The technical floor is 3GPP: SA3 writes Security Assurance Specifications (SCAS) per network function — hardening requirements, test cases, expected evidence. GSMA’s NESAS wraps them in an assurance process: an audit of the vendor’s development and lifecycle practices, plus product evaluations executed by accredited labs against the SCAS test cases. For the SIM ecosystem, GSMA’s SAS certifies production sites and subscription-management processes, while eUICC platforms themselves carry CC/EUCC evaluations.
Open RAN adds a parallel track: O-RAN Alliance WG11 specifies security for the disaggregated architecture — open fronthaul, RIC and apps, cloud layer — and the Open RAN MoU operators publish escalating certification requirements that lean on NESAS/SCAS logic wherever the interfaces allow.
Above it all sits the political layer. The EU 5G Toolbox survives in national high-risk-vendor decisions; Germany’s BSI operates a NESAS-based national certification; and ENISA’s candidate EU5G scheme is designed to absorb NESAS/SCAS and GSMA eUICC certification into a Cybersecurity Act certificate. The pattern is the same one EUCC followed with SOG-IS: proven industry machinery, European legal wrapper. Vendors whose assurance is industrialised will convert cheaply; the rest will pay for their improvisation twice. 6G, meanwhile, is being specified with security assurance discussions running from the start — the first generation where certification is a design input rather than a retrofit.