ENISA 5G Cybersecurity Toolbox → GSMA FS.21

The EU 5G Toolbox defines strategic (SM) and technical (TM) measures member states apply to reduce 5G risk. This crosswalk maps the technical measures to GSMA FS.21 where they concern interconnect.

Scope: TM01–TM11 technical measures. SM measures (supply-chain designation) are policy, not FS.21.

CategoryENISA 5G Cybersecurity ToolboxGSMA FS.21Notes
Baseline security5G Toolbox TM01FS.21 §3 threat modelBoth require documented 5G threat model.
Trusted access5G Toolbox TM02FS.21 §4 – SEPP mutual TLSCertificate-based mutual auth on N32-c.
Multi-vendor security5G Toolbox TM04FS.21 §5 – SEPP interopPRINS profile interop between vendors.
Monitoring5G Toolbox TM06FS.21 §7 – TelemetrySEPP logs must reach the SOC.

Gaps

  • SM03/SM05 (HRV supply-chain) are political, not technical — no GSMA equivalent.
  • ENISA leaves incident-notification timing to national NRAs.

Key takeaways

  • FS.21 covers most Toolbox technical measures on the interconnect plane.
  • Supply-chain measures remain a national-level obligation.
  • PRINS interop is the practical multi-vendor security test.