Why NESAS matters: independent security assurance for a mobile industry under growing pressure - GSMA Services

Why NESAS matters: independent security assurance for a mobile industry under growing pressure

Featured partner blog by: Chris Proctor, Telecoms Practice Associate Director, NCC Group, James Moran, Head of Security, GSMA and Joanne Heaphy, Product Director, GSMA Industry Services

Mobile networks are increasingly classified as critical national infrastructure in many jurisdictions. Governments plan around them, hospitals depend on them, financial systems run over them. As societal dependency has grown, so has the pressure on everyone in the supply chain to prove the networks are secure and resilient, not just claim they are.

That pressure sits differently depending on where you stand in the ecosystem. Operators need confidence in the equipment they buy. Regulators want operators to have increased visibility of how that equipment was designed, built and maintained. Vendors need a way to demonstrate all of this – consistently, and without re-proving it to every customer and every market separately.

This is one of the challenges the GSMA Network Equipment Security Assurance Scheme (NESAS) was designedto help address. To understand why it matters now more than ever, we spoke with NCC Group, a global cyber security consultancy and one of the accredited auditors and test laboratories operating within the NESAS ecosystem.

Security assurance has become a business necessity, not a technical checkbox

Ask NCC Group how the importance of security assurance has changed in recent years, and the answer isn’t really about technology, it’s about status. Mobile networks, they explain, are now widely recognised as critical national infrastructure, which has shifted assurance from a technical nice-to-have into something closer to a business obligation.

“Security assurance is no longer simply a technical requirement; it is increasingly a regulatory, commercial and operational necessity,” NCC Group notes. Operators are under growing pressure to understand the security of their supply chains, while governments are introducing requirements that demand greater visibility into how products are designed, developed and maintained.

The result is that assurance now sits inside a much bigger conversation about resilience and supplier risk management, not a standalone technical activity that happens once and gets filed away.

A consistency problem NESAS was built to solve

Ask any vendor operating across multiple markets what the hardest part of security assurance is, and complexity comes up fast. Products today are built on cloud-native architectures, virtualisation and open-source components, sourced through increasingly diverse global supply chains; while customers and regulators simultaneously expect clear evidence of secure development, vulnerability management and software provenance.

That combination creates a consistency problem. Different operators, different markets and different regulators have historically asked for different kinds of proof, in different formats, at different times. NESAS aims to provide a common framework that can reduce this fragmentation.

“NESAS helps address this by providing a common framework for assessing product development practices and product security levels against defined security requirements. This improves consistency across the industry and provides an independent source of assessment that can support supplier risk management, procurement decisions and regulatory compliance activities.” Chris Proctor, Telecoms Practice Associate Director, NCC Group

In practice, that means one recognised evaluation – an audit of a vendor’s development lifecycle processes, paired with an independent product evaluation against security requirements defined in security assurance specifications developed by globally recognised standards development organisations — rather than a different justification written for every RFP.

What vendors gain from going through the process

For vendors weighing whether NESAS is worth the investment, NCC Group’s answer is direct: it’s increasingly becoming a differentiator, not just a formality.

“As security assurance becomes a more significant factor in procurement and supplier selection, demonstrating independent assurance can provide an important differentiator in the market.” – Chris Proctor, Telecoms Practice Associate Director, NCC Group

Beyond the assessment itself, organisations subjecting their processes and products to NESAS audits and evaluations tend to come out with stronger internal governance and better-aligned security engineering practices, improvements that outlast the audits and evaluations themselves.

That’s echoed in what NCC Group sees – separate strong security programmes from compliance-only ones: the organisations that get the most value treat NESAS as an ongoing improvement exercise rather than a one-off audit to pass. “Compliance becomes a by-product of those activities rather than the primary objective,” they note, the vendors that embed security into design and development from the start, with clear ownership and governance, are consistently the ones that get the most out of the process.

What it means for operators

For operators, the value is less about paperwork and more about better-informed decisions. NESAS gives operators independent evidence to draw on when evaluating a supplier’s product security posture, evidence they didn’t have to generate themselves.

Crucially, NCC Group is clear that NESAS isn’t a replacement for an operator’s own due diligence. It’s “a valuable source of independent assurance that can help inform risk-based procurement and supplier management decisions”, one more form of objective evidence in a decision that ultimately still belongs to the operator.

Looking ahead: assurance will only get more important

As the industry moves toward 5G Advanced, Open RAN, AI-driven network functions and increasingly cloud-native architectures, NCC Group expects assurance requirements to evolve too with more focus on software, automation and supply chain security, and greater visibility into AI governance and interconnected supplier ecosystems.

That’s exactly where schemes like NESAS need to keep evolving. As NCC Group puts it, “no single organisation can address these challenges in isolation.” The most effective assurance frameworks bring operators, vendors, test laboratories, auditors and regulators together around a shared understanding of what good security looks like and NESAS is built to do exactly that.

The bottom line

Asked to sum up the value of NESAS in a single sentence, NCC Group didn’t hesitate:

“NESAS helps establish trust across the mobile ecosystem by providing an independent and internationally recognised approach to security assurance designed to support the needs of vendors, operators and regulators alike.” – Chris Proctor, Telecoms Practice Associate Director, NCC Group

For vendors, that trust can become something very practical: stronger evidence to support procurement conversations and a clearer way to demonstrate security assurance from the outset.

About NESAS

The Network Equipment Security Assurance Scheme (NESAS) is a security assurance framework jointly defined by the GSMA and 3GPP. It combines a process audit of a vendor’s product development and lifecycle management with independent network product evaluations carried out by accredited test laboratories, giving operators, regulators and vendors a common, internationally recognised basis for security assurance.

To find out more about NESAS and how to get started, visit:

gsmaservices.com/assurance-services/network-equipment-security-assurance-scheme-nesas

Contact us

 Fill out the form below and we will be in touch with you shortly.












THIRD PARTY DISCLAIMER
GSMA PathFinder is powered by TransUnion which means it manages the sales and product delivery on behalf of the GSMA. The information you submit will be passed directly to TransUnion in a secure manner. TransUnion will not use your data for any other purpose.