GSMA SMS and Signaling Security Guidelines Explained

Operators and vendors cite GSMA documents constantly, but rarely explain them. This guide summarises the ones that matter for SMS and signaling security, and what each asks operators to do.

Short answer

The GSMA publishes guidance that mobile operators use to secure interconnects and messaging. For SMS and signaling, the key documents are FF.09 (SMS fraud), FS.07 (SS7 and SIGTRAN security), FS.11 (SS7 interconnect monitoring and firewall rules), FS.12 (A2P SMS bypass and fraud), SG.22 (SMS firewall best practices), FS.19 (Diameter), FS.20 (GTP) and FS.52 (Global Title leasing). Several are available only to GSMA members.

The documents at a glance

DocumentTopicWhy it matters
FF.09SMS fraudDescribes SMS types, normal traffic flows and how fraud scenarios arise
FS.07SS7 and SIGTRAN network securityAnalyses security at each layer of the SS7 and SIGTRAN stack
FS.11SS7 interconnect security monitoring and firewall guidelinesThe basis for SS7 firewall rules, including message categories 1, 2 and 3
FS.12A2P SMS bypass and fraud: methods, detection and mitigationCovers A2P bypass, artificially inflated traffic and unauthorised HLR lookups
SG.22SMS firewall best practices and policiesHigh-level guidance for designing and managing SMS firewall policies
FS.19Diameter interconnect securityThe 4G counterpart to FS.11
FS.20GTP securityProtection of data-roaming signaling
FS.21Interconnect signaling security recommendationsA risk-based approach across interconnect protocols
FS.52Global Title leasing code of conductRules for leasing Global Titles, a common route for signaling abuse

The GSMA lists these documents on its interworking security page. Access to several requires GSMA membership.

FS.11 categories explained

FS.11 sorts SS7 messages by where they may legitimately come from, which turns into firewall rules:

Category 1
Messages that should only be received from within the same network, or from partners with an explicit bilateral agreement. Arriving from any other interconnect, they are blocked.
Category 2
Messages that should only be received from a visiting subscriber's home network. The firewall checks that the sender is the subscriber's home operator.
Category 3
Messages that should only be received from the network the subscriber is actually visiting. Enforcing this needs location checks, such as whether the subscriber could plausibly be in that network now.

FS.12 and A2P bypass

FS.12 addresses the commercial side of SMS fraud: A2P traffic delivered through bypass routes, artificially inflated traffic, and HLR lookups used to harvest subscriber data. It is the reference document behind grey route policies on operator SMS firewalls. See SMS grey routes.

SG.22 and SMS firewall policy

SG.22 is about how operators run an SMS firewall: which traffic to classify, how to set and review policies, and how to avoid blocking legitimate traffic. It is a management guide rather than a technical specification.

How the guidelines translate into products

  • A signaling firewall implements FS.11, FS.19 and FS.20 rules on SS7, Diameter and GTP interconnects.
  • An SMS firewall applies FS.12 and SG.22 to the messages themselves.
  • Global Title screening reflects FS.52 concerns about leased and misused GTs.

A caution

Compliance with a GSMA document is not a certification, and the documents are guidance rather than law. Ask a vendor which specific rules and categories its product enforces, and how it shows that in reports.

Talk to our carrier team

Tell us which destinations, volumes or networks you are working with. A member of our team will reply by email.

We use these details only to reply to your request. See the privacy policy.