Description
The Service Capability Exposure Function (SCEF) is a pivotal network element defined from 3GPP Release 13 onwards, specifically architected to support Cellular Internet of Things (CIoT) and Machine-Type Communication (MTC). It resides in the core network, typically within the Service-Based Architecture (SBA) of the 5G Core, though it was initially introduced for the Evolved Packet Core (EPC). The SCEF's primary role is to act as a secure northbound API gateway, abstracting and exposing a defined set of network capabilities to external Application Servers (AS) belonging to service providers or enterprises. It provides a standardized, RESTful API (based on HTTP/JSON) defined in 3GPP TS 29.122 (Nnef).
Architecturally, the SCEF interfaces internally with numerous core network functions. Key interfaces include the T6a interface to the MME (for non-IP device triggering and monitoring), the S6t interface to the HSS (for subscribing to subscriber data changes), and interfaces to the PCRF/PGW for policy and charging control. When an external AS needs to send a downlink message to a dormant IoT device (Device Triggering), it sends an HTTP request to the SCEF's API. The SCEF authenticates and authorizes the request, then uses the T6a interface to instruct the MME to page the device and establish a connection so the data can be delivered. Similarly, for monitoring, the AS can request to be notified when a device becomes available (reachability) or moves (location reporting), and the SCEF manages these subscriptions with the HSS and MME.
How it works involves several key components: an API Exposure Layer that handles the external REST API, a Security and Policy Enforcement function that validates AS credentials and applies access control policies, a Network Function Orchestrator that translates API requests into the appropriate legacy or SBA signaling messages (e.g., Diameter or HTTP/2), and a Subscription Manager that tracks active monitoring requests from ASes. Its role is to enable efficient, network-optimized IoT services. By centralizing exposure, it allows the network to offer valuable services like Non-IP Data Delivery (NIDD) over Control Plane, which is critical for low-power, infrequent data transmissions, while maintaining strict security, privacy, and network resource control. It is the cornerstone of the 3GPP's network exposure framework for IoT.
Purpose & Motivation
The SCEF was created to address specific challenges in the massive-scale deployment of IoT devices over cellular networks. Traditional cellular architectures were designed for human-centric, always-online communication with high data rates. IoT devices, in contrast, are often battery-powered, send very small amounts of data infrequently, and can remain dormant for long periods. The existing method of exposing capabilities—often through direct, bespoke integrations with the PGW or PCRF—was insecure, inefficient, and not scalable for millions of devices. There was no standardized, secure way for a third-party weather sensor service, for example, to request a network-triggered wake-up of its device or to check its connectivity status.
The limitations of previous approaches were clear: a lack of a unified exposure point led to security vulnerabilities, complex integration projects for each new service, and an inability to leverage network optimizations like Control Plane CIoT EPS optimization. The SCEF solves these problems by providing a single, standardized, and secure point of exposure. It abstracts the complex, signaling-intensive network procedures into simple API calls. This allows IoT service providers to easily build applications that interact with their devices without needing to understand Diameter, GTP, or other core network protocols.
Historically, its creation was motivated by the 3GPP's work on CIoT optimizations in Release 13. The SCEF, along with concepts like NIDD and User Plane CIoT EPS optimization, formed a complete package to make cellular networks viable for low-cost, low-power IoT. It enables new business models and services, such as predictive maintenance, smart metering, and asset tracking, by giving service providers controlled access to powerful network intelligence and device management capabilities, thereby transforming the cellular network into an IoT-enabling platform.
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (32 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- Background Data Transfer Policy Activation via the SCEF TS 23.682CR0263
- Northbound APIs for SCEF - SCS/AS Interworking - Clause 1-3 enhancements TS 23.682CR0271
- Northbound APIs for SCEF - SCS/AS Interworking - Clause 4 enhancements TS 23.682CR0272
- Enabling the Routing of non-IP traffic between the UE and SCEF TS 23.682CR0277
- SCEF Behaviour in the NIDD Configuration and NIDD Authorisation Update Procedures TS 23.682CR0278
- SCEF Behaviour in the Mobile Terminated NIDD Procedure TS 23.682CR0279
+ 16 more changes
Explore further
Broader topics and technologies where SCEF plays a role.
Defining Specifications
3GPP specifications that define or reference SCEF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 22.830 vg10 | Business Role Models for Network Slicing | Rel-16 |
| TS 23.203 vk00 | Policy and Charging Control Architecture | Rel-20 |
| TS 23.222 vk00 | Common API Framework (CAPIF) for 3GPP Northbound APIs | Rel-20 |
| TS 23.286 vk00 | V2X Application Enabler Architecture | Rel-20 |
| TS 23.433 vk30 | SEAL Data Delivery Enabler Architecture | Rel-20 |
| TS 23.434 vk10 | Service Enabler Architecture Layer (SEAL) for Verticals | Rel-20 |
| TS 23.554 vj80 | MSGin5G Service Application Architecture | Rel-19 |
| TS 23.558 vk20 | Edge Computing Application Layer Architecture | Rel-20 |
| TS 23.682 vj30 | Architecture for MTC and SCEF Enhancements | Rel-19 |
| TS 23.700 vk10 | AI/ML Application Layer Support Phase 2 | Rel-20 |
| TS 23.722 vf10 | Common API Framework (CAPIF) for 3GPP Northbound APIs | Rel-15 |
| TR 23.745 vh00 | Study on App Layer Support for Factories of the Future in 5G | Rel-17 |
| TR 23.758 vh00 | Study on Edge Application Architecture | Rel-17 |
| TS 24.301 vk00 | 3GPP TS 24301 vk00: NAS Protocols for EPS | Rel-20 |
| TS 24.538 vj40 | MSGin5G Service Protocol Specification | Rel-19 |
| TS 24.542 vj00 | SEAL Notification Management Protocol | Rel-19 |
| TS 24.545 vj40 | SEAL Location Management Protocol Specification | Rel-19 |
| TS 24.560 vk00 | AI/ML Enabling SEAL Services Stage 3 Protocol and Data Model | Rel-20 |
| TS 26.348 vj00 | xMB Interface Specification | Rel-19 |
| TR 28.816 vh00 | Charging for 5G Cellular IoT | Rel-17 |
| TS 28.849 vj10 | CAPIF Phase2 Charging Study | Rel-19 |
| TS 29.061 vk00 | PLMN-PDN/PLMN Interworking for Packet Domain | Rel-20 |
| TS 29.122 vk00 | T8 Reference Point Protocol for SCEF and SCS/AS | Rel-20 |
| TS 29.128 vj20 | MME/SGSN Interfaces for PDN Interworking | Rel-19 |
| TS 29.153 vj00 | Ns Reference Point Protocol between SCEF and RCAF | Rel-19 |
| TS 29.154 vj00 | Nt Reference Point Protocol | Rel-19 |
| TS 29.212 vj10 | Diameter-based Gx, Gxx, Sd, St Interfaces | Rel-19 |
| TS 29.213 vj30 | PCC Procedures and Flows | Rel-19 |
| TS 29.214 vj30 | Rx Reference Point Stage 3 Specification | Rel-19 |
| TS 29.222 vk01 | CAPIF Protocol for 3GPP Northbound APIs | Rel-20 |
| TS 29.250 vj00 | Nu Reference Point Stage 3 Specification | Rel-19 |
| TS 29.251 vj00 | Gw/Gwn Reference Points Stage 3 Specification | Rel-19 |
| TS 29.272 vj50 | EPS Diameter Interfaces MME/SGSN-HSS/EIR | Rel-19 |
| TS 29.336 vk00 | Diameter-based Interfaces for MTC and Packet Data Networks | Rel-20 |
| TS 29.522 vk00 | NEF Northbound Interface Specification | Rel-20 |
| TS 29.549 vk01 | SEAL Services APIs | Rel-20 |
| TS 29.558 vj70 | Edge Applications over 3GPP Networks APIs | Rel-19 |
| TS 32.240 vk00 | Charging Architecture and Principles in 3GPP | Rel-20 |
| TS 32.253 vj00 | Charging for Control Plane Data Transfer | Rel-19 |
| TS 32.254 vk00 | 3GPP TS 32.254: Charging for Northbound APIs | Rel-20 |
| TS 32.278 vj00 | Monitoring Events Offline Charging Specification | Rel-19 |
| TS 32.299 vj00 | Diameter Charging Applications for 3GPP | Rel-19 |
| TS 33.108 vj00 | LI Handover Interface Specification | Rel-19 |
| TS 33.127 vj70 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.187 vj00 | Security for Machine-Type Communications Enhancements | Rel-19 |