SCEF

Service Capability Exposure Function

IoT →
Introduced in Rel-13 Also in: Core Network

SCEF is a core network function that securely exposes cellular IoT network services and capabilities, like device triggering, to authorized third-party servers via a controlled gateway.

Category
IoT
Introduced
Rel-13
Where
Services › Codecs
Also touches
1 segments
Specifications
45 specs
SCEF Description Purpose Detected Changes Specifications

Description

The Service Capability Exposure Function (SCEF) is a pivotal network element defined from 3GPP Release 13 onwards, specifically architected to support Cellular Internet of Things (CIoT) and Machine-Type Communication (MTC). It resides in the core network, typically within the Service-Based Architecture (SBA) of the 5G Core, though it was initially introduced for the Evolved Packet Core (EPC). The SCEF's primary role is to act as a secure northbound API gateway, abstracting and exposing a defined set of network capabilities to external Application Servers (AS) belonging to service providers or enterprises. It provides a standardized, RESTful API (based on HTTP/JSON) defined in 3GPP TS 29.122 (Nnef).

Architecturally, the SCEF interfaces internally with numerous core network functions. Key interfaces include the T6a interface to the MME (for non-IP device triggering and monitoring), the S6t interface to the HSS (for subscribing to subscriber data changes), and interfaces to the PCRF/PGW for policy and charging control. When an external AS needs to send a downlink message to a dormant IoT device (Device Triggering), it sends an HTTP request to the SCEF's API. The SCEF authenticates and authorizes the request, then uses the T6a interface to instruct the MME to page the device and establish a connection so the data can be delivered. Similarly, for monitoring, the AS can request to be notified when a device becomes available (reachability) or moves (location reporting), and the SCEF manages these subscriptions with the HSS and MME.

How it works involves several key components: an API Exposure Layer that handles the external REST API, a Security and Policy Enforcement function that validates AS credentials and applies access control policies, a Network Function Orchestrator that translates API requests into the appropriate legacy or SBA signaling messages (e.g., Diameter or HTTP/2), and a Subscription Manager that tracks active monitoring requests from ASes. Its role is to enable efficient, network-optimized IoT services. By centralizing exposure, it allows the network to offer valuable services like Non-IP Data Delivery (NIDD) over Control Plane, which is critical for low-power, infrequent data transmissions, while maintaining strict security, privacy, and network resource control. It is the cornerstone of the 3GPP's network exposure framework for IoT.

Purpose & Motivation

The SCEF was created to address specific challenges in the massive-scale deployment of IoT devices over cellular networks. Traditional cellular architectures were designed for human-centric, always-online communication with high data rates. IoT devices, in contrast, are often battery-powered, send very small amounts of data infrequently, and can remain dormant for long periods. The existing method of exposing capabilities—often through direct, bespoke integrations with the PGW or PCRF—was insecure, inefficient, and not scalable for millions of devices. There was no standardized, secure way for a third-party weather sensor service, for example, to request a network-triggered wake-up of its device or to check its connectivity status.

The limitations of previous approaches were clear: a lack of a unified exposure point led to security vulnerabilities, complex integration projects for each new service, and an inability to leverage network optimizations like Control Plane CIoT EPS optimization. The SCEF solves these problems by providing a single, standardized, and secure point of exposure. It abstracts the complex, signaling-intensive network procedures into simple API calls. This allows IoT service providers to easily build applications that interact with their devices without needing to understand Diameter, GTP, or other core network protocols.

Historically, its creation was motivated by the 3GPP's work on CIoT optimizations in Release 13. The SCEF, along with concepts like NIDD and User Plane CIoT EPS optimization, formed a complete package to make cellular networks viable for low-cost, low-power IoT. It enables new business models and services, such as predictive maintenance, smart metering, and asset tracking, by giving service providers controlled access to powerful network intelligence and device management capabilities, thereby transforming the cellular network into an IoT-enabling platform.

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (32 CRs across 4 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 22 changes

In Release 15, the SCEF saw significant enhancements to its Non-IP Data Delivery (NIDD) procedures, including detailed behaviors for configuration, authorization, and mobile originated/terminated data transfer. The release also introduced a standardized Common API framework for the northbound T8 interface, improved charging management, and expanded capabilities like Background Data Transfer Policy Activation and enhanced coverage restriction control. Furthermore, reliability improvements were made through corrections to monitoring events, rate control, and parameter handling on interfaces like SCEF-PFDF.

  • Background Data Transfer Policy Activation via the SCEF TS 23.682CR0263
  • Northbound APIs for SCEF - SCS/AS Interworking - Clause 1-3 enhancements TS 23.682CR0271
  • Northbound APIs for SCEF - SCS/AS Interworking - Clause 4 enhancements TS 23.682CR0272
  • Enabling the Routing of non-IP traffic between the UE and SCEF TS 23.682CR0277
  • SCEF Behaviour in the NIDD Configuration and NIDD Authorisation Update Procedures TS 23.682CR0278
  • SCEF Behaviour in the Mobile Terminated NIDD Procedure TS 23.682CR0279

+ 16 more changes

Rel-16 4 changes

In Release 16, specific corrections and clarifications were made to the Service Capability Exposure Function (SCEF) to improve its reliability and definition. These included corrections for IWK-SCEF interactions and SCEF aggregation, alongside defining the URI and failure responses for the SCEF northbound APIs. These updates refined the interface allowing access to specific network capabilities, such as for third-party applications.

  • IWK-SCEF correction TS 23.682CR0422
  • URI of the SCEF northbound APIs TS 29.122CR0249
  • Correct SCEF aggregation TS 29.122CR0208
  • Failure response for SCEF northbound APIs TS 29.122CR0307
Rel-17 4 changes

In Release 17, the SCEF saw enhancements including new support for Lawful Interception (LI) for its services, the introduction of an Application Identifier for the SCEF API's ChargeableParty and AS Session with QoS parameters, and functionality to support redirection for pure 4G SCEF northbound APIs. Additionally, corrections were made to the resource definitions for the SCEF Northbound APIs to ensure accuracy and consistency.

  • LI for SCEF services TS 33.127CR0128
  • Application Identifier for SCEF API ChargebleParty and AS Session with QoS TS 23.682CR0475
  • Support redirection for pure 4G SCEF northbound APIs TS 29.122CR0406
  • Resource corrections for SCEF Northbound APIs TS 29.122CR0415
Rel-19 2 changes

In Release 19, the SCEF was enhanced to support the provisioning of the "MPS for Messaging Indication" parameter via its interface. Additionally, the specifications were updated to explicitly clarify that the Subscription and Feature (S&F) event notification is sent from the SCEF to the SCS/AS.

  • MPS for Messaging Indication parameter provisioning via SCEF TS 29.122CR0880
  • Clarify the S&F event is sent from SCEF to SCS/AS TS 23.682CR0498

Explore further

Broader topics and technologies where SCEF plays a role.

Defining Specifications

3GPP specifications that define or reference SCEF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 22.830 vg10 Business Role Models for Network Slicing Rel-16
TS 23.203 vj20 Policy and charging control architecture Rel-19
TS 23.222 vj80 Common API Framework for 3GPP Northbound APIs Rel-19
TS 23.286 vj00 V2X Application Enabler Architecture Rel-19
TS 23.433 vk00 SEAL Data Delivery (SEALDD) for Verticals Rel-20
TS 23.434 vk00 Service Enabler Architecture for Verticals Rel-20
TS 23.554 vj70 MSGin5G Service Application Architecture Rel-19
TS 23.558 vk00 Architecture for Edge Applications Rel-20
TS 23.682 vj30 3GPP TS 23682: MTC Architecture Enhancements Rel-19
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 23.722 vf10 Common API Framework (CAPIF) for 3GPP Northbound APIs Rel-15
TR 23.745 vh00 Study on App Layer Support for Factories of the Future in 5G Rel-17
TR 23.758 vh00 Study on Edge Application Architecture Rel-17
TS 24.301 vj60 NAS protocol for Evolved Packet System Rel-19
TS 24.538 vj30 MSGin5G Service Protocol Specification Rel-19
TS 24.542 vj00 SEAL Notification Management Protocol Rel-19
TS 24.545 vj40 SEAL Location Management Protocol Specification Rel-19
TS 24.560 vj00 AIML Enablement (AIMLE) Services Stage 3 Protocol Rel-19
TS 26.348 vj00 xMB Interface Specification Rel-19
TR 28.816 vh00 Charging for 5G Cellular IoT Rel-17
TS 28.849 vj10 CAPIF Phase2 Charging Study Rel-19
TS 29.061 vj00 Packet Domain Interworking for PLMN Rel-19
TS 29.122 vj40 T8 Reference Point for Northbound APIs Rel-19
TS 29.128 vj10 MME/SGSN-SCEF Diameter Interfaces for PDN Interworking Rel-19
TS 29.153 vj00 Ns Reference Point Protocol between SCEF and RCAF Rel-19
TS 29.154 vj00 Nt Reference Point Protocol Rel-19
TS 29.212 vj00 Gx/Gxx/Sd/St Diameter Protocol Rel-19
TS 29.213 vj20 PCC Signalling Flows and QoS Mapping Rel-19
TS 29.214 vj20 Policy and Charging Control over Rx Rel-19
TS 29.222 vj40 Common API Framework (CAPIF) for 3GPP Northbound APIs Rel-19
TS 29.250 vj00 Nu Reference Point Stage 3 Specification Rel-19
TS 29.251 vj00 Gw/Gwn Reference Points Stage 3 Specification Rel-19
TS 29.272 vj40 Diameter Interfaces for MME/SGSN Rel-19
TS 29.336 vj10 HSS Diameter Interfaces for PDN Interworking Rel-19
TS 29.522 vj40 5G NEF Northbound APIs Stage 3 Rel-19
TS 29.549 vj40 SEAL API Specification for Vertical Applications Rel-19
TS 29.558 vj40 Enabling Edge Applications Rel-19
TS 32.240 vj40 Charging Management Architecture & Principles Rel-19
TS 32.253 vj00 Charging for Control Plane Data Transfer Rel-19
TS 32.254 vj21 Charging for Northbound APIs Rel-19
TS 32.278 vj00 Monitoring Events Offline Charging Specification Rel-19
TS 32.299 vj00 Diameter Charging Applications for 3GPP Rel-19
TS 33.108 vj00 LI Handover Interface Specification Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.187 vj00 Security for Machine-Type Communications Enhancements Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.