PCF (Policy Control Function)

Also known as: Policy Control Function

PCF is the 5G core function (3GPP TS 23.503) that provides unified policy for session management, access, QoS, charging and UE route selection. It replaces the EPC PCRF, exposes service-based Npcf APIs, integrates with NWDAF analytics for closed-loop policy, and enforces slicing and roaming policy. PCF is a high-value target because compromising it can silently downgrade QoS, disable steering or manipulate charging policy.

Categories: Core NetworkProtocols and StandardsOperations and Business

PCF in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place PCF in the wider telecom-security picture, review 3GPP, AES, Charging System, Conformance Testing, DRP and EIR — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.