Monday 5 October 2026 533 stories on file Full archive
Daily Edition
newscms

Volume III Edition Daily

Three Companies, One Week, One Idea: The SIM Card Is No Longer Part of the Device

For most of the cellular industry's commercial life, the question "which network does this thing talk to?" was answered with a physical object. A SIM card — that familiar cut-corner plastic rectangle — was inserted into…

IoT 1,992 words 10 min read

Three Companies, One Week, One Idea: The SIM Card Is No Longer Part of the Device — IoT No Image IoT
Lead image · Filed 4 October 2026, 23:44

Three Companies, One Week, One Idea: The SIM Card Is No Longer Part of the Device

Introduction

For most of the cellular industry's commercial life, the question "which network does this thing talk to?" was answered with a physical object. A SIM card — that familiar cut-corner plastic rectangle — was inserted into a slot, and it stayed there. If the operator behind it was acquired, if the network it depended on was decommissioned, or if the commercial contract expired, the remedy was a field visit: a truck, a ladder, a technician, and a swap. For a fleet of a few hundred devices that was an expense. For a utility with millions of electricity meters on poles and walls, it was a structural problem that quietly constrained how long any piece of communications hardware could be expected to live.

That assumption is now being dismantled, and in the space of a few days in late September and early October 2026, three separate corners of the supply chain announced work that all attack it from a different direction. Aeris, the Chicago-based secure connectivity platform, launched a next-generation eSIM orchestrator built around the GSMA SGP.32 specification, aimed at operators, OEMs and enterprises that need to reprogram connectivity across large fleets. Kigen, the UK eSIM and iSIM supplier, announced the industry's first GSMA eUICC Security Assurance (eSA) certified automotive eSIMs supporting SGP.32 v1.3, the hardware-layer counterpart. And Thales, working with meter manufacturer Landis+Gyr, put SGP.32 into actual smart meter deployments across North America through the Revelo and Surent platforms.

Taken together, these are not three variations on a product launch. They are a platform, a chip, and a deployment — and the fact that all three landed within about ten days is the clearest signal yet that SGP.32 has moved from standards work into commercial delivery. This is the story of what actually changed, and what has to change next for it to matter.

The Standard Nobody Could Deploy at Scale

The reason SIM cards were physical for so long is not a failure of engineering. It is that eSIM management, until recently, was built for the wrong workload. Consumer eSIM, standardised as SGP.22, is designed for a human being holding a phone. Someone taps, scans a QR code, or reads a long activation code off a screen, and one profile moves onto one device. That is a fine model for a person and a terrible one for a logistics company with 80,000 asset trackers.

The machine-to-machine standard, SGP.02, came later but retained a profile-by-profile management model. Operators could push new profiles to individual devices, which is functionally the same as the old SIM card with a more expensive delivery mechanism. GSMA addressed the gap with SGP.32, published in successive versions, which defines an architecture for IoT eSIM remote management: an IoT Remote Manager (eIM) on the platform side and an IoT eUICC on the device side, with profile operations driven by policies and events rather than manual per-device commands.

That distinction is the whole story. Aeris' Chief Product Officer, Jon Connet, put it plainly in the company's own announcement: the difficulty "isn't changing a SIM profile on one device; it's doing it reliably across thousands or millions of devices." Kigen's CEO Vincent Korstanje framed the same requirement from the hardware side — vehicles are "long-lived software platforms, so their connectivity trust anchor must remain secure and manageable long after production."

For the wider Internet of Things industry, this matters because it converts connectivity from a procurement decision made once, at manufacture, into an operational capability exercised continuously across an installed base.

What Aeris Actually Shipped

Aeris' October 1 announcement, covered in its own press release, introduced three capabilities under the Aeris IoT Accelerator platform, which previously ran under the name eSIM Hub.

The first is SGP.32 eSIM orchestration for automated profile management: instead of instructing one device at a time, customers define policies and events that determine which local profile a device holds, when it downloads it, what that profile is permitted to do, and what happens when an operation fails. The second is Single SKU eSIM, which lets an OEM ship one device variant globally and let an enterprise assign the appropriate local operator profile after deployment — removing the need for market-specific SIM trays or regional hardware variants. The third is eIM as a Service, a fully managed remote manager integrated into IoT Accelerator, with an alternative path for customers who already run their own eIM from Thales, G+D, Kigen or IDEMIA.

The scale numbers attached to that announcement give the move some context. Aeris says IoT Accelerator manages 110 million IoT devices, of which 44 million are eSIM-based — more than 40 percent of its installed base, against roughly 12 percent for the broader market. The platform serves more than 7,000 enterprises, devices attach in more than 200 countries every month, and about 70 percent of those attachments land on a partner's own network rather than through roaming. The company also says the platform is growing more than 20 percent year over year, and cites Frost & Sullivan and Counterpoint Research recognition. Orange Business EVP Elisabeth Reille framed the transition as strategic rather than technical, calling SGP.32 "a strategic enabler for enterprises managing connected devices across markets."

The Hardware Has To Catch Up

Orchestration software is only half a system. The other half is a secure element that can carry the new management model, and here Kigen moved first.

Kigen's September 23 announcement covers the industry's first eSA-certified eSIMs supporting SGP.32 v1.3. The eSA scheme is GSMA's security assurance certification for the eUICC itself; certification matters because it is a supply-chain gate, not a marketing claim — it means the hardware root has been independently assessed against defined attack scenarios.

The certified product pairs Kigen's eSIM OS with Infineon's TEGRION SLI22 automotive security controller. It forms a three-product portfolio sharing one OS, one hardware platform, one toolchain and one management stack: Automotive on SLI22, Consumer on SLC22 supporting SGP.22 v2.7, and Industrial IoT on SLM22 supporting SGP.32 v1.3. That shared platform is a deliberate commercial argument — an automaker can use the same security architecture across infotainment, telematics and headless vehicle systems rather than qualifying three separate stacks.

The version detail is also more than pedantry. SGP.32 v1.3, published in May 2026, adds direct and indirect profile downloads, digital activation codes, and emergency profile handling — the last of which is explicitly aimed at connected vehicles, where a connectivity profile may need to change under conditions nobody planned for. Kigen also highlighted post-quantum preparation: while PQC is not yet in the GSMA specifications, the company says OEMs can test hybrid classical-plus-quantum-safe key encapsulation on the same platform using its C-SDK. Sampling is planned from October 2026 in the ETSI MFF2 package. Gloria Trujillo, eSIM Technical Director at GSMA, and China Mobile International's Katherine Diao both appeared in the release, the latter noting a partnership to bring SGP.32-based security to Chinese automakers.

The Payoff Is Biggest Where Fleets Are Oldest

The deployment that demonstrates the commercial logic is the least glamorous and potentially the largest. Landis+Gyr and Thales announced a collaboration focused initially on smart meter deployments in North America, with Thales supplying eSIM technology and connectivity management and the resulting functions becoming part of Landis+Gyr's Revelo and Surent platforms. Per IoT Business News, the management layer will combine Thales technology with Simetric's connectivity platform and will support both conventional SIM and eSIM-enabled meters.

That last point is the one most press releases would bury. Utilities do not replace a meter estate in one procurement cycle, so a platform limited to new eSIM hardware would simply create a second management problem. Supporting both generations from a common operational layer is what makes remote provisioning useful across a mixed fleet rather than only in new deployments.

The numbers are large enough to make the economics obvious. Landis+Gyr says it serves more than 2,000 utilities and has more than 180 million connected intelligent devices in the field, and citing Berg Insight, the companies expect the North American installed base of smart electricity meters to rise from 152.4 million in 2024 to 180.9 million by 2030. At that scale, infrequent interventions multiply into field visits. The structural shift described here is that a network change becomes a software operation applied to one meter or a group of them, rather than a maintenance task. As the analysis in that report puts it, the value of remote provisioning "lies as much in operations after deployment as in eliminating SIM handling during installation."

What Still Has to Be Solved

Three announcements in ten days is momentum, not resolution, and the constraints are worth naming.

First, certification is a per-vendor process. Kigen's eSA achievement certifies its own eSIM on Infineon silicon; it does not certify the market. The lock-in question that industry analysts keep raising remains live: an OEM that adopts one eIM and one eUICC vendor's toolchain gains portability of profiles, not necessarily portability of management software. Aeris' answer — support eIMs from Thales, G+D, Kigen and IDEMIA — is the right shape of answer, but the depth of interoperability is not something a product announcement can establish.

Second, the security claims are forward-leaning by necessity. Emergency profile handling and hybrid post-quantum key encapsulation address real risks in vehicles and meters with service lives measured in decades, but PQC is explicitly not yet in the GSMA specifications. That is a statement about timelines, not about vendor roadmaps.

Third, none of this removes the physical constraint it is aimed at; it relocates it. A meter that can be reprogrammed remotely still has to be physically reachable for the first deployment, and it still sits somewhere that costs money to reach. Remote management changes the cost of the second intervention, not the first.

What is genuinely settled is the direction. Three companies on three different layers — platform, silicon, deployment — converged on the same specification inside a ten-day window, and the deployment case is anchored in an installed base measured in hundreds of millions of devices rather than in a demonstration.

Conclusion

The boring framing of the past fifteen years was that SIM cards were how IoT devices got onto networks. That framing is now out of date, and the last week of September and the first week of October 2026 is roughly when it stopped being current.

Aeris shipped the orchestration layer that makes profile management a policy problem instead of a logistics problem. Kigen shipped the certified hardware that lets that orchestration reach vehicles built to run for a decade or more. Thales and Landis+Gyr shipped the proof that it works where the field population is oldest and the cost of a truck roll is highest. None of those three announcements would have been routine a year ago; none of them is routine now.

For anyone deploying connected hardware at scale, the practical implication is narrower and more useful than any of the marketing. Treat the operator profile as configuration rather than as hardware, evaluate management platforms on how they handle a heterogeneous fleet that includes legacy SIM devices, and insist that your eIM and eUICC choices are portable. The companies that win the next phase of IoT connectivity will be the ones that make changing a fleet's network a line of software instead of a season of field work.

Images

Bare eUICC chip packages mounted on green carrier boards inside a clear storage box — the physical form factor that SGP.32 remote management operates on, replacing the plastic SIM card with soldered silicon. Illustrative photograph, not a specific vendor's product.

A round digital electricity meter with a small LCD register, sealed behind a clear cover and mounted in an exterior enclosure on a house wall. This is the kind of device class that utility operators are now shifting to remotely managed eSIM connectivity. Wikimedia Commons file Aclara I-210+; an illustrative AMI meter, not a Landis+Gyr or Thales installation.

References