Description
A Closed Access Group (CAG) is a 3GPP-defined mechanism in 5G systems that facilitates controlled and restricted network access for a defined group of User Equipment (UEs) within a specific geographical area, such as an enterprise campus, factory, or hospital. It operates by associating one or more CAG Identifiers (CAG IDs) with specific cells, known as CAG cells, which are part of a Public Land Mobile Network (PLMN). Only UEs that are subscribed to and explicitly authorized for a particular CAG ID are permitted to access the corresponding CAG cells. This creates a logical, access-controlled network slice within the public 5G infrastructure, ensuring that the radio resources and network services are dedicated to the authorized group, thereby preventing unauthorized public access.
The architecture involves several key network functions. The Access and Mobility Management Function (AMF) plays a central role in enforcing CAG access control during registration and service request procedures. The Unified Data Management (UDM) stores the subscriber's CAG subscription data, including the list of Allowed CAG IDs for each UE. This subscription data is provided to the AMF via the Authentication Server Function (AUSF) during authentication. The Radio Access Network (RAN), specifically the gNB, broadcasts the supported CAG IDs for a cell in System Information Block 1 (SIB1) using the `cag-IdentityList` parameter. A UE configured for CAG access scans for these broadcasts and only attempts to select or camp on a cell if its subscribed Allowed CAG list includes one of the IDs broadcast by that cell.
The operational flow begins with the UE, which must have a USIM containing a CAG-specific Access Control List. When the UE is powered on or enters the area, it reads the CAG ID list from the cell's SIB1. The UE compares this list with its stored Allowed CAG list. If a match is found, the UE proceeds with the initial registration procedure, indicating its selected CAG ID to the network. The AMF then verifies the UE's authorization by checking the subscription data received from the UDM. If the UE is not authorized for the requested CAG, the AMF rejects the registration with an appropriate cause code, such as "CAG not allowed." For mobility, a UE is generally not permitted to handover into a CAG cell unless it is authorized for that CAG, ensuring the closed nature of the group is maintained during movement.
CAG is closely integrated with other 5G features like Network Slicing. A CAG can be associated with one or more Network Slice Instances (NSIs), allowing the closed group of users to access specific, tailored services (e.g., ultra-reliable low-latency communication for factory automation) on a dedicated logical network. This combination provides both access control and service isolation. Management and exposure of CAG capabilities are handled by the Network Exposure Function (NEF) and the Service Capability Exposure Function (SCEF) for northbound APIs, enabling enterprise applications to manage their CAG memberships and policies.
Purpose & Motivation
CAG was introduced in 3GPP Release 16 to address the growing demand from vertical industries (e.g., manufacturing, energy, healthcare) and enterprises for private, secure, and controlled 5G network access. Prior to CAG, similar concepts existed like Closed Subscriber Groups (CSG) in 4G LTE, which were primarily designed for residential femtocells. However, CSG had limitations for large-scale enterprise deployments, including less flexible subscription management and limited integration with modern 5G core network principles like network slicing and service-based architecture. CAG was created to provide a more scalable, policy-driven, and network-slice-aware access control mechanism suitable for professional and industrial use cases.
The primary problem CAG solves is enabling a public network operator to offer a "virtual private network" experience on a shared public RAN and core infrastructure. Without CAG, an enterprise would require a physically separate, dedicated network (a true private network) to ensure only its devices can connect, which is costly and inefficient. CAG allows the operator to logically partition a portion of its public network, designating certain cells for exclusive use by a customer's authorized devices. This solves the problems of unauthorized access, radio resource contention with public users, and lack of service guarantees for critical enterprise applications.
Furthermore, CAG supports the 5G vision of network-as-a-service and network slicing by providing the foundational access control layer. It allows enterprises to have guaranteed connectivity for their mission-critical IoT devices, autonomous guided vehicles, and AR/VR tools without interference from public traffic. The motivation stems from industry digitization trends (Industry 4.0) where reliable, low-latency, and secure wireless connectivity is a prerequisite. CAG, combined with network slicing, enables operators to meet stringent Service Level Agreements (SLAs) for these vertical customers on a shared infrastructure, unlocking new revenue streams and use cases beyond traditional consumer mobile broadband.
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (62 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- Clarification on the CAG ID and slicing TS 23.501CR1199
- CAG and Network Slice Selection TS 23.501CR1297
- NPN: Corrections to handling of Allowed CAG list and CAG-only indication TS 23.501CR1338
- NPN: Correction to CAG-only indication TS 23.501CR1339
- NPN: Update and enforcement of new Allowed CAG list and CAG-only indication TS 23.501CR1341
- Clarification for the related CAG identifier TS 23.501CR1371
+ 19 more changes
- Introduce a USIM file to store pre-configured CAG information list TS 31.102CR0904
- Toolkit support of CAG Cell Selection TS 31.111CR0772
- AT command for CAG selection TS 27.007CR0713
- Introduction of a CAG-ID range in the CAG information list TS 31.102CR0927
- Clarification of CAG-ID range indication in the CAG information list for HPLMN or EHPLMN TS 31.102CR0960
- Enforcing CAG restrictions during E-UTRAN to NG-RAN connected mode mobility TS 23.501CR2998
+ 7 more changes
- Support of allowed CAG list with validity condition TS 23.501CR4119
- Clarify the allowed CAG list with validity condition TS 23.501CR4202
- CAG application for MBSR TS 23.501CR4772
- Correction on validity information for CAG TS 23.501CR5264
- Updation to AT command to include CAG only information TS 27.007CR0792
- Providing the already available (current) information during CAG Cell Selection event TS 31.111CR0833
+ 8 more changes
- CAG information provisioning TS 23.501CR5808
- CAG information Provisioning clarification of roaming support TS 23.501CR5856
- 5G Femto Hosting Party acting as a CAG owner TS 23.501CR5667
- Clarification on CAG information provisioning TS 23.501CR6080
- CAG Information provisioning functionality TS 23.501CR6155
- UDM functional description update for CAG information provisioning TS 23.501CR6214
+ 4 more changes
Explore further
Broader topics and technologies where CAG plays a role.
Defining Specifications
3GPP specifications that define or reference CAG, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.501 vk20 | 5G System Architecture Stage 2 | Rel-20 |
| TS 24.501 vk00 | 5G System (5GS) Non-Access Stratum (NAS) Protocol | Rel-20 |
| TS 27.007 vj60 | AT Command Set for User Equipment | Rel-19 |
| TS 28.622 vk30 | Generic Network Resource Model (NRM) Integration Reference Point (IRP) Information Service (IS) | Rel-20 |
| TR 28.828 vi00 | Charging Aspects for Non-Public Networks | Rel-18 |
| TS 31.102 vj50 | USIM Application for 3GPP Telecom Networks | Rel-19 |
| TS 31.111 vj40 | 3GPP TS 31111 vj40: USIM Application Toolkit | Rel-19 |
| TS 32.255 vk20 | 5G Data Connectivity Charging | Rel-20 |
| TS 32.422 vk20 | Subscriber and equipment trace: Trace control and configuration management | Rel-20 |
| TS 33.127 vj70 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.545 vk00 | Security Architecture for NR Femto Subsystem | Rel-20 |
| TS 33.745 vj10 | Security Study for 5G NR Femto | Rel-19 |
| TS 33.819 vg10 | 5GS Security for Vertical & LAN Services | Rel-16 |
| TS 37.483 vj30 | E1 Application Protocol (E1AP) Specification | Rel-19 |
| TS 38.300 vj30 | NR and NG-RAN Overall Description | Rel-19 |
| TS 38.304 vj30 | NR UE Idle and Inactive State Procedures | Rel-19 |
| TS 38.331 vj30 | NR Radio Resource Control Protocol Specification | Rel-19 |
| TS 38.401 vj30 | NG-RAN Architecture Description | Rel-19 |
| TS 38.413 vj30 | NG Application Protocol (NGAP) for 5G NG Interface | Rel-19 |
| TS 38.423 vj30 | Xn Application Protocol (XnAP) for NG-RAN | Rel-19 |
| TS 38.463 vj00 | E1 Application Protocol (E1AP) | Rel-19 |
| TS 38.473 vj30 | F1 Application Protocol (F1AP) for 5G | Rel-19 |