Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› Why do some enterprises still keep the eSIM…
NHI Lifecycle Management

Why do some enterprises still keep the eSIM M2M model for certain IoT use cases?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: NHI Lifecycle Management

Some organisations keep the M2M model because it preserves strong operational control over devices that are already deployed and expected to remain in the field for many years. The source highlights the SM-SR as a control point, since whoever controls it controls access to the eUICC. That makes M2M attractive where lifecycle longevity and device governance matter most.

Why the M2M model still fits long-lived IoT fleets

The M2M model persists when the operating reality is closer to industrial asset governance than consumer device provisioning. If devices are installed once and expected to stay in service for many years, enterprises often value a model that keeps provisioning, ownership and access control tightly anchored to the deployment lifecycle rather than to a user-centric activation flow.

That matters most where the fleet is already at scale, field replacement is expensive, and the business wants a stable control plane for connectivity decisions. In those conditions, the eSIM M2M model is less about convenience and more about preserving predictable control over device identity and subscription state over time.

Why SM-SR control changes the governance trade-off

The source points to the SM-SR as the decisive control point because controlling it means controlling access to the eUICC. That shifts the model from “who can activate a profile quickly” to “who can govern the device’s connectivity posture across its full lifecycle.” For enterprises that treat connectivity as part of the device trust boundary, that centralised control can be an advantage.

This is especially relevant when the organisation needs explicit approval paths, traceable change control, and fewer hands touching deployed assets. The stronger the requirement for operational oversight, the more attractive a model becomes that concentrates provisioning authority in a managed service layer rather than distributing it broadly across installers, users, or local operators.

That same control point also explains why some teams stay with M2M even as newer eSIM models offer more flexible remote switching. M2M is often chosen not because it is the most dynamic option, but because it best matches environments where connectivity should change only through deliberate governance, not through frequent self-service or end-user-driven activation.

When flexibility matters less than lifecycle certainty

The core decision is usually about lifecycle posture, not technical novelty. If a device is expected to remain in the field for a long time, the enterprise may prefer a model that supports stable subscription management, consistent policy enforcement and lower ambiguity about who can alter the device’s network access.

That makes M2M a good fit for use cases where outage risk, maintenance burden and ownership clarity matter more than rapid consumer-style portability. In practice, the question is whether the organisation wants maximum agility or maximum governance. When governance wins, the older model can still be the right one.

Risk and Threat Considerations

Centralised control over the SM-SR reduces operational ambiguity, but it also concentrates trust. If that control plane is mismanaged, compromised or poorly governed, the blast radius can extend across many deployed devices because access decisions propagate from a small number of authoritative systems.

Failure mechanism: A weakly governed provisioning path, overbroad administrative access, or failure to protect the SM-SR can let an attacker or insider alter profile access at scale, disrupt connectivity, or redirect devices into an unintended state.

Impact: The result can be fleet-wide service loss, loss of device governance, or unauthorized connectivity changes that are difficult to unwind once devices are distributed in the field.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-9 — Service Identification and AuthenticationCovers non-user device and service authentication in fleet connectivity models.
AC-6 — Least PrivilegeLimits who can alter connectivity and profile control in the M2M control plane.
Recommendation — Apply IA-9 to constrain device authentication and subscription access to approved provisioning paths. Restrict SM-SR administration and profile changes to the minimum required roles.
ISO/IEC 27001:2022A.5.15 — Access controlSupports governance of who can administer long-lived device connectivity and control points.
Recommendation — Define and enforce access rules for the SM-SR and related device control systems.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIM2M control points can become overprivileged if provisioning access is too broad.
NHI-07 — Long-Lived SecretsLong-lived IoT deployments often rely on credentials or access material that persists too long.
Recommendation — Reduce provisioning privileges so no single operator can alter fleet access unnecessarily. Shorten credential and profile lifetimes wherever the device lifecycle allows it.

Practitioner Guidance

What to prioritise: Treat the choice of M2M as a lifecycle governance decision, not a telecom preference. If device replacement is hard and control needs to stay central, anchor the architecture around explicit ownership of the provisioning path and clear approval for profile changes.

What to verify: Confirm who can administer the SM-SR, how changes are logged, and whether emergency revocation or profile replacement can be executed without losing control of the fleet. If those answers are vague, the model’s governance advantage is weaker than it first appears.

Practitioner takeaway: M2M remains useful when the enterprise wants durable, centralised control over long-lived devices, but the model only pays off if the provisioning authority is tightly governed and operationally recoverable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org