Other Industry compliance

GSMA eSIM compliance baseline update

For teams running eSIM distribution, device launches, operator onboarding, or activation flows, the latest GSMA update affects certification timing and supplier readiness. GSMA marked SGP.24 v2.7 active on 17 July 2026 and kept the consumer and IoT specification map aligned across SGP.21/22 and SGP.31/32. Any legacy evidence pack or procurement checklist should now be re-validated against the current version set.

Published:08/15/2026 Updated:08/15/2026

1. Regulatory focus

GSMA is not publishing a policy memo here; it is resetting the live compliance baseline. Its specification matrix shows SGP.24 v2.7 as active from 17 July 2026, alongside SGP.22 v2.7, SGP.31 v1.3, and SGP.32 v1.3. For vendors, the issue is no longer whether the product supports eSIM, but whether certificates, test sets, and declaration templates still match the current version stack.

2. Business impact

For travel eSIM, IoT connectivity, white-label channels, or operator partnerships, version drift quickly becomes a launch blocker. If procurement, legal, product, and QA are citing different spec versions, the same SM-DP+, eUICC, device certificate, or vendor questionnaire can end up with multiple contradictory records. That usually shows up first as resubmission, retesting, and delayed commercial rollout rather than a direct enforcement action.

3. Operating recommendations

Start with a single version-control sheet: list the current SGP.24, SGP.22, SGP.31, and SGP.32 versions, certificate IDs, test labs, and expiry dates in one register. Then rewrite supplier clauses so “GSMA compliant” becomes an auditable obligation with a named version and proof artifact. For new bids or renewals, require the latest compliance declaration instead of an old screenshot or legacy approval letter.

Frequently Asked Questions

We only resell eSIM plans. Do we still need to track this update?
Yes. If your contract says “GSMA compliant” or you rely on upstream certificates as a sales condition, you must verify the current version set. If the upstream stack moves and your materials stay legacy, customer audits, marketplace onboarding, and distributor due diligence will flag the mismatch.
Can we keep using legacy SGP.24 materials with customers?
You can archive it, but do not use it as the current compliance proof. Mark legacy documents as historical only, and standardize all outward-facing packs on the latest declaration, test report, and certificate ID so sales, legal, and certification teams stay aligned.
Will this update affect SMS OTP or activation flows?
Indirectly, yes. If eSIM certificates, remote provisioning, or identity checks stall, OTP receipt, number activation, and fallback delivery can all slow down. Put eSIM compliance review and SMS verification or account-opening flows on the same launch checklist.
This article is for informational purposes only and does not constitute legal advice.

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch