Assurance stack · Cloud & Connectivity

5G / 6G — where industry assurance becomes state interest

Mobile network security runs on a stack of interlocking schemes: 3GPP writes the test cases, GSMA runs the audits, national authorities harden them into law, and ENISA is converting the whole edifice into EU certification. Knowing which layer answers which stakeholder is the skill.

At a glance

3GPP SCAS

Security assurance specs

Per-network-function test cases, written by 3GPP SA3

GSMA NESAS

Vendor audit + product evaluation

Development lifecycle audit plus SCAS testing in accredited labs

GSMA SAS

Site & process certification

eUICC production and subscription management security

O-RAN WG11

Open RAN security specs

Plus Open RAN MoU operators’ certification requirements

EU5G

Candidate CSA scheme

ENISA building on NESAS/SCAS and GSMA eUICC certification

National layer

BSI-NESAS, 5G Toolbox

NESAS hardened into national law; high-risk-vendor rules persist

What it is

A stack, not a standard

The technical floor is 3GPP: SA3 writes Security Assurance Specifications (SCAS) per network function — hardening requirements, test cases, expected evidence. GSMA’s NESAS wraps them in an assurance process: an audit of the vendor’s development and lifecycle practices, plus product evaluations executed by accredited labs against the SCAS test cases. For the SIM ecosystem, GSMA’s SAS certifies production sites and subscription-management processes, while eUICC platforms themselves carry CC/EUCC evaluations.

Open RAN adds a parallel track: O-RAN Alliance WG11 specifies security for the disaggregated architecture — open fronthaul, RIC and apps, cloud layer — and the Open RAN MoU operators publish escalating certification requirements that lean on NESAS/SCAS logic wherever the interfaces allow.

Above it all sits the political layer. The EU 5G Toolbox survives in national high-risk-vendor decisions; Germany’s BSI operates a NESAS-based national certification; and ENISA’s candidate EU5G scheme is designed to absorb NESAS/SCAS and GSMA eUICC certification into a Cybersecurity Act certificate. The pattern is the same one EUCC followed with SOG-IS: proven industry machinery, European legal wrapper. Vendors whose assurance is industrialised will convert cheaply; the rest will pay for their improvisation twice. 6G, meanwhile, is being specified with security assurance discussions running from the start — the first generation where certification is a design input rather than a retrofit.

When it's the right tool

Match the layer to the stakeholder

Equipment vendors: NESAS + SCAS is table stakes

Operator procurement writes it in; Germany certifies on top of it; EU5G will convert it. Industrialise SCAS evidence per release or renegotiate your roadmap every audit.

eSIM ecosystem: SAS + platform certificates

SAS for sites and processes, CC/EUCC for the eUICC platform — the two halves of one trust story your customers’ schemes will compose.

Open RAN players: own the seams

WG11 specs cover components; nobody certifies your integration but you. The security responsibility matrix is the deliverable that decides liability.

Operators: convert certificates into NIS2 evidence

Vendor NESAS results, SAS certificates and future EU5G certificates are your Article 21 supply-chain inputs — if contracts oblige vendors to maintain them.

Where it matters

The 5G/6G stack in your industry

The full treatment

NESAS beyond the checkbox, the road to EU5G, O-RAN composition and operator-side NIS2 — the complete telecom assurance picture.

The eUICC and baseband layer

eSIM silicon carries EUCC evaluations composed with GSMA SAS — one hardware certificate serving the whole subscription chain.

Private 5G in the plant

Campus networks put SCAS-graded equipment inside 62443 zone architectures — two assurance vocabularies, one risk model.

The next scheme conversion

NESAS-to-CSA conversion is a scheme-operations story.

Expert notes

What we tell clients before they commit

Industrialise SCAS evidence or lose the compounding

The stack rewards vendors who treat SCAS conformity as a per-release pipeline output: hardening baselines in CI, test evidence generated with the build, documentation that maps release deltas to affected test cases. Vendors who treat each NESAS round as a campaign pay full price every time — and will pay a third time when EU5G certification arrives with essentially the same technical substance under a stricter wrapper.

Our position: the EU5G conversion cost is being determined now, by how you run NESAS today. Build the pipeline; the certificate layer on top is then a formality whose timing Brussels controls, not you.

6G standardisation is proceeding with security assurance in the room from day one — SA3 continuity, European research programmes with explicit trust agendas, and regulators who have learned from the 5G Toolbox experience that retrofitting sovereignty and assurance is expensive and political. The realistic expectation: SCAS-style specifications evolving alongside the architecture, and certification hooks designed in, not bolted on.

Our position: vendors and operators engaging in 6G pre-standardisation should bring certification requirements into their contributions now — the cheapest influence over your 2030 compliance costs is exercised in 2026 working groups.

Network assurance, layer by layer

NESAS readiness, SCAS pipelines, O-RAN responsibility matrices, EU5G positioning — thirty minutes to see the stack whole.

Contact us

Request this document

We’ll send you access by email.