Other Industry compliance

India operationalizes M2M eSIM authorization

This matters for teams running IoT connectivity, connected-device exports, travel connectivity, OTP fallback, and number lifecycle operations in India because eSIM platform management is no longer just a technical workflow; it is now inside the telecom authorization perimeter. In late June 2026, India’s Department of Telecommunications opened fresh authorizations and migration into the new framework, and the M2M authorization expressly covers M2M eSIM subscription profile management, together with logging, traceability, and technical-security obligations.

Published:08/11/2026 Updated:08/11/2026

1. Regulatory focus

India’s DoT switched on the Telecom eServices Portal on 25 June for fresh authorizations and migration of existing licences, following the notification of the Miscellaneous Telecommunication Services Rules on 23 June 2026. Under that framework, M2M services, WPAN/WLAN operations using exempted spectrum, and platforms that manage M2M eSIM subscription profiles are expressly grouped within one authorization path. The portal materials also make the compliance perimeter unusually concrete: operators must follow M2M eSIM standards, use genuine telecom identifiers, keep devices identifiable and traceable, and retain data, system, and event logs for at least one year.

2. Business impact

For device makers, connectivity aggregators, automotive platforms, payment-terminal operators, and travel-connectivity distributors, the compliance bottleneck is shifting away from mere activation and toward platform eligibility, profile-management accountability, and auditability of device identity. That has direct spillover into messaging operations. If eSIM lifecycle controls, identifier mapping, and log retention are weak, a fraud review or regulator request can quickly become a broader carrier-trust issue affecting OTP delivery, number legitimacy checks, and partner onboarding. In practice, teams that used to separate IoT connectivity governance from messaging governance will now have a harder time doing so in India.

3. Operating recommendations

Create a three-layer control matrix for India: the authorized entity, the eSIM subscription-profile management platform, and the downstream use cases that rely on messaging such as OTP, onboarding, or service alerts. Then build a minimum audit dataset that ties EID, ICCID, IMSI, MSISDN, device model, activation timestamp, profile changes, suspension, and deactivation events into one traceable record. Finally, push the one-year log-retention requirement into supplier contracts, API schemas, and incident workflows. If you are still operating under legacy licensing assumptions, treat migration planning as a near-term compliance task rather than a back-office cleanup project.

Frequently Asked Questions

If we only ship connected devices and do not sell messaging directly, do we still need to care?
Yes. The new framework is not limited to messaging traffic. It reaches the M2M service layer and the eSIM subscription-profile management platform itself. If your devices or support workflows operate in India and involve eSIM control, traceability, or number-based fallback verification, authorization status, log retention, and identifier mapping can all become review points.
The rules mention at least one year of logs. What should teams actually retain?
Do not keep only message-delivery logs. Build a joined record containing EID, ICCID, IMSI, MSISDN, device serial, customer account, activation and reassignment timestamps, profile download or deletion events, alert history, operator actions, and API logs. Without that chain, it is difficult to prove which device, profile, and operational change sat behind a disputed OTP or service notice.
We still run on a legacy licence or registration model. When should migration planning start?
Start now. DoT opened the fresh authorization and migration path on 25 June 2026, and the portal materials say the government will decide applications within 60 days of receipt. If your India stack combines device connectivity, number management, and SMS fallback, migration should begin with a scope-and-gap review of entity eligibility, service coverage, supplier roles, and retention controls.
This article is for informational purposes only and does not constitute legal advice.

Related products

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch