ENISA 5G Cybersecurity Toolbox → GSMA FS.21
The EU 5G Toolbox defines strategic (SM) and technical (TM) measures member states apply to reduce 5G risk. This crosswalk maps the technical measures to GSMA FS.21 where they concern interconnect.
Scope: TM01–TM11 technical measures. SM measures (supply-chain designation) are policy, not FS.21.
| Category | ENISA 5G Cybersecurity Toolbox | GSMA FS.21 | Notes |
|---|---|---|---|
| Baseline security | 5G Toolbox TM01 | FS.21 §3 threat model | Both require documented 5G threat model. |
| Trusted access | 5G Toolbox TM02 | FS.21 §4 – SEPP mutual TLS | Certificate-based mutual auth on N32-c. |
| Multi-vendor security | 5G Toolbox TM04 | FS.21 §5 – SEPP interop | PRINS profile interop between vendors. |
| Monitoring | 5G Toolbox TM06 | FS.21 §7 – Telemetry | SEPP logs must reach the SOC. |
Gaps
- SM03/SM05 (HRV supply-chain) are political, not technical — no GSMA equivalent.
- ENISA leaves incident-notification timing to national NRAs.
Key takeaways
- FS.21 covers most Toolbox technical measures on the interconnect plane.
- Supply-chain measures remain a national-level obligation.
- PRINS interop is the practical multi-vendor security test.