O-RAN Security Test Plan and Assurance Program Development

Author
Regulations

EU 5G cybersecurity certification (upcoming)

Open RAN changes how telecom networks are designed, integrated and operated. Open interfaces, disaggregated components, multi-vendor deployments and cloud-native environments break the assumptions that traditional telecom security testing was built on. For the assurance to keep up, security requirements can’t stay as principles — they have to become concrete evaluation criteria, test specifications and repeatable practices that a lab can actually run.

Client / Project Need

Objectives & drivers

The O-RAN ALLIANCE needed security test specifications and assurance material for O-RAN architecture elements, built on the requirements and controls defined by WG11. The goal was a structured assurance basis for evaluating O-RAN products — one solid enough to feed certification, badging and telecom security assurance schemes, rather than a set of guidelines each lab would interpret its own way.

Challenge

Key hurdles

Turning WG11’s security requirements and controls into something testable was the core of the work: concrete requirements and test cases a laboratory could apply and get the same result twice. Two constraints made that harder. First, the methodology had to stay aligned with established 3GPP SCAS practice while adapting to what makes O-RAN different — open interfaces, disaggregated components, multi-vendor integration, cloud-native deployment. Second, the output couldn’t serve just one audience. Vendors, operators, laboratories, certification bodies and regulators all had to be able to pick it up and use it, which meant the criteria had to be unambiguous enough to survive being read by five very different kinds of reader.

Approach

What we did

01

Analysed WG11 security requirements and controls, and identified which O-RAN components and interfaces the test specifications needed to cover.

02

Wrote the security test specifications themselves: concrete, testable cases mapped back to the WG11 controls they verify.

03

Adapted the 3GPP SCAS evaluation model — proven for monolithic network products — to O-RAN’s disaggregated, multi-vendor reality, where no single vendor owns the whole product under test.

04

Aligned the result with GSMA NESAS principles so the assurance material would slot into schemes the industry already recognises, rather than standing alone.

Key outcomes

Impact delivered

Lessons learned

What we took away

The hard part of O-RAN assurance isn’t writing requirements — it’s making them testable across a product no single vendor fully controls. A disaggregated, multi-vendor architecture only gets consistent evaluation if the test criteria are precise enough to apply the same way regardless of who integrated the pieces. The other takeaway is structural: adapting a mature model like 3GPP SCAS, rather than inventing an O-RAN-specific one from scratch, is what let the result connect to schemes the market already trusts. For the 5G and 6G assurance work coming next, that’s the pattern worth repeating — extend what regulators and labs already accept, instead of asking them to learn something new.

FAQ

Frequently asked questions

Which O-RAN components do the test specifications cover?

lorem

No. It adapts the SCAS evaluation model to O-RAN’s disaggregated, multi-vendor architecture, and aligns with GSMA NESAS — so existing practice carries forward rather than being replaced.

Vendors, operators, laboratories, certification bodies and regulators — the same reference, read for different purposes.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

CRA Box Unified Standard for HWSB

Read case study →

Security Analysis of 5G Network Products

Read case study →

Structuring IoT Cybersecurity for Decathlon’s eBike System

Read case study →

Contact us

Request this document

We’ll send you access by email.