← All insights
compliance mandates7 min read

ETSI SA3 and 3GPP 5G LI requirements: what operators need to implement and by when

The 3GPP specifications for 5G lawful intercept — principally TS 33.127 for architecture and TS 33.128 for details — define the interfaces, data formats, and functional requirements for LI in a 5G SA core. ETSI TS 103 221 aligns with these specifications for the European context. Together they represent the most comprehensive technical framework for LI that has ever existed for a mobile generation. They also represent a significant implementation lift for operators that have deployed or are deploying 5G SA core infrastructure.

The X1/X2/X3 interface model

The 3GPP 5G LI architecture replaces the mediation-device-centric model of previous generations with a distributed interface model. The X1 interface carries warrant management — intercept subject activation and deactivation. The X2 interface delivers intercept-related information (IRI) — metadata, signalling, and call records. The X3 interface carries content of communication (CC) — the actual intercepted data payload.

Each network function in the 5G SA core that is subject to intercept obligations — the AMF, SMF, UPF, and in IMS deployments the P-CSCF and S-CSCF — is expected to expose these interfaces to a Licensed Interception Management System (LIMS) and Licensed Interception Function (LIF). The distributed nature of this model means that a 5G SA core deployment with ten or more network functions potentially requires ten or more sets of LI interface implementations, each tested and certified.

What Release 16 and 17 add beyond Release 15

Release 15 established the basic 5G SA LI framework. Release 16 extended it to cover network slicing — adding requirements for per-slice intercept capability and NSSAI (Network Slice Selection Assistance Information) as a target identifier. Release 17 added requirements for edge computing deployments, where user plane functions may be instantiated at distributed edge nodes rather than centralised data centres.

The edge computing extension is operationally significant: it means that an operator deploying MEC (Multi-access Edge Computing) for low-latency services may need LI capability at every edge node, not just at centralised UPFs. The number of intercept-capable deployment points multiplies with the edge topology, and each point must be included in the certification and test regime.

National implementation variation

The 3GPP and ETSI specifications define what must be implemented technically. National regulators define when it must be implemented, for which operator categories, and with what certification requirements. The variation across markets is significant: some national frameworks reference the 3GPP specifications directly as the compliance standard; others have national technical annexes that modify or extend the requirements; and a few have not yet updated their technical specifications to address 5G SA at all.

Operators with multi-market footprints should map their 5G SA deployment timeline against each national framework's LI requirements and timelines. The regulatory expectation in Germany, France, the UK, and the US already assumes 5G SA LI capability for deployed infrastructure. Markets that are early in 5G SA deployment may still be in a transitional period where 5G NSA (with 4G LI capability) is accepted — but that window is closing as SA deployment accelerates.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →