Summary
- The NCSC is seeking partners working on secure and resilient private 5G rather than awarding a procurement contract at this stage.
- Priorities include rapid deployment, operation without conventional backhaul, certificate-based identity, monitoring, and cyber recovery.
- Responses will inform possible future engagement or procurement involving sensitive UK communications capabilities.
The UK’s National Cyber Security Centre has set out a series of requirements for private 5G systems capable of operating through infrastructure failures and cyber incidents, as it seeks technology partners for future research and potential procurement activity.
The National Cyber Security Centre is inviting expressions of interest from companies and researchers developing secure, resilient, and rapidly deployable private 5G technology. The exercise is market engagement rather than a commitment to buy a particular product or fund a project.
The agency’s priorities move beyond conventional mobile-network performance. It wants private 5G platforms that can be deployed quickly with limited specialist resources, retain connectivity when conventional backhaul is unavailable, integrate enterprise-grade identity controls, withstand cyber incidents, recover rapidly after disruption, and support operations in challenging environments.
Potential uses include emergency communications, temporary operational environments, remote and disconnected locations, research facilities, and other settings where fixed communications infrastructure cannot be assumed to remain available.
One area under consideration is wireless mesh networking combined with Integrated Access and Backhaul, which can allow network nodes to use wireless connections for both user access and backhaul. The NCSC is interested in self-forming and self-healing designs intended to reduce reliance on fixed infrastructure.
Identity is another major focus. The agency specifically identifies EAP-TLS authentication, public-key infrastructure integration, certificate lifecycle management, zero-trust architectures, and stronger identity assurance as areas for exploration as private mobile networks become more closely integrated with enterprise access systems.
The recovery requirements extend to secure backup and restoration of private 5G services and subscriber information. The NCSC also wants better visibility across radio, transport, and core-network layers through 5G-specific intrusion detection, protocol and signalling anomaly detection, rogue-element identification, security analytics, and integration with SIEM and security-operations environments.
Private 5G has increasingly moved into industrial sites, logistics environments, campuses, critical services, and other locations where organisations want greater control over coverage, performance, and connectivity than public mobile networks can provide. That control also transfers more responsibility for security architecture and operational resilience to the organisation running the private network.
Connectivity therefore becomes part of the dependency map for the operational systems using it. A private network carrying machine telemetry, industrial control traffic, emergency communications, or access-control functions cannot be assessed only by radio availability. Identity systems, certificate infrastructure, network-management platforms, backhaul, monitoring, and recovery all become part of the service.
The NCSC’s requirements reflect that broader architecture. Resilience is being treated as the ability to continue or restore communications when infrastructure is degraded, rather than simply preventing unauthorised access to a normally functioning network.
That distinction becomes particularly important for critical and public services. Conventional enterprise connectivity often assumes access to fixed backhaul, central identity systems, management platforms, and external cloud services. A crisis, infrastructure outage, physical disruption, or cyber incident can remove several of those dependencies at once.
The agency is accepting expressions of interest until 5pm on 31 August 2026. It says information gathered through the process will help identify organisations for possible future collaboration and inform any subsequent procurement or engagement.
No contract or funding commitment follows from the current exercise. Any future procurement would be subject to separate governance and approval. The document nevertheless provides an unusually specific view of how the UK’s technical cyber authority expects private 5G to behave when communications infrastructure is no longer operating under normal conditions.




