SMDP+ is the eSIM subscription management function used to securely deliver profiles to devices. It is a core component of remote provisioning in enterprise IoT, where organisations need controlled, standards-based handling of identity and subscription data across large, often globally distributed deployments.
Expanded Definition
SMDP+ refers to the secure subscription management function that delivers eSIM profiles to devices under controlled, standards-based procedures. In NHI security terms, it matters because the profile being delivered is not just configuration data; it can contain identity, trust, and connectivity material that determines whether a device is accepted by a network. The term is often used alongside the broader eSIM remote provisioning model, but SMDP+ specifically covers the server-side function that prepares and securely transfers subscriptions to the device lifecycle. Industry usage is relatively consistent here, though implementation details vary across carriers, device vendors, and enterprise IoT platforms.
For governance purposes, SMDP+ should be treated as a high-value identity delivery control point, similar in risk posture to other remote credential issuance systems described in the Ultimate Guide to NHIs. The closest standards context comes from the NIST Cybersecurity Framework 2.0, especially where organisations map identity provisioning, access control, and recovery processes to managed assets. The most common misapplication is treating SMDP+ as a simple connectivity utility, which occurs when teams ignore the identity and lifecycle controls embedded in profile issuance.
Examples and Use Cases
Implementing SMDP+ rigorously often introduces operational and assurance overhead, requiring organisations to weigh provisioning speed against tighter identity governance, auditability, and device trust validation.
- An enterprise IoT fleet uses SMDP+ to activate cellular connectivity for thousands of sensors deployed across multiple countries, while keeping subscription issuance centralised and traceable.
- A logistics operator provisions eSIM profiles into rugged handheld devices during warehouse onboarding, reducing manual SIM handling and limiting exposed credentials in the field.
- A manufacturer ties SMDP+ issuance to device enrolment workflows so that only approved hardware receives a usable subscription, aligning with the lifecycle discipline discussed in the Ultimate Guide to NHIs.
- A telecom operations team monitors SMDP+ activity as part of a broader identity control plane, using standards guidance and the NIST Cybersecurity Framework 2.0 to structure access, logging, and incident response.
- A roaming-enabled medical device receives a new profile after replacement in the field, allowing connectivity to continue without physically swapping a SIM card.
Why It Matters in NHI Security
SMDP+ matters because remote provisioning concentrates trust, and concentrated trust becomes a security boundary. If the function is misconfigured or poorly governed, attackers may be able to issue, redirect, or reuse profiles that enable device impersonation, unauthorised connectivity, or operational disruption. That risk is especially significant in enterprise IoT, where devices often behave like long-lived non-human identities with limited human oversight.
NHIMG research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, and the same governance failure pattern applies when subscription delivery is left without strong controls, visibility, and revocation discipline. The Ultimate Guide to NHIs also highlights that only 5.7% of organisations have full visibility into their service accounts, a warning sign that identity-like assets often outgrow manual oversight. SMDP+ should therefore be aligned with lifecycle management, access logging, and rapid deprovisioning from the start. Organisations typically encounter the seriousness of SMDP+ only after a device fleet is hijacked, a subscription is cloned, or connectivity must be revoked at scale, at which point the term becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Covers lifecycle and governance risks when identities or profiles are issued to machines. |
| NIST CSF 2.0 | PR.AA | Identity management and access control principles apply to remote subscription provisioning. |
| NIST Zero Trust (SP 800-207) | 3.2 | Zero Trust requires continuous trust evaluation for device onboarding and credential delivery. |
| NIST SP 800-63 | Digital identity assurance concepts inform how strong provisioning trust should be. | |
| CSA MAESTRO | Agentic and automated control planes need governed, auditable credential delivery paths. |
Treat SMDP+ as a privileged issuance control and require approval, logging, and revocation tracking.