IoT teams should treat SIM strategy as an architecture decision, not a card replacement exercise. The practical goal is to align connectivity, device lifecycle, and remote provisioning across fleets that span manufacturers, operators, and geographies. As eSIM and iSIM adoption grows, teams need supply chain visibility, policy control, and operational processes that support scale without fragmenting device management.
Why SIM strategy has become a fleet architecture decision
For IoT programmes, the shift from removable SIMs to eSIM and iSIM changes more than the form factor. It alters how connectivity is provisioned, who controls operator relationships, how devices are onboarded and replaced, and how quickly a fleet can be recovered when a profile or carrier arrangement fails. That makes SIM strategy part of device lifecycle design, not an afterthought in procurement. Guidance such as NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because the question is really about control, accountability, and resilience across a distributed device estate. In practice, many teams discover the operational cost of weak SIM strategy only after they have to recover a fleet at scale, rather than during the original rollout.
How eSIM and iSIM change provisioning, ownership, and recovery
Traditional SIM management often assumed a physical object could be inserted, swapped, and tracked locally. Embedded and integrated SIMs move the decision point into software, silicon, and remote subscription management, which improves scale but also raises the bar for governance. Teams need to understand where the subscription is issued, who can change profiles, what happens if devices are reimaged or returned, and how carrier dependency is handled across regions.
The practical model is to separate three layers. First is device identity and hardware trust, which determines whether the platform can safely accept remote provisioning. Second is subscription and profile control, which governs activation, switching, suspension, and retirement. Third is operational policy, which defines when a device is allowed to roam, fail over, or remain offline. If those layers are not aligned, teams can end up with devices that are technically connected but operationally unmanaged.
- Design for lifecycle events up front, including manufacturing, staging, field replacement, and end-of-life decommissioning.
- Track which party owns provisioning authority for each device class, region, and carrier relationship.
- Make profile change, suspension, and revocation processes auditable so support teams can recover devices without improvisation.
- Test fallback behaviour when a carrier, profile service, or provisioning workflow is unavailable.
For high-volume fleets, the largest failure mode is usually not the embedded SIM itself but the mismatch between remote provisioning capability and the organisation’s ability to govern it consistently. Teams that treat eSIM as a simple procurement swap often discover too late that they have created a more flexible connectivity layer than their operations model can safely manage.
Where the usual SIM model breaks down across geographies and device types
Tighter connectivity control often increases operational overhead, requiring organisations to balance portability against governance and support complexity. That tradeoff becomes most visible when fleets span many countries, use multiple manufacturers, or must survive long device lifetimes.
One common edge case is multi-operator resilience. eSIM can make carrier switching easier, but only if the commercial and technical agreements already exist. Another is constrained or hard-to-reach devices, where physical SIM replacement was never realistic and iSIM may simplify hardware design but complicate recovery if provisioning logic is weak. Guidance on best practice is still evolving for some of these fleet patterns, especially where procurement, firmware, and telecom ownership sit in different teams.
Teams also need to distinguish portability from portability with control. A SIM profile that can move quickly between devices or operators is useful, but that same flexibility increases the importance of inventory accuracy, release governance, and offboarding discipline. The more integrated the SIM becomes, the more the organisation must rely on trusted records, not manual local handling, to know what is active and where it belongs. The model breaks down when device records, provisioning authority, and network entitlements drift apart.
Risk and Threat Considerations
The main risk in eSIM and iSIM strategy is not just connectivity failure. It is control loss across a large device fleet, especially when provisioning authority, inventory, and carrier access are distributed across manufacturers, operators, and internal teams. Poorly governed remote provisioning can create exposure through unauthorised profile changes, weak offboarding, or inability to recover devices consistently.
Failure mechanism: Risk materialises when the organisation treats subscription management as a logistics task instead of a controlled lifecycle process. If profile issuance, revocation, and replacement are not tightly bound to asset records and approval workflows, devices may remain active after handover, decommissioning, or compromise. In adversarial scenarios, the same control gaps can be abused to redirect connectivity, obscure a device’s operational state, or preserve unauthorised access paths.
Impact: The result can be fleet fragmentation, unexpected service loss, regulatory or contractual exposure, and reduced confidence in which devices are actually active. In a compromised environment, the organisation may lose the ability to reliably suspend connectivity, isolate affected devices, or prove that retired endpoints no longer retain network access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 5.2 — Account Management | SIM profile control depends on tightly governed activation and revocation authority. |
| 1.1 — Inventory and Control of Enterprise Assets | eSIM and iSIM strategy depends on accurate fleet and subscription inventory. | |
| 12.1 — Network Infrastructure Management | Carrier and roaming choices affect operational resilience and network dependency. | |
| Recommendation — Restrict who can activate, switch, and revoke device connectivity profiles. Maintain authoritative inventory linking each device to its current connectivity entitlement. Define approved carrier and roaming paths for each device class and region. | ||
| NIST CSF 2.0 | ID.AM-1 — Physical devices and systems are inventoried | SIM strategy fails when device and entitlement inventories drift apart. |
| PR.AC-1 — Identities and credentials are issued, managed, verified, revoked | Remote provisioning creates credential-like control needs for SIM profiles. | |
| RC.RP-1 — Recovery plan is executed during or after an incident | Fleet recovery depends on restoring connectivity and control after profile or carrier failure. | |
| Recommendation — Keep device and subscription inventories synchronised before changing provisioning models. Manage profile issuance and revocation with the same discipline as sensitive access. Test how you will restore device connectivity after provisioning or carrier disruption. | ||
| NIST AI RMF | GV-1 — Govern AI governance processes | Not directly applicable to AI; omitted from final selection. |
| MITRE ATT&CK | T1556 — Modify Authentication Process | Abuse of provisioning or profile controls can redirect trusted connectivity. |
| Recommendation — Hunt for unauthorised changes to provisioning paths and subscription state. | ||
Practitioner Guidance
What to prioritise: Treat provisioning governance and offboarding as the core control problem, not the SIM format itself. The first question should be whether your device records, carrier entitlements, and change approvals stay aligned when a device is shipped, replaced, returned, or retired.
What to verify: Confirm that your operations team can answer, for any device class, who can activate a profile, who can suspend it, and how those actions are recorded. If that answer depends on tribal knowledge or a carrier-specific workaround, the strategy is not ready for scale.
What practitioners underestimate: The hardest part is often not technical activation but governance across many lifecycles. A strong eSIM or iSIM approach reduces physical handling, but it also removes an informal control point, so inventory accuracy and delegated authority become more important than they were with removable cards.
Practitioner takeaway: The best SIM strategy is the one your organisation can govern at fleet scale under outage, transfer, and retirement conditions, not the one that looks easiest during procurement.
Related resources from NHI Mgmt Group
- How should IoT operators approach expanding SIM and eSIM infrastructure into new regions without weakening supply chain resilience?
- What should security teams do when IoT devices reach end of life?
- How should security teams govern access when users move across devices and cloud apps?
- How should security teams secure Linux IoT devices with limited CPU and memory?