For a long time, running an RSP environment meant significant upfront investment in secure infrastructure, specialised expertise, and complex certification. That barrier has largely disappeared. Cloud-native deployment models and globally available, GSMA-compliant hosting now make it realistic for mobile network operators, MVNOs, and IoT connectivity providers to build and operate their own sovereign RSP environments, rather than relying solely on fully managed third-party services.
Why Sovereignty Matters Now
Newer standards, particularly SGP.32 for IoT, are raising the stakes around remote identity management. As eSIM increasingly becomes core digital infrastructure rather than a peripheral feature, questions about who controls provisioning systems, cryptographic trust material, and operational governance carry real strategic weight.
Organizations exploring eSIM services typically face one central question early on: should the RSP environment be operator-controlled, hybrid, or fully outsourced? The answer shapes infrastructure architecture, integration strategy, security governance, and regional flexibility for years to come.
Operator-controlled deployments give direct authority over the provisioning architecture, whether hosted on-premises, in sovereign cloud infrastructure, or on dedicated public cloud platforms – und suited to operators wanting eSIM services closely aligned with broader digital transformation efforts.
Hybrid approaches are increasingly common in practice. Many organizations combine internally operated components with selected external services, for example, running their own SM-DP+ platform while using externally hosted HSM infrastructure. This allows faster deployment, reduced initial complexity, and a gradual path toward greater sovereignty as internal expertise grows.
Three Architectures, Different Use Cases
The GSMA is the global association that represents mobile network operators and defines the technical standards behind eSIM. Its ecosystem spans three main RSP architectures. SGP.22 remains the dominant model for consumer devices, built around the SM-DP+ platform and direct user interaction via the Local Profile Assistant. SGP.02, the original M2M standard, is still widely used in automotive and industrial environments, though its multi-party integration requirements make it less suited to constrained IoT deployments.
SGP.32 was introduced to close that gap. Built on proven SM-DP+ components but adding a new orchestration layer, the eIM (eSIM IoT Remote Manager), it supports remote profile lifecycle control across large, heterogeneous device populations, including devices without a user interface or reliable HTTPS connectivity.
Security Is the Foundation, Not an Afterthought
RSP environments sit among the most security-sensitive systems in the mobile industry. Production deployments typically separate staging and production environments with network architecture segmented into clearly defined trust zones: Internet-facing services run in a demilitarized zone (DMZ), an isolated network segment shielding internal systems from direct access via the public internet. Core provisioning systems remain isolated in tightly controlled internal segments. Further separation exists between applications, databases, administration, and cryptographic services.
At the centre sits the Hardware Security Module, the trust anchor responsible for generating, storing, and processing the cryptographic material provisioning operations depend on. Decisions about where the HSM is deployed, on-premises, private cloud, or dedicated hosting, tend to shape the entire security architecture and audit scope, which is why they belong among the earliest decisions in any deployment project.
Certification: The Path to GSMA Trust
Any organization deploying SM-DP+, SM-DP, or SM-SR infrastructure needs GSMA SAS-SM certification to participate in the trusted ecosystem. The process typically runs in stages: a "dry audit" against the staging environment using test certificates, followed by production go-live, and finally a "wet audit" within nine months of launch using live operational data to achieve full certification.
A Practical Path Forward
Establishing sovereign RSP capability is rarely a single leap. It tends to unfold as an incremental journey: assessing objectives and target operating models, preparing infrastructure and deploying the platform, and working through certification readiness alongside operational rollout.
That is where achelos brings value. Focused on SIM, eSIM, and RSP technology for more than a decade, achelos develops its own platforms in-house covering SM-DP+, eIM, M2M, and OTA and built on cloud-native, Kubernetes-compatible architecture that adapts to operator-owned, sovereign cloud, public cloud, or hybrid environments.
Beyond the technology, achelos supports customers across the full journey: architecture and certification strategy, secure environment setup and HSM integration, and SAS-SM gap analysis and pre-audit preparation thus giving operators, MVNOs, and IoT providers a controlled, realistic path toward operating their own trusted RSP environment.
Whether the goal is a regional consumer eSIM platform or large-scale IoT connectivity management, sovereignty in eSIM provisioning is no longer a distant ambition. It's an achievable strategic choice.