1. Regulatory focus
India’s DoT switched on the Telecom eServices Portal on 25 June for fresh authorizations and migration of existing licences, following the notification of the Miscellaneous Telecommunication Services Rules on 23 June 2026. Under that framework, M2M services, WPAN/WLAN operations using exempted spectrum, and platforms that manage M2M eSIM subscription profiles are expressly grouped within one authorization path. The portal materials also make the compliance perimeter unusually concrete: operators must follow M2M eSIM standards, use genuine telecom identifiers, keep devices identifiable and traceable, and retain data, system, and event logs for at least one year.
2. Business impact
For device makers, connectivity aggregators, automotive platforms, payment-terminal operators, and travel-connectivity distributors, the compliance bottleneck is shifting away from mere activation and toward platform eligibility, profile-management accountability, and auditability of device identity. That has direct spillover into messaging operations. If eSIM lifecycle controls, identifier mapping, and log retention are weak, a fraud review or regulator request can quickly become a broader carrier-trust issue affecting OTP delivery, number legitimacy checks, and partner onboarding. In practice, teams that used to separate IoT connectivity governance from messaging governance will now have a harder time doing so in India.
3. Operating recommendations
Create a three-layer control matrix for India: the authorized entity, the eSIM subscription-profile management platform, and the downstream use cases that rely on messaging such as OTP, onboarding, or service alerts. Then build a minimum audit dataset that ties EID, ICCID, IMSI, MSISDN, device model, activation timestamp, profile changes, suspension, and deactivation events into one traceable record. Finally, push the one-year log-retention requirement into supplier contracts, API schemas, and incident workflows. If you are still operating under legacy licensing assumptions, treat migration planning as a near-term compliance task rather than a back-office cleanup project.
Frequently Asked Questions
If we only ship connected devices and do not sell messaging directly, do we still need to care?
The rules mention at least one year of logs. What should teams actually retain?
We still run on a legacy licence or registration model. When should migration planning start?
Sources
- PIB: DoT Opens Online Portal for Telecommunication Service Authorisations and License Migration under Telecommunications Act, 2023
- Department of Telecom eServices Portal: Authorisation Portal
- Department of Telecom eServices Portal: Machine to Machine (M2M) Service Authorisation
- Government of India Gazette: Telecommunications (Authorisation for Provision of Miscellaneous Telecommunication Services) Rules, 2026