Skip to content

Initial NAS Message Security: Applying 5G Cybersecurity and Privacy Capabilities

Csrc.Nist August 6, 2026

Michael Bartock (NIST) , Jeffrey Cichonski (NIST) , Parisa Grayeli (MITRE) , Sanjeev Sharma (MITRE)

This NIST Cybersecurity White Paper describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.

This white paper is part of the NCCoE’s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.

Current 5G standards include specifications to address cybersecurity and privacy challenges present in generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network—the Initial NAS Message—was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.

Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.

This White Paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.

Publication:

Supplemental Material: Project homepage

Document History: 08/06/26: CSWP 36F (Draft)

general security & privacy

communications & wireless