NESAG

Network Equipment Security Assurance Group

Security →
Introduced in Rel-13

NESAG is the 3GPP working group responsible for developing and maintaining the Network Equipment Security Assurance Scheme (NESAS), which defines security requirements and assessment methodologies for vendor network equipment.

Category
Security
Introduced
Rel-13
Where
Security
Specifications
1 specs
NESAG Description Purpose Related Classification Specifications

Description

The Network Equipment Security Assurance Group (NESAG) is a formal group within the 3GPP standards organization, operating under the Security Working Group SA3. Its primary function is the stewardship and evolution of the Network Equipment Security Assurance Scheme (NESAS). NESAG does not perform certifications itself but develops the technical specifications and methodologies that form the basis for independent security evaluations. The group's work ensures that security assurance activities for 3GPP network equipment are consistent, repeatable, and based on internationally recognized security standards.

NESAG's work is documented primarily in the 3GPP specification TS 33.916. This document outlines two main pillars: Security Requirements and Security Test Specifications. The group defines a comprehensive set of security requirements derived from 3GPP's own security specifications (e.g., TS 33.501) and other standards like ISO/IEC 27000-series. These requirements cover areas such as secure development lifecycle, vulnerability management, and product security testing. Furthermore, NESAG develops detailed test cases and assessment methodologies that accredited security test laboratories use to verify a vendor's development process and the final product's compliance with the stated security requirements.

The operational model involves NESAG collaborating with other bodies, notably the GSMA, which manages the scheme's governance and accreditation of auditors and test labs. NESAG's specifications provide the technical rigor. A vendor undergoes an audit of its development lifecycle by an accredited auditor and independent testing of its product by an accredited lab. The results feed into the overall NESAS assurance, providing network operators with a standardized benchmark for comparing the security posture of equipment from different suppliers. This process is crucial for building trust in the supply chain for mobile network infrastructure.

Purpose & Motivation

NESAG was established to address growing concerns about the security of the global telecommunications supply chain, particularly as networks evolved towards 5G and became more software-defined and virtualized. Prior to NESAS, security evaluations of network equipment were often ad-hoc, vendor-specific, or based on differing national regulations, making it difficult for operators to consistently assess and compare security claims. This lack of a common, industry-wide assurance framework created potential vulnerabilities and increased risk.

The group's creation was motivated by the need to establish a standardized, transparent, and globally applicable security baseline. It solves the problem of fragmented security assurance by providing a unified set of requirements and test methodologies developed through the consensus-based 3GPP process. This allows vendors to design products to a known standard and allows operators to make procurement decisions with greater confidence in the underlying security of the equipment. By decoupling the technical specifications (NESAG's role) from the scheme administration (GSMA's role), it ensures the technical requirements remain robust and independent of commercial interests, enhancing the overall security integrity of mobile networks.

Classification

Part ofNESAS
Specific typesNESAS
Related approachesGSMA

Evolution Across Releases

Rel-13 Initial

Established the NESAG group and initiated the foundational work on what would become the Network Equipment Security Assurance Scheme (NESAS). The initial focus was on scoping the problem, defining the high-level framework, and beginning the development of standardized security requirements for network equipment.

Explore further

Broader topics and technologies where NESAG plays a role.

Defining Specifications

3GPP specifications that define or reference NESAG, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 33.916 vj00 3GPP Security Assurance Methodology (SECAM) Rel-19