What is an IoT SIM?

An IoT SIM (Internet of Things SIM) is a SIM card or embedded SIM profile made for machine-to-machine communication rather than personal mobile use. It provides cellular connectivity for equipment and can support the security, scalability and central management required for remotely deployed devices. It performs the same core function as a consumer SIM by providing the subscriber identity and credentials used to authenticate a connection to a mobile network. An enterprise IoT service can add the lifecycle management, security controls and commercial flexibility required to operate large fleets of connected devices.

The three eras of IoT connectivity

The way organisations buy connectivity has moved through three eras, and the IoT SIM sits at the centre of the current shift.

  • Coverage-first. The only question that mattered was whether a network reached the site.
  • Cost-first. Once coverage was widely available, buyers optimised for the lowest price per SIM and per megabyte.
  • Resilience-first. In mature deployments, basic coverage is increasingly treated as a minimum requirement rather than the endpoint. The deciding question is whether the connectivity architecture can sustain the service when one network path becomes unavailable.

This third priority is the focus of the rest of this guide. For services where a loss of connectivity carries a safety, compliance or revenue cost, an IoT service should be assessed not only on coverage and price, but on how effectively the wider connectivity architecture supports operational continuity.

How an IoT SIM works

Every SIM holds a secure identity, the IMSI (International Mobile Subscriber Identity), together with cryptographic keys. When a device powers on, its cellular modem uses the SIM’s identity and credentials to attempt registration with an available mobile network permitted by the subscription. The network authenticates the subscription before allowing the device to connect. Once connected, the device uses an APN (Access Point Name) to select the data service through which traffic is routed to the internet or a private corporate network.

Enterprise IoT connectivity can add three important capabilities around this exchange that are not normally central to a consumer mobile service:

  • Multi-network access. Many multi-network IoT SIMs use a roaming IMSI, a single network identity that, through roaming agreements, can attach to any of several permitted radio networks reachable at a site rather than being tied to one operator. The modem selects from the available permitted networks according to its network-selection logic, configured preferences and roaming arrangements, and reselection may happen automatically or through device or platform controls. Some services use more than one IMSI (multi-IMSI), switching identity to reach networks a single IMSI cannot.
  • Remote provisioning. An eUICC is a secure SIM platform capable of storing and managing operator profiles. Where the service and device architecture support remote SIM provisioning, authorised systems can download, enable, disable or delete profiles over the air without replacing the SIM physically.
  • Central management. A connectivity management platform can provide administrators with information about SIM status and data use, together with diagnostics and lifecycle controls across the estate.
How an IoT SIM connects

Connected device

Modem selects from available permitted radio networks
Standard multi-network SIM

IoT SIM

One roaming identity (IMSI)
Permitted radio networks
Radio A
Radio B
Radio C
Operator core
Roaming core
One identity roams between radio networks on a single operator-core path
rSIM (resilient SIM)

rSIM®

Two independent profiles
Permitted radio networks
Radio A
Radio B
Radio C
Separate operator cores
Core A
Core B
Autonomous failover between two independent connectivity paths

Private APN + VPN

Secure, isolated path where configured

Customer platform

Monitoring and control
Both approaches can use permitted radio networks. rSIM adds a second, independent profile associated with a separate operator core, with autonomous failover between the two paths.

Figure 1. How an IoT SIM connects. A standard multi-network SIM uses one roaming identity across several permitted radio networks on a single operator-core path.

rSIM instead uses two independent profiles associated with separate operator cores, with autonomous failover between them. Where configured, traffic can then pass through a private APN and VPN to the customer platform.

Illustrative architecture. Exact routing, network access and security arrangements vary by deployment.

IoT SIM form factors

IoT SIMs come in several physical forms. Removable cards follow the familiar sizes: 2FF (mini), 3FF (micro) and 4FF (nano). For equipment deployed in demanding environments, an MFF2 SIM is soldered directly onto the circuit board. Removing the card slot can improve resistance to vibration, contamination and accidental removal, subject to the component and device’s environmental specifications.

In standards-based usage, eSIM refers to remotely provisionable SIM capability implemented through an eUICC, although the term is also commonly used commercially for an embedded MFF2 SIM. A newer implementation, the integrated SIM (iSIM), builds the secure SIM capability into the device’s system-on-chip, reducing component count, space and potentially power consumption.

How an IoT SIM differs from a consumer SIM

A consumer mobile service is normally designed around an individual user, a personal device and a subscription centred on one home operator. Enterprise IoT connectivity is designed for fleets of devices that may remain deployed for years with little or no human attention. The practical differences are set out below.

 

Attribute Consumer SIM Enterprise IoT SIM
Primary use Personal calls, texts and data on a single device Machine-to-machine data across many devices
Typical lifespan Typically follows the user’s handset or subscription cycle Designed to support devices that may remain deployed for many years
Network access Usually centred on one home operator, with roaming where included May support one or several permitted networks, depending on the service
Provisioning Individual activation through the operator or device Bulk lifecycle management, with remote profile management where eUICC is supported
Management User account or operator app Central platform for fleet status, usage, controls and reporting
Security Operator-standard mobile security and service configuration May add private APN, VPN, traffic policies, device binding and controlled addressing
Resilience Usually depends on the home subscription and available roaming May support multi-network selection; rSIM adds autonomous profile switching across independent operator cores
Commercials Individual voice and data tariff Fleet tariffs may include pooled data, low-usage plans and estate-level billing

Why multi-network and DualCore® resilience matters

Coverage alone does not guarantee continuity of service. A device may sit within a single operator’s coverage yet still lose connectivity when that operator has a local outage, network congestion or a coverage gap inside a building. Designing for resilience means giving the device more than one way to connect.

It helps to separate three ideas that are often merged.

  • Availability is whether a network is present at a site.
  • Connectivity is whether the device can reach a network at a given moment.
  • Operational continuity is whether the service the device supports keeps running.

A site can have availability yet lose connectivity during an outage, and a device can have intermittent connectivity yet still fail to deliver operational continuity. Resilience is designed for the third of these, not the first.

The context in figures

  • IoT Analytics estimates that cellular IoT connections reached 4.7 billion in 2025 and forecasts 9.2 billion by 2030.
  • Devices are commonly planned around long operational lives. For example, surveyed utilities generally see an AMI 1.0 smart-meter service life of around 15 years, within a total range of 10 to 20 years, spanning several network and operator changes (Exponent, 2026).
  • UK mobile operators have retired their 3G services and have committed to retire 2G by 2033 at the latest, with individual operator timetables differing (Ofcom).

For many critical applications, a single-network design may prove to be a false economy. A roaming IMSI lets a device attach to an available radio network permitted by its roaming arrangements. It may attach to another permitted network when the current network becomes unavailable or when its configured network-selection and reselection rules cause it to change network.

CSL takes this further with rSIM®, its patented resilient SIM, which holds two independent multi-network roaming profiles, each using a separate operator core. It can switch profiles automatically at the SIM level when it detects a sustained loss of data connectivity and a viable fallback profile is available. For alarms, healthcare monitoring and other critical services, automatic profile failover can reduce the duration and operational impact of a network-related loss of connectivity.

What is the solution to the cost of connectivity downtime? CSL resilient SIM connectivity solution

Security for connected devices

IoT devices are attractive targets, and many sit in exposed locations for years, so security has to be built into the connectivity rather than added later. A private APN can route device traffic through a controlled private path rather than exposing the device directly to the public internet, while site-to-site VPNs can extend that protection back to the customer’s own systems. SIM-level access policies, device locking by IMEI and firewall allow-listing can restrict what each SIM and device is permitted to do.

Where controlled inbound access is required, private or static addressing can be combined with VPNs, firewall rules and access-control lists so that only authorised systems can reach the device. A private APN does not provide complete security by itself, so it should form part of a layered design that includes encryption, authentication, firewalling and secure device configuration. When correctly configured and maintained, these controls can reduce the network exposure of a large, distributed estate.

Managing an IoT estate over its lifetime

An IoT deployment is not finished at installation. Over a device’s life of five, ten or more years, networks change, tariffs change and requirements change. A connectivity management platform is where that lifecycle is handled: activating and suspending SIMs, watching data use to catch faults or unexpected behaviour, diagnosing problems remotely and reporting across the estate.

For compatible eUICC deployments, the GSMA’s SGP.31 architecture and SGP.32 technical specification support remote profile management designed for IoT devices, including constrained or unattended equipment. Depending on the service architecture and assigned permissions, this can allow authorised connectivity providers or enterprise systems to manage network profiles over the air, which can support a single device design across multiple markets, subject to radio-band compatibility, certification, local regulation, operator support and commercial arrangements.

Planning for the switch-off of legacy networks

Connectivity planning now has to account for the retirement of older mobile networks. In the UK, the retirement of legacy mobile networks is under way. Operators have completed their 3G switch-offs and have committed to retire 2G by 2033 at the latest, although individual operator timetables differ.

Devices that depend solely on retired legacy services will need compatible replacement hardware or a migration path to an available technology such as 4G, LTE-M, NB-IoT or 5G, depending on the application and network. For long-life equipment specified today, choosing a SIM and a device that support current and emerging networks, including an assessment of whether technologies such as 5G RedCap suit the application, can reduce dependence on networks approaching retirement.

Which sectors depend on critical connectivity

CSL defines Critical Connectivity® as secure, resilient connectivity for systems where loss of connectivity could affect safety, compliance, public services or business continuity.

That description fits a wide range of sectors, among them building and security, healthcare and telecare, critical infrastructure, utilities, transport and logistics, the public sector, industrial operations, and retail. In each, the cost of an unnoticed loss of connection is measured not only in inconvenience, but in safety, regulatory exposure or lost revenue.

Choosing an IoT SIM is a resilience decision

Choosing an IoT SIM means looking beyond coverage and commodity pricing. Buyers should establish which networks and radio technologies the device can use, how it responds to a loss of connectivity, how traffic is protected, how the estate will be managed and whether the device can remain supported throughout its intended life.

For critical deployments, the IoT SIM and the managed connectivity around it form a resilience control within the operational technology stack. The design determines whether a service has an alternative path when its primary connection fails.

Frequently asked questions

What is the difference between an IoT SIM and a normal SIM?

A consumer mobile service is normally designed around an individual user, a personal device and a subscription centred on one home operator. An IoT connectivity service supports connected equipment, often across a large fleet and over a much longer deployment life, and can add multi-network access, remote provisioning, central management and additional security controls.

Do IoT SIMs roam between networks?

Multi-network IoT SIMs can. A single-network IoT SIM may not. Many multi-network IoT SIMs use a roaming IMSI, a single identity that can attach to any permitted partner radio network at a location. The modem selects from permitted networks according to its configuration, available radio conditions and roaming arrangements. It may reselect another permitted network when the current connection becomes unavailable or its selection rules trigger a change. Some SIMs also hold multiple IMSIs for wider access.

What is the difference between an eSIM and an IoT SIM?

An IoT SIM is defined by its purpose: connecting machines and equipment. eSIM describes remotely provisionable SIM technology, in which operator profiles can be securely downloaded to an eUICC. The eUICC may be implemented in a removable SIM, a soldered MFF2 component or, in an integrated implementation, within the device chipset.

How long do IoT SIMs last?

IoT devices are often deployed for five to ten years or longer. The SIM service, component specification, network support and commercial agreement therefore need to be selected for the intended operating life.

Are IoT SIMs secure?

IoT connectivity can be configured with additional controls that are not normally included in a basic consumer mobile service, including private APNs, VPNs, device binding, traffic policies and restricted addressing.

What does the 2G and 3G switch-off mean for IoT SIMs?

UK mobile operators have retired their 3G services and have committed to retire 2G by 2033 at the latest, with individual timetables differing. UK devices that depended solely on 3G require a migration path, while 2G-only devices will lose service as operators complete their individual switch-offs. New deployments should use SIMs and hardware that support an appropriate current technology such as 4G, LTE-M, NB-IoT or 5G.

What is a multi-IMSI SIM?

A multi-IMSI SIM holds more than one subscriber identity, allowing the service to use different operator or regional identities for international coverage, localised connectivity or to help address permanent-roaming restrictions. This differs from a roaming IMSI, which uses one identity to access permitted partner networks through roaming agreements. Depending on its implementation and switching rules, multi-IMSI can extend network reach, support local connectivity arrangements or optimise commercial terms. It should not be confused with eUICC technology, which enables complete operator profiles to be downloaded and managed remotely. rSIM combines autonomous, SIM-resident connectivity monitoring and profile switching with eUICC capability aligned with the GSMA SGP.32 specification. This supports profile lifecycle management across regions while adding autonomous resilience during operation.

Can an IoT SIM work internationally?

Yes, where the provider has suitable roaming or local-profile arrangements. Coverage, permanent-roaming restrictions, registration requirements and supported radio bands should be checked for every target country.

What is an M2M SIM?

M2M (machine-to-machine) SIM is an earlier term for a SIM used by connected equipment rather than a phone. It is used interchangeably with IoT SIM, though IoT SIM is the more current term.

What happens if a mobile network fails?

If a device’s only available network path fails, connectivity may be lost until service returns. rSIM can detect a sustained loss of data connectivity and switch automatically to an independent profile when a viable fallback path is available. This reduces dependence on a single radio-network or mobile-core path.

Is an IoT SIM suitable for alarm signalling?

Yes. Alarm signalling is a strong use case for managed IoT connectivity because availability, network diversity, path monitoring and failover can be specified according to the application’s risk and signalling requirements. The complete solution should also be designed and assessed against the relevant alarm-signalling requirements, rather than relying on the SIM alone.

Can IoT SIM services support private APNs?

Yes. Many enterprise IoT connectivity services support private APNs. A private APN can route device traffic through a controlled private path rather than exposing it directly to the public internet, and can be combined with a VPN, static or private addressing and access policies to isolate and protect the estate.

Talk to CSL

To assess the resilience of your connectivity architecture, or discuss how IoT SIMs and rSIM could support a critical deployment, contact the CSL team.

CSL MFF2 eSIM
Published on: 22nd July, 2026
Sectors: Building & Security, Healthcare & Telecare, Infrastructure, Public Sector, Retail & Hospitality, Transport & Logistics, Utilities
Applications: Agriculture & Farming, Alarm Systems & Worker Safety, Building Automation/Smart Building, Car Parks, Construction, Critical Resilience & Multi-Site Operations, Customer Experience, Emergency Lighting, Energy Efficiency Monitoring, Environmental Monitoring & Management, EV Charging & Parking solutions, Healthcare Infrastructure, Manufacturing & Automation, Medical Devices, Onsite Connectivity Access Point, Renewable Energy, Retail & Payment Systems, Security & Surveillance, Smart Commercial/Business Appliances, Supply Chain & Asset Management, Telecare/Remote Monitoring, Vehicle & Fleet Management