The GSMA Network Equipment Security Assurance Scheme (NESAS) is a voluntary, global security assurance framework jointly led by the GSMA and 3GPP. It was established to provide a universal, industry-driven security evaluation for mobile network equipment — primarily targeting 4G/LTE and 5G infrastructure — that avoids the fragmentation of country-specific security requirements. NESAS operates through two complementary components: first, an audit of the vendor’s development and product lifecycle processes (covering secure design, implementation, testing, and vulnerability handling), conducted by GSMA-appointed auditing organizations; second, a product evaluation against 3GPP-defined Security Assurance Specifications (SCAS), performed by ISO/IEC 17025 accredited security test laboratories. The GSMA manages scheme governance (accreditation, dispute resolution, publication of results), while 3GPP’s SA3 working group defines the technical security requirements and test cases in SCAS documents. The scheme is currently at NESAS v3.0 (specifications published early 2025), which introduces revised security requirements and expands coverage to include virtualized network functions. NESAS is voluntary — no government mandates it — but it is increasingly referenced by national 5G security reviews and procurement requirements (including the EU 5G Toolbox), and major operators use NESAS assessment results as a procurement criterion. Evaluated vendors and their results are publicly listed on the GSMA website.
Red Hat’s role in the NESAS ecosystem is as the platform provider underneath the network equipment vendors being evaluated. Vendors like Ericsson, Nokia, Samsung, and others run their 5G Core network functions (AMF, SMF, UPF, NSSF, etc.) on Red Hat OpenShift, and their RAN software on RHEL. When these vendors undergo NESAS SCAS evaluation for a specific network product, the security properties of the underlying platform directly affect the test results — if the OS or container runtime has vulnerabilities or misconfigurations, the network function inherits those weaknesses. Red Hat supports vendors’ NESAS compliance by providing a hardened, attestable platform: FIPS 140-3 validated cryptography satisfies SCAS requirements around secure communication; SELinux and seccomp profiles provide the workload isolation that SCAS test cases verify; the real-time kernel (for RAN DU) meets timing security requirements while maintaining hardening; and Red Hat’s secure supply chain (signed images, SLSA attestations, SBOMs) supports the vendor’s demonstration of secure development practices during the NESAS process audit. As NESAS v3.0 explicitly incorporates requirements for virtualized/containerized network functions, the security assurance of the CaaS platform becomes an increasingly integral part of the overall NESAS evaluation — making Red Hat’s security posture a direct contributor to its telco customers’ NESAS outcomes.
