← All insights
compliance mandates5 min read

3GPP Release 18 is live: what 5G Advanced means for lawful intercept obligations

3GPP Release 18, the specification that formally defines 5G Advanced (sometimes referred to as 5.5G), is now being actively deployed by equipment vendors and network operators. Its headline capabilities — improved MIMO efficiency, sidelink enhancements, AI/ML network management integration — receive most of the industry attention. What receives less attention is the set of architectural changes Release 18 introduces that directly complicate how lawful intercept must be designed, deployed, and maintained. For compliance teams, Release 18 is not a future-state concern. Networks are being upgraded now.

Why 5G Advanced makes legacy LI architectures structurally insufficient

Release 18 accelerates the cloud-native disaggregation of the 5G core. Network functions that were previously co-located — and therefore interceptable through a single mediation point — are increasingly distributed across cloud instances, multi-vendor container environments, and edge compute nodes. A probe-based or centralised hardware intercept architecture that worked adequately in a 4G core does not follow a function that has been containerised and may be running on a hyperscaler edge node in a different jurisdiction from the subscriber.

The specific challenge is function mobility. In a cloud-native 5G Advanced core, the AMF (Access and Mobility Management Function) and SMF (Session Management Function) that together carry the data needed to construct a lawful intercept record may not be running on the same infrastructure, or in the same physical location, across two consecutive sessions from the same subscriber. An LI architecture that assumes static function placement will produce incomplete intercept records.

ETSI interface updates operators need to act on

ETSI's LI standards have been updated to address the 5G Advanced architecture. The X1 (provisioning), X2 (intercept-related information), and X3 (content of communications) interfaces defined in ETSI TS 103 221 have been revised to reduce processing overhead and accommodate the throughput requirements of 5G Advanced sessions — which can sustain significantly higher peak data rates than Release 15 5G NR.

The H1 interface, used for warrant exchange under ETSI TS 103 120, has been streamlined and hardened in the latest revision. Operators whose LI systems were built to earlier ETSI specifications and have not been updated since 5G SA deployment should audit their handover interface implementations against the current versions. The interface gap between a Release 15-era LI deployment and a Release 18 network is not theoretical — it produces real data loss in active intercept sessions.

The audit operators should run before year-end

The practical compliance question for operators upgrading to 5G Advanced is whether their LI architecture has a defined implementation path for cloud-native core interception — not whether they have a policy position on it. Equipment vendors are shipping Release 18 upgrades now. Operators that have not mapped their LI mediation layer against the current ETSI X-interface specifications, and have not confirmed that their intercept coverage follows container-based core functions across cloud instances, should treat that as an open compliance gap.

The operators in the best position are those that moved to software-based, probe-free LI architectures during 5G NR deployment — their intercept layer is coupled to the logical function rather than the physical node. Those still relying on hardware probes or centralised mediation points face a more significant re-architecture as Release 18 deployments scale.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →