Industry perspectives: The adoption of SEPP for 5G roaming – why it matters and what’s next
The role of SEPP in 5G Standalone (SA) core network deployment
The telecom industry is slowly adopting a 5G Standalone (SA) Core to be able to unlock its potential to open new revenue streams. Supporting this transformation is the Security Edge Protection Proxy (SEPP), a key technology for enabling secure and seamless 5G roaming. As operators around the globe adopt SEPP, it’s important to understand why it matters, how it’s evolving, and why independent vendors like BroadForward are leading the way. Why operator cloud readiness matters for SEPP, 5GSA and roaming 5G Standalone (SA) networks are designed to support secure signaling for interconnect. This marks a significant shift from earlier generations like 4G and 2G/3G, which relied on intermediary systems (such as a Gateway STP and DEA) to handle roaming traffic without securing end-to-end integrity/encryption. The SEPP deals with this omission by securing the communication between roaming partners and protecting signaling traffic. And while it is widely understood that establishing secure inter-connectivity is essential for services relying on 5G Standalone (5GSA), the practical reality is that this fully depends on the availability of the mandatory Security Edge Protection Proxy (SEPP). SEPP however is typically implemented in a cloud-native environment - an operational model that at this moment isn't yet available at roughly 70% of operators worldwide (source: Heavy Reading 2025). As a result, SEPP uptake has been slow. Analysts at Juniper and Analysys Mason even project that fewer than half of operators will offer cloud-based network services by 2028, constraining and delaying both 5GSA roaming and slowing 5GSA adoption.Although the BroadForward SEPP supports cloud-native deployment (as well as bare metal and virtualized environments), not surprisingly nearly every BroadForward SEPP in the field has initially been deployed on virtual machines - immediately enabling interconnectivity for our customers in their existing data centers where rivals cannot. This deployment versatility, combined with the ability to seamlessly move configurations across deployment models, has proven to be a decisive factor in the remarkable rate of adoption of the BroadForward SEPP. It not only positioned us to power the world’s first live 5GSA roaming service with IPX BICS already in 2022 but also helped establish BroadForward as a global frontrunner in SEPP deployments.
Changes in SEPP standardization Despite service providers slowly adopting SEPP for a few years now, its standardization is still evolving. A key topic of debate is the security model, particularly whether to use PRINS (Protocol for N32 Interconnect Security) next to Hop-by-Hop TLS for IPX providers. PRINS enables end-to-end integrity/encryption by negotiating security levels between operators, offering stronger security but also adding complexity. Until now the 3GPP specifications prescribed the application of PRINS for IPX connections. In September 2025 the GSMA nuanced the 3GPP specification (TS 29.573) by stating that hop-by-hop TLS is also an accepted option next to PRINS for IPX connections. The GSMA Permanent Reference Document NG.113 describes these options in table 4 (Model and security mechanisms) as shown below:| Model | Security mechanism |
| Model 1 ̶ Direct Bilateral | TLS |
| Model 2.1 ̶ Outsourced SEPP | TLS |
| Model 2.2 ̶ Hosted SEPP | TLS |
| Model 2.3 ̶ Operator Group | TLS |
| Model 3 ̶ Service Hub architecture | Hop-by-Hop TLS or PRINS |
| Model 4 ̶ Roaming Hub architecture | Hop-by-Hop TLS or PRINS |
source: GSMA PRD NG.113
In the Outsourced SEPP model 2.1 (as shown in the image below), the MNO relies on an IPX provider to host and manage the SEPP on its behalf, rather than deploying its own SEPP infrastructure. The outsourced SEPP also means less control over security policies and key management, as these are handled by the IPX provider rather than the MNO itself. Model 2.1 allows operators to adopt secure 5G roaming more quickly without investing in their own SEPP infrastructure. A drawback of this model 2.1 is that operators should expose their SBI interfaces outside of their own network. These SBI interfaces must be secured by TLS or any VPN connection between the PLMN and the Outsourced SEPP. It is particularly beneficial for smaller MNOs, as it provides a cost-effective, scalable alternative that helps them compete with larger players, despite the disadvantages.
source: GSMA PRD NG.113
