SCAS

3GPP Security Assurance Specification

Security →
Introduced in Rel-12

SCAS is a suite of 3GPP specifications defining security evaluation and testing methodologies to provide a common assurance framework for verifying network products meet security requirements.

Category
Security
Introduced
Rel-12
Where
Security
Specifications
6 specs
SCAS Description Purpose Related Classification Detected Changes Specifications

Description

The 3GPP Security Assurance Specification (SCAS) is a comprehensive and critical framework within the 3GPP security architecture. It is not a single document but a family of technical specifications (TS) that define the methodology for evaluating the security of specific 3GPP network products. The SCAS framework establishes a standardized set of security requirements, test purposes, and test cases tailored to individual network element types, such as the Home Subscriber Server (HSS), Mobility Management Entity (MME), Serving Gateway (SGW), Packet Data Network Gateway (PGW), and many others, including 5G elements like the AMF and SMF. Its primary goal is to provide assurance that a product implementation conforms to the security provisions outlined in the 3GPP system architecture specifications (e.g., TS 33. series).

The SCAS works by breaking down the high-level security objectives from the architecture specs into concrete, testable assertions. For each defined network product, a dedicated SCAS document (e.g., TS 33.117 for HSS, TS 33.516 for AMF) is created. This document typically contains several key sections: a security problem definition, stating the threats the product must defend against; a set of Security Functional Requirements (SFRs) derived from 3GPP security specs; and a detailed suite of test cases designed to verify each SFR. The test cases specify the test configuration, procedures, expected results, and often the test severity level. This methodology is closely aligned with international common criteria concepts, providing a structured assurance lifecycle.

Architecturally, the SCAS framework sits between the 3GPP system design specifications and the real-world product certification processes conducted by laboratories and industry groups like the GSMA's Network Equipment Security Assurance Scheme (NESAS). Vendors use SCAS documents during their development and internal security testing phases. Independent security evaluation laboratories use them as the basis for formal conformance testing. Mobile network operators reference SCAS compliance when procuring equipment, as it provides a standardized measure of security robustness. The framework covers a wide range of security aspects, including cryptographic algorithm implementation, secure protocols (e.g., NAS, Diameter, HTTP/2), access control, log auditing, resilience against denial-of-service attacks, and the security of operations and maintenance interfaces. By providing this common testing baseline, SCAS reduces ambiguity, prevents vendor lock-in due to proprietary security claims, and elevates the overall security baseline of global mobile networks.

Purpose & Motivation

The SCAS framework was created to address a critical gap in the early deployment of 3G and 4G networks: the lack of a standardized, objective means to verify the security implementation of network equipment. While 3GPP specifications meticulously defined *what* security features a system should have (e.g., mutual authentication, ciphering), they did not originally specify *how* to test if a vendor's product correctly and robustly implemented those features. This led to potential vulnerabilities due to implementation flaws, configuration errors, or incomplete feature support, which could be exploited to compromise network integrity and subscriber privacy.

The motivation for SCAS stemmed from growing operator and regulatory concerns about supply chain security and the need for mutual recognition of security evaluations across different markets. Before SCAS, operators had to conduct their own, often duplicative and inconsistent, security assessments of vendor equipment. This was costly, time-consuming, and did not guarantee a consistent security bar. SCAS solves this by providing a unified, 3GPP-defined assurance methodology. It allows vendors to design to a known set of testable requirements, enables labs to perform evaluations consistently, and gives operators confidence that certified equipment has undergone rigorous, standardized testing. Its development was historically aligned with and supports broader industry initiatives like NESAS, which uses SCAS as its technical basis. SCAS addresses the limitations of the previous ad-hoc approach by introducing predictability, repeatability, and transparency into the security evaluation of network products, which is foundational for building trust in increasingly software-defined and virtualized 5G networks.

Classification

Part ofNESAS
Specific typesCVEFOSSGNP
Related approachesHSSAMF

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (14 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, the SCAS function was newly introduced with the addition of an eNB Annex to support SCAS_eNB. This provided the foundational security assurance specification and testing framework for eNodeB network products. The specification established that SCAS testing is applied to a network product brought into use to provide its intended functionality, independent of specific operator deployments.

  • Adding eNB Annex to Support SCAS_eNB TS 33.926CR0004
Rel-17 4 changes

In Release 17, the SCAS framework was expanded with new threat and asset specifications for several network functions. This included the addition of security assurance specifications for the Network Data Analytics Function (NWDAF), the IPUPS (IP User Plane Security) capability, the IMS (IP Multimedia Subsystem), and the Service Communication Proxy (SCP). These updates provided a more comprehensive security assessment catalogue for these Release 17 features within the general SCAS testing framework.

  • Adding asset, description and threats to TR 33.926 for NWDAF SCAS TS 33.926CR0041
  • IMS SCAS: living doc for the threats TS 33.926CR0044
  • SCAS_5G_IPUPS: New threats to IPUPS to TR 33.926 TS 33.926CR0048
  • New Annex with Assets and Threats specific to SCAS SCP TS 33.926CR0049
Rel-18 6 changes

In Release 18, the SCAS function was updated to include threats and critical assets, as well as updates to the general catalogue, for features introduced in Release 17. The release also incorporated corrections to SCAS release references and provided clarifications on SCAS definitions, abbreviations, and modal text. These changes ensured the security assurance specifications remained aligned with the latest network product functionalities.

  • SCAS updates to threats and assets for Release 17 features TS 33.926CR0074
  • SCAS release reference corrections TS 33.117CR0115
  • SCAS updates to the general catalogue for Release 17 features TS 33.117CR0120
  • SCAS release reference corrections TS 33.515CR0010
  • Clarification on SCAS TS 33.916CR0012
  • SCAS release reference corrections TS 33.926CR0071
Rel-19 3 changes

In Release 19, the SCAS framework was expanded to include the SMSF (Session Management Function) as a new 3GPP network product class. This addition introduced a dedicated annex specifying the unique threats and critical assets associated with the SMSF product for security assurance testing. Consequently, the SCAS threats catalogue now contains a new clause providing the specific testing prerequisites and security requirements for SMSF implementations.

  • Add annexure to Security Assurance Specification (SCAS) threats and critical assets in 3GPP network product classes specific to SMSF TS 33.926CR0085
  • Security Assurance Specification (SCAS) threats specific to SMSF TS 33.926CR0099
  • Add a new clause in annexure to Security Assurance Specification (SCAS) threats and critical assets in 3GPP network product classes specific to SMSF TS 33.926CR0105

Explore further

Broader topics and technologies where SCAS plays a role.

Defining Specifications

3GPP specifications that define or reference SCAS, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.117 vk00 Catalogue of General Security Assurance Requirements Rel-20
TS 33.515 vk00 5G SMF Security Assurance Specification Rel-20
TS 33.805 vc00 3GPP Network Product Security Assurance Methodology Rel-12
TR 33.916 vj00 3GPP Security Assurance Methodology (SECAM) Rel-19
TR 33.926 vk00 Security Assurance Specification (SCAS) Rel-20
TR 33.927 vj00 Security Assurance for Virtualized Network Products Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.