As 5G FWA deployments scale across multiple operators and geographies, the SIM architecture embedded within CPE devices has evolved from a simple authentication token into a strategic enabler of deployment flexibility, operational efficiency, and long-term lifecycle management. This technical buyer’s guide examines the eSIM and Multi-IMSI architectures now being integrated into enterprise-grade 5G CPE platforms, providing procurement teams with the technical framework needed to evaluate solutions for multi-operator, multi-region, and future-proof FWA deployments.
The Evolution from Physical SIM to eSIM in CPE
Traditional 5G CPE devices relied on removable UICC (Universal Integrated Circuit Card) formats—typically 2FF (Mini-SIM) or 4FF (Nano-SIM) physical cards. While functional, this approach introduced significant operational friction: truck rolls for SIM swaps during operator changes, physical SIM inventory management across distribution channels, vulnerability to theft and tampering, and limited ability to dynamically re-provision connectivity profiles in response to network conditions or commercial agreements.
The GSMA’s eSIM specifications—particularly GSMA SGP.02 (M2M) and SGP.22 (Consumer) architectures—have matured to address these pain points for CPE deployments. An eSIM (embedded UICC or eUICC) is a soldered, non-removable SIM chip that supports remote SIM provisioning (RSP), enabling operators to download, enable, disable, and delete operator profiles over-the-air without physical access to the device.
The SGP.22 Consumer architecture, originally designed for smartphones and wearables, has proven particularly suitable for 5G CPE. It supports a “pull” model where the device initiates profile download via an SM-DP+ (Subscription Manager – Data Preparation+) server, activated through a QR code or activation code delivered via the operator’s mobile app or web portal. This consumer-friendly activation flow is increasingly adopted for residential FWA CPE, enabling self-install and zero-touch provisioning.
For enterprise and industrial CPE deployments, the SGP.02 M2M architecture offers a “push” model where profiles are provisioned remotely by the operator via an SM-DP (Subscription Manager – Data Preparation) server, with minimal end-user interaction. This architecture supports bulk provisioning, scheduled profile switching, and integration with operator OSS/BSS systems—critical capabilities for deployments with thousands of distributed CPE endpoints.
Multi-IMSI Architecture: Operational Flexibility for Roaming and Multi-Operator Deployments
While eSIM enables remote profile management, Multi-IMSI (Multiple International Mobile Subscriber Identity) architecture extends the concept by allowing a single device to hold multiple active operator profiles simultaneously, with intelligent switching logic that selects the optimal profile based on configurable policies.
A Multi-IMSI 5G CPE typically integrates a eUICC with support for multiple IMSI/applet combinations, managed through a SIM applet framework running on the UICC’s Java Card platform. The device maintains several operator profiles—each containing its own IMSI, authentication keys (Ki), OPC, and network parameters—with an applet that monitors network availability and switches active profiles based on rules such as:
- Geographic Location: Automatically select the home network profile when on the home PLMN, switch to a roaming partner profile when abroad to achieve local-rate data pricing
- Network Quality: Switch to an alternate operator profile if the primary network’s signal quality or throughput falls below defined thresholds
- Time-Based Scheduling: Use a specific operator profile during business hours for guaranteed SLA performance, switch to a lower-cost profile outside peak hours
- Application-Based Steering: Route critical enterprise traffic through one operator while offloading bulk data to another
This Multi-IMSI capability is particularly valuable for: cross-border deployments where a single CPE model must operate across multiple countries; maritime and logistics applications where vessels and containers traverse multiple territorial waters; and enterprise branch offices requiring redundant WAN connectivity with automatic failover between operators.
GSMA eSIM Compliance and Certification Considerations
Procurement teams evaluating eSIM-enabled 5G CPE should verify compliance with the relevant GSMA specifications based on deployment use case:
- SGP.02 v4.2: M2M eSIM architecture with push-based provisioning; required for enterprise/industrial CPE managed through operator OSS/BSS platforms
- SGP.22 v3.0: Consumer eSIM architecture with pull-based provisioning; suitable for residential and SOHO CPE with end-user self-activation
- SGP.32 v1.0: IoT eSIM specification; increasingly relevant for massive IoT deployments with constrained devices and LPWA connectivity
GSMA SAS (Security Accreditation Scheme) certification for the eUICC manufacturer and SM-DP+ provider is essential. SAS-UP (UICC Production) certifies the secure manufacturing and personalization process for eUICCs, while SAS-SM (Subscription Management) certifies the security of the RSP platform infrastructure. Devices integrating non-certified eSIM components face interoperability risks and potential operator rejection during certification.
Security Architecture: Mutual Authentication and Profile Isolation
The eSIM security model builds on the proven 3GPP AKA (Authentication and Key Agreement) framework while adding eUICC-specific protections. Key security considerations include:
ISD-R (Issuer Security Domain – Root): The root security domain on the eUICC, managed by the eUICC manufacturer (EUM), responsible for creating and managing ISD-Ps (Issuer Security Domain – Profiles). The ISD-R private key never leaves the eUICC secure element, ensuring that only authorized entities can manage profiles.
Profile Interlock and Isolation: Each operator profile operates within its own ISD-P, providing cryptographic isolation between profiles. One operator’s profile cannot access another’s credentials or network parameters. This is critical for scenarios where the CPE may switch between competing operators.
CI (Certificate Issuer) Trust Chain: GSMA’s Certificate Issuer root of trust ensures that only authenticated SM-DP+ servers can communicate with the eUICC for profile operations. Buyers should confirm that the eUICC vendor participates in the GSMA CI program and supports the latest ECC (Elliptic Curve Cryptography) key algorithms in addition to legacy RSA.
Integration with 5G CPE Platform Architecture
From a system integration perspective, the eSIM/Multi-IMSI subsystem must interface with several CPE platform components:
- Modem Baseband: The modem must support eUICC ISO 7816 interface or SPI-based eUICC connections, with modem firmware capable of hot-swapping IMSI/applet sessions without requiring a full modem reset—a non-trivial requirement that varies significantly between modem vendors
- Device Management Client: Integration with TR-369 USP or LwM2M device management agents to enable remote profile management operations through standardized APIs, including profile enable/disable, profile list query, and profile download initiation
- Local Management UI/API: A web GUI or mobile app interface for end-users or field technicians to initiate profile downloads (e.g., scan a QR code), view active profile information, and manage basic eSIM settings
Procurement Checklist for eSIM/Multi-IMSI 5G CPE
When evaluating 5G CPE solutions with eSIM and Multi-IMSI capabilities, technical buyers should verify the following specifications:
- eUICC compliance: GSMA SGP.02 and/or SGP.22 certified, with SAS-UP accreditation
- Number of simultaneously stored operator profiles: minimum 3 profiles for Multi-IMSI use cases; 5+ preferred for global deployments
- Profile switching time: target under 30 seconds for seamless failover; modem vendors’ support for hot-swap without full baseband re-initialization should be confirmed
- RSP platform interoperability: verified against major SM-DP+ providers (IDEMIA, G+D, Thales, Kigen, Valid) used by target operators
- Fallback physical SIM slot: dual-SIM architecture with one eSIM and one physical SIM slot provides maximum deployment flexibility during eSIM ecosystem transition periods
- Remote management API compliance: TR-369 USP or equivalent for operator-managed profile operations
- Security certification: CC EAL4+ or higher for eUICC secure element; GSMA SAS-SM for the RSP infrastructure
The transition to eSIM and Multi-IMSI architectures in 5G CPE represents a foundational shift in how connectivity is provisioned, managed, and monetized. For operators and enterprises deploying FWA at scale, selecting the right SIM architecture today will determine deployment agility, operational cost structure, and vendor flexibility for years to come.

