State of 3GPP: September 2026

3GPP Scout · Newsroom · September 2026

The 6G band is in the tables, and slicing finally has a price tag

RAN#113 opens in Madrid on September 14 to pick the 6G migration path. The specifications published ahead of it have already committed to a lot: bands n102 and n104 in the radio tables, a consumer slice on sale in Britain, learning schedulers running on live commercial networks, phones measuring satellite cells before they reselect, and a study of what breaks when cryptographic keys get longer. This issue sticks to what the documents say.

The 60-second version

A note on timing. RAN#113 sits in Madrid from September 14 to 17 with the 6G migration options and the CU/DU split deferred from Singapore on the agenda. Everything below was in published specification text by September 11. What Madrid decides is next month's issue.

1. The 6G capacity band already has its rows in the radio tables

The upper 6 GHz fight got sharper this month. The GSMA declared the device ecosystem ready and urged regulators to open 6.425 to 7.125 GHz for mobile (Sep 7). Optus and Nokia ran the band in Sydney at 3.5 Gbps with macro coverage comparable to 3.5 GHz. Spain's MásOrange started its own 6 GHz tests with Ericsson. Ofcom went the other way: it wants only a sliver (7125 to 7250 MHz) for mobile at WRC-27, and the rest of Europe is split.

The specification work, meanwhile, is finished. TS 38.104 v20.0.0, the first Release 20 edition of the base-station radio requirements, stretches the first frequency range to cover the new airwaves and lists the bands by name:

“Frequency range designation Corresponding frequency range FR1 410 MHz – 7125 MHz…” (TS 38.104 §5.1, Table 5.1-1)
“n102 5925 – 6425 5925 – 6425 TDD… n104 6425 – 7125 6425 – 7125 TDD” (TS 38.104 §5.2, Table 5.2-1)

Band n104 arrives with its own unwanted-emissions table, its own expected-radiated-power limits, and its own channel bandwidth rows up to 100 MHz. That is a complete radio specification for a band regulators are still arguing about.

A second document does the plumbing. The first Release 20 edition of TS 38.307 v20.0.0 defines:

“Requirements on User Equipments (UEs) supporting a release-independent frequency band” (TS 38.307 (title))

So a phone can support a band defined after its own release of the standard. Handsets follow the regulator's clock instead of the release calendar.

Why it matters: the radio requirements exist, so the upper 6 GHz argument is now entirely about permission. The number to watch is how much of 6425 to 7125 MHz each regulator puts on the table at WRC-27.

2. Slicing went from slideware to store shelves

Network slicing spent years as the feature every operator demoed and no customer could buy. In August EE put one on sale. Fast Lane is a paid consumer tier on its standalone 5G network that hands buyers a dedicated slice when a cell congests (Light Reading, Aug 20). VodafoneThree answered with tiered enterprise and critical-service slices, one of them carrying a 15 Mbps performance guarantee, and declared a slicing war on BT. In India, the regulator moved to require per-slice tariffs and measured-speed disclosure, and is debating whether any single slice should be capped at 80 percent of a cell's resources.

The management specs moved in step. The provisioning spec, TS 28.531 v20.1.0 (its keyword line reads “5G, Network Slicing, Slice, Provisioning”), lays out the machinery that turns a commercial order into a running slice:

“The provisioning of network slicing includes the four phases which are preparation, commissioning, operation and decommissioning…” (TS 28.531 §4.1)

The same cycle updated the Network Resource Model (TS 28.541 v20.3.0), which defines the slice objects on management interfaces, and the performance measurements (TS 28.552 v20.3.0), which cover 5G networks including network slicing. The slice an operator sells, the managed object that represents it, and the counters that show whether it delivered are now specified as a set. That is what turns a 15 Mbps guarantee into something billable.

Why it matters: slicing revenue was supposed to arrive with 6G. Britain made it a 5G product in August, and the management plane is keeping pace. The next fight is over measurement, and India already wants speeds disclosed per slice.

3. AI touched a live tower and the numbers held up

June's AI story was in the core network. August's is on the mast. SoftBank and Ericsson switched on what they describe as the first AI-native link-adaptation scheduler on a commercial 5G network in Japan, reporting up to 25 percent better spectral efficiency, 50 percent higher downlink throughput, and 10 percent average gains (Aug 20). T-Mobile and Ericsson followed with a large-scale 5G-Advanced trial of an AI-native scheduler showing 15 percent downlink and 10 percent efficiency gains. The counterpoint came from a study of Nokia and Nvidia's AI-RAN pitch: the GPUs only pencil out at the right sites, and the study expects field trials late this year and commercial deployments late next.

The spec that matters here sits on the management side. TS 28.105 v19.6.0, the AI/ML management specification, opens with its scope:

“The present document specifies the Artificial Intelligence / Machine Learning (AI/ML) management capabilities and services for 5GS where AI/ML is used, including management and orchestration…and NG-RAN…” (TS 28.105 §1)

Its information model covers the lifecycle an operator needs before handing a model a live cell: model loading, model updates, the inference function itself, and inference emulation for testing. A scheduler that learns is only deployable if the network can version it, monitor it, and roll it back, and this is the document that says how.

Why it matters: the argument has moved from whether learning schedulers work to which sites they pay for. The operating model is already written down. The site economics are what the Nokia and Nvidia trials will have to show late this year.

Deep dives: the talk, then the text

What people were saying this month, then what the specification says.

Phones calling from space stopped being a demo

The buzz: direct-to-device had its busiest fortnight. AST SpaceMobile won FCC permission for 30-day direct-to-device tests in the 800 MHz band with a hundred off-the-shelf phones, then filed to extend the window. ST Engineering iDirect demonstrated a multi-waveform NR-NTN modem at ESA. The satellite association MSSA released a reference architecture for regenerative payloads aligned to current 3GPP releases, and the GSMA pushed an interoperability drive for the sector’s next phase. What landed: 6G’s first requirements study (TR 38.914 v20.0.0) gives satellite its own scenario clause and a design principle that terrestrial and satellite share one radio:

“Aim at a harmonized 6G Radio design for TN and NTN, including their integration” (TR 38.914 §5.5 (see also §4.10 Non-Terrestrial Network))

The current generation keeps getting hardened in the meantime. TS 38.133 v20.0.0, the first Release 20 edition of the radio-resource-management requirements, sets out how a phone measures a satellite cell before it reselects:

“This clause defines the following conditions for NR intra-frequency measurements performed based on SSBs for cell re-selection: SSB_RP and SSB Ês/Iot, applicable for a corresponding operating band for satellite access.” (TS 38.133 Annex B.1.6 (see also B.1.7))

The takeaway: in June the satellite story was voice squeezed through sensor links. This month it is broadband phones moving between terrestrial and satellite cells, and a 6G study that designs for that handover from the start. The SSB_RP and Ês/Iot conditions in Annex B are the thresholds to keep an eye on.

Security started planning for the quantum era

The buzz: SA3#129 met in Prague in late August with post-quantum cryptography on the agenda: hybrid key exchange in TLS 1.3, retiring TLS 1.2, certificate profiles, and a liaison to the IETF pressing for the underlying standards. What landed: TR 33.703 v20.0.1, the study on the transition, states the problem in two lines:

“Studies the impact of using hybrid and standalone PQC algorithms in 3GPP procedures” and the “Impact to 3GPP procedures due to larger length of PQC key, signature, and message compared to the length of those in traditional cryptography.” (TR 33.703 §1 (see also §5))

The study lists more than twenty candidate solutions for concealing the subscriber identity alone, including hybrid designs that pair today’s elliptic-curve encryption with the lattice-based ML-KEM algorithm. The candidates come with named algorithms and measured key and message lengths attached, which is what engineering work looks like.

The takeaway: cryptography transitions take a decade, and this one has started. Which of those twenty-odd candidates survives the evaluation is the thing to watch.

Also worth knowing

Want the receipts?

Every quote above is a real line from a 3GPP specification. 3GPP Scout searches the full text and figures of every TS and TR across Rel-15 through Rel-20, and answers follow-ups in plain English.

Search the specs → | Plug Scout into Claude or ChatGPT (MCP) →

How we make this: we follow the plenary and working-group output and the telco press, then check what people are saying against the specification text itself, so each issue carries both the conversation and what made it into the documents. This issue drew on the September 11 specification crawl and the published Release 20 texts. Madrid’s decisions land next month.

3GPP Scout is an independent product of SuperPenguin and is not affiliated with, endorsed or sponsored by 3GPP, ETSI or any 3GPP Organizational Partner. 3GPP™ is a trade mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. Excerpts are quoted for reference and the official documents govern. Copyright, correction or removal requests: contact@3gppscout.com.