A Technical Buyer’s Guide to eSIM and iSIM Integration in 5G CPE: GSMA SGP.32 Remote SIM Provisioning, Multi-IMSI Architecture, and Operator Procurement Criteria

eSIM and iSIM integration in 5G CPE procurement guide

For operators and service providers procuring 5G Fixed Wireless Access (FWA) CPE at scale, the SIM — whether physical, embedded, or integrated — is not merely a subscriber identity module. It is the logistical linchpin of deployment: determining which network a device attaches to, how roaming is handled, and whether a CPE can be provisioned without physical intervention. As the industry transitions from removable SIM cards to embedded SIM (eSIM) and integrated SIM (iSIM) architectures, procurement teams must understand the technical, operational, and commercial implications of each form factor. This guide provides a comprehensive framework for evaluating eSIM and iSIM integration in 5G CPE devices.

The SIM Evolution: From Plastic Card to Silicon Die

Traditional 4G/LTE CPE devices overwhelmingly use the 2FF/3FF/4FF removable SIM card — a plastic form factor that requires physical handling, inventory management, and manual insertion. While familiar, this approach introduces several operational pain points for large-scale CPE deployments: SIM card procurement and logistics across geographies, physical tampering and theft risks, SIM swap fraud vulnerabilities, and the operational burden of truck rolls when operator profiles change.

The GSMA’s embedded SIM specifications address these limitations through two architectural approaches:

  • eSIM (eUICC): A soldered, non-removable chip (MFF2 form factor, typically 5×6 mm or 3×3 mm) containing an embedded Universal Integrated Circuit Card (eUICC) that supports remote SIM provisioning (RSP). The eUICC can store multiple operator profiles and switch between them over-the-air.
  • iSIM (Integrated SIM): The SIM functionality is integrated directly into the device’s System-on-Chip (SoC) or secure enclave processor die, eliminating the need for a discrete SIM component entirely. Qualcomm’s Snapdragon 8 Gen 2 and later platforms integrate iSIM capability within the secure processing unit.

GSMA SGP.32: The IoT eSIM Standard Comes to CPE

The GSMA’s SGP.32 specification, finalized in mid-2024, represents the most significant advancement in eSIM architecture for IoT and CPE devices. Unlike the consumer-focused SGP.22 (which requires end-user interaction via QR codes or carrier apps), SGP.32 is purpose-built for machine-to-machine and network-equipment scenarios where zero-touch provisioning is essential.

SGP.32 introduces the IoT Profile Assistant (IPA) — a lightweight software component that runs on the device and manages profile download, activation, and deletion without user interaction. Key architectural elements include:

  • eIM (eSIM IoT Manager): A server-side component operated by the service provider or a third-party eSIM management platform that orchestrates profile lifecycle across thousands or millions of devices.
  • IPA (IoT Profile Assistant): A device-resident agent that communicates with the eIM via HTTPS, downloads encrypted operator profiles, and installs them on the eUICC.
  • SM-DP+ (Subscription Manager Data Preparation): The GSMA-certified platform that securely generates and encrypts operator profiles for over-the-air delivery.

For CPE OEMs and the operators who procure from them, SGP.32 compatibility means that a single CPE SKU can be manufactured, warehoused, and shipped globally — with the operator profile loaded post-manufacturing via the eIM platform when the device first powers on in its destination network. This collapses what was previously a multi-week, multi-SKU logistics chain into a single universal hardware platform.

Multi-IMSI and Multi-Profile Architecture

Advanced eUICC implementations in 5G CPE support multiple concurrently active International Mobile Subscriber Identities (IMSIs) — a capability that transforms how operators manage roaming, failover, and multi-network deployments.

In a typical multi-IMSI configuration, a CPE might store:

  • Primary home network profile: The default operator identity for normal operation.
  • Roaming partner profile: A local operator profile for specific geographic regions, avoiding expensive roaming charges.
  • Failover profile: A backup operator identity that activates automatically if the primary network experiences an outage.
  • Bootstrap profile: A provisioning-only profile used during initial device setup, replaced by the operational profile upon first activation.

The CPE’s connection manager — typically implemented in the modem baseband firmware — monitors network conditions and triggers profile switching based on configurable policies: signal strength thresholds, latency metrics, cost optimization rules, or geographic location determined by PLMN codes.

Procurement Checklist: What to Demand from CPE Vendors

When evaluating 5G CPE with eSIM/iSIM capabilities, operators and procurement teams should require vendors to demonstrate the following capabilities:

  1. GSMA SGP.32 compliance certification: Request evidence of successful interoperability testing with major eIM platforms (Thales, G+D, IDEMIA, Kigen, Valid). Self-declared compliance is insufficient; demand GSMA SAS-certified test reports.
  2. eUICC chip vendor transparency: Know which eUICC silicon is used (Infineon, STMicroelectronics, Samsung, etc.) and verify that the chip supports the required number of concurrent profiles — minimum four, ideally eight or more — with sufficient memory for operator profile storage (minimum 512 KB per profile for 5G authentication vectors).
  3. OTA update capability for connection manager: The CPE’s profile switching logic and network selection algorithms must be field-updatable via FOTA (Firmware Over-the-Air) without requiring eUICC profile changes.
  4. Local profile management API: For enterprise and private network deployments, request a documented local API (AT commands or REST) for profile management, enabling integration with on-premises network orchestration systems.
  5. iSIM roadmap: If the vendor offers iSIM-based CPE, request the specific SoC platform (e.g., Qualcomm Snapdragon X80) and GSMA certification status for the integrated secure element. iSIM in CPE remains an emerging technology; verify that the vendor’s iSIM implementation has passed GSMA SAS-UP certification.
  6. Fallback to physical SIM: Even in eSIM-first designs, a physical SIM slot (4FF nano-SIM) provides operational flexibility during field troubleshooting, lab testing, and emergency profile recovery scenarios. The best CPE designs offer both eSIM and physical SIM with software-controlled priority.

Security Considerations: eSIM and the CPE Threat Model

The eUICC in a 5G CPE is a high-value attack surface. Unlike consumer smartphones where eSIM profiles are protected by device-level biometrics and OS sandboxing, CPE devices often operate in physically accessible locations — mounted on building exteriors, installed in shared telecom closets, or deployed in outdoor cabinets. The threat model must account for physical access attacks.

Key security requirements for eSIM/eUICC in carrier-grade CPE:

  • CC EAL 5+ or higher certification for the eUICC hardware security module (per Common Criteria for Information Technology Security Evaluation).
  • Mutual TLS (mTLS) with certificate pinning for all eIM-IPA communications, preventing man-in-the-middle attacks on profile download channels.
  • Secure boot chain verification extending from the device boot ROM through the modem firmware to the eUICC applet layer, ensuring that profile-switching logic has not been tampered with.
  • Physical tamper detection: The CPE should log and optionally alert the eIM platform if physical intrusion is detected (enclosure switch, light sensor, or electrical continuity monitoring).
  • Profile deletion on tamper: Policy-configurable automatic deletion of operator profiles when physical tampering is detected — a critical requirement for devices deployed in high-risk environments.

Operational Economics: The Logistics Case for eSIM CPE

Beyond the technical architecture, the business case for eSIM-based CPE procurement is compelling. Operators who transition from physical SIM to eSIM for CPE deployments typically realize:

  • 70–85% reduction in SIM logistics costs: No physical SIM procurement, warehousing, kitting, or shipping. Profile delivery is purely digital via the eIM platform.
  • Single-SKU global inventory: One CPE model serves all markets. Operator profiles are loaded at first power-on based on the device’s shipping destination or detected network environment. This dramatically simplifies supply chain management for multinational operators.
  • 50–60% reduction in provisioning truck rolls: Subscriber activations that previously required technician dispatch for SIM installation can now be completed remotely. Combined with self-install CPE form factors, operators can achieve fully zero-touch subscriber onboarding.
  • Churn reduction through seamless profile migration: When subscribers change plans or operators, profile updates happen over-the-air — no new SIM, no truck roll, no service interruption. This frictionless experience demonstrably reduces voluntary churn by 15–20%.

The Path Forward: iSIM and Beyond

Looking ahead, integrated SIM (iSIM) technology — where the SIM function is absorbed into the device SoC’s trusted execution environment — represents the next frontier for CPE design. iSIM eliminates the need for a discrete eUICC chip, reducing BOM cost by approximately $1.50–2.50 per device, freeing PCB real estate (roughly 15–30 mm²), and simplifying the supply chain by one component. For operators procuring CPE in volumes of 100,000 units or more, these marginal savings compound into meaningful budget impact.

However, iSIM in CPE is still nascent. As of mid-2026, only Qualcomm offers a commercially certified iSIM solution integrated into its mobile platforms (Snapdragon X80 and newer), with MediaTek expected to follow in 2027. Operators evaluating iSIM-based CPE should conduct thorough interoperability testing with their chosen eIM platform and demand a clear iSIM-to-eSIM fallback architecture.

The eSIM/iSIM evolution in 5G CPE is not merely a component swap — it is a fundamental rearchitecture of how operators provision, manage, and secure their device fleets. Procurement teams that build SGP.32 compliance, multi-profile capability, and hardware-rooted security into their CPE requirements today will be positioned to operate more efficiently, respond faster to market opportunities, and deliver a superior subscriber experience compared to competitors still managing physical SIM logistics.

Explore Honlly’s eSIM-Ready 5G CPE Portfolio

Honlly Telecom offers a growing portfolio of 5G FWA CPE devices with GSMA SGP.32-compliant eSIM capability, multi-IMSI profile support, and integrated remote provisioning. Our engineering team works directly with operator procurement teams to customize eSIM configurations, validate eIM platform interoperability, and ensure seamless deployment at scale. Contact us to discuss your eSIM CPE requirements and request evaluation units.

Contact Honlly Telecom →