A Technical Buyer’s Guide to eSIM and Multi-IMSI 5G CPE: GSMA SGP.32 Compliance, Carrier Profile Switching, and Global IoT Roaming Architecture

Honlly Telecom 4G/5G wireless router image

The evolution from physical SIM cards to embedded SIM (eSIM) technology represents one of the most significant architectural shifts in cellular CPE design since the transition from 3G to 4G. For enterprise buyers and telecom operators deploying 5G FWA and IoT gateways at scale, eSIM and Multi-IMSI capabilities fundamentally transform how devices are provisioned, how carrier relationships are managed, and how connectivity resilience is architected across global deployments. This guide examines the key technical and commercial dimensions of eSIM-enabled 5G CPE that procurement teams must understand.

eSIM Architecture: GSMA Standards and Compliance

The eSIM ecosystem is governed by GSMA specifications that define the architecture for remote SIM provisioning. The foundational standard for consumer and M2M devices is GSMA SGP.22 (Consumer Architecture), while the IoT-optimized GSMA SGP.32 (IoT Architecture) specification, finalized in 2023, addresses the specific requirements of constrained IoT devices — including those embedded in 5G CPE gateways deployed at scale.

The key architectural distinction between physical SIM and eSIM lies in the separation of the Secure Element from the profile. In an eSIM-enabled CPE, the embedded Universal Integrated Circuit Card (eUICC) is a tamper-resistant hardware security module soldered directly to the device PCB during manufacturing. Unlike a traditional SIM where the carrier profile is burned into the card at the factory, the eUICC can receive, store, and manage multiple operator profiles downloaded over-the-air (OTA) throughout the device’s operational lifetime. This capability is enabled by the Subscription Manager – Data Preparation (SM-DP+) server, which securely packages and delivers encrypted operator profiles to the device.

For enterprise CPE procurement, GSMA SGP.32 compliance should be considered a forward-looking requirement. SGP.32 simplifies the profile download protocol compared to SGP.22, reducing the data overhead and power requirements for profile switching — factors that become critical when managing fleets of thousands of CPE devices. Buyers should verify that their selected CPE platform supports SGP.32 or has a confirmed firmware upgrade path to SGP.32 compliance.

Multi-IMSI: Carrier Diversity and Failover Architecture

Multi-IMSI (International Mobile Subscriber Identity) technology enables a single SIM or eSIM to store multiple operator profiles, each associated with a different IMSI. When combined with eSIM architecture, Multi-IMSI provides a powerful framework for carrier diversity and connectivity resilience that is particularly valuable for enterprise FWA deployments.

The operational model works as follows: a 5G CPE device ships with an eSIM pre-loaded with multiple IMSI profiles corresponding to different mobile network operators (MNOs) in the target geographic region. The device’s connection manager software monitors the quality of each available network — evaluating RSRP, SINR, latency, and available bandwidth — and can automatically switch to an alternative carrier profile based on configurable policies. Common trigger conditions include:

  • Signal quality degradation: When the primary carrier’s RSRP or SINR falls below a configurable threshold for a sustained period.
  • Scheduled maintenance windows: Planned network maintenance or known outage periods on the primary carrier.
  • Cost optimization: Switching between carriers based on time-of-day data pricing or data cap thresholds.
  • Geographic relocation: For semi-mobile CPE deployments (construction trailers, temporary offices), automatic carrier selection based on GPS location.

The profile switch process in modern eUICC implementations typically completes within 30-60 seconds, though this can vary based on the complexity of the network attach procedure and whether the new profile requires a full protocol stack re-initialization. Enterprise buyers should request specific failover timing specifications from CPE vendors and validate these in testing scenarios that replicate their actual deployment conditions.

Global Roaming and Carrier Profile Management

For multinational enterprises and global IoT deployments, the combination of eSIM and Multi-IMSI eliminates the logistical burden of physically swapping SIM cards when devices cross national borders. Instead, carrier profiles for each country or region of operation can be pre-loaded or downloaded on-demand through the SM-DP+ infrastructure.

This capability has particular relevance for several deployment categories:

  • International freight and logistics: Container tracking gateways, refrigerated trailer monitors, and port automation CPE that must maintain connectivity across multiple countries along shipping routes.
  • Global enterprise branch networks: Organizations with offices in multiple countries can standardize on a single CPE model globally, with local carrier profiles downloaded during installation rather than requiring country-specific SKUs.
  • Maritime and aviation connectivity: Near-shore and in-flight connectivity systems that transition between terrestrial cellular networks and satellite backhaul as they cross coverage boundaries.

The eSIM ecosystem also enables new commercial models for connectivity provisioning. Enterprises can contract with a single connectivity management platform provider that maintains relationships with multiple MNOs globally, receiving a unified bill and management interface while the platform handles carrier profile distribution, policy enforcement, and usage analytics across all deployed devices.

Security Architecture and Profile Protection

The security architecture of eSIM-enabled CPE is built on hardware root of trust principles. The eUICC is a certified secure element — typically certified to Common Criteria EAL4+ or higher — that performs cryptographic operations including profile decryption, key generation, and authentication challenge-response within a physically isolated execution environment.

Key security considerations for enterprise buyers include:

  • Profile encryption: Operator profiles are encrypted during transmission (over TLS 1.3 as a minimum) and remain encrypted at rest within the eUICC’s protected memory. The decryption keys never leave the secure element.
  • Profile locking: Individual profiles can be locked to a specific eUICC identity (EID), preventing profile extraction and cloning even if the device firmware is compromised.
  • Attestation: The eUICC can provide cryptographic attestation of its identity and integrity to the SM-DP+ server before receiving a new profile, preventing profile delivery to compromised or counterfeit devices.
  • Remote profile deletion: In the event of device theft or decommissioning, profiles can be remotely deleted through the SM-DP+ infrastructure, ensuring that network credentials cannot be extracted from decommissioned hardware.

Procurement Checklist for eSIM-Enabled 5G CPE

Enterprise buyers evaluating eSIM-capable 5G CPE should structure their technical evaluation around the following key criteria:

  1. GSMA compliance level: Confirm SGP.22 or SGP.32 certification status and verify the specific specification version (SGP.32 v1.0 or later preferred).
  2. eUICC manufacturer and certification: Identify the eUICC silicon vendor (Infineon, STMicroelectronics, Thales, G+D, etc.) and verify Common Criteria certification level and GSMA SAS-UP certification status.
  3. Profile capacity: Determine how many operator profiles the eUICC can store simultaneously — typical enterprise-grade implementations support 5-10 profiles, though specifications vary by vendor.
  4. SM-DP+ compatibility: Verify interoperability with major SM-DP+ platform providers (IDEMIA, Thales, G+D, Truphone, etc.) and confirm that the CPE vendor provides documentation for SM-DP+ API integration.
  5. Local Profile Assistant (LPA) implementation: Understand whether the LPA functionality (responsible for profile download and management on the device side) is implemented in the CPE’s application processor or within the baseband modem — modem-based LPA implementations generally offer better reliability across firmware updates.
  6. Failover timing and policy flexibility: Test profile switch latency under realistic network conditions and verify the granularity of configurable failover policies.

As the global eSIM ecosystem matures and GSMA SGP.32 adoption accelerates through 2026 and 2027, eSIM capability will transition from a differentiating feature to a baseline requirement for enterprise-grade 5G CPE. Procurement teams that build eSIM evaluation criteria into their current RFPs will be well-positioned to deploy connectivity solutions that are both carrier-flexible and future-proofed against evolving global connectivity requirements.