1. Regulatory focus
GSMA is not publishing a policy memo here; it is resetting the live compliance baseline. Its specification matrix shows SGP.24 v2.7 as active from 17 July 2026, alongside SGP.22 v2.7, SGP.31 v1.3, and SGP.32 v1.3. For vendors, the issue is no longer whether the product supports eSIM, but whether certificates, test sets, and declaration templates still match the current version stack.
2. Business impact
For travel eSIM, IoT connectivity, white-label channels, or operator partnerships, version drift quickly becomes a launch blocker. If procurement, legal, product, and QA are citing different spec versions, the same SM-DP+, eUICC, device certificate, or vendor questionnaire can end up with multiple contradictory records. That usually shows up first as resubmission, retesting, and delayed commercial rollout rather than a direct enforcement action.
3. Operating recommendations
Start with a single version-control sheet: list the current SGP.24, SGP.22, SGP.31, and SGP.32 versions, certificate IDs, test labs, and expiry dates in one register. Then rewrite supplier clauses so “GSMA compliant” becomes an auditable obligation with a named version and proof artifact. For new bids or renewals, require the latest compliance declaration instead of an old screenshot or legacy approval letter.