Cheat sheet
CT1 — the group that writes what your phone says
The working reference on 3GPP CT WG1 and TS 24.501
- Depth
- In depth
- Chapters
- 14
- Reading
- 100 min
- Questions
- 73
- Document
- TS 24.501 v20.0.0
- Sources cited
- 149
The shape of it
1 The group and what stage 3 means
- 1 What CT1 is, and the three names it answers to
- 2 Stage 3 — the difference between a plan and a protocol
- 3 What CT1 owns — 229 documents and the six that matter
2 TS 24.501, the document it is known by
- 4 TS 24.501 — two protocols living in one document
- 5 Finding your way around TS 24.501
- 6 Getting on the network, and getting a connection through it
- 7 What a NAS message looks like on the wire
3 How the work actually happens
- 8 From a document number to a published version
- 9 One CT1 meeting, by the numbers
- 10 Who CT1 writes to, and what the letters count
- 11 The work items that fill a CT1 year
4 Around the group, and the limits of the record
Keep these in your head
-
1.1 What CT1 is, and the three names it answers to
CT1 writes the conversation between a device and the core network. Not the radio, not the architecture drawing — the actual sequence of messages, and what every field in them means.
-
2.1 Stage 3 — the difference between a plan and a protocol
Stage 1 is what is wanted. Stage 2 is which function does what, in what order. Stage 3 is what goes on the wire, to the bit. They are three documents, not three drafts of one.
-
3.1 What CT1 owns — 229 documents and the six that matter
229 active documents is the size of the group's shelf. It is not the size of its workload: six documents lead the change traffic, and the rest sit still for years at a time.
-
4.2 TS 24.501 — two protocols living in one document
Two protocols, one document. 5GMM handles being on the network; 5GSM handles having a connection through it. Almost every confusion about TS 24.501 comes from mixing the two up.
-
5.2 Finding your way around TS 24.501
A procedure is described in clause 5 or 6, its messages in clause 8, its field coding in clause 9, its timers in clause 10 and its rejection reasons in Annex A or B. Five stops, always in that order.
-
6.2 Getting on the network, and getting a connection through it
One procedure, three jobs: get on the network, tell it you have moved, tell it you are still alive. They share a message and differ by one field.
-
7.2 What a NAS message looks like on the wire
Read the first two octets and you know almost everything: which protocol, and whether the rest is protected, or which session it belongs to. The third octet tells you which message it is.
- 8.1 From a document number to a published version
-
9.1 One CT1 meeting, by the numbers
Five working days at a time, nine meetings from August 2025 to November 2026, in a different part of the world each time. Everything else in this chapter follows from how little time that is for how much paper.
-
10.1 Who CT1 writes to, and what the letters count
CT1 sent 108 letters out in the year and received 135 in. Whatever else CT1 is, it is a group that spends a lot of its time asking other groups questions.
-
11.1 The work items that fill a CT1 year
219 work items, 4235 documents, one group. Six names lead the list, and every other work item shares the rest.
-
12.5 The neighbours — and how little the record says about them
CT1's edge is not where its subject ends. It is where a document stops being about what the device says and starts being about what the network decides, how it is secured, or how the radio carries it.
-
13.1 Following CT1 yourself
Two of those seven answer questions this course cannot: the status report says who owns a specification that is not CT1's, and the work plan says what a work item name stands for.
-
14.1 What this record cannot tell you
The register counts paper. Nothing in it is evidence of intent, agreement, disagreement or reasoning, and no chapter of this course claims otherwise.
Easy to get wrong
-
1.3 What CT1 is, and the three names it answers to
Searching for "CT1" in the wrong store finds nothing. This is not a naming quirk to smile at — it is the single most common reason somebody concludes a document or a meeting does not exist when it does. Match the store:
C1in the catalogue,C1-in front of a document number, "3GPP CT 1" in the calendar. -
2.4 Stage 3 — the difference between a plan and a protocol
"Stage 3 is the detailed version of stage 2" is the mistake that wastes the most time. It leads people to read the architecture document, form a picture, and then argue with the protocol document when the picture does not fit. The protocol document is not elaborating on the architecture — it is answering a different question, and it is the one an implementation has to obey.
-
3.2 What CT1 owns — 229 documents and the six that matter
"Active" is a flag in the catalogue, not a promise that anybody is working on the document. A specification can be active, have had no change proposed to it for years, and still be the thing an implementation has to obey. Do not read the 229 as 229 live pieces of work.
-
4.3 TS 24.501 — two protocols living in one document
The NAS has no link of its own. It is glued together out of two other connections that other documents define, which is why a NAS procedure can fail for reasons that have nothing to do with NAS — the radio side dropped, or the leg between the base station and the core did. The document handles this explicitly, as "lower layer failure", in the abnormal-case subclause of nearly every procedure.
-
5.3 Finding your way around TS 24.501
Reading clause 5 without clause 4 produces confident wrong answers. A registration procedure in clause 5 will say the device applies unified access control before sending — and the rules for what that means, which category applies and what happens when access is barred are entirely in clause 4.
-
6.4 Getting on the network, and getting a connection through it
A 5G-GUTI is not an account number. It is deliberately replaced, and code that treats it as a stable key for a subscriber will break the first time the network reassigns one — which the specification requires it to do on every successful initial registration.
-
7.4 What a NAS message looks like on the wire
An information element identifier is not a global name. The same hexadecimal value means one thing in a registration request and something else in a service accept, so a parser that keeps one table of identifiers for the whole protocol will decode fields into the wrong shape. The identifier is only meaningful inside its message.
-
8.3 From a document number to a published version
A document number and a change request number are different things and neither can be worked out from the other. C1-262074 is a document filed to a CT1 meeting; 7174 is the change request number against TS 24.501; CP-261125 is the document under which the change reached the meeting recorded in the change history. Three numbers, one change, and the change history only holds two of them.
- 9.3 One CT1 meeting, by the numbers
-
10.2 Who CT1 writes to, and what the letters count
Both tables stop at four on purpose: the register carries the four busiest partners in each direction and no more. A group missing from them has no entry at all, so its absence is not a zero and no number may be quoted for it. This is the single easiest mistake to make with this data.
-
11.2 The work items that fill a CT1 year
A work item name is not an abbreviation the register can explain. "TEI19", "5GSAT_Ph3_ARCH" and "MINT_Ph2" are labels a document carried; anybody translating them is using knowledge from somewhere else. Where a specification defines the term in its own text, that is a citable source — and where it does not, the honest answer is that the name is just a name.
- 12.1 The neighbours — and how little the record says about them
-
13.3 Following CT1 yourself
The six counted words do not add up to the 617 documents at that meeting [7], and the two uncounted words are why. Never work out a missing outcome by subtracting the ones you have — the answer will be wrong and will look convincing.
-
14.3 What this record cannot tell you
Both mistakes produce numbers that look derived rather than invented, which is exactly what makes them dangerous. A number nobody counted is not more trustworthy for having been calculated from two that somebody did.
The numbers, and where each came from
Every one was counted out of a file on this machine. Hover a row to read the question that produced it.
- 4 4 CT1 office holders have no end date on record
- 44 44 CT1 terms of office are on record
- 105699 105699 CT1 documents on record
- 2005-2026 CT1 documents on record run from 2005 to 2026
- 4235 4235 CT1 documents in the twelve months to 2026-08-04
- 237 237 specifications listed against CT1
- 229 229 active CT1 specifications
- 8 8 CT1 specifications no longer active
- 184 184 CT1 meetings are listed, held and planned
- 172 172 CT1 meetings had started by 2026-08-04
- 2005-04-25 the earliest CT1 meeting on record started 2005-04-25
- 133 133 CT1 meetings have documents on record
- 415 415 different organisations put a document to CT1 in the twelve months to 2026-08-04
- 447 447 CT1 documents from Huawei, HiSilicon in the twelve months to 2026-08-04
- 338 338 CT1 documents from Ericsson in the twelve months to 2026-08-04
- 317 317 CT1 documents from Nokia in the twelve months to 2026-08-04
- 15623 15623 CT1 documents change 24.501 (Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3), over the whole record
- 199 199 active CT1 technical specifications (TS)
- 30 30 active CT1 technical reports (TR)
- 175 175 active CT1 specifications in the 24 series
- 16 16 active CT1 specifications in the 23 series
- 149 149 active CT1 specifications have a Rel-18 version
- 154 154 active CT1 specifications have a Rel-19 version
- 31 31 active CT1 specifications have a Rel-20 version
- 5422 5422 CT1 documents change 24.301 (Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3), over the whole record
- 3413 3413 CT1 documents change 24.229 (IP multimedia call control protocol based on Session Initiation Protocol (SIP) and Session Description Protocol (SDP); Stage 3), over the whole record
- 2447 2447 CT1 documents change 23.122 (Non-Access-Stratum (NAS) functions related to Mobile Station (MS) in idle mode), over the whole record
- 2364 2364 CT1 documents change 24.379 (Mission Critical Push To Talk (MCPTT) call control; Protocol specification), over the whole record
- 2064 2064 CT1 documents change 24.554 (Proximity-services (ProSe) in 5G System (5GS) protocol aspects; Stage 3), over the whole record
- 499 499 CT1 documents change 24.301 (Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3), in the twelve months to 2026-08-04
- 498 498 CT1 documents change 24.501 (Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3), in the twelve months to 2026-08-04
- 430 430 CT1 documents change 24.369 (Ambient IoT Non-Access-Stratum (AIoT NAS) protocol for 5G System (5GS); Stage 3), in the twelve months to 2026-08-04
- 165 165 CT1 documents change 24.860 (Study on NAS protocol for 6G System), in the twelve months to 2026-08-04
- 162 162 CT1 documents change 24.554 (Proximity-services (ProSe) in 5G System (5GS) protocol aspects; Stage 3), in the twelve months to 2026-08-04
- 144 144 CT1 documents change 23.122 (Non-Access-Stratum (NAS) functions related to Mobile Station (MS) in idle mode), in the twelve months to 2026-08-04
- 143 143 CT1 documents change 24.543 (Data delivery management - Service Enabler Architecture Layer for Verticals (SEAL); Protocol Specification;), in the twelve months to 2026-08-04
- 125 125 CT1 documents change 24.548 (Network Resource Management - Service Enabler Architecture Layer for Verticals (SEAL); Protocol specification), in the twelve months to 2026-08-04
- 157 157 of 229 active CT1 specifications have parsed text on this machine
- 71679 71679 CT1 documents of kind 'CR' over the whole record
- 2835 2835 CT1 documents of kind 'CR' uploaded on or after 2025-08-04
- 563 563 CT1 documents of kind 'pCR' uploaded on or after 2025-08-04
- 9772 9772 CT1 documents of kind 'pCR' over the whole record
- 174 174 documents were agreed at C1-161
- 617 617 documents were put to C1-161
- 259 259 documents came out of C1-161 as 'revised'
- 70 70 documents came out of C1-161 as 'postponed'
- 53 53 documents came out of C1-161 as 'noted'
- 33 33 documents came out of C1-161 as 'merged'
- 19 19 documents came out of C1-161 as 'withdrawn'
- 87 87 CT1 documents of kind 'WID new' uploaded on or after 2025-08-04
- 136 136 CT1 documents of kind 'SID new' uploaded on or after 2025-08-04
- 197 197 CT1 documents of kind 'discussion' uploaded on or after 2025-08-04
- 172 172 people are listed as taking part in C1-161
- 165 165 people are listed as taking part in C1-160
- 9 9 new or revised work items were agreed at C1-161
- 5 5 new or revised work items were agreed at C1-160
- 69 69 documents are already filed under C1-162
- 2026-07-31 10:40:59 the newest CT1 document on record was uploaded 2026-07-31 10:40:59, for meeting C1-162
- 108 108 CT1 documents of kind 'LS out' uploaded on or after 2025-08-04
- 135 135 CT1 documents of kind 'LS in' uploaded on or after 2025-08-04
- 3002 3002 CT1 documents of kind 'LS out' over the whole record
- 2507 2507 CT1 documents of kind 'LS in' over the whole record
- 44 44 outgoing liaison statements to RAN2 in the twelve months to 2026-08-04
- 19 19 outgoing liaison statements to SA2 in the twelve months to 2026-08-04
- 8 8 outgoing liaison statements to CT4 in the twelve months to 2026-08-04
- 5 5 outgoing liaison statements to SA1 in the twelve months to 2026-08-04
- 39 39 incoming liaison statements from SA2 in the twelve months to 2026-08-04
- 15 15 incoming liaison statements from RAN2 in the twelve months to 2026-08-04
- 10 10 incoming liaison statements from SA3 in the twelve months to 2026-08-04
- 7 7 incoming liaison statements from CT4 in the twelve months to 2026-08-04
- 7181 7181 CT1 documents carry no upload date
- 219 219 named work items received CT1 documents in the twelve months to 2026-08-04
- 420 420 CT1 documents for the work item AmbientIoT-CT in the twelve months to 2026-08-04
- 200 200 CT1 documents for the work item TEI19 in the twelve months to 2026-08-04
- 192 192 CT1 documents for the work item 5GSAT_Ph3_ARCH in the twelve months to 2026-08-04
- 172 172 CT1 documents for the work item MINT_Ph2 in the twelve months to 2026-08-04
- 170 170 CT1 documents for the work item FS_6G_NAS_CT in the twelve months to 2026-08-04
- 142 142 CT1 documents for the work item 5G_ProSe_Ph3 in the twelve months to 2026-08-04
The document's own words
One quotation per chapter that carries one, of 16.
-
1.5 What CT1 is, and the three names it answers to
The present document is applicable to the UE, the access and mobility management function (AMF), the session management function (SMF), and the PCF in the 5GS.
-
2.2 Stage 3 — the difference between a plan and a protocol
The following documents contain provisions which, through reference in this text, constitute provisions of the present document.
-
4.3 TS 24.501 — two protocols living in one document
The non-access stratum (NAS) described in the present document forms the highest stratum of the control plane between the UE and the AMF (reference point "N1" see 3GPP TS 23.501 [8]) for both 3GPP and non-3GPP access.
-
5.4 Finding your way around TS 24.501
At any time only one UE initiated 5GMM specific procedure can be running for each of the access network(s) that the UE is camping on.
-
6.1 Getting on the network, and getting a connection through it
The registration procedure is always initiated by the UE and used for initial registration as specified in clause 5.5.1.2.2 or mobility and periodic registration update as specified in clause 5.5.1.3.2.
-
7.3 What a NAS message looks like on the wire
A 5GMM message received with the security header type encoded as 0000 shall be treated as not security protected, plain 5GS NAS message.
-
8.6 From a document number to a published version
The contents of the present document are subject to continuing work within the TSG and may change following formal TSG approval. …
-
10.4 Who CT1 writes to, and what the letters count
When the UE is in 5GMM-IDLE mode over 3GPP access and needs to transmit an initial NAS message, the UE shall request the lower layer to establish an RRC connection.
-
11.3 The work items that fill a CT1 year
The UE and the network may support Minimization of service interruption (MINT). MINT aims to enable a UE to obtain service from a PLMN offering disaster roaming services when a disaster condition applies to the UE determined PLMN with disaster condition.
The words
19 the course explains, out of 201 the document defines — all of them.
- 5G-GUTI
- 5G-Globally Unique Temporary Identifier
- 5G-S-TMSI
- 5G S-Temporary Mobile Subscription Identifier
- 5GMM
- 5GS Mobility Management
- 5GS
- 5G System
- 5GSM
- 5GS Session Management
- AIoT
- Ambient Internet of Things
- AKA
- Authentication and Key Agreement
- AMF
- Access and Mobility Management Function
- DNS
- Domain Name System
- EPS
- Evolved Packet System
- IMEI
- International Mobile station Equipment Identity
- IMEISV
- International Mobile station Equipment Identity and Software Version number
- MAC
- Message Authentication Code
- MINT
- Minimization of Service Interruption
- ProSe
- Proximity based Services
- SMF
- Session Management Function
- SNPN
- Stand-alone Non-Public Network
- SUCI
- Subscription Concealed Identifier
- SUPI
- Subscription Permanent Identifier
Where to look it up
The 64 clauses of TS 24.501 this course is built from.
§Foreword§1§2§3.1§3.2§4.1§4.2§4.5.6§4.23.1§4.24§5.1.1§5.1.2§5.1.3.2.1§5.1.3.2.2§5.1.3.2.3§5.3.1.1§5.3.3§5.4.1.1§5.4.2.1§5.4.3.1§5.5.1.1§5.5.1.2.1§5.5.1.3.1§5.5.2.1§6.1.1§6.1.2§6.1.3.2.2§6.1.3.2.4§6.2.1§6.2.2§6.2.3§6.3.1.1§6.3.2.1§6.3.3.1§6.4.1.1§6.4.2.1§6.4.3.1§7.1§7.4§7.7§7.8§8.1§8.2.28§9.1.1§9.1.2§9.2§9.3§9.4§9.5§9.6§9.7§9.8§9.9§9.10§10.1§10.2§Annex A§A.1§Annex B§B.2§Annex C§Annex D§Annex E§Annex F
The 71 named sources it cites, by what they are.
Specification 27
TS 24.501TS 24.007TS 24.301TS 24.229TS 24.554TS 24.587TS 24.193TS 24.369TR 21.904TR 27.903TR 29.846TS 04.08TS 03.68TS 09.08TS 23.122TS 24.379TR 24.860TS 24.008TS 24.543TS 24.548TS 24.588TS 24.558TS 24.526TS 24.502TR 24.801TR 24.890TR 23.700-10
Meeting document 21
C1-262074C1-262440C1-262442C1-262554C1-262596C1-262597C1-262610C1-262611C1-262612C1-262617C1-261459C1-261460C1-261599C1-261602C1-261603C1-262254C1-262227C1-262258C1-262144C1-262343C1-262064
Meeting 9
C1-156C1-157C1-158C1-159C1-160C1-161C1-162C1-163C1-164
Page on the standards body's own site 7
The 3GPP work planThe 3GPP specification status reportThe CT1 file area on the 3GPP serverThe CT1 mirror area on the 3GPP serverCT1 documents on whatthespec.netThe 3GPP meeting calendar on whatthespec.netThe CT1 list of office holders
Official 4
CT1 Chair: CHAPONNIERE, LenaCT1 Vice Chair: AGHILI, BehrouzCT1 Vice Chair: WON, Sung HwanCT1 Secretary: BIONDIC, Nevenka
Report 2
CT1 meeting report C1-161CT1 meeting report C1-160
Working group 1
CT1 — Mobility, call control, session management (WG1_mm-cc-sm_ex-CN1)
Where to go from here
- The same subject, quick start — Under an hour, four chapters, the shape of the thing.
- The same subject, overview — Enough to follow the conversation and know what to look up.
- Every question of this course — 73 of them, on one page.
- The final test — 20 questions, 70 per cent to pass.
- The whole of TS 24.501 — all 1340 clauses.
- Every source behind the course — 354 of them, each with its method.
The raised numbers on this page
- 71679 CT1 documents of kind 'CR' over the whole record — rows in the pygppe document database, table tdoc where meeting starts with 'C1-' and tdoctype='CR', read 2026-08-04
- 105699 CT1 documents on record — rows in the pygppe document database, table tdoc where meeting starts with 'C1-', read 2026-08-04
- CT1 meeting report C1-161 — the Markdown conversion pygppe keeps at /var/www/whatthespec.net/data/data/meetings/ftp.3gpp.org/tsg_ct/WG1_mm-cc-sm_ex-CN1/TSGC1_161_Dalian/Report/Draft_CT1_161_meeting_report_v100/Draft_CT1_161_meeting_report_v100.md, read 2026-08-04
- CT1 meeting report C1-160 — the Markdown conversion pygppe keeps at /var/www/whatthespec.net/data/data/meetings/ftp.3gpp.org/tsg_ct/WG1_mm-cc-sm_ex-CN1/TSGC1_160_Malta/Report/CT1_160_meeting_report/CT1_160_meeting_report.md, read 2026-08-04
- The 3GPP specification status report — pygppe libs/pygpp/pygpp_globals.py:134, glob['3gpp_specs_url']; address checked against pygppe's source 2026-08-04
- The 3GPP work plan — pygppe libs/pygpp/pygpp_globals.py:133, glob['3gpp_wp_url']; address checked against pygppe's source 2026-08-04
- 617 documents were put to C1-161 — rows in the pygppe document database, table tdoc where meeting='C1-161', read 2026-08-04