NIS2 Directive → GSMA FS.21 (5G Interconnect Security)
FS.21 defines the 5G interconnect security baseline. It builds on 3GPP TS 33.501 SEPP requirements and adds operational guidance. This crosswalk maps NIS2 obligations to FS.21 controls for 5G roaming.
Scope: 5G roaming over N32 with SEPP-to-SEPP protection using PRINS (JOSE) or TLS.
| Category | NIS2 Directive | GSMA FS.21 (5G Interconnect Security) | Notes |
|---|---|---|---|
| Network security | NIS2 Art.21(2)(e) | FS.21 §4 – SEPP filtering | Modification policies, IE-level integrity, replay protection. |
| Cryptography | NIS2 Art.21(2)(h) | FS.21 §4.2 – PRINS on N32-f | JWE for confidentiality, JWS for integrity across IPX hops. |
| Incident handling | NIS2 Art.21(2)(b) | FS.21 §7 – SEPP telemetry | Log N32 handshakes; monitor cert-transparency events. |
| Supply chain | NIS2 Art.21(2)(d) | FS.21 §5 – IPX-Provider trust | IPX must not decrypt PRINS-protected IEs. |
| Access control | NIS2 Art.21(2)(j) | FS.21 §8 – SEPP admin | MFA and role separation for modification-policy changes. |
Gaps
- FS.21 is technical baseline; NIS2 governance/liability duties need separate policy work.
- 5G-to-4G interworking still exposes Diameter attack surface (see FS.19).
Key takeaways
- PRINS is the technical answer to NIS2 encryption-in-transit for 5G roaming.
- Modification policies (which IEs an IPX may alter) are the highest-value FS.21 control.
- 4G-5G interworking means FS.21 alone is not sufficient — pair with FS.19.