Glossary term · Services

CAG

Closed Access Group

Services →

CAG is a 5G feature that provides restricted and secure network access exclusively to authorized users within a specific location, such as an enterprise campus.

Introduced
Rel-16
Specifications
22 specs
Category
Services
Introduced
Rel-16
Specifications
22 specs
CAG Description Purpose Detected Changes Specifications

Description

A Closed Access Group (CAG) is a 3GPP-defined mechanism in 5G systems that facilitates controlled and restricted network access for a defined group of User Equipment (UEs) within a specific geographical area, such as an enterprise campus, factory, or hospital. It operates by associating one or more CAG Identifiers (CAG IDs) with specific cells, known as CAG cells, which are part of a Public Land Mobile Network (PLMN). Only UEs that are subscribed to and explicitly authorized for a particular CAG ID are permitted to access the corresponding CAG cells. This creates a logical, access-controlled network slice within the public 5G infrastructure, ensuring that the radio resources and network services are dedicated to the authorized group, thereby preventing unauthorized public access.

The architecture involves several key network functions. The Access and Mobility Management Function (AMF) plays a central role in enforcing CAG access control during registration and service request procedures. The Unified Data Management (UDM) stores the subscriber's CAG subscription data, including the list of Allowed CAG IDs for each UE. This subscription data is provided to the AMF via the Authentication Server Function (AUSF) during authentication. The Radio Access Network (RAN), specifically the gNB, broadcasts the supported CAG IDs for a cell in System Information Block 1 (SIB1) using the `cag-IdentityList` parameter. A UE configured for CAG access scans for these broadcasts and only attempts to select or camp on a cell if its subscribed Allowed CAG list includes one of the IDs broadcast by that cell.

The operational flow begins with the UE, which must have a USIM containing a CAG-specific Access Control List. When the UE is powered on or enters the area, it reads the CAG ID list from the cell's SIB1. The UE compares this list with its stored Allowed CAG list. If a match is found, the UE proceeds with the initial registration procedure, indicating its selected CAG ID to the network. The AMF then verifies the UE's authorization by checking the subscription data received from the UDM. If the UE is not authorized for the requested CAG, the AMF rejects the registration with an appropriate cause code, such as "CAG not allowed." For mobility, a UE is generally not permitted to handover into a CAG cell unless it is authorized for that CAG, ensuring the closed nature of the group is maintained during movement.

CAG is closely integrated with other 5G features like Network Slicing. A CAG can be associated with one or more Network Slice Instances (NSIs), allowing the closed group of users to access specific, tailored services (e.g., ultra-reliable low-latency communication for factory automation) on a dedicated logical network. This combination provides both access control and service isolation. Management and exposure of CAG capabilities are handled by the Network Exposure Function (NEF) and the Service Capability Exposure Function (SCEF) for northbound APIs, enabling enterprise applications to manage their CAG memberships and policies.

Purpose & Motivation

CAG was introduced in 3GPP Release 16 to address the growing demand from vertical industries (e.g., manufacturing, energy, healthcare) and enterprises for private, secure, and controlled 5G network access. Prior to CAG, similar concepts existed like Closed Subscriber Groups (CSG) in 4G LTE, which were primarily designed for residential femtocells. However, CSG had limitations for large-scale enterprise deployments, including less flexible subscription management and limited integration with modern 5G core network principles like network slicing and service-based architecture. CAG was created to provide a more scalable, policy-driven, and network-slice-aware access control mechanism suitable for professional and industrial use cases.

The primary problem CAG solves is enabling a public network operator to offer a "virtual private network" experience on a shared public RAN and core infrastructure. Without CAG, an enterprise would require a physically separate, dedicated network (a true private network) to ensure only its devices can connect, which is costly and inefficient. CAG allows the operator to logically partition a portion of its public network, designating certain cells for exclusive use by a customer's authorized devices. This solves the problems of unauthorized access, radio resource contention with public users, and lack of service guarantees for critical enterprise applications.

Furthermore, CAG supports the 5G vision of network-as-a-service and network slicing by providing the foundational access control layer. It allows enterprises to have guaranteed connectivity for their mission-critical IoT devices, autonomous guided vehicles, and AR/VR tools without interference from public traffic. The motivation stems from industry digitization trends (Industry 4.0) where reliable, low-latency, and secure wireless connectivity is a prerequisite. CAG, combined with network slicing, enables operators to meet stringent Service Level Agreements (SLAs) for these vertical customers on a shared infrastructure, unlocking new revenue streams and use cases beyond traditional consumer mobile broadband.

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (62 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 25 changes
  • Clarification on the CAG ID and slicing TS 23.501CR1199
  • CAG and Network Slice Selection TS 23.501CR1297
  • NPN: Corrections to handling of Allowed CAG list and CAG-only indication TS 23.501CR1338
  • NPN: Correction to CAG-only indication TS 23.501CR1339
  • NPN: Update and enforcement of new Allowed CAG list and CAG-only indication TS 23.501CR1341
  • Clarification for the related CAG identifier TS 23.501CR1371

+ 19 more changes

Rel-17 13 changes
  • Introduce a USIM file to store pre-configured CAG information list TS 31.102CR0904
  • Toolkit support of CAG Cell Selection TS 31.111CR0772
  • AT command for CAG selection TS 27.007CR0713
  • Introduction of a CAG-ID range in the CAG information list TS 31.102CR0927
  • Clarification of CAG-ID range indication in the CAG information list for HPLMN or EHPLMN TS 31.102CR0960
  • Enforcing CAG restrictions during E-UTRAN to NG-RAN connected mode mobility TS 23.501CR2998

+ 7 more changes

Rel-18 14 changes
  • Support of allowed CAG list with validity condition TS 23.501CR4119
  • Clarify the allowed CAG list with validity condition TS 23.501CR4202
  • CAG application for MBSR TS 23.501CR4772
  • Correction on validity information for CAG TS 23.501CR5264
  • Updation to AT command to include CAG only information TS 27.007CR0792
  • Providing the already available (current) information during CAG Cell Selection event TS 31.111CR0833

+ 8 more changes

Rel-19 10 changes
  • CAG information provisioning TS 23.501CR5808
  • CAG information Provisioning clarification of roaming support TS 23.501CR5856
  • 5G Femto Hosting Party acting as a CAG owner TS 23.501CR5667
  • Clarification on CAG information provisioning TS 23.501CR6080
  • CAG Information provisioning functionality TS 23.501CR6155
  • UDM functional description update for CAG information provisioning TS 23.501CR6214

+ 4 more changes

Explore further

Broader topics and technologies where CAG plays a role.

Defining Specifications

3GPP specifications that define or reference CAG, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk20 5G System Architecture Stage 2 Rel-20
TS 24.501 vk00 5G System (5GS) Non-Access Stratum (NAS) Protocol Rel-20
TS 27.007 vj60 AT Command Set for User Equipment Rel-19
TS 28.622 vk30 Generic Network Resource Model (NRM) Integration Reference Point (IRP) Information Service (IS) Rel-20
TR 28.828 vi00 Charging Aspects for Non-Public Networks Rel-18
TS 31.102 vj50 USIM Application for 3GPP Telecom Networks Rel-19
TS 31.111 vj40 3GPP TS 31111 vj40: USIM Application Toolkit Rel-19
TS 32.255 vk20 5G Data Connectivity Charging Rel-20
TS 32.422 vk20 Subscriber and equipment trace: Trace control and configuration management Rel-20
TS 33.127 vj70 Lawful Interception Architecture and Functions Rel-19
TS 33.545 vk00 Security Architecture for NR Femto Subsystem Rel-20
TS 33.745 vj10 Security Study for 5G NR Femto Rel-19
TS 33.819 vg10 5GS Security for Vertical & LAN Services Rel-16
TS 37.483 vj30 E1 Application Protocol (E1AP) Specification Rel-19
TS 38.300 vj30 NR and NG-RAN Overall Description Rel-19
TS 38.304 vj30 NR UE Idle and Inactive State Procedures Rel-19
TS 38.331 vj30 NR Radio Resource Control Protocol Specification Rel-19
TS 38.401 vj30 NG-RAN Architecture Description Rel-19
TS 38.413 vj30 NG Application Protocol (NGAP) for 5G NG Interface Rel-19
TS 38.423 vj30 Xn Application Protocol (XnAP) for NG-RAN Rel-19
TS 38.463 vj00 E1 Application Protocol (E1AP) Rel-19
TS 38.473 vj30 F1 Application Protocol (F1AP) for 5G Rel-19