Remote SIM Provisioning: Two Standards, Two Owners

Publish: , Modified: TTR: 00:21:084,226 WordsBookmarkShareSummary

Remote SIM provisioning (RSP) is how an operator profile gets onto an eSIM or iSIM over the air, without a physical swap. Two GSMA standards govern it: SGP.22, where the person holding the device triggers the download, and SGP.32, where a fleet manager does it for devices that have no screen and nobody standing next to them.

Remote SIM Provisioning (RSP) is the technology and set of standardized processes that enable mobile network operator profiles to be downloaded, installed, switched, and deleted on an eSIM (Embedded SIM) or iSIM (Integrated SIM) over the air, without any physical SIM swap. For MVNOs (Mobile Virtual Network Operators), IoT companies, and M2M operators, understanding Remote SIM Provisioning is no longer optional. It is a foundational capability that determines how flexibly and scalably you can connect, manage, and retain subscribers and devices across an increasingly eSIM-driven market. Whether you are launching a consumer mobile brand, scaling an IoT deployment across thousands of devices, or building a Roaming MVNO proposition, RSP is the technology that makes it possible to deliver connectivity without borders, without physical logistics, and without the friction of traditional SIM distribution.

On this page

History and Evolution of Remote SIM Provisioning

Remote SIM Provisioning emerged from the GSMA's recognition that the physical SIM card model was incompatible with the long-term needs of connected devices and globalized mobile services. The GSMA published its first M2M RSP standard, SGP.01 and SGP.02, in 2013, followed by the consumer RSP standard SGP.21 and SGP.22 in 2016. These specifications defined the SM-DP+ and SM-DS server architecture that underpins all consumer eSIM deployments today. The IoT-specific evolution continued with SGP.32, published in 2023, which addressed the unique constraints of resource-limited IoT devices operating without a local user interface. RSP has since become the defining technology of the post-physical-SIM era.

Core Utility and Functionality of Remote SIM Provisioning

What is Remote SIM Provisioning Used For?

Remote SIM Provisioning is used to manage the entire lifecycle of a connectivity profile on an eSIM or iSIM device, from initial download and activation through to profile switching and deletion, all performed remotely over a secure data connection. In practical terms, RSP eliminates the need to physically handle, distribute, or swap a SIM card at any point in a device's life.

For consumer MVNOs, this means a new subscriber can activate a mobile plan instantly by downloading a profile directly to their smartphone, without waiting for a SIM card in the post. For IoT operators, it means a fleet of devices manufactured in one country can be shipped globally and remotely provisioned with the correct local operator profile after deployment, without any physical intervention on the device in the field. For Roaming MVNOs and travel connectivity providers, RSP enables seamless in-country profile switching that gives subscribers local rates without needing to purchase a local SIM.

RSP also works hand in hand with Multi-IMSI Connectivity strategies, enabling more flexible and standards-based approaches to managing multiple operator profiles on a single device. Understanding the full history, current state, and future of the SIM gives valuable context for how RSP fits into the broader evolution of subscriber identity management.

Key Functions of Remote SIM Provisioning

The RSP ecosystem performs a set of tightly defined and standardized functions that together enable fully automated, secure, and scalable profile management across millions of devices:

  • Profile Download: The core function of RSP is enabling an operator profile, containing the IMSI, cryptographic keys, network access parameters, and service configuration, to be securely downloaded from a subscription management server to an eSIM or iSIM over the air.
  • Profile Activation: After download, a profile must be activated to become the operative subscription on the device. RSP manages this activation process, including the notification to the mobile core network to update the subscriber's registration in the Home Subscriber Server (HSS) or Home Location Register (HLR).
  • Profile Switching: A device may hold multiple downloaded profiles simultaneously. RSP enables the switch between profiles, for example moving from one operator to another or from a default bootstrap profile to a target operator profile, without any physical action.
  • Profile Deletion: When a subscriber terminates their contract or a device is decommissioned, RSP enables the remote deletion of the operator profile, removing the credentials and freeing the eSIM for future use.
  • Profile Enabling and Disabling: Profiles can be enabled or disabled remotely without deletion, which is useful for temporary suspension of service, IoT device hibernation, or multi-profile management scenarios.
  • Remote Profile Management: Administrators can query the status of profiles on deployed eSIMs, push configuration updates, and trigger lifecycle events across entire device fleets from a central management console, without physical access to any device.
  • Secure Authentication and Key Establishment: Every RSP transaction is secured through a chain of cryptographic certificates that authenticate both the eSIM device and the subscription management server, preventing unauthorized profile downloads or modifications.
  • Bootstrap Profile Management: Newly manufactured eSIM devices are pre-loaded with a minimal bootstrap or test profile that provides temporary connectivity for the initial RSP download. RSP manages the transition from this bootstrap profile to the target operator profile.
  • Event Notification: The RSP architecture includes mechanisms for notifying the operator's backend systems when profile events occur, including successful downloads, activations, and deletions, enabling automated downstream actions in the BSS and OSS.

Technical Integration and Architecture

Integration with Other Systems

Remote SIM Provisioning does not operate as a standalone system. It is deeply integrated with the operator's core network, business support systems, and operational support systems, forming a connected provisioning and lifecycle management ecosystem.

  • Home Subscriber Server (HSS) and Home Location Register (HLR): When a new eSIM profile is activated through RSP, the corresponding IMSI and subscriber credentials must be registered in the operator's HSS or HLR to enable network authentication and service delivery. This integration must be automated and near-real-time to ensure that a subscriber who downloads and activates a profile is immediately able to connect to the network without manual intervention.
  • Business Support System (BSS): The BSS manages the commercial side of RSP by triggering profile downloads when a subscriber purchases a plan, tracking active profiles for billing purposes, and processing subscription changes or terminations that require RSP profile lifecycle events. A tightly integrated BSS-RSP workflow is essential for delivering a seamless subscriber activation experience, whether for a consumer eSIM order or an IoT device provisioning campaign.
  • Operational Support System (OSS): The OSS monitors the health and performance of the RSP platform, tracks provisioning success and failure rates across device fleets, and generates alerts when download failures or profile conflicts occur. For IoT operators managing large device populations, OSS integration with the RSP platform is critical for maintaining operational visibility across the entire connected estate.
  • Online Charging System (OCS): For prepaid subscribers using eSIM, the OCS must be notified of profile activations and switches to ensure that charging records are correctly associated with the active profile and that balance checks are applied to the right subscriber account.
  • IoT Device Management Platforms: For IoT deployments, the RSP platform must integrate with the operator's IoT device management system to coordinate profile provisioning events with device-level configuration updates, firmware management, and connectivity policy enforcement. See the guidance on IoT devices and IoT device strategy for the broader context in which RSP operates.

Technical Architecture and Key Interfaces

Who is who in remote SIM provisioning

Remote SIM provisioning roles, what they do and their use in consumer and IoT architectures.
Role What it does Consumer / IoT
SM-DP+ Prepares, protects and delivers the profile Both
SM-DS Lets a device discover that a profile is waiting Consumer (SGP.22)
LPA Local Profile Assistant — the download logic on the device Consumer (SGP.22)
IPA IoT Profile Assistant — the same job, without a user IoT (SGP.32)
eIM eSIM IoT remote Manager — decides on the fleet's behalf IoT (SGP.32)
eUICC The chip the profile lands on Both

Technical Architecture and Key Interfaces

The GSMA-standardized RSP architecture defines a set of specific server components and interfaces that govern how profiles are created, stored, delivered, and managed. Understanding this architecture is essential for any MVNO or IoT operator evaluating RSP platform options.

  • SM-DP+ (Subscription Manager Data Preparation Plus): The SM-DP+ server is the heart of the consumer RSP architecture (SGP.22). It is responsible for preparing and encrypting operator profiles, binding them to a specific eSIM's unique identifier (EID), and securely delivering them to the device over a mutually authenticated HTTPS connection. The SM-DP+ holds the operator's profile credentials and must be either owned by the MVNO or accessed through a trusted MVNO/MVNE partner.

  • SM-DS (Subscription Manager Discovery Service): The SM-DS is a globally distributed directory service that allows an eSIM device to discover which SM-DP+ server holds a pending profile for it, without the device needing to know the SM-DP+ address in advance. The device queries the SM-DS, receives a notification that a profile is waiting, and then connects to the correct SM-DP+ to complete the download.

  • SM-DP (Subscription Manager Data Preparation) for M2M: The original M2M RSP architecture (SGP.02) uses an SM-DP in combination with an SM-SR (Subscription Manager Secure Routing) to manage profile delivery to M2M devices. The SM-SR holds a trusted relationship with each eUICC and manages which profiles are enabled or disabled on the device, acting as the remote control for the eUICC's profile state.

  • eUICC (Embedded Universal Integrated Circuit Card): The eUICC is the hardware component embedded in the device that stores and executes operator profiles. It holds a manufacturer-issued certificate that is used to authenticate with the SM-DP+ during profile download. The eUICC is compliant with GSMA specifications and must be certified before it can participate in the RSP ecosystem.

  • LPA (Local Profile Assistant): In consumer devices, the LPA is the software component that runs on the device operating system and acts as the local interface between the user or the SM-DS/SM-DP+ and the eUICC. The LPA handles the discovery, download, and management of profiles on behalf of the user or the operator.

  • Key Interfaces: The primary interfaces in the RSP architecture include ES1 (between SM-DP+ and the operator), ES2+ (between the operator's BSS and the SM-DP+ for profile order management), ES8+ (between SM-DP+ and the eUICC for profile binding), ES9+ (between the LPA and the SM-DP+ for profile download), and ES11 (between the LPA and the SM-DS for profile discovery). For the IoT-specific SGP.32 architecture, these interfaces are adapted to accommodate constrained devices operating without a local user interface.

mvno-index-remote-sim-provisioning

RSP for MVNOs and IoT Companies

Why Own or Integrate an RSP Platform?

For a Full MVNO, a Consumer MVNO targeting smartphone users, or an IoT MVNO managing connected devices, integrating RSP capability into your platform is becoming a commercial necessity rather than a technical luxury. The market is moving decisively toward eSIM. Smartphone manufacturers including Apple, Google, and Samsung have progressively reduced or eliminated physical SIM card slots from their flagship devices. IoT chipset vendors are embedding eUICC functionality as standard. MVNOs that cannot support RSP-based eSIM activation will find themselves unable to serve an increasingly large segment of their target subscriber base.

Owning or closely managing your RSP integration also gives you control over the subscriber activation experience, which is one of the most critical moments in the customer journey. A subscriber who can activate their MVNO plan in under two minutes by scanning a QR code or tapping a button in your mobile app will have a materially better first impression than one who must wait days for a physical SIM to arrive. This activation experience directly influences early churn rates and sets the tone for the entire subscriber relationship, as explored in the MVNO's guide to exceptional customer care.

For IoT operators, the business case for RSP is even more compelling. The alternative to RSP-based IoT provisioning is physical SIM logistics: ordering, storing, distributing, and swapping physical SIM cards across potentially thousands or millions of devices in the field. This process is expensive, slow, error-prone, and completely incompatible with the scale and global reach that modern IoT deployments demand. RSP eliminates this logistics burden entirely, replacing it with automated, software-driven profile management at any scale.

Advantages and Disadvantages of RSP

Advantages:

  • Instant Digital Activation: Subscribers can activate a new MVNO plan in minutes by downloading an eSIM profile, eliminating SIM delivery times and associated logistics costs.
  • No Physical SIM Logistics: RSP removes the need to manufacture, stock, distribute, and recycle physical SIM cards, delivering significant cost savings especially for large IoT deployments.
  • Remote Profile Management at Scale: Operators can provision, switch, update, and decommission profiles across millions of devices from a central platform, without any physical access to individual devices.
  • Operator Switching Without Device Access: Subscribers or operators can switch network provider without touching the device, which is transformative for IoT devices deployed in remote or inaccessible locations.
  • Improved Subscriber Experience: A frictionless digital activation process reduces early churn and generates positive first impressions that set the foundation for a long-term subscriber relationship.
  • Global Device Deployment: Devices can be manufactured with a single bootstrap profile and provisioned with the correct local operator profile after deployment anywhere in the world, simplifying global supply chain management for IoT companies.
  • Alignment with Market Direction: Supporting RSP and eSIM positions the MVNO as a forward-looking operator aligned with the direction of the device and connectivity market.

Disadvantages:

  • Platform Investment and Complexity: Deploying or integrating an RSP platform, including SM-DP+ and SM-DS components, requires significant technical investment and specialist expertise.
  • GSMA Certification Requirements: Participation in the RSP ecosystem requires GSMA-certified infrastructure and compliance with GSMA specifications, which involves a formal certification process that takes time and resources.
  • Integration Complexity: Connecting the RSP platform to the BSS, OSS, HLR/HSS, and OCS requires careful integration work, particularly to ensure that profile lifecycle events trigger the correct downstream actions in real time.
  • eUICC Device Dependency: RSP only works on devices equipped with a GSMA-compliant eUICC. Legacy devices with standard SIM cards cannot participate, meaning RSP and physical SIM management must often be operated in parallel during the transition period.
  • Consumer Education: Many consumers are still unfamiliar with eSIM and RSP. MVNOs must invest in clear onboarding materials, support resources, and customer care training to guide subscribers through the activation process confidently.
  • Vendor Lock-In Risk: Choosing a proprietary RSP platform that deviates from GSMA standards can create lock-in risks that limit future flexibility. Selecting GSMA-certified, standards-compliant platforms is strongly recommended.

Organizational Impact of RSP

Operational Impact: Introducing RSP fundamentally changes the subscriber activation and SIM management workflow. Operations teams must replace physical SIM order management processes with digital provisioning workflows that integrate the RSP platform with the BSS and OSS. Profile management dashboards replace physical SIM inventory systems. Customer care agents must be trained to support eSIM activation queries, QR code troubleshooting, and profile transfer requests. The guide to exceptional customer care provides relevant guidance on how to equip your support team for digital-first subscriber interactions.

Financial Impact: The financial case for RSP is strong. Eliminating physical SIM manufacturing, personalization, packaging, warehousing, and distribution delivers direct cost savings that accumulate significantly at scale. For consumer MVNOs, digital activation also reduces the cost per acquisition by shortening the activation journey and reducing handling of failed or returned SIM orders. When modelling the financial impact in your MVNO financial plan, account for both the upfront platform investment and the ongoing per-profile transaction costs charged by RSP platform providers, offset against the SIM logistics cost savings and the reduction in activation-related churn.

Security Impact: RSP transactions carry sensitive cryptographic credentials and must be protected against interception, replay attacks, and unauthorized profile downloads. The GSMA specifications mandate end-to-end encryption and mutual authentication for all RSP transactions. The SM-DP+ must be operated in a highly secured environment, with strict access controls, hardware security modules (HSMs) for key storage, and comprehensive audit logging. Any compromise of the SM-DP+ or the profile credentials it holds would have severe consequences for subscriber security and operator reputation.

Technical Impact: RSP requires the MVNO's technical architecture to support automated, event-driven provisioning workflows that can handle high volumes of concurrent profile transactions without manual intervention. The integration between the RSP platform and the BSS and OSS must be robust, low-latency, and fully tested for edge cases such as download interruptions, partial activations, and profile conflicts. Selecting the right BSS and OSS from the outset, as described in the guidance on how to select the right BSS and OSS, is critical to ensuring that your core back-office systems can support RSP workflows without major re-engineering.

Redundancy and High Availability

The RSP platform is a critical dependency for subscriber activation and device connectivity management. Any outage of the SM-DP+ or SM-DS infrastructure directly prevents new subscribers from activating their eSIM plans and blocks profile management operations across deployed device fleets. For an MVNO, this translates directly into lost revenue, increased churn risk, and damage to brand reputation.

Achieving the high availability required for a production RSP deployment demands a fully redundant architecture. The SM-DP+ must be deployed across at least two geographically separated data centers in an active-active or active-standby configuration, with automatic failover in the event of a component failure. All cryptographic key material must be stored in certified Hardware Security Modules (HSMs) that are themselves redundant and geographically distributed. Database replication must ensure that profile state and transaction records are synchronized across all nodes in real time.

Network connectivity between the RSP platform and the GSMA SM-DS infrastructure must also be redundant, with multiple carrier interconnects to eliminate single points of failure at the network level. For IoT deployments, where profile management operations may need to reach devices across multiple countries and network types, the RSP platform must be accessible from any network and optimized for operation over high-latency or intermittent connections. Regular failover testing and documented recovery procedures are as important as the underlying architecture in ensuring that availability commitments can be met.

RSP Standards: Consumer vs. IoT and the Road Ahead

SGP.22 and SGP.32 compared

SGP.22 consumer and SGP.32 IoT provisioning compared by download trigger, initiation, confirmation, scale, device assumptions and use cases.
Feature SGP.22 — consumer SGP.32 — IoT
Who triggers the download The person holding the device The fleet owner, through an eIM
How it starts QR code, app, or carrier push A command from the eIM
Confirmation The user accepts on screen Policy, with no user involved
Scale One device at a time Thousands in one operation
Device assumption A screen, a user, a data connection Possibly none of the three
Where it fits Handsets, tablets, watches Sensors, trackers, meters, vehicles

Understanding the Two RSP Ecosystems

The GSMA has defined separate RSP architectures for consumer devices and for M2M and IoT devices, reflecting the fundamentally different operational environments and device capabilities in each domain.

The consumer RSP architecture (SGP.21/SGP.22) is designed for smartphones, tablets, and wearables that have a local user interface, sufficient processing power to run an LPA, and reliable internet connectivity. In this architecture, the user or the operator initiates a profile download through the device's LPA, which communicates with the SM-DS to discover pending profiles and then connects to the SM-DP+ to complete the download. This is the architecture that powers eSIM activation on iPhones, Android smartphones, and Apple Watches today.

The M2M RSP architecture (SGP.01/SGP.02) was designed for constrained IoT devices that may have no user interface, limited processing resources, and intermittent connectivity. In this architecture, the operator retains full remote control over the device's eUICC through the SM-SR, which can push profile changes to the device without any local user action. This is the architecture widely used in automotive telematics, industrial sensors, and smart metering deployments.

The newer IoT RSP standard SGP.32, covered in detail in the dedicated SGP.32 page on MVNO Index, bridges the gap between these two architectures by adapting the consumer RSP model for resource-constrained IoT devices, offering greater flexibility and lower complexity than the original M2M architecture.

The Road Ahead for RSP

The trajectory of RSP development points toward greater standardization, broader device support, and deeper integration with 5G network capabilities. The 5G core network introduces new subscription management functions that align naturally with RSP, enabling more dynamic and automated management of connectivity profiles in a cloud-native environment. The Unified Data Management (UDM) function in the 5G core is designed to work seamlessly with eSIM and RSP, providing a more integrated and flexible subscriber identity architecture than was possible in previous network generations.

As iSIM (Integrated SIM) technology matures and becomes embedded directly into chipsets, RSP will extend its reach to an even wider range of devices, including those too small or power-constrained to accommodate a separate eUICC component. This will further accelerate the shift away from physical SIM logistics and make RSP the universal provisioning mechanism for connected devices of all types. MVNOs and IoT operators that build RSP capability into their platforms now will be well positioned to capture the growth opportunities that this transition creates.

Frequently Asked Questions about Remote SIM Provisioning

What is the difference between RSP and a traditional SIM?

A traditional SIM card is a physical component pre-programmed with a single operator's credentials. RSP enables operator profiles to be downloaded, switched, and deleted on an eSIM over the air, without any physical SIM swap. RSP gives both operators and subscribers far greater flexibility in managing connectivity.

What is the SM-DP+ and why does an MVNO need one?

The SM-DP+ (Subscription Manager Data Preparation Plus) is the server that prepares, encrypts, and delivers eSIM profiles to subscriber devices. An MVNO needs access to an SM-DP+ to provision eSIM subscribers. This can be achieved by owning and operating an SM-DP+ directly, or by accessing one through an MVNE or MVNA partner.

What is the difference between the consumer RSP standard and the M2M RSP standard?

The consumer RSP standard (SGP.22) is designed for devices with a local user interface and runs an LPA on the device. The M2M RSP standard (SGP.02) is designed for constrained IoT devices with no local user interface, giving the operator full remote control through an SM-SR. The newer SGP.32 standard adapts the consumer architecture for resource-constrained IoT devices.

Can an MVNO support both physical SIM and eSIM RSP simultaneously?

Yes. Most MVNOs operate both physical SIM and eSIM RSP capabilities in parallel during the market transition. The BSS must be configured to manage both physical ICCID-based subscriptions and eSIM EID-based profiles within the same subscriber management framework.

How does RSP affect the subscriber activation experience?

RSP enables instant digital activation. A subscriber purchases a plan online or in an app and receives a QR code or activation code that triggers an immediate profile download to their eSIM device. This eliminates SIM delivery delays and creates a frictionless activation journey that positively impacts first impressions and early churn rates.

What security measures protect RSP transactions?

RSP transactions are protected by mutual TLS authentication between the device and the SM-DP+, end-to-end encryption of profile data using the eUICC's public key, GSMA-certified certificates managed through Hardware Security Modules, and audit logging of all profile lifecycle events. The GSMA specifications mandate these security controls as non-negotiable requirements.

How does RSP integrate with the MVNO's BSS?

The BSS connects to the SM-DP+ through the ES2+ interface to trigger profile creation, download, and deletion events. When a subscriber purchases an eSIM plan, the BSS sends a profile order to the SM-DP+, which prepares the profile and makes it available for download. Profile activation events flow back to the BSS to trigger service activation and billing. See what a BSS is for more context on how this integration fits into the broader back-office architecture.

Summary

Remote SIM Provisioning (RSP) is the technology that defines how operator profiles are delivered, managed, and deleted on eSIM and iSIM devices over the air. For MVNOs and IoT companies, it is a strategic capability that eliminates physical SIM logistics, enables instant digital subscriber activation, and makes it possible to manage connectivity across global device fleets at scale. RSP is built on GSMA-standardized architectures including SGP.22 for consumer devices, SGP.02 for M2M, and the newer SGP.32 for IoT, each designed for the specific requirements of their respective device environments.

Integrating RSP requires investment in platform infrastructure, BSS/OSS integration, GSMA certification, and customer care capability, but the commercial and operational benefits are substantial and growing. As the market moves decisively toward eSIM and iSIM, MVNOs that build RSP capability now will be positioned to activate subscribers faster, manage devices more efficiently, and compete more effectively in both the consumer and IoT segments.

Explore the solution providers listed on MVNO Index to find RSP platform vendors and eSIM specialists who work with MVNOs and IoT operators. If you need expert guidance on how to design your RSP integration or select the right platform partner, the consultancy companies on MVNO Index offer specialized support for exactly this kind of strategic technology decision.

SIM (Cards), eSIM and iSIM

How to start an MVNO, how to start a mobile brand
MVNO Index - SIM_eSIM_Architecture_small
MVNO Index - remote sim-provisioning_small
What is a Subscriber Identity Module (SIM) Card
Features of the SIM Cards, eSIM and iSIM compared
How to create a Marketing Plan for your Mobile Brand MVNO
What is an Integrated SIM (iSIM)
What is an Integrated SIM (iSIM)
Features of the SIM Cards, eSIM and iSIM compared