NESAS and 3GPP SCAS are becoming law by another name: national schemes cite them, the EU5G candidate scheme builds on them, and NIS2 puts operators on the hook for their suppliers. We make network security assurance a process, not a fire drill.
The landscape
Telecom security assurance is consolidating around a small set of schemes — and hardening into national law. The short version:
NESAS is the entry ticket: a GSMA-governed audit of your development and lifecycle processes, plus product evaluations against 3GPP SCAS test cases in accredited labs. Operators write it into procurement; Germany’s BSI has built a national certification on top of it. And your equipment carries digital elements — the CRA applies to it like everything else.
NESAS · SCAS
CRA
NIS2 replaced the old telecom security articles and raised the bar: risk management, incident reporting, supply-chain accountability — with management liability. The 5G Toolbox lives on in national high-risk-vendor rules and hardware swap deadlines. Your security evidence now has three consumers: the regulator, the board and the procurement team.
NIS2
5G TOOLBOX
Disaggregation multiplies the attack surface: open interfaces, multi-vendor stacks, cloud infrastructure under the RAN. O-RAN Alliance WG11 specifications and the Open RAN MoU security requirements define the assurance expectations, and they lean on NESAS/SCAS logic where they can. Integrating five vendors means owning the security architecture nobody else will.
O-RAN WG11
MoU REQS
The GSMA security ecosystem applies: SAS certification for production and provisioning sites, CC/EUCC evaluation for eUICC platforms — and the coming EU5G scheme is designed to absorb exactly this domain. If your eUICC roadmap and your certification roadmap are two documents, one of them is wrong.
GSMA SAS
EUCC
Telco cloud pulls in the cloud assurance stack — ISO 27001, national schemes like SecNumCloud or C5 where sovereignty matters, and NIS2 flowing down to your infrastructure providers. The 5G core is now a cloud workload; its certification story has to say so.
TELCO CLOUD
NIS2 CHAIN
The clock is running
Voluntary schemes are becoming procurement conditions, then national law, then EU certification.
National transpositions keep landing, replacing EECC security rules with broader duties and personal management liability.
BSI's NESAS-based national scheme leads the way; other member states reference NESAS in telecom security rules. Procurement teams follow.
Network equipment vendors must report actively exploited vulnerabilities to ENISA and CSIRTs. Two reporting regimes, one PSIRT: design it that way.
ENISA's candidate scheme builds on NESAS/SCAS and GSMA eUICC certification. When adopted, it converts today's voluntary audits into EU cybersecurity certificates — vendors with mature NESAS postures will convert cheapest.
Network products need cybersecurity conformity for CE marking. NESAS evidence helps; it does not substitute./p>
How we work
NESAS, national schemes, EU5G trajectory, CRA — mapped to your product lines and target markets in one plan.
Development and lifecycle processes against GSMA requirements — gap-fixed and evidenced before the auditors arrive.
Product hardening and documentation against 3GPP SCAS test cases, so lab time is confirmation, not discovery.
Zones of responsibility across disaggregated stacks — who secures what, evidenced for operators and regulators.
Supplier assurance frameworks that turn vendor certificates into your Article 21 evidence.
Release-cycle-aligned re-evaluations, CVD/CRA reporting integration, certificate maintenance as networks evolve.
A NESAS-structured security programme feeds SCAS evaluations, national scheme requirements, operator procurement and your future EU5G certificate. Build the machine once.
For the specialists
If you already live in SA3 minutes and NESAS releases, start here.
NESAS is two distinct exercises: the vendor development-and-lifecycle audit against GSMA requirements, and per-product SCAS evaluations in accredited test labs. The audit is process maturity; the evaluation is 3GPP test-case execution against a specific release. Passing once means little — the value is a pipeline where every network-product release can be evaluated without heroics.
National overlays diverge: BSI’s scheme adds certification and government oversight on top of GSMA governance, and other member states reference NESAS with their own conditions.
Our position: treat NESAS as the design spec for your secure development machine, not an audit to survive. Vendors who industrialise SCAS evidence per release will convert to EU5G certification at marginal cost; the rest will pay again.
ENISA’s candidate EU5G scheme builds deliberately on NESAS/SCAS for network equipment and GSMA eUICC/remote-provisioning certification for SIM ecosystems — the Cybersecurity Act pattern of absorbing proven industry schemes rather than inventing new ones (as EUCC did with SOG-IS). Adoption timing remains political, and the Cybersecurity Act review adds uncertainty to scheme pipelines.
Our position: don’t wait for adoption and don’t bet against it. The technical substance is already knowable — NESAS + SCAS + documented lifecycle. Anything you build on that base converts; bespoke national workarounds don’t.
WG11 specifications cover the O-RAN-specific surface — open fronthaul, near-RT RIC and xApps, A1/E2/O1 interfaces, cloud infrastructure requirements — and the Open RAN MoU operators publish escalating security certification requirements referencing NESAS and SCAS where applicable. The unsolved problem is composition: certifying components does not certify the integrated RAN, and responsibility for the seams defaults to whoever signed the integration contract.
Our position: write the security responsibility matrix before the integration contract, not after the first pentest report. We’ve seen the other order; it costs more.
NIS2 folded telecom operators into the horizontal regime: Article 21 measures, Article 23 reporting, management accountability. The 5G Toolbox persists through national high-risk-vendor decisions and swap deadlines, which change your vendor mix and therefore your assurance baseline. Supply-chain accountability means vendor certificates (NESAS, ISO, future EU5G) become your compliance inputs — if your contracts oblige vendors to maintain them.
Our position: put certificate-maintenance clauses in procurement now. An expired vendor audit discovered during your own NIS2 inspection is an avoidable way to look bad.
Thirty minutes with a telecom assurance expert. A straight answer on your NESAS, SCAS or NIS2 position — and what it converts into next.
We’ll send you access by email.