved questions are practical ones: how a reactor emplaced permanently on the lunar surface fits a framework built around orbital disposal, what safety-zone conventions apply around it, and how a launch state discharges its responsibility for a system built and operated by a private company.
Conclusion
The distinction stated at the outset should now be concrete. Radioisotope power is a mature, flight-proven technology that supplies watts to a few hundred watts, degrades on a curve known before launch, has never failed to deliver power on a mission, and is constrained principally by the availability of plutonium-238 and by a conversion efficiency of a few percent that turns most of its output into a thermal management problem. Fission power is a developmental technology that supplies kilowatts to megawatts, has flown perhaps three dozen times, almost all of it before 1990 and almost all of it Soviet, and is constrained by heat rejection mass, shielding geometry, and the difficulty of qualifying a controlled nuclear system for launch.
Several themes carry across both. Waste heat dominates each: for radioisotope generators because efficiency is low and the heat cannot be switched off, for reactors because radiator mass sets the scale of the entire vehicle. Predictability is valued above peak performance, which is why thermoelectric conversion has repeatedly defeated dynamic conversion despite losing every efficiency comparison. The power source shapes the electronics around it, adding a self-generated radiation environment to an already hostile natural one. And approval is a schedule item measured in years, with a national process and an international framework that both trace back to specific accidents.
The direction of the field is set by destinations rather than by technology push. Missions to the outer planets, to the permanently shadowed lunar poles, and to any sustained surface presence all encounter the same wall: sunlight is inadequate, and no chemical store can bridge the gap. That is why plutonium-238 production restarted after a twenty-five-year hiatus, why a kilowatt-class reactor was demonstrated at Nevada in 2018 after decades of paper studies, and why fission surface power has moved from concept to funded development. Whether the current schedules hold is another question, but the engineering requirement behind them is not in doubt.