What Did the Galileo Test on 16 September Show? Critical Infrastructure Must Know Whether It Can Trust the Navigation Signal
On 16 September 2026, a test carried out in Norway demonstrated a new dimension of satellite navigation security. Europe’s Galileo system was tested under so-called spoofing conditions — a situation in which a receiver is fed a fake signal and may therefore receive incorrect information about its position.
The result was significant. During the test, a conventional receiver was deceived and determined an incorrect position. A receiver using the new Galileo Signal Authentication Service (SAS), however, was able to verify the authenticity of the signal and maintain the correct position. This was the first demonstration of the technology under real-world spoofing conditions.
The difference compared with conventional jamming is fundamental. In the event of a signal outage, the system knows that the signal is unavailable. With spoofing, however, it may receive false information and treat it as valid.
Why does this matter for critical infrastructure?
A Global Navigation Satellite System (GNSS) is not just about navigation. Satellite signals also provide precise timing, which is used, for example, to synchronise telecommunications and electricity networks, as well as financial systems and data centres. If such a signal is manipulated, the problem may not be immediately visible. The system may continue to operate, but make decisions based on incorrect information.
For critical entities, this raises a simple but important question: It is not enough to know that we have a signal. Do we know that we can trust it?
What does the new Galileo SAS bring?
SAS is designed to enable a receiver to verify whether the data it uses to determine its position actually originates from an authentic Galileo signal. It complements the already operational Galileo OSNMA service, which has enabled the authentication of navigation messages since 2025. SAS adds another layer of protection: authentication of the measurements used to calculate position.
Europe will continue testing the technology. EUSPA plans to declare the Initial Service in 2027. This will mark the beginning of service provision to civil users, rather than its final form. Before then, the technology will continue to be validated on additional Galileo satellites.
“For critical infrastructure, it is no longer enough for a system simply to function. We need to know that it is operating with the correct data. If a system’s decision is based on an incorrect signal, the problem can be far greater than the loss of navigation itself,” says Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic.
What does this mean in practice?
For critical entities, the test is above all a prompt to map their dependence on GNSS and identify systems for which a manipulated signal could pose a risk.
In practice, they should assess:
* which systems use GNSS for positioning or precise timing,
* whether they have a backup source of time or positioning,
* whether they can distinguish between a signal outage and a manipulated signal,
* how operations will respond to the loss of, or loss of trust in, GNSS,
* and whether these scenarios are included in security and operational testing.
The Galileo test is therefore not merely a technological demonstration. It is a practical reminder that a critical entity needs to know which external signals its systems rely on, what happens when those signals can no longer be trusted, and how it will continue providing a basic service in such a situation.
For critical infrastructure, it is therefore necessary to assess not only the availability of data, but also its trustworthiness.









