CAG

Closed Access Group

Services →
Introduced in Rel-16 Also in: Core Network, User Equipment, Management, Security

CAG is a 5G feature that provides restricted and secure network access exclusively to authorized users within a specific location, such as an enterprise campus.

Category
Services
Introduced
Rel-16
Where
Radio Access Network › NG-RAN (5G)
Also touches
4 segments
Specifications
22 specs
CAG Description Purpose Detected Changes Specifications

Description

A Closed Access Group (CAG) is a 3GPP-defined mechanism in 5G systems that facilitates controlled and restricted network access for a defined group of User Equipment (UEs) within a specific geographical area, such as an enterprise campus, factory, or hospital. It operates by associating one or more CAG Identifiers (CAG IDs) with specific cells, known as CAG cells, which are part of a Public Land Mobile Network (PLMN). Only UEs that are subscribed to and explicitly authorized for a particular CAG ID are permitted to access the corresponding CAG cells. This creates a logical, access-controlled network slice within the public 5G infrastructure, ensuring that the radio resources and network services are dedicated to the authorized group, thereby preventing unauthorized public access.

The architecture involves several key network functions. The Access and Mobility Management Function (AMF) plays a central role in enforcing CAG access control during registration and service request procedures. The Unified Data Management (UDM) stores the subscriber's CAG subscription data, including the list of Allowed CAG IDs for each UE. This subscription data is provided to the AMF via the Authentication Server Function (AUSF) during authentication. The Radio Access Network (RAN), specifically the gNB, broadcasts the supported CAG IDs for a cell in System Information Block 1 (SIB1) using the `cag-IdentityList` parameter. A UE configured for CAG access scans for these broadcasts and only attempts to select or camp on a cell if its subscribed Allowed CAG list includes one of the IDs broadcast by that cell.

The operational flow begins with the UE, which must have a USIM containing a CAG-specific Access Control List. When the UE is powered on or enters the area, it reads the CAG ID list from the cell's SIB1. The UE compares this list with its stored Allowed CAG list. If a match is found, the UE proceeds with the initial registration procedure, indicating its selected CAG ID to the network. The AMF then verifies the UE's authorization by checking the subscription data received from the UDM. If the UE is not authorized for the requested CAG, the AMF rejects the registration with an appropriate cause code, such as "CAG not allowed." For mobility, a UE is generally not permitted to handover into a CAG cell unless it is authorized for that CAG, ensuring the closed nature of the group is maintained during movement.

CAG is closely integrated with other 5G features like Network Slicing. A CAG can be associated with one or more Network Slice Instances (NSIs), allowing the closed group of users to access specific, tailored services (e.g., ultra-reliable low-latency communication for factory automation) on a dedicated logical network. This combination provides both access control and service isolation. Management and exposure of CAG capabilities are handled by the Network Exposure Function (NEF) and the Service Capability Exposure Function (SCEF) for northbound APIs, enabling enterprise applications to manage their CAG memberships and policies.

Purpose & Motivation

CAG was introduced in 3GPP Release 16 to address the growing demand from vertical industries (e.g., manufacturing, energy, healthcare) and enterprises for private, secure, and controlled 5G network access. Prior to CAG, similar concepts existed like Closed Subscriber Groups (CSG) in 4G LTE, which were primarily designed for residential femtocells. However, CSG had limitations for large-scale enterprise deployments, including less flexible subscription management and limited integration with modern 5G core network principles like network slicing and service-based architecture. CAG was created to provide a more scalable, policy-driven, and network-slice-aware access control mechanism suitable for professional and industrial use cases.

The primary problem CAG solves is enabling a public network operator to offer a "virtual private network" experience on a shared public RAN and core infrastructure. Without CAG, an enterprise would require a physically separate, dedicated network (a true private network) to ensure only its devices can connect, which is costly and inefficient. CAG allows the operator to logically partition a portion of its public network, designating certain cells for exclusive use by a customer's authorized devices. This solves the problems of unauthorized access, radio resource contention with public users, and lack of service guarantees for critical enterprise applications.

Furthermore, CAG supports the 5G vision of network-as-a-service and network slicing by providing the foundational access control layer. It allows enterprises to have guaranteed connectivity for their mission-critical IoT devices, autonomous guided vehicles, and AR/VR tools without interference from public traffic. The motivation stems from industry digitization trends (Industry 4.0) where reliable, low-latency, and secure wireless connectivity is a prerequisite. CAG, combined with network slicing, enables operators to meet stringent Service Level Agreements (SLAs) for these vertical customers on a shared infrastructure, unlocking new revenue streams and use cases beyond traditional consumer mobile broadband.

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (141 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 60 changes

In Release 16, the CAG function was enhanced with new provisioning, signaling, and storage capabilities. Specifically, the release introduced the provisioning of an "Allowed CAG list" and a "CAG-only indication" to the UE, the inclusion of a CAG information list in REGISTRATION ACCEPT and REJECT messages, and support for transmitting UE CAG capability to the network. It also defined new procedures for CAG information handling during paging, RRC resume, and handover, along with clarifications on CAG's independence from network slice selection.

  • Providing CAG ID to the lower layer TS 24.501CR0997
  • Provisioning of an allowed CAG list and a CAG access only indication TS 24.501CR1056
  • 5GMM cause value for CAG TS 24.501CR1057
  • Storage for CAG information TS 24.501CR1236
  • Transmission of the UE CAG capability to the network TS 24.501CR1431
  • CAG information towards the lower layers for paging TS 24.501CR1567

+ 54 more changes

Rel-17 45 changes

In Release 17, key enhancements for the Closed Access Group (CAG) function included introducing a USIM file to store a pre-configured CAG information list and enabling the AMF to provide this list via procedures like Registration Accept and De-registration. The release also added specific UE behaviours, such as handling a CAG information list with no entry and clarifying actions for CAG-only UEs during emergency PDU sessions or when rejected via a non-CAG cell. Furthermore, it addressed scalability by providing solutions for when CAG IDs of a PLMN exceed a single message limit and introduced the definition of a non-CAG cell.

  • Usage of initial CAG information list TS 24.501CR2774
  • Introduce a USIM file to store pre-configured CAG information list TS 31.102CR0904
  • Toolkit support of CAG Cell Selection TS 31.111CR0772
  • The solution to CAG IDs of a PLMN beyond the limit of one Entry-IE part TS 24.501CR4124
  • The solution to CAG IDs of a PLMN beyond the limit of one Entry-Procedure part TS 24.501CR4125
  • The requirement of AMF to provide CAG information list for the current PLMN TS 24.501CR2452

+ 39 more changes

Rel-18 25 changes

In Release 18, the CAG function was enhanced to introduce an Allowed CAG list with time validity conditions, requiring UE support for this feature. The release also specified UE handling procedures for CAG validity state changes and enhanced CAG selection enforcement in both successful and unsuccessful cases. Furthermore, updates were made to the UE Configuration Update procedure to carry an extended CAG information list and to clarify the deregistered limited service state for CAG.

  • Support of allowed CAG list with validity condition TS 23.501CR4119
  • Enhanced CAG selection - enforcement in successful cases TS 24.501CR4977
  • Enhanced CAG selection - enforcement in unsuccessful cases TS 24.501CR4978
  • Enhanced CAG selection - providing additional information TS 24.501CR4976
  • UE handling upon CAG validity state change TS 24.501CR5301
  • Clarify the allowed CAG list with validity condition TS 23.501CR4202

+ 19 more changes

Rel-19 11 changes

In Release 19, the enhancements for the Closed Access Group (CAG) function primarily focused on provisioning and management. Key introductions included formalizing CAG information provisioning procedures, clarifying roaming support for this provisioning, and defining the role of a 5G Femto Hosting Party as a CAG owner. The release also provided updates for the UDM's functional description regarding CAG information and introduced verification checks for NR Femto cell CAG IDs.

  • CAG information provisioning TS 23.501CR5808
  • CAG information Provisioning clarification of roaming support TS 23.501CR5856
  • 5G Femto Hosting Party acting as a CAG owner TS 23.501CR5667
  • Clarification on CAG information provisioning TS 23.501CR6080
  • CAG Information provisioning functionality TS 23.501CR6155
  • UDM functional description update for CAG information provisioning TS 23.501CR6214

+ 5 more changes

Explore further

Broader topics and technologies where CAG plays a role.

Defining Specifications

3GPP specifications that define or reference CAG, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 27.007 vj40 AT Command Set for UE Rel-19
TS 28.622 vk20 Telecommunication Management; Generic NRM Information Service Rel-20
TR 28.828 vi00 Charging Aspects for Non-Public Networks Rel-18
TS 31.102 vj40 USIM Application Specification Rel-19
TS 31.111 vj30 USIM Application Toolkit (USAT) Specification Rel-19
TS 32.255 vk10 Telecom Management; Charging for 5G Data Connectivity Rel-20
TS 32.422 vk00 Telecom Management: Trace Control & Configuration Rel-20
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.545 vj20 Security for NR Femto Subsystem Rel-19
TS 33.745 vj10 Security Study for 5G NR Femto Rel-19
TS 33.819 vg10 5GS Security for Vertical & LAN Services Rel-16
TS 37.483 vj10 E1 Application Protocol (E1AP) Rel-19
TS 38.300 vj00 NG-RAN Overall Description Rel-19
TS 38.304 vj00 UE RRC_IDLE and RRC_INACTIVE Procedures Rel-19
TS 38.331 vj00 NR Radio Resource Control (RRC) Protocol Specification Rel-19
TS 38.401 vj10 NG-RAN Architecture Specification Rel-19
TS 38.413 vj10 NG Application Protocol (NGAP) Rel-19
TS 38.423 vj10 Xn Application Protocol (XnAP) specification Rel-19
TS 38.463 vj00 E1 Application Protocol (E1AP) Rel-19
TS 38.473 vj10 5G F1 Application Protocol (F1AP) Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.