GSMA SGP.22 v3.0: What the Latest eSIM Standard Means for Travelers
An analysis of the updated Remote SIM Provisioning specification and its practical implications for consumer eSIM devices in 2025.
Read analysis →Independent technical analysis and editorial coverage of embedded SIM technology, network standards, and mobile connectivity across Europe. Built for engineers, researchers, and informed travelers.
An analysis of the updated Remote SIM Provisioning specification and its practical implications for consumer eSIM devices in 2025.
Read analysis →Examining 5G NR deployment progress and eSIM compatibility across Berlin, Paris, Amsterdam, Madrid, and Warsaw.
Read analysis →A technical examination of the cryptographic mechanisms that make eSIM more resistant to SIM-swapping attacks than physical SIM cards.
Read analysis →The eSIM ecosystem is built on a layered architecture defined by the GSMA's RSP (Remote SIM Provisioning) specifications. Understanding this architecture is essential for anyone working with eSIM technology professionally or making informed decisions as a consumer.
At the hardware level, the eUICC (embedded Universal Integrated Circuit Card) is a tamper-resistant secure element containing a Java Card operating system. This chip stores operator profiles — each containing the authentication keys, network credentials, and service parameters needed to connect to a specific carrier's network.
The provisioning infrastructure consists of two main server types: the SM-DP+ (Subscription Manager Data Preparation Plus), which prepares and stores operator profiles, and the SM-DS (Subscription Manager Discovery Service), which helps devices discover available profiles. When you scan a QR code to activate an eSIM, your device contacts the SM-DP+ server encoded in that QR code.
Read Full Technical GuideTamper-resistant secure element with Java Card OS. Stores up to 8+ operator profiles. Cryptographically isolated from main processor.
Software layer on the device that manages profile downloads, activation, and deletion. Provides the user interface for eSIM management in device settings.
Operator-side infrastructure for profile preparation and secure delivery. Authenticates device eUICC before profile download using PKI certificates.
Root of trust for the entire eSIM ecosystem. Issues certificates to device manufacturers and operators. GSMA acts as the primary CI for consumer eSIM.
| Manufacturer | Series | eSIM Support | Dual SIM | 5G |
|---|---|---|---|---|
| Apple | iPhone 14–16 | Full | Dual eSIM | Yes |
| Samsung | Galaxy S20–S24 | Full | Physical + eSIM | Yes |
| Pixel 3–9 | Full | Physical + eSIM | Pixel 5+ | |
| Xiaomi | Mi 11 Ultra, 12–13 | Partial | Region-dependent | Select |
| Motorola | Razr 40, Edge 40+ | Partial | Physical + eSIM | Select |
SGP.22 is the GSMA's technical specification for consumer eSIM (Remote SIM Provisioning for Consumer Devices). It defines the protocols for profile download, management, and the interfaces between devices, operators, and infrastructure servers.
eSIM profiles are cryptographically bound to specific eUICC chips using PKI certificates. Unlike physical SIMs, an eSIM profile cannot simply be moved to another device — any transfer requires authentication through the provider's infrastructure.
SM-DP+ (Subscription Manager Data Preparation Plus) is the server infrastructure operated by eSIM providers to prepare, store, and securely deliver operator profiles to consumer devices. It's the backend system your device contacts when you scan an eSIM QR code.
Yes. eSIM is network-generation agnostic — the same eSIM hardware and provisioning protocols work with 2G, 3G, 4G, and 5G networks, including both NSA (Non-Standalone) and SA (Standalone) 5G architectures.