Telco

Prove your network gear is trustworthy — before the regulator asks.

NESAS and 3GPP SCAS are becoming law by another name: national schemes cite them, the EU5G candidate scheme builds on them, and NIS2 puts operators on the hook for their suppliers. We make network security assurance a process, not a fire drill.

RAN & CORE SCAS TESTS NESAS AUDIT

The landscape

What applies to you

Telecom security assurance is consolidating around a small set of schemes — and hardening into national law. The short version:

You are a network equipment vendor

NESAS is the entry ticket: a GSMA-governed audit of your development and lifecycle processes, plus product evaluations against 3GPP SCAS test cases in accredited labs. Operators write it into procurement; Germany’s BSI has built a national certification on top of it. And your equipment carries digital elements — the CRA applies to it like everything else.

NESAS · SCAS

CRA

You are a mobile network operator

NIS2 replaced the old telecom security articles and raised the bar: risk management, incident reporting, supply-chain accountability — with management liability. The 5G Toolbox lives on in national high-risk-vendor rules and hardware swap deadlines. Your security evidence now has three consumers: the regulator, the board and the procurement team.

NIS2

5G TOOLBOX

You build or deploy Open RAN

Disaggregation multiplies the attack surface: open interfaces, multi-vendor stacks, cloud infrastructure under the RAN. O-RAN Alliance WG11 specifications and the Open RAN MoU security requirements define the assurance expectations, and they lean on NESAS/SCAS logic where they can. Integrating five vendors means owning the security architecture nobody else will.

O-RAN WG11

MoU REQS

You provide eSIM / eUICC products or services

The GSMA security ecosystem applies: SAS certification for production and provisioning sites, CC/EUCC evaluation for eUICC platforms — and the coming EU5G scheme is designed to absorb exactly this domain. If your eUICC roadmap and your certification roadmap are two documents, one of them is wrong.

GSMA SAS

EUCC

You run network functions on cloud infrastructure

Telco cloud pulls in the cloud assurance stack — ISO 27001, national schemes like SecNumCloud or C5 where sovereignty matters, and NIS2 flowing down to your infrastructure providers. The 5G core is now a cloud workload; its certification story has to say so.

TELCO CLOUD

NIS2 CHAIN

The clock is running

Assurance is hardening into regulation

Voluntary schemes are becoming procurement conditions, then national law, then EU certification.

Since 2024 ROLLING

NIS2 applies to telecom operators

National transpositions keep landing, replacing EECC security rules with broader duties and personal management liability.

Ongoing LIVE

NESAS embeds into national frameworks

BSI's NESAS-based national scheme leads the way; other member states reference NESAS in telecom security rules. Procurement teams follow.

11 Sep 2026 WEEKS AWAY

CRA reporting obligations begin

Network equipment vendors must report actively exploited vulnerabilities to ENISA and CSIRTs. Two reporting regimes, one PSIRT: design it that way.

In preparation

EU5G candidate scheme advances

ENISA's candidate scheme builds on NESAS/SCAS and GSMA eUICC certification. When adopted, it converts today's voluntary audits into EU cybersecurity certificates — vendors with mature NESAS postures will convert cheapest.

11 Dec 2027

CRA applies in full

Network products need cybersecurity conformity for CE marking. NESAS evidence helps; it does not substitute./p>

How we work

From audit scramble to assurance machine

1

Assurance strategy

NESAS, national schemes, EU5G trajectory, CRA — mapped to your product lines and target markets in one plan.

2

NESAS audit readiness

Development and lifecycle processes against GSMA requirements — gap-fixed and evidenced before the auditors arrive.

3

SCAS evaluation prep

Product hardening and documentation against 3GPP SCAS test cases, so lab time is confirmation, not discovery.

4

O-RAN security architecture

Zones of responsibility across disaggregated stacks — who secures what, evidenced for operators and regulators.

5

Operator-side NIS2 support

Supplier assurance frameworks that turn vendor certificates into your Article 21 evidence.

6

Continuous assurance

Release-cycle-aligned re-evaluations, CVD/CRA reporting integration, certificate maintenance as networks evolve.

One assurance base, every stakeholder served

A NESAS-structured security programme feeds SCAS evaluations, national scheme requirements, operator procurement and your future EU5G certificate. Build the machine once.

NESAS / SCAS BASE BSI NESAS (DE) EU5G scheme CRA Annex I Operator procurement NIS2 supply chain O-RAN MoU reqs

For the specialists

The detail behind the summary

If you already live in SA3 minutes and NESAS releases, start here.

NESAS beyond the checkbox

NESAS is two distinct exercises: the vendor development-and-lifecycle audit against GSMA requirements, and per-product SCAS evaluations in accredited test labs. The audit is process maturity; the evaluation is 3GPP test-case execution against a specific release. Passing once means little — the value is a pipeline where every network-product release can be evaluated without heroics.

National overlays diverge: BSI’s scheme adds certification and government oversight on top of GSMA governance, and other member states reference NESAS with their own conditions.

Our position: treat NESAS as the design spec for your secure development machine, not an audit to survive. Vendors who industrialise SCAS evidence per release will convert to EU5G certification at marginal cost; the rest will pay again.

ENISA’s candidate EU5G scheme builds deliberately on NESAS/SCAS for network equipment and GSMA eUICC/remote-provisioning certification for SIM ecosystems — the Cybersecurity Act pattern of absorbing proven industry schemes rather than inventing new ones (as EUCC did with SOG-IS). Adoption timing remains political, and the Cybersecurity Act review adds uncertainty to scheme pipelines.

Our position: don’t wait for adoption and don’t bet against it. The technical substance is already knowable — NESAS + SCAS + documented lifecycle. Anything you build on that base converts; bespoke national workarounds don’t.

WG11 specifications cover the O-RAN-specific surface — open fronthaul, near-RT RIC and xApps, A1/E2/O1 interfaces, cloud infrastructure requirements — and the Open RAN MoU operators publish escalating security certification requirements referencing NESAS and SCAS where applicable. The unsolved problem is composition: certifying components does not certify the integrated RAN, and responsibility for the seams defaults to whoever signed the integration contract.

Our position: write the security responsibility matrix before the integration contract, not after the first pentest report. We’ve seen the other order; it costs more.

NIS2 folded telecom operators into the horizontal regime: Article 21 measures, Article 23 reporting, management accountability. The 5G Toolbox persists through national high-risk-vendor decisions and swap deadlines, which change your vendor mix and therefore your assurance baseline. Supply-chain accountability means vendor certificates (NESAS, ISO, future EU5G) become your compliance inputs — if your contracts oblige vendors to maintain them.

Our position: put certificate-maintenance clauses in procurement now. An expired vendor audit discovered during your own NIS2 inspection is an avoidable way to look bad.

Talk to people who read SA3 specs for a living

Thirty minutes with a telecom assurance expert. A straight answer on your NESAS, SCAS or NIS2 position — and what it converts into next.

Contact us

Request this document

We’ll send you access by email.