The EU5G cybersecurity certification scheme is a certification framework being developed under the EU Cybersecurity Act (Regulation 2019/881), intended to provide harmonized security assurance for 5G network products and components across the European Union. ENISA established an Ad Hoc Working Group (AHWG) on EU5G in Q4 2021 following a European Commission request. As of mid-2026, the scheme has not been formally adopted and no complete public draft is available — making it the least mature of the three schemes requested under the CSA (after EUCC, adopted in January 2024, and EUCS, still stalled). Current work has focused on specific components: in June 2024, ENISA launched a public consultation on technical specifications for eUICC (embedded Universal Integrated Circuit Card) certification, which will be handled under the existing EUCC framework rather than a new standalone scheme. A broader EU NESAS scheme for 5G network products is under development, leveraging the existing GSMA NESAS/3GPP SCAS methodology. The scheme is expected to be voluntary once adopted, with assurance levels aligned to the CSA’s basic/substantial/high structure. Its practical significance will be shaped by the revised Cybersecurity Act (CSA2), proposed in January 2026, which strengthens ENISA’s mandate and may provide additional impetus for adoption.
Red Hat’s relevance to EU5G lies in its role as the platform provider underpinning 5G network infrastructure for major telecom operators and vendors. Red Hat OpenShift is the Kubernetes platform running containerized 5G Core network functions (AMF, SMF, UPF, etc.) for vendors such as Ericsson, Nokia, and Samsung, while RHEL serves as the base operating system for both the platform and the RAN Distributed Unit. If EU5G certification ultimately applies to the software platform hosting network functions — not just the network functions themselves — Red Hat’s security posture becomes directly relevant. Red Hat already supports telco-specific security requirements: real-time kernel hardening, FIPS 140-3 validated cryptography, SELinux confinement of workloads, and the Compliance Operator for automated CIS/STIG enforcement on telco clusters. Additionally, Red Hat’s existing GSMA NESAS alignment through its participation in the telco ecosystem (supporting vendors through their SCAS evaluations by providing a hardened, attestable platform) positions it well for whatever form the EU5G scheme takes. The relationship between EU5G, GSMA NESAS, and 3GPP SCAS is collaborative: EU5G is expected to build upon — not replace — the NESAS framework, meaning Red Hat’s current investments in telco security translate directly into future EU5G readiness.
