Skip to main content
  1. Index/

EU5G Certification Scheme

Table of Contents

The EU5G cybersecurity certification scheme is a certification framework being developed under the EU Cybersecurity Act (Regulation 2019/881), intended to provide harmonized security assurance for 5G network products and components across the European Union. ENISA established an Ad Hoc Working Group (AHWG) on EU5G in Q4 2021 following a European Commission request. As of mid-2026, the scheme has not been formally adopted and no complete public draft is available — making it the least mature of the three schemes requested under the CSA (after EUCC, adopted in January 2024, and EUCS, still stalled). Current work has focused on specific components: in June 2024, ENISA launched a public consultation on technical specifications for eUICC (embedded Universal Integrated Circuit Card) certification, which will be handled under the existing EUCC framework rather than a new standalone scheme. A broader EU NESAS scheme for 5G network products is under development, leveraging the existing GSMA NESAS/3GPP SCAS methodology. The scheme is expected to be voluntary once adopted, with assurance levels aligned to the CSA’s basic/substantial/high structure. Its practical significance will be shaped by the revised Cybersecurity Act (CSA2), proposed in January 2026, which strengthens ENISA’s mandate and may provide additional impetus for adoption.

Red Hat’s relevance to EU5G lies in its role as the platform provider underpinning 5G network infrastructure for major telecom operators and vendors. Red Hat OpenShift is the Kubernetes platform running containerized 5G Core network functions (AMF, SMF, UPF, etc.) for vendors such as Ericsson, Nokia, and Samsung, while RHEL serves as the base operating system for both the platform and the RAN Distributed Unit. If EU5G certification ultimately applies to the software platform hosting network functions — not just the network functions themselves — Red Hat’s security posture becomes directly relevant. Red Hat already supports telco-specific security requirements: real-time kernel hardening, FIPS 140-3 validated cryptography, SELinux confinement of workloads, and the Compliance Operator for automated CIS/STIG enforcement on telco clusters. Additionally, Red Hat’s existing GSMA NESAS alignment through its participation in the telco ecosystem (supporting vendors through their SCAS evaluations by providing a hardened, attestable platform) positions it well for whatever form the EU5G scheme takes. The relationship between EU5G, GSMA NESAS, and 3GPP SCAS is collaborative: EU5G is expected to build upon — not replace — the NESAS framework, meaning Red Hat’s current investments in telco security translate directly into future EU5G readiness.

Additional Information
#

Related

3GPP SCAS

3GPP Security Assurance Specifications (SCAS) are technical specifications developed by 3GPP’s SA3 working group (Security) that define security requirements and associated test cases for specific network product classes — each 3GPP-defined network function (AMF, SMF, UPF, gNB, MME, etc.) has its own SCAS document. 3GPP is the international standards body responsible for mobile telecommunications standards (comprising seven organizational partners covering Europe, US, China, Japan, Korea, India), making SCAS a globally recognized specification set rather than a national or regional scheme. Each SCAS document follows a structured approach: it identifies the assets of the network product class that require protection, performs a threat analysis describing how those assets can be exploited, defines security requirements (objectives) that mitigate the identified threats, and specifies concrete test cases to verify that a product implementation meets those requirements. SCAS specifications serve as the technical foundation for the GSMA NESAS scheme — when a vendor submits a network product for NESAS evaluation, accredited test laboratories evaluate it against the applicable SCAS test cases. Compliance is voluntary (there is no legal mandate to pass SCAS tests), but SCAS/NESAS evaluation results are increasingly used as a procurement requirement by telecom operators and are referenced by the EU 5G Security Toolbox and national security assessments. The list of adopted SCAS documents is maintained by the GSMA in FS.63 and continues to expand as 3GPP defines new network functions.

EU Cloud Services Scheme (EUCS)

The European Cybersecurity Certification Scheme for Cloud Services (EUCS) is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is not yet adopted — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, voluntary certification that would harmonize the fragmented national cloud certifications (such as France’s SecNumCloud or Germany’s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the “high” assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.

EU Cybersecurity Act (CSA)

The EU Cybersecurity Act (CSA) — Regulation (EU) 2019/881 — was adopted by the European Council in April 2019 and fully entered into force on 28 June 2021. It is a European regulation (directly applicable in all Member States without transposition) that serves two primary functions: it strengthened and made permanent the mandate of ENISA (the EU Agency for Cybersecurity), and it established a voluntary EU-wide cybersecurity certification framework for ICT products, services, and processes. The CSA is not itself a certification scheme but rather the legal foundation upon which specific schemes are built — currently EUCC (adopted January 2024), EUCS (cloud, under development), EU5G (5G networks, under development), EUDI Wallets, and EUMSS (managed security services). Each scheme defines assurance levels (basic, substantial, high), evaluation methodologies, and mutual recognition rules so that a certificate issued in one Member State is valid across the entire EU. The CSA applies to any entity — manufacturer, service provider, or operator — that voluntarily seeks EU cybersecurity certification for its offerings, though sector-specific regulations (NIS2, CRA, DORA) may make certification effectively mandatory for certain use cases. A recast of the CSA (CSA2) was proposed by the European Commission on 20 January 2026, aiming to strengthen certification mandates, reinstate sovereignty requirements in cloud certification, and reinforce ENISA’s supervisory role.