NIS2 Directive → GSMA FS.21 (5G Interconnect Security)

FS.21 defines the 5G interconnect security baseline. It builds on 3GPP TS 33.501 SEPP requirements and adds operational guidance. This crosswalk maps NIS2 obligations to FS.21 controls for 5G roaming.

Scope: 5G roaming over N32 with SEPP-to-SEPP protection using PRINS (JOSE) or TLS.

CategoryNIS2 DirectiveGSMA FS.21 (5G Interconnect Security)Notes
Network securityNIS2 Art.21(2)(e)FS.21 §4 – SEPP filteringModification policies, IE-level integrity, replay protection.
CryptographyNIS2 Art.21(2)(h)FS.21 §4.2 – PRINS on N32-fJWE for confidentiality, JWS for integrity across IPX hops.
Incident handlingNIS2 Art.21(2)(b)FS.21 §7 – SEPP telemetryLog N32 handshakes; monitor cert-transparency events.
Supply chainNIS2 Art.21(2)(d)FS.21 §5 – IPX-Provider trustIPX must not decrypt PRINS-protected IEs.
Access controlNIS2 Art.21(2)(j)FS.21 §8 – SEPP adminMFA and role separation for modification-policy changes.

Gaps

  • FS.21 is technical baseline; NIS2 governance/liability duties need separate policy work.
  • 5G-to-4G interworking still exposes Diameter attack surface (see FS.19).

Key takeaways

  • PRINS is the technical answer to NIS2 encryption-in-transit for 5G roaming.
  • Modification policies (which IEs an IPX may alter) are the highest-value FS.21 control.
  • 4G-5G interworking means FS.21 alone is not sufficient — pair with FS.19.