Every time you tap the “activate eSIM” button on an iPhone, or watch an electric vehicle like the VinFast VF3 update its firmware overnight, what looks like a simple action is actually powered by a technical standards system developed and refined by GSMA over more than a decade. GSMA standard eSIM includes 7 SGP standards, from SGP.01/02 for M2M in 2014 to SGP.32 for IoT devices in 2023, creating the common framework for how embedded SIM works, is remotely activated, and stays secure. This article will help you understand each standard in chronological order, its target devices, and the deployment landscape in Vietnam during 2024-2026.
What is GSMA and what role does it play in eSIM standardization?
The story of GSMA began with a document signed in Copenhagen in 9 1987: the GSM Memorandum of Understanding. At that time, European mobile operators committed to building a unified mobile system so users could stay connected while crossing borders. By 1995, this document officially evolved into the GSM MoU Association, registered in Switzerland. Today, GSMA’s headquarters are at 1 Angel Lane, London.

GSMA currently represents more than 750 mobile operators and 400 device companies in the global mobile ecosystem. One of the organization’s most important roles is issuing technical standards for eSIM, ensuring that an Apple Watch bought in Hanoi can still operate using the same “technical language” as a device purchased in Tokyo, Singapore, or Europe.
If you picture eSIM as a house, there are three technical organizations helping build it. ETSI, or the European Telecommunications Standards Institute, is responsible for the “building materials”, including the MFF2 chip form factor, chip soldering, and traditional UICC standards. 3GPP, or the 3rd Generation Partnership Project, is responsible for the “connectivity pipes”, including network protocols such as 5G NR, LTE-M, and NB-IoT. Meanwhile, GSMA handles the “software inside the house”, meaning how the operator profile is loaded onto the chip, remotely activated, and kept secure.
These three organizations work together to create the eSIM experience that users rely on every day. To understand the common foundation of embedded SIM technology before diving into each standard, you can also read the article What is an eSIM?
Overview of the main GSMA eSIM 7 standards
GSMA’s seven SGP standards can be divided into three major groups based on device type. Each group addresses a different market need, from M2M devices in vehicles, consumer devices such as smartphones and smartwatches, to screenless IoT devices.
| Standard | Category | Release year | Current version | Target devices | Status |
|---|---|---|---|---|---|
| SGP.01 | M2M | 2014 | — | Architecture cho M2M | Active, legacy |
| SGP.02 | M2M | 2014-2015 | v4.2 | Technical Specification M2M | Active, legacy |
| SGP.21 | Consumer | 2017 | v3.1, 12/2023 | Architecture Consumer | Active |
| SGP.22 | Consumer | 2017 | v3.1, 12/2023 | Technical Specification Consumer | Active |
| SGP.23 | Consumer | 2017+ | — | Test Specification Consumer | Active |
| SGP.31 | IoT | 19/4/2022, v1.0 | v1.2, 4/2024 | Architecture IoT | Active, latest |
| SGP.32 | IoT | 26/5/2023 | v1.1, 2024 | Technical Specification IoT | Active, latest |
In addition to the 7 main standards, GSMA also maintains SGP.25, a security Protection Profile for eUICC used in both Consumer and IoT. In addition, test and compliance standards such as SGP.11, SGP.16, and SGP.23 act as a “certification toolkit”, helping ensure that devices and carriers’ backend systems operate according to the standard. The official documentation for each version is published by GSMA at gsma.com/esim-specifications so businesses, engineers, and developers can consult it in depth.
SGP.01 and SGP.02: Legacy M2M standards
GSMA’s first pair of eSIM standards, SGP.01 and SGP.02, was introduced during 2014-2015. These two standards were not designed for consumer phones, but to solve a very specific problem in the automotive industry.
When the European Union adopted Regulation (EU) 2015/758 on 19 5 2015 and set the mandatory deadline from 31 3 2018, all new vehicles sold in the EU had to include eCall, the automatic emergency calling system triggered in an accident. This raised an important technical question: how can a vehicle automatically call the emergency number 112 if the driver is unconscious, in any European country, without requiring the user to swap SIMs manually? The answer is M2M eSIM under SGP.01/02.
SMS-based push model architecture
SGP.02 uses a push model, in which the server sends commands via SMS to update the profile on the device. The two important backend entities in this architecture are SM-DP and SM-SR. SM-DP, or Subscription Manager Data Preparation, is responsible for preparing and managing profiles. SM-SR, or Subscription Manager Secure Routing, acts as the control center for executing platform management commands.
This architecture is suitable for passive devices with no direct user interaction, no display, and no need to scan a QR code. An automotive module is a typical example, because the device needs to operate stably over a long period and can be managed remotely by the manufacturer or carrier.
SGP.02 v4.2: Current version in 2024-2025
The latest version of SGP.02 is v4.2. This version adds the Automatic Emergency Call feature to meet automotive requirements, and also adds the M2M SP role, meaning M2M Service Provider, for businesses that want to own and manage the eSIM lifecycle. In addition, SGP.02 v4.2 also includes PLMA, short for Profile Lifecycle Management Authorisation.
The SGP.11 test standards and SGP.16 compliance standards are used in parallel to ensure devices meet technical requirements before real-world deployment. Thanks to this, legacy M2M systems can maintain stable operation in high-reliability industries such as automotive, energy, or smart electricity meters.
Current status of SGP.02
SGP.02 is still widely used in legacy M2M devices, especially in the automotive industry and first-generation smart electricity meters. However, GSMA recommends that new devices gradually move to the SGP.32 IoT standard because it offers more flexible management and is better suited to modern devices and large-scale deployments.
SGP.21, SGP.22, SGP.23: Consumer eSIM standards
Three years after SGP.02 was introduced, the consumer device market had matured enough for eSIM to enter mainstream life. In 2017, GSMA announced the trio of SGP.21, SGP.22, and SGP.23, opening the era of eSIM on devices such as smartwatches, smartphones, tablets, and laptops.
The first consumer device to mark a major milestone was the Apple Watch Series 3, launched on 22 9 2017. This smartwatch allowed users to make calls and access the network even without carrying an iPhone. One year later, the iPhone XS Series launched in 9 2018, bringing eSIM to mainstream smartphones. After that, the Samsung Galaxy S20+ and many other high-end Android smartphones also added eSIM support.
SGP.21: Architecture Specification
SGP.21 describes the overall eSIM architecture for consumer devices across multiple markets. The current version is v3.1, released in 12/2023. In addition, branch v2.x continues to be updated, with version v2.6 in 10/2024.
The SGP.21 document defines three main entities in the consumer eSIM system: eUICC, SM-DP+, and SM-DS. eUICC is the eSIM chip inside the device. SM-DP+, or Subscription Manager Data Preparation Plus, is the upgraded replacement for the old SM-DP and is responsible for preparing and distributing profiles. SM-DS, or Subscription Manager Discovery Server, supports the discovery process when the device needs to find a suitable profile.
SGP.22: Technical Specification
SGP.22 details the protocol and API for the Remote SIM Provisioning architecture on consumer devices. The current version of SGP.22 is aligned with SGP.21, including v3.1 and v2.6 maintained in parallel.
Unlike the push model of SGP.02, SGP.22 uses a pull model via QR code. The user scans the QR code, then the device actively connects to SM-DP+ to download the profile. This is the familiar mechanism used when activating eSIM on iPhone, Apple Watch, Samsung Galaxy, Google Pixel, or many consumer devices today.
SGP.23: Test Specification
SGP.23 plays the role of ensuring interoperability, meaning compatibility between devices, eUICC chips, and carriers’ SM-DP+ systems. This standard checks whether all components communicate properly according to SGP.22, thereby reducing errors when users activate eSIM across different devices and providers.
The SGP.21/22/23 group of standards applies to smartphones, smartwatches, tablets, laptops, and consumer devices with screens and user interfaces. Today, this set of standards is still active and widely used on iPhone models from XS onward, Samsung Galaxy S20+ and above, Google Pixel from Pixel 3 onward, and Apple Watch from Series 3.
SGP.31 and SGP.32: New IoT standards
Entering the 2020s, a new generation of devices emerged that made both SGP.02 M2M and SGP.22 Consumer no longer truly suitable. These include agricultural sensors placed in fields, containers crossing borders, smart electricity meters mounted on poles, fleet tracking devices, wearable medical devices, and smart city systems. What they have in common is that they have no screen, no user standing nearby to scan a QR code, and often need large-scale remote management.
This challenge led to the creation of SGP.31 and SGP.32, the latest generation of GSMA eSIM standards dedicated to the headless Internet of Things. The full IoT architecture of these two standards is analyzed in more detail in the article What is an eSIM for IoT.
SGP.31: Architecture & Requirements
SGP.31 describes the overall architecture and technical requirements for eSIM IoT. Version v1.0 was released on 19 4 2022, then updated to v1.2 in 4 2024.
This document defines the main roles including eUICC, eIM, and IPA. eIM, or eSIM IoT remote Manager, is the remote management component dedicated to IoT. IPA, or IoT Profile Assistant, supports the download, activation, and management of profiles on IoT devices. This is a new backend layer, different from the familiar SM-DP+ model in Consumer eSIM.
SGP.32: Technical Specification
GSMA released SGP.32 v1.0 on 26 5 2023 and updated it to v1.1 in 2024. If SGP.31 describes the overall architecture and requirements, SGP.32 goes deeper into the protocol, API, and specific deployment process.
The biggest difference between SGP.32 and SGP.22 is headless activation capability. IoT devices do not need a screen, do not require a user to scan a QR code, and can still have their profiles managed remotely. This is especially important for systems with thousands to millions of devices distributed across multiple regions or countries.
Target devices for SGP.31 and SGP.32
SGP.31 and SGP.32 serve device groups such as smart meters, fleet tracking, smart agriculture, smart cities, medical wearables, and many other industrial machines. The Trustworthy Connectivity Alliance published an analysis document for SGP.32 v1.0 in 9/2024 to help providers better understand how to deploy this standard in real-world scenarios.
SGP.25: eUICC security Protection Profile
When a tiny chip stores both the carrier profile and encryption keys, security is a question that cannot be ignored. SGP.25 was created to answer exactly that question. This is the security Protection Profile for eUICC, applicable to both Consumer and IoT devices.
SGP.25 is the standard framework for eUICC to be certified under Common Criteria, the international safety standard coded ISO/IEC 15408 and recognized by many countries. GSMA reached an important milestone when eUICC was certified Common Criteria EAL4+ augmented with AVA_VAN.5 and ALC_DVS.2, through cooperation with the German Federal Office for Information Security, or BSI, and Deutsche Telekom Security.
This Protection Profile document has the official code PP-0100 in the Common Criteria portal system. This is the code international security engineers use to look up the eUICC standard during product certification.
Alongside SGP.25, GSMA runs the eSA program, short for eUICC Security Assurance. This is the common security certification framework for eUICC software developers. Products that achieve certification are listed on the GSMA eSA Certified Products page, allowing businesses to check them before choosing a device or provider. Detailed eSIM security content is further explained in the article is eSIM secure?
How do GSMA, ETSI, and 3GPP divide standardization responsibilities?

A common question in technical forums is: which organization actually manages the eSIM standard? The answer is that GSMA, ETSI, and 3GPP work together, with each responsible for a different part of the entire ecosystem.
| Organization | Main responsibility | Representative standard |
|---|---|---|
| GSMA | Profile management, RSP architecture, security framework | SGP.02, SGP.22, SGP.32, SGP.25 |
| ETSI | Physical form factor, traditional UICC | MFF2, ETSI 102 671; nano-SIM, ETSI TS 102 221 |
| 3GPP | Cellular protocols and underlying mobile networks | 5G NR, LTE-M, NB-IoT, Release 13, 17, 18 |
Simply put, ETSI decides what shape the chip has and how it is soldered. GSMA decides how the carrier profile is loaded onto the chip, activated, and managed. 3GPP decides what language the chip uses to communicate with the mobile network. These standard groups reference one another when needed, for example GSMA’s SGP.32 relies on LPWA technologies such as LTE-M and NB-IoT defined by 3GPP in Release 13.
Understanding this division of roles helps technical users and businesses know where to look when problems arise. If the question concerns profiles and eSIM activation, go to GSMA. If it concerns chip form factor, look to ETSI. If it concerns the network 5G, LTE-M, or NB-IoT, 3GPP is the source to consult.
History and roadmap of GSMA eSIM standards 2014-2030
Looking back over more than a decade of development, GSMA eSIM standards have passed through many important milestones. Each milestone is not only a new technical document, but also reflects the maturation of a new device market.
The 2014-2015 period marked the beginning of M2M eSIM with SGP.01 and SGP.02. This group of standards serves Regulation (EU) 2015/758, the mandatory eCall regulation effective from 31 3 2018 in the European automotive industry.
In 2017, eSIM expanded into consumer devices with SGP.21, SGP.22, and SGP.23. The Apple Watch Series 3, launched on 22 9 2017, became the first consumer device to use eSIM under SGP.22, paving the way for eSIM adoption on smartphones and smartwatches.
On 19 4 2022, GSMA released SGP.31 v1.0, laying the architectural foundation and requirements for eSIM IoT. Then on 26 5 2023, SGP.32 v1.0 Technical Specification was launched, opening the door to smart city, smart agriculture, fleet tracking, and smart meter applications.
2024 was a year of version alignment. SGP.32 was updated to v1.1, SGP.31 to v1.2 in 4/2024, SGP.21/22 to v2.6 in 10/2024 alongside branch v3.1 released from 12/2023, and SGP.02 to v4.2.
Outlook for the 2025-2030 period
During the 2025-2030 period, the GSMA eSIM roadmap is shaped by four major trends. First is the SGP.33 test standard for IoT, which has been used by GCF, or the Global Certification Forum, to certify SGP.32 eSIM IoT devices since the beginning of 2026. Second is the integration of iSIM, or integrated SIM, into SoCs, which requires new standards for 5G IoT.
Third is the emergence of standards for NTN, or Non-Terrestrial Network, through satellite networks such as Starlink and OneWeb. Fourth, IoT eSIM is forecast to reach mass-market scale by the end of 2025 or during 2026, according to analysis by the Trusted Connectivity Alliance. You can read more about the longer roadmap in the future of eSIM 2030 article.
See also: eSIM vs physical SIM 2026: A 12-criteria comparison for Vietnamese users
Applying GSMA standards in Vietnam: Which carriers comply?
If you use an iPhone or Apple Watch in Vietnam, you may already be familiar with activating an eSIM in just a few minutes. This experience comes from the fact that the three major carriers, Viettel, VNPT, and MobiFone, have all deployed consumer eSIMs under the GSMA SGP.22 standard for several years now.
The current infrastructure works well for iPhone XS and later, Samsung Galaxy S20+ and later, eSIM-supported Apple Watch models, and many other compatible devices. Users can buy an eSIM plan directly through the carrier app, website, or at a store, then activate it by QR code using the familiar pull model.
Status of SGP.02 M2M in Vietnam
VNPT and MobiFone still maintain support for SGP.02 M2M for some legacy devices, mainly imported cars with eCall systems and first-generation smart electricity meters from EVN. However, deployments under this standard are trending downward as newer devices move to more modern architectures, especially SGP.32 IoT.
Gap analysis of SGP.32 IoT in Vietnam
As of mid-2026, no Vietnamese carrier has announced official support for SGP.32 IoT under the GSMA standard. There are three main reasons for this gap.
First, NB-IoT infrastructure has not yet achieved full coverage outside major cities. Second, the IoT chipset ecosystem of Vietnamese vendors remains limited. Third, specific legal regulations for IoT eSIM from the Ministry of Information and Communications are still being finalized under the Telecommunications Law 24/2023/QH13, which took effect on 1 7 2024.
According to the roadmap announced at Mobile World Congress events, Viettel is expected to officially launch SGP.32 during the 2026-2027 period. The remaining carriers are still in the stage of assessing infrastructure and the device ecosystem.
If you are looking to buy a travel eSIM for your upcoming trip, you can check out China eSIM, Korea eSIM, Japan eSIM,… and eSIMs for 200+ other countries at SimPM.
See also: Is a secure eSIM safe? Standard analysis






