TCCE Security; Application of ETSI CVD process within TCCE

DTR/TCCE-06210

General Information

Status
Not Published
Technical Committee
TCCE 6 - TCCE Security
Current Stage
12 - Citation in the OJ (auto-insert)
Due Date
30-Jan-2026
Completion Date
22-Jan-2026
Standard

ETSI TR 104 246 V1.1.1 (2026-01) - TCCE Security; Application of ETSI CVD process within TCCE

English language
13 pages
sale 15% off
Preview
sale 15% off
Preview

Frequently Asked Questions

ETSI TR 104 246 V1.1.1 (2026-01) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "TCCE Security; Application of ETSI CVD process within TCCE". This standard covers: DTR/TCCE-06210

DTR/TCCE-06210

ETSI TR 104 246 V1.1.1 (2026-01) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


TECHNICAL REPORT
TCCE Security;
Application of ETSI CVD process within TCCE

2 ETSI TR 104 246 V1.1.1 (2026-01)

Reference
DTR/TCCE-06210
Keywords
coordination, security, TETRA, vulnerabilities
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and
microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.

© ETSI 2026.
All rights reserved.
ETSI
3 ETSI TR 104 246 V1.1.1 (2026-01)
Contents
Intellectual Property Rights . 4
Foreword . 4
Modal verbs terminology . 4
Introduction . 4
1 Scope . 5
2 References . 5
2.1 Normative references . 5
2.2 Informative references . 5
3 Definition of terms, symbols and abbreviations . 6
3.1 Terms . 6
3.2 Symbols . 6
3.3 Abbreviations . 6
4 Overview of TETRA networks . 7
4.1 Standardization of TETRA networks . 7
4.2 Typical TETRA network environments . 7
4.3 TETRA network architectures . 7
4.4 TETRA network operations . 8
5 Mitigation of vulnerabilities in TETRA networks . 8
5.1 Options to mitigate vulnerabilities in TETRA networks . 8
5.2 Update processes in TETRA networks . 9
5.3 Vulnerability mitigation at Mobile Station . 9
5.4 Vulnerability mitigation in SwMI . 10
6 ETSI CVD in TCCE TETRA context . 10
6.1 Roles and responsibilities . 10
6.2 Reporting obligations of network operators . 10
6.3 Reporting obligations of manufacturers . 10
6.4 ETSI CVD process in the TCCE environment . 11
6.5 Example time frames for resolving vulnerabilities in the TETRA standards . 11
6.6 Example time frames for resolving vulnerabilities in TETRA networks . 12
History . 13

ETSI
4 ETSI TR 104 246 V1.1.1 (2026-01)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations
pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be
found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to
ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee TETRA and Critical Communications
Evolution (TCCE).
Modal verbs terminology
In the present document "should", "should not", "may", "need not", "will", "will not", "can" and "cannot" are to be
interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
Introduction
Security vulnerabilities play a crucial role in all lifecycles of systems, components and services of telecommunication
networks. The ETSI Coordinated Vulnerability Disclosure (CVD) process provides a way for Finders to disclose
vulnerabilities found in TETRA standards. These vulnerabilities may have an impact on the security of numerous
TETRA networks worldwide. This coordinated disclosure will help to respond to security vulnerabilities, to evaluate
potential vulnerabilities, to mitigate confirmed vulnerabilities and therefore allow to reduce the risk of compromise.
The main clauses of the present document contain the following information:
• Clause 4 gives an overview on TETRA standardization, typical network environments, architectures and
operations.
• Clause 5 outlines options to mitigate vulnerabilities in TETRA networks and explains the complexities of
update processes.
• Clause 6 explains the ETSI CVD in the TETRA context.
ETSI
5 ETSI TR 104 246 V1.1.1 (2026-01)
1 Scope
The present document defines the policy of the Technical Committee (TC) Terrestrial Trunked Radio and Critical
Communications Evolution (TCCE) in the ETSI Coordinated Vulnerability Disclosure (CVD) [i.1]. This policy is based
on the ETSI CVD and applies to ETSI deliverables of the TCCE [i.2] only.
The present document is intended for all roles in the ETSI CVD process and provides guidance to: Finder, ETSI CVD
Steering Committee, TC TCCE and the rapporteur(s) of the impacted standard(s). It details the process for Finders of
potential vulnerabilities, explains the actions of the TC TCCE and may be used as guidance for all roles.
For Finders not acquainted with Terrestrial Trunked Radio (TETRA) the present document outlines typical TETRA
network environments and explains typical constraints and complexities in vulnerability mitigations.
2 References
2.1 Normative references
Normative references are not applicable in the present document.
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee
their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's
understanding, but are not required for conformance to the present document.
[i.1] ETSI Coordinated Vulnerability Disclosure (CVD).
[i.2] ETSI Technical Committee (TC) Terrestrial Trunked Radio and Critical Communications
Evolution (TCCE).
[i.3] ETSI TR 103 838 (V1.1.1): "Cyber Security; Guide to Coordinated Vulnerability Disclosure".
[i.4] ETSI EN/TS 3/100 392-2: "Terrestrial Trunked Radio (TETRA); Voice plus Data (V+D); Part 2:
Air Interface (AI)".
[i.5] Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on
horizontal cybersecurity requirements for products with digital elements and amending
Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber
Resilience Act) (Text with EEA relevance).
[i.6] ETSI EN/TS 3/100 392-3 series: "Terrestrial Trunked Radio (TETRA); Voice plus Data (V+D);
Part 3: Interworking at the Inter-System Interface (ISI)".
ETSI
6 ETSI TR 104 246 V1.1.1 (2026-01)
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the following terms apply:
ETSI CVD Steering Committee: committee which, for each vulnerability report, triages the vulnerability, interacts
with the Chair and the ETSI Technical Officer of the TC TCCE and the rapporteur(s) of the impacted standard(s) to
resolve the vulnerability, and communicates on the progress of the handling of the vulnerability report with the Finder
NOTE: As defined in [i.1].
finder: individual or organization who has found a potential vulnerability
NOTE: As defined in [i.1].
manufacturer: designer or manufacturer of TETRA equipment or components of TETRA networks
Mobile Station (MS): physical grouping that contains all of the mobile equipment that is used to obtain TETRA
services
network operator: organization that operates a TETRA network
subscription: permit for a Mobile Station to use a TETRA network, characterized by a subscriber identity and,
optionally, an authentication key provided by the TETRA network
TCCE Technical Experts Group (TCCE TEG): expert group consisting of delegates of manufacturers and operators,
which looks for a solution to reported vulnerabilities.
TETRA network: SwMI with one or more Base Station(s) broadcasting the same Mobile Network Identity
user organization: organization that holds subscriptions of a TETRA network
vulnerability: security weakness that can be abused to cause unintended behaviour
NOTE: As defined in [i.1].
3.2 Symbols
Void.
3.3 Abbreviations
For the purposes of the present document, the following abbreviations apply:
BS Base Station
CRA Cyber Resilience Act
CVD Coordinated Vulnerability Disclosure
DMO Direct Mode Operation
EU European Union
IOP InterOPerability
ISG Industry Specification Group
ISI Inter-System Interfaces
ITSI Individual TETRA Subscriber Identity
K, K2 authentication Key
MS Mobile Station
NCSC National Cyber Security Centre
PAMR Public Access Mobile Radio
PMR Private Mobile Radio
SDS Short Data Service
SIM Subscriber Identity Module
ETSI
7 ETSI TR 104 246 V1.1.1 (2026-01)
SwMI Switching and Management Infrastructure
TB Technical Body
TC Technical Committee
TCCA The Critical Communications Association
TCCE Terrestrial Trunked Radio and Critical Communications Evolution
TEDS TETRA Enhanced Data Service
TEG Technical Experts Group
TETRA TErrestrial Trunked RAdio
TF Technical Forum
TMO Trunked Mode Operation
4 Overview of TETRA networks
4.1 Standardization of TETRA networks
ETSI's Technical Committee (TC) Terrestrial Trunked Radio and Critical Communications Evolution (TCCE) is
responsible for the design and standardization of Terrestrial Trunked Radio (TETRA) and its evolution to critical
communications mobile broadband solutions.
TETRA standards define the TETRA air interface, TETRA algorithms of the air interface, the TETRA speech codec
and external interfaces of TETRA networks. This enables the development and deployment of interoperable solutions.
To ensure interoperability, The Critical Communications Association (TCCA) has established an Interoperability (IOP)
certification process managed by TCCA's Technical Forum (TF). This allows for an open multi-vendor market for
TETRA infrastructure and mobile equipment.
The standardized frequency bands range from 100 to 900 MHz. TETRA networks are narrowband systems optimized
for voice services and Short Data Services (SDSs). The use of TETRA Enhanced Data Service (TEDS) allows for
higher packet data rates depending on bandwidth, modulation and coding rate. However, as these narrowband systems
provide moderate data rates, TETRA data services are usually not used to deploy firmware updates to Mobile Stations
(MSs).
4.2 Typical TETRA network environments
TETRA is used in Private and Public Access Mobile Radio (PMR and PAMR) networks. Major markets include:
• Public Safety
• Transportation
• Utilities
• Government
• Military
• Commercial and Industry
• Oil and Gas
4.3 TETRA network architectures
In TETRA standards TETRA networks comprise Mobile Stations (MSs) and components of the Switching and
Management Infrastructure (SwMI).
A MS comprises all of the mobile equipment that is used to obtain TETRA services. In TETRA networks a MS may be
directly provisioned with the Individual TETRA S
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...