NIS2 Directive → GSMA FS.19 (Diameter Interconnect Security)

FS.19 is the GSMA baseline for Diameter interconnect security — the Diameter equivalent of FS.11. This crosswalk shows how NIS2 obligations for LTE roaming map to FS.19 controls, and where the two documents diverge.

Scope: Diameter S6a/S6d, S9, and Rx interfaces over IPX.

CategoryNIS2 DirectiveGSMA FS.19 (Diameter Interconnect Security)Notes
Risk analysis policyNIS2 Art.21(2)(a)FS.19 §3 – Diameter threat modelCategories 1-3 mirror FS.11; adds Diameter-specific attacks.
Incident handlingNIS2 Art.21(2)(b)FS.19 §7 – Anomaly monitoringDEA/DRA logs must be retained per national NRA rules.
Network securityNIS2 Art.21(2)(e)FS.19 §4 – DEA filteringOrigin-Host validation, ULR/AIR rate limits, unexpected AVP drop.
Supply chainNIS2 Art.21(2)(d)FS.19 §5 – Roaming agreement obligationsIncludes IPX carrier obligations under IR.88.
CryptographyNIS2 Art.21(2)(h)FS.19 §4.4 – DTLS/TLS transportDTLS on SCTP recommended; rarely deployed end-to-end.
Vulnerability handlingNIS2 Art.21(2)(f)FS.19 §6 – TestingAnnual Diameter pentest; test IDR/PUR abuse paths.

Gaps

  • FS.19 does not address 5G SBI — see FS.21 for SEPP crosswalk.
  • NIS2 requires management liability; FS.19 is technical only.

Key takeaways

  • FS.19 is the standard implementation of NIS2 network-security duties on Diameter.
  • Origin-Host validation and Cat-1 AVP filtering are the highest-impact controls.
  • IPX supply-chain vetting is a shared obligation with roaming partners.