Ambimat GroupAmbimatAmbiSecureV2XeSIMAmbiAutomationAhmedabad · India · Est. 1982
Technology reference

C-V2X — cellular vehicle-to-everything, from Release 14 to Release 19.

C-V2X is the radio technology that carries V2X messages, built on the same engineering as mobile phone networks. The “C” is for cellular.

That name misleads people, so it is worth clearing up immediately: most C-V2X does not use a mobile network at all. It has two separate modes. In one, vehicles talk directly to each other, phone-to-phone style, with no tower, no SIM card and no subscription — this is the mode that carries all the safety messaging, and it works in a tunnel or a blackspot. In the other, the vehicle uses an ordinary mobile connection to reach a server, which is useful for things like map updates and hazard information from far away, but far too slow for a collision warning.

C-V2X exists because it beat the alternative. For about a decade there were two competing technologies for the direct mode — one derived from Wi-Fi, one derived from mobile technology. Since 2018, every country that has made a choice has picked C-V2X: the United States, China, South Korea, Japan and India. The comparison, and why it went that way →

If you only need that much, how V2X works is the better page. What follows is the engineering.


The precise version. C-V2X is not “V2X over a cellular network.” The safety-critical half of it never touches a network at all. C-V2X is a 3GPP-defined family with two distinct interfaces: PC5, a direct device-to-device sidelink that works with no base station, no SIM and no coverage, and Uu, the conventional cellular link to a base station and a server. Almost everything people mean by “C-V2X safety” is PC5.

1 · The two interfaces

PC5 is the sidelink. Uu is the network. They do different jobs.

 PC5Uu
PathDevice to device, directDevice → base station → core → server
Coverage requiredNoYes
Subscription requiredNo — the Qualcomm 9150 explicitly supports USIM-less operationYes
LatencyAir-interface only, ~15 ms end to end for a small packetTens to hundreds of ms
CarriesV2V, V2I, V2P safety messagingV2N, V2C, certificate batches, OTA, MEC
ITS bandn47, 5855–5925 MHz globallyOperator's licensed bands

PC5 channel bandwidths are 10, 20, 30 and 40 MHz. What each jurisdiction has allocated →

2 · The release history

Five releases, and the thing to understand is that Release 14 is still what ships.

ReleaseFrozenWhat it added
Rel-14June 2017LTE-V2X. First C-V2X. Sidelink over PC5, Modes 3 and 4, broadcast only. This is the basis of essentially every commercial C-V2X deployment through 2026.
Rel-15June 2019 (ASN.1)LTE-V2X enhancements: 64-QAM on sidelink, carrier aggregation up to 8 carriers, transmit diversity, latency reduction. Also the first 5G NR release — but NR sidelink was not yet specified.
Rel-16July 2020NR-V2X sidelink. Unicast, groupcast and broadcast; HARQ feedback; CSI reporting; QoS via SDAP; Modes 1 and 2; 256-QAM. Designed explicitly to complement, not replace, LTE-V2X.
Rel-17March 2022Sidelink DRX and partial sensing for power-limited VRU devices; inter-UE coordination to reduce hidden-node collisions; sidelink relay.
Rel-18Stage 3 frozen March 2024; ASN.1 June 20245G-Advanced: sidelink on unlicensed spectrum (SL-U) with listen-before-talk; sidelink positioning with SL-PRS, targeting 1.5 m or 0.5 m horizontal accuracy at 90% of UEs for V2X; sidelink carrier aggregation; FR2 sidelink up to 400 MHz channel bandwidth with beam management.
Rel-19Frozen December 2025 (TSG#106); Stage 3 September 2025, ASN.1 December 2025, RAN4 performance March 20265G-Advanced phase 2, and now complete rather than in prospect. Sidelink work carried into it includes sidelink positioning and ranging, and NR sidelink multi-hop UE-to-network relay.
3 · Resource allocation

How a device decides which slice of spectrum to transmit in, with no scheduler.

This is the heart of what makes C-V2X different from Wi-Fi-derived DSRC.

LTE-V2X (Rel-14):

  • Mode 3 — network-scheduled. The eNB assigns sidelink resources via downlink control information. Requires in-coverage operation. Little to no commercial deployment.
  • Mode 4 — autonomous and distributed, and what everything actually uses. The device performs sensing-based semi-persistent scheduling: it decodes sidelink control information and measures received power over a 1,000 ms sensing window, excludes resources it can see are reserved or occupied, then selects randomly from the cleanest roughly 20% of candidate resources within a selection window. It works fully out of coverage.

NR-V2X (Rel-16) renames these Mode 1 and Mode 2 and adds substantially:

  • Mode 1 — network-scheduled, with dynamic grants plus Configured Grant Type 1 (RRC-configured, immediately usable) and Type 2 (RRC-configured, DCI-activated)
  • Mode 2 — autonomous, sensing window from 1,100 ms to 100 ms before the trigger for periodic traffic, up to three resource reservations signalled in the control information, and pre-emption: higher-priority traffic can take a resource reserved by lower-priority traffic

Congestion control in both is driven by two measurements: Channel Busy Ratio, computed every 4 ms in LTE-V2X and every 1 or 2 ms in NR-V2X, and Channel occupancy Ratio over 1,000 ms. Both feed priority-weighted adaptation of modulation and coding scheme, transmit power and duty cycle.

4 · NR-V2X in detail

What Release 16 added, for engineers who need the specifics.

  • Physical channels: PSCCH (control, first-stage SCI), PSSCH (data plus second-stage SCI and the transport block), PSFCH (one-bit HARQ feedback), PSBCH (sidelink MIB, 160 ms periodicity), and S-SSB for synchronisation.
  • Two-stage SCI: the first stage on PSCCH carries resource reservation and is decodable by everyone for sensing; the second stage on PSSCH carries source and destination IDs, HARQ process, CSI request and cast type.
  • Numerology: μ = 0/1/2 in FR1 giving 15/30/60 kHz subcarrier spacing and 1/0.5/0.25 ms slots; 60/120 kHz in FR2. Fourteen OFDM symbols per slot with normal cyclic prefix. No mini-slot scheduling on sidelink in Release 16.
  • Sub-channel — the smallest allocation unit — is 10, 12, 15, 20, 25, 50, 75 or 100 physical resource blocks.
  • Exactly one sidelink bandwidth part is pre-configured per carrier for all devices, unlike NR uplink/downlink which allow up to four.
  • HARQ: ACK/NACK for unicast and groupcast option 2; NACK-only for groupcast option 1, where receivers inside a distance or zone signal only failure. PSFCH resources are configured with a period of 1, 2 or 4 slots.
  • Modulation up to 256-QAM, with a default MCS table plus up to two further tables configurable per resource pool.
  • QoS: an SDAP layer is added to the sidelink user plane, and a PC5 QoS Identifier replaces LTE's ProSe Per-Packet Priority.
5 · Coexistence

LTE-V2X and NR-V2X cannot share a channel. This is the spectrum argument in one sentence.

3GPP designed NR-V2X to complement LTE-V2X, and there is no in-band coexistence. Separation is by carrier: LTE-V2X on one 10 or 20 MHz channel, NR-V2X on another. Dual-mode chipsets — Autotalks TEKTON3, Qualcomm's current automotive platforms — run both radios concurrently. The silicon →

The practical consequence is that a 30 MHz allocation, as in the US and as planned in Japan, is tight: it has to host a legacy LTE-V2X Day-1 channel, an NR-V2X Day-2 channel, and leave room for growth. 78% of respondents to ITS America's 2024 survey supported allocating additional spectrum beyond 30 MHz. India's proposed 50 MHz, with 30 MHz for initial deployment and 20 MHz reserved for future ITS, is a more comfortable starting position — and is one of the genuinely well-judged parts of the Indian proposal. Spectrum, jurisdiction by jurisdiction →

6 · The Uu side needs a subscription

And that is an eSIM problem.

The half of C-V2X nobody sizes until late.

PC5 needs no SIM, no subscription and no operator relationship. Uu needs all three. And because Uu is what delivers certificate batches, trust-list updates, revocation material and firmware, a vehicle whose Uu path is not working is a vehicle that will eventually stop being able to sign messages. The connectivity is not an optional convenience feature sitting alongside the safety function; it is part of the safety function's supply chain.

That creates a specific and awkward requirement, and it is not really a V2X requirement at all. It is a cellular-identity requirement, with three properties that rule out a conventional SIM card:

  • Service life. A vehicle is on the road for fifteen years or more. Nobody is opening a sealed automotive telematics unit to change a SIM in year nine — and in many designs there is no accessible slot to open.
  • Market mobility. A vehicle built on one line is sold into several markets, exported, re-registered, resold across borders. Its cellular profile has to change without the hardware changing.
  • Scale and automation. Millions of units, provisioned at the factory before anyone knows which operator will serve them, and re-provisioned remotely afterwards.

That is precisely the problem eSIM and eUICC were designed for, and it is why automotive is one of the largest embedded-SIM segments in the world. The relevant specification for this class of device is GSMA SGP.32, the IoT variant of remote SIM provisioning, designed for devices with no user interface and no human to tap “confirm”.

The structural parallel is worth noticing, because it is not a coincidence. Set the two credential architectures side by side:

 eSIM remote provisioningV2X PKI
Long-term device identityeUICC identity (EID), bound to the chip at manufactureEnrolment Credential, bound to the secure element at manufacture
Operational credentialOperator profile, remotely installed and switchablePseudonymous certificate / authorisation ticket, rotated on a schedule
Issuing infrastructureSM-DP+ prepares and delivers; SM-DS discoversAuthorisation Authority issues; Enrolment Authority vouches
Provisioning triggerRemote, authenticated, no physical accessRemote, authenticated, no physical access
WithdrawalProfile deletion or disablementRevocation, or the authority simply declining to reissue
Where the secret livesInside the eUICC's tamper-resistant boundaryInside the secure element's tamper-resistant boundary

Two industries, twenty years apart, arriving independently at the same architecture: a hardware-bound long-term identity that never moves, issuing short-lived operational credentials that do, provisioned remotely, revocable without touching the device. Anyone designing V2X credential lifecycle from scratch should read the telecom answer first — it is a decade further along, and it has already made most of the available mistakes at national scale.

And in a real on-board unit, both credentials frequently live on the same silicon. A JavaCard secure element can host a V2X identity applet and a SIM applet as separate, isolated applications on one chip, each with its own security domain. That is a bill-of-materials decision with consequences: one part instead of two, one provisioning step instead of two, one attack surface to certify — and one supplier relationship that has to understand both domains.

Ambimat's work on the telecom side runs on a separate property. eSIM and eUICC architecture → · How remote SIM provisioning actually works → · Multi-applet secure elements →

Frequently asked

Questions this page answers.

What does C-V2X stand for?

Cellular Vehicle-to-Everything. It is the 3GPP-standardised family of V2X radio technologies, comprising LTE-V2X from Release 14 and NR-V2X from Release 16.

What is C-V2X, simply?

C-V2X is the radio technology that carries V2X messages between vehicles and infrastructure, built on the same engineering used by mobile phone networks. Despite the name, its safety-critical mode does not use a mobile network: vehicles transmit directly to each other with no tower, no SIM card and no subscription. It is the technology every country that has made a choice since 2018 has selected.

Why is it called cellular if it does not use a mobile network?

Because it reuses the engineering — the modulation, the coding, the way the radio is organised — developed for mobile networks, not because it needs one. That inherited design is why it performs better than the Wi-Fi-derived alternative on range and under congestion. The direct mode, called the sidelink, is the same technology operating without a tower in the path.

Is C-V2X the same as 5G?

No. C-V2X began with LTE in Release 14 and remains overwhelmingly LTE-based in deployment. NR-V2X, introduced in Release 16, is the 5G variant. A device can be C-V2X capable without being 5G capable.

Does C-V2X need a SIM card or a mobile subscription?

Not for direct safety messaging. PC5 sidelink operation requires neither. The Qualcomm 9150 chipset explicitly supports USIM-less operation. A subscription is only needed for the V2N side — network-delivered services, certificate provisioning over cellular, and OTA updates.

Why does C-V2X need GPS?

Two reasons. The obvious one: the position in the message payload. The less obvious and more important one: C-V2X devices synchronise their transmission timing to GNSS time so that subframe boundaries align across all devices, which is what makes the time-and-frequency-division resource allocation work. A device can also synchronise from a base station or from a neighbouring device acting as a sidelink synchronisation reference, which is how tunnels and urban canyons are handled.

What is the difference between LTE-V2X and NR-V2X?

LTE-V2X (Release 14) is broadcast-only with blind HARQ retransmission, SC-FDMA, turbo coding and a 64-QAM ceiling. NR-V2X (Release 16) adds unicast and groupcast, feedback-based HARQ, CP-OFDM with LDPC coding, 256-QAM, flexible numerology and much finer congestion measurement. NR-V2X targets the advanced use cases — collective perception, manoeuvre coordination, teleoperation — that LTE-V2X cannot meet.

Can LTE-V2X and NR-V2X run on the same channel?

No. There is no in-band coexistence. They must be on separate carriers, which is why spectrum quantity matters so much to the long-term roadmap.

Does a C-V2X on-board unit need an eSIM?

For direct safety messaging over PC5, no — that path needs no SIM and no subscription at all. But the network side, Uu, does, and Uu is what delivers certificate batches, trust-list updates and firmware. Because a vehicle is on the road for fifteen years, is sold across markets, and has no accessible SIM slot, that connectivity is almost always provided by an embedded SIM under GSMA's remote provisioning specifications rather than a removable card. eSIM and eUICC.

How is V2X PKI related to eSIM provisioning?

They are structurally the same problem solved in two industries. Both bind a long-term identity to tamper-resistant hardware at manufacture, use it to obtain short-lived operational credentials, provision those remotely to a device nobody will physically touch again, and withdraw them without a recall. eSIM's SM-DP+ and SM-DS map closely onto V2X's Authorisation and Enrolment Authorities. Telecom is roughly a decade ahead on operating this at national scale, which makes it worth studying. Remote SIM provisioning architecture.