8/25/2026
The National Institute of Standards and Technology's National Cybersecurity Center of Excellence (NCCoE) is accepting public comments through September 7, 2026, on the initial public draft of Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security.
Visit the NCCoE project page to download the white paper and submit comments.
The paper describes a 5G security feature that protects sensitive information exchanged when a device first connects to a cellular network, and it explains how organizations can verify that these protections are working in deployed 5G networks.
When a phone or other device connects to a cellular network, it exchanges an initial “handshake” message with the network. In 4G, this message was sent without encryption, which left both the device and the network vulnerable to attacks. 5G specifications address this weakness by allowing the sensitive contents of that initial message to be encrypted and protected. The white paper documents how the NCCoE demonstrated these protections on its operational 5G security testbed and offers guidance to help network operators put them into practice.
The draft is part of a broader NCCoE effort to accelerate adoption of 5G security features through real-world demonstration and actionable guidance. Stakeholders are encouraged to review the draft and submit feedback before the September 7 deadline.