The migration from 5G Non-Standalone (NSA) to Standalone (SA) is a significant architectural shift: the Evolved Packet Core (EPC) that manages 4G and 5G NSA sessions is replaced by a native 5G core (5GC) with new network functions, new interfaces, and new data models. Operators have invested heavily in understanding the service and performance implications of this migration. The lawful intercept implications have received substantially less attention in most deployment programmes — and the gap is closing faster than many compliance teams realise.
How intercept architecture changes between NSA and SA
In a 5G NSA deployment, the EPC handles session management and user plane anchoring. The LI architecture is the 4G LI architecture: mediation devices connected to EPC interfaces, probes on the SGi interface for IP intercept, and IMS-based voice intercept through existing PGW/P-CSCF paths. This is a well-understood compliance architecture that most operators have implemented and certified.
In a 5G SA deployment, the AMF replaces the MME, the SMF replaces the SGW/PGW control plane, and the UPF replaces the SGW/PGW user plane. Each of these functions has different LI interfaces: the 3GPP X1/X2/X3 model described in TS 33.127 and 33.128 rather than the 4G mediation interfaces. A 4G-certified LI system connected to an EPC does not provide intercept capability on a 5G SA core.
The compliance gap in migration programmes
The typical 5G SA migration programme treats LI as a dependency to be resolved before commercial launch — but "resolved" is often interpreted as "the core vendor has confirmed the X2/X3 interfaces are available," not "we have a certified, tested, and operationally integrated LI system for the SA core." The vendor interface availability is a necessary condition; it is not a sufficient one.
Operators that have launched 5G SA commercially without completing the LI system integration have a compliance exposure that varies by national framework but is generally significant. US operators are subject to CALEA capability requirements from the day new infrastructure carries traffic. EU operators face national implementation of the European Electronic Communications Code with equivalent timing requirements. The FCC has been explicit that the CALEA obligation attaches to new deployments; there is no grace period for infrastructure that is commercially active.
Planning the LI component of an SA migration
LI compliance for a 5G SA deployment should be treated as a programme workstream, not a go-live checklist item. The workstream includes: LI architecture design for the 5G SA core (which network functions require LI interfaces, how the mediation and delivery layer connects to the 5GC), procurement and integration of 5GC-capable LI systems, end-to-end testing against real SA core deployments in a lab environment, certification if required by the national framework, and operational readiness — warrant processing workflows, law enforcement delivery interfaces, and helpdesk procedures.
Running this workstream in parallel with the core migration programme rather than sequentially after it is the difference between a compliant SA launch and a compliance gap that must be remediated after the network is live. The cost of parallel workstreams is modest; the cost of post-launch LI remediation — in engineering resources, regulatory exposure, and potential enforcement action — is substantially higher.



