Skip to content

Evidence request lists

3GPP 5G Security Architecture (TS 33.501)

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Security

33.501-9
Security for Non-3GPP Access

Non-3GPP access (untrusted Wi-Fi, wireline) must use N3IWF or TNGF with IKEv2 and IPsec for secure tunneling to the 5G core, with authentication anchored in 5G AKA.

Artefacts an auditor will ask for
  • N3IWF configuration
  • IKEv2 policy
  • IPsec algorithm selection
Where this commonly fails
  • Weak IKEv2 cipher suites
  • Certificate validation skipped
  • Trusted vs untrusted access mixed

Authentication

33.501-6.1
Primary Authentication (5G AKA / EAP-AKA')

Mutual authentication between UE and network must use 5G AKA or EAP-AKA' procedures involving the AUSF, UDM, SEAF, and ARPF, producing keys anchored at the SEAF for serving network derivation.

Artefacts an auditor will ask for
  • AUSF configuration
  • Test reports for AKA flows
  • Key hierarchy documentation
Where this commonly fails
  • EAP-AKA' fallback not tested
  • Authentication failure handling weak
  • Replay protection unverified

Authentication Procedures

TS33.501-6.1
Authentication Framework

Primary authentication and key agreement based on EAP-AKA' and 5G-AKA protocols

Artefacts an auditor will ask for
  • AUSF and UDM authentication configuration baseline
  • SUCI/SUPI handling specification implementation review
  • Primary authentication test vectors and conformance evidence
  • Key derivation diagrams (KAUSF, KSEAF, KAMF, KgNB)
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-6.2
Key Hierarchy and Derivation

Maintain the 5G key hierarchy from K to KAUSF, KSEAF, KAMF, and access stratum keys with documented derivation functions.

Artefacts an auditor will ask for
  • Key hierarchy diagram
  • KDF implementation review
  • Key lifecycle SOP
Where this commonly fails
  • No KDF code review
  • Missing key destruction logs
  • Undocumented key flows
TS33.501-6.3
EAP-AKA' Authentication

Authentication procedure using EAP-AKA' protocol for 5G

Artefacts an auditor will ask for
  • AUSF and UDM authentication configuration baseline
  • SUCI/SUPI handling specification implementation review
  • Primary authentication test vectors and conformance evidence
  • Key derivation diagrams (KAUSF, KSEAF, KAMF, KgNB)
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-6.4
NAS Security

Apply integrity and confidentiality protection to NAS signalling between UE and AMF using selected 5G algorithms.

Artefacts an auditor will ask for
  • NAS SMC trace logs
  • Algorithm negotiation records
  • AMF configuration baseline
Where this commonly fails
  • NULL integrity allowed
  • Weak ciphers in policy
  • No algorithm capability validation

Core Network Security

33.501-8
Security Aspects of UDM/UDR

UDM and UDR store sensitive subscriber data including long-term keys and authentication credentials. Storage must be protected with appropriate physical, logical, and cryptographic controls.

Artefacts an auditor will ask for
  • HSM attestation
  • UDR encryption configuration
  • Access control matrices
Where this commonly fails
  • Long-term keys in software
  • DBA access not segregated
  • Backups unencrypted

Cryptography

33.501-Annex-D
Cryptographic Algorithms

Supported algorithms include NEA0/NIA0 (null), 128-NEA1/NIA1 (SNOW 3G), 128-NEA2/NIA2 (AES), 128-NEA3/NIA3 (ZUC). Operators must configure policies to disallow null algorithms in production.

Artefacts an auditor will ask for
  • Algorithm selection policy
  • Operator configuration evidence
  • Lawful intercept exception documentation
Where this commonly fails
  • Null algorithms allowed for emergency calls broadly
  • 256-bit support roadmap missing
  • Test devices in production with weak algorithms

General Security Architecture

TS33.501-4.1
5G Security Architecture Overview

Define the overall 5G security architecture covering UE, RAN, core network, and service-based interfaces with documented trust boundaries.

Artefacts an auditor will ask for
  • 5G security architecture diagram
  • Trust boundary map
  • Network domain security policy
Where this commonly fails
  • Outdated architecture diagrams
  • Missing trust boundary definitions
  • No SBA security overlay
TS33.501-4.2
Security Feature Groups

Network access security, network domain security, user domain security, application domain security, SBA domain security, visibility and configurability of security

Artefacts an auditor will ask for
  • 5G security architecture diagrams aligned to TS 33.501
  • Security feature group inventory and assignment
  • Inter-stratum trust boundary documentation
  • Conformance test reports against TS 33.501
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-4.3
Security Domains and Stratum

Grouping of network entities for security in home and visited networks and protected communication links

Artefacts an auditor will ask for
  • 5G security architecture diagrams aligned to TS 33.501
  • Security feature group inventory and assignment
  • Inter-stratum trust boundary documentation
  • Conformance test reports against TS 33.501
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-4.4
Network Functions in the Security Architecture

Security roles of AUSF, SEAF, SIDF, and other NFs

Artefacts an auditor will ask for
  • 5G security architecture diagrams aligned to TS 33.501
  • Security feature group inventory and assignment
  • Inter-stratum trust boundary documentation
  • Conformance test reports against TS 33.501
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced

Identifiers and Privacy

33.501-5.1
Subscription Permanent Identifier Protection

The SUPI must never be transmitted in cleartext over the radio interface. SUCI (concealed identifier) must be derived using the home network public key via ECIES schemes to prevent IMSI catcher attacks.

Artefacts an auditor will ask for
  • SUCI configuration evidence
  • Home network key management procedures
  • UE provisioning records
Where this commonly fails
  • Null scheme used for SUCI
  • Home key rotation not defined
  • Legacy SIM provisioning bypasses SUCI

Interworking

33.501-10
Security for Interworking with EPS

Interworking between 5GS and EPS requires secure mapping of security contexts during handover and idle mode mobility, preventing downgrade and ensuring key freshness.

Artefacts an auditor will ask for
  • N26 interface configuration
  • Mobility test reports
  • Key mapping procedures
Where this commonly fails
  • Context mapping not tested
  • Downgrade attack risk
  • Inter-PLMN handover untested

Key Management

33.501-6.2
Key Hierarchy

5G key hierarchy starts from long-term key K stored in USIM and ARPF, deriving CK/IK, KAUSF, KSEAF, KAMF, and subsequent NAS and AS keys with separation between security contexts.

Artefacts an auditor will ask for
  • Key derivation function tests
  • ARPF/UDM hardening evidence
  • USIM personalization audit
Where this commonly fails
  • Key separation not validated across contexts
  • Long-term keys not in HSM
  • Derived keys logged

Management Security

33.501-OAM
Management Plane Security

Operations and management interfaces to 5G NFs must be authenticated, encrypted, and logged. Administrative access requires strong authentication, role separation, and privileged access management.

Artefacts an auditor will ask for
  • PAM configuration
  • Admin access logs
  • MFA enrollment for ops staff
Where this commonly fails
  • Shared admin accounts
  • Unencrypted SNMP
  • No session recording for privileged actions

Non-3GPP Access Security

TS33.501-7.1
Untrusted Non-3GPP Access Security

Security for access to 5G core via untrusted non-3GPP access networks through N3IWF

Artefacts an auditor will ask for
  • N3IWF configuration baseline and IPsec tunnel policy
  • TNGF authentication flow records for trusted non-3GPP access
  • Wireline 5G access (W-5GAN) security configuration
  • EAP based authentication test logs for non-3GPP access
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-7.2
Security Visibility and Configurability

Provide operators with visibility into active security parameters and ability to configure algorithm preferences.

Artefacts an auditor will ask for
  • Security configuration dashboard
  • Algorithm preference policy
  • Operator runbook
Where this commonly fails
  • No security visibility tooling
  • Static configurations
  • Missing operator training
TS33.501-7.3
Wireline Access Security

Security for access to 5G core via wireline access networks

Artefacts an auditor will ask for
  • N3IWF configuration baseline and IPsec tunnel policy
  • TNGF authentication flow records for trusted non-3GPP access
  • Wireline 5G access (W-5GAN) security configuration
  • EAP based authentication test logs for non-3GPP access
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced

Privacy

33.501-17
Privacy and Pseudonymization

Privacy protections include SUCI concealment, GUTI reallocation, paging strategies that avoid permanent identifier leakage, and minimization of subscriber data in signaling outside trust boundaries.

Artefacts an auditor will ask for
  • GUTI reallocation policy
  • Paging configuration
  • Privacy impact assessment
Where this commonly fails
  • GUTI reallocation infrequent
  • Tracking via persistent identifiers possible
  • PIA not completed

Roaming Security

33.501-13.4
SEPP and Inter-PLMN Security (N32)

Security Edge Protection Proxies protect signaling between visited and home PLMNs over N32, using TLS for N32-c and PRINS (application layer security) for N32-f to handle IPX intermediaries.

Artefacts an auditor will ask for
  • SEPP certificate inventory
  • PRINS policy
  • IPX agreement documents
  • N32 message inspection rules
Where this commonly fails
  • TLS-only N32-f without PRINS
  • Modification rules unreviewed
  • IPX trust assumptions undocumented
33.501-15
Steering of Roaming Security

Steering of roaming information sent to UE must be protected for authenticity and integrity using SoR-MAC to prevent unauthorized PLMN selection manipulation.

Artefacts an auditor will ask for
  • SoR configuration
  • UDM SoR procedure logs
  • USIM SoR support evidence
Where this commonly fails
  • SoR-MAC not enabled
  • UE acknowledgment not enforced
  • List update freshness not managed

SBA Security

33.501-13.1
Service-Based Architecture Security (TLS)

5G SBI between Network Functions must be protected using TLS 1.2 or higher with mutual authentication via certificates. Direct communication may use OAuth 2.0 for service authorization.

Artefacts an auditor will ask for
  • TLS certificate inventory
  • OAuth 2.0 token policies
  • NF profile registrations
Where this commonly fails
  • Self-signed certificates in production
  • TLS 1.2 with weak ciphers
  • Mutual TLS not enforced
33.501-13.2
Network Function Service Authorization (OAuth 2.0)

NF service consumers must obtain access tokens from the NRF to invoke services on NF service producers. Tokens must be validated for scope, audience, expiry, and signature.

Artefacts an auditor will ask for
  • NRF configuration
  • OAuth scope definitions
  • Token validation logs
Where this commonly fails
  • Scope checks omitted
  • Long token lifetimes
  • NRF compromise risk not modeled

Security Architecture

33.501-4.2
Security Domains and Trust Model

5G security architecture defines security domains including UE, access network, serving network, and home network, with trust boundaries that govern key derivation, authentication, and authorization flows.

Artefacts an auditor will ask for
  • Security domain diagrams
  • Trust model documents
  • Interface specifications
  • Roaming agreements
Where this commonly fails
  • Trust boundaries not documented for partners
  • Domain assumptions not validated
  • Roaming interface threats unaddressed

Security for NAS and AS Protocols

TS33.501-6.5
AS Security and PDCP Protection

Protect access stratum traffic via PDCP layer integrity and ciphering for user plane and RRC signalling.

Artefacts an auditor will ask for
  • PDCP configuration
  • AS SMC validation
  • User plane integrity enablement record
Where this commonly fails
  • UP integrity disabled
  • Missing AS SMC verification
  • Mismatched algorithm IDs
TS33.501-6.6
AS Security

RRC and UP security over air interface including ciphering and integrity protection

Artefacts an auditor will ask for
  • AS security mode command sequence test logs
  • RRC and UP integrity and ciphering algorithm policy
  • Key hierarchy and refresh policy documentation
  • Capture and analysis of RRC security mode procedures
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-6.7
Security Key Hierarchy

Key derivation hierarchy from KAUSF to KgNB, KNAS and lower-level keys

Artefacts an auditor will ask for
  • AS security mode command sequence test logs
  • RRC and UP integrity and ciphering algorithm policy
  • Key hierarchy and refresh policy documentation
  • Capture and analysis of RRC security mode procedures
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-6.8
Security in Handover

Maintain security context during intra and inter system handovers with proper key refresh and vertical key derivation.

Artefacts an auditor will ask for
  • Handover key derivation logs
  • Xn/N2 handover test results
  • Key refresh policy
Where this commonly fails
  • Reused keys across cells
  • No NCC counter validation
  • Missing handover security tests

Security for Specific Services

TS33.501-14.1
Security for Network Slicing

Security considerations and requirements for network slicing

Artefacts an auditor will ask for
  • Network slice security policy and slice isolation design
  • NSSAI authentication and authorisation records
  • Slice-specific key derivation and lifecycle documentation
  • Penetration test report covering inter-slice isolation
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-14.2
Security for Edge Computing

Security for Multi-access Edge Computing in the 5G system

Artefacts an auditor will ask for
  • MEC platform hardening baseline and security configuration
  • Edge node onboarding and attestation records
  • Application-to-edge authentication flows
  • Edge platform vulnerability scan reports
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-14.3
Security for URLLC Services

Security considerations for Ultra-Reliable Low-Latency Communication services

Artefacts an auditor will ask for
  • URLLC security profile referencing latency-aware controls
  • Integrity protection algorithm selection records
  • URLLC test reports showing meeting of security SLOs
  • Threat model for ultra-reliable low-latency communications
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-14.4
Security for IAB

Security for Integrated Access and Backhaul nodes

Artefacts an auditor will ask for
  • IAB node integration and authentication procedure records
  • Backhaul security key hierarchy documentation
  • IAB topology diagrams with trust boundaries
  • IAB security test reports per 3GPP profile
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced

Service Based Architecture Security

TS33.501-13.1
NF Registration and Discovery Security

Security for NF registration, discovery and authorization using NRF

Artefacts an auditor will ask for
  • NRF configuration baseline with TLS and mutual authentication settings
  • OAuth 2.0 access token policy and scope definitions for NFs
  • SBA topology diagram with security boundaries
  • NF profile registration approval workflow records
  • Audit logs of NF discovery requests and access token issuance
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced
TS33.501-13.2
NF Service Authorization

Use OAuth 2.0 client credentials grant for NF to NF service authorization with NRF as authorization server.

Artefacts an auditor will ask for
  • Authorization server configuration
  • Token validation policy
  • NRF audit logs
Where this commonly fails
  • No token scope enforcement
  • Long lived tokens
  • Missing NRF audit trail
TS33.501-13.3
N32 Interconnect Security

Secure inter PLMN N32 interface using SEPP with application layer protection (PRINS) or TLS, including topology hiding.

Artefacts an auditor will ask for
  • SEPP configuration
  • N32-c handshake logs
  • Topology hiding policy
Where this commonly fails
  • No SEPP deployed
  • Missing JWE protection for N32-f
  • Topology leaks in error messages
TS33.501-13.4
OAuth 2.0 Authorization Framework

NF service consumer authorization using OAuth 2.0 tokens issued by NRF

Artefacts an auditor will ask for
  • NRF configuration baseline with TLS and mutual authentication settings
  • OAuth 2.0 access token policy and scope definitions for NFs
  • SBA topology diagram with security boundaries
  • NF profile registration approval workflow records
  • Audit logs of NF discovery requests and access token issuance
Where this commonly fails
  • Missing or weak mutual authentication between network functions
  • OAuth scope definitions overly broad for NF access
  • Slice isolation not validated by independent testing
  • Key hierarchy refresh policy not enforced

Service Security

33.501-11
Security Aspects of IMS

5G IMS services use SIP signaling with security mechanisms including IMS AKA, IPsec, and TLS to protect signaling and media between UE and IMS core.

Artefacts an auditor will ask for
  • IMS AKA configuration
  • SIP TLS settings
  • Media encryption (SRTP) policy
Where this commonly fails
  • SIP over UDP unprotected
  • SRTP not enforced
  • P-CSCF security capabilities outdated

Signaling Security

33.501-6.4
NAS Security

NAS signaling between UE and AMF must be integrity protected and confidentiality protected using NAS keys derived from KAMF, with negotiated algorithms from the 5G security algorithm set.

Artefacts an auditor will ask for
  • NAS SMC test reports
  • Algorithm policy
  • AMF configuration
Where this commonly fails
  • Null algorithm permitted in production
  • Algorithm downgrade detection missing
  • Replay window not configured
33.501-6.5
AS Security (RRC and User Plane)

Access Stratum security protects RRC signaling and user plane between UE and gNB using AS keys derived from KgNB, with PDCP-layer ciphering and integrity protection.

Artefacts an auditor will ask for
  • gNB configuration
  • PDCP test reports
  • UP integrity policy from SMF
Where this commonly fails
  • UP integrity disabled at high rates
  • Integrity policy not enforced per slice
  • Key change on handover not verified
33.501-6.7
Security Mode Command Procedures

SMC procedures activate NAS and AS security. The network selects algorithms based on UE security capabilities, with bidding-down attack prevention by including UE capabilities in protected SMC.

Artefacts an auditor will ask for
  • SMC trace logs
  • Algorithm selection policy
  • Bidding-down test cases
Where this commonly fails
  • Capability echo not verified
  • Algorithm policy permits weak choices
  • SMC reject handling untested

Slicing

33.501-14
Network Slicing Security

Network slice isolation must prevent cross-slice information leakage and ensure that authentication, authorization, and access for one slice cannot affect another slice. Slice-specific authentication may apply.

Artefacts an auditor will ask for
  • Slice isolation architecture
  • NSSAA configuration
  • Slice access policies
Where this commonly fails
  • Shared NF without slice tagging
  • NSSAA not deployed
  • Slice boundary leakage in OAM

User Plane

33.501-16
Security for User Plane Integrity Protection

User plane integrity protection may be enabled per-DRB based on SMF policy and UE/gNB capability. Full-rate UP integrity is mandated for 5G UEs to mitigate user plane manipulation attacks.

Artefacts an auditor will ask for
  • UP integrity policy templates
  • UE capability matrices
  • gNB capability reports
Where this commonly fails
  • UPIP disabled by default
  • Policy not enforced per slice
  • Legacy UE assumption blocks UPIP
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.