Security Accreditation Scheme (SAS)

What is SAS?

The most important security element for every mobile device is the SIM card – whether it’s a UICC (Universal Integrated Circuit Card) or an eUICC (embedded Universal Integrated Circuit Card).

If you’re a supplier of UICCs/eUICCs, or a subscription management service, you need to demonstrate that your environment and processes are secure. And if you’re procuring cards, you need to assess that security – both reliably and cost-effectively.

SAS enables this through two standardised global audits – one for UICC/eUICC suppliers and one for subscription management service providers.

Why is it important for your business?

SAS is highly respected in the mobile industry and adopted by over 100 of the world’s leading UICC/eUICC and subscription management suppliers. It is also relied on by mobile network operators and device manufacturers when selecting suppliers.

Here are the main reasons why SAS is trusted by all the relevant players in the ecosystem:

Universal standard 

A standardised security framework agreed by a cross-industry working group and endorsed by the global association for the mobile industry 

Robust, independent auditing

Each supplier accreditation is conducted by two independent audit companies appointed by the GSMA. They inspect everything from people and premises, to policies and production.

Drives security improvement

Audits enable experts to provide in-depth analysis to aid supplier improvements. This helps build trust in the wider industry that sensitive assets are secure and customers are protected.

Continually high standards 

The standard continually evolves to meet the requirements of the industry, according to measures agreed by the cross-industry working group. 

Meeting national security requirements

SAS benefits the regulatory community by ensuring that national security needs are met. Through one global scheme that reflects the security needs of the entire ecosystem and provides complete transparency as to which suppliers are accredited.

Practical examples of what it can do

Whether you’re a SIM supplier, subscription management service provider, mobile operator or device manufacturer, the GSMA Security Accreditation Scheme improves confidence in your business. 

SIM and subscription management providers

SIM and subscription management providers 

  • Required for eUICC compliance – part of the GSMA remote SIM provisioning compliance scheme for eUICC production and subscription management.
  • Preferred by your customers’ procurement teams – presence on global accredited supplier list boosts business opportunities.
  • Global assurance – from the global association for the mobile industry demonstrates your commitment to security and reduces risks for customers.
  • Fewer individual inspections from different customers – with one accreditation to meet industry expectations.
  • Supports business development – rigorous, transparent security review of your operations highlights potential best practice improvements.

Mobile Network Operators

Mobile Network Operators

  • Offers peace of mind to investors and stakeholders – with certification from the global association for the mobile industry that suppliers are secure.
  • Cost-free service for mobile operators – avoiding expensive individual audits of suppliers.
  • The GSMA’s website provides 24/7 visibility of accredited suppliers – so you can make fast, informed decisions and focus on development and deployment.
  • Rely on a rigorous global security standard – requiring full supplier commitment and detailed accreditation, conducted by highly qualified independent auditors.
  • Continuous updates and ongoing accreditation renewal – provides assurance that suppliers continue to maintain high security standards.

Device Manufacturers

Device Manufacturers

  • Reduce cost and time-to-market – instantly viewing accredited suppliers and avoiding expensive, time-consuming individual audits.
  • Rely on a rigorous security standard – requiring full supplier commitment and detailed accreditation, conducted by highly qualified independent auditors.
  • Offers peace of mind to investors and stakeholders – with certification from the global association for the mobile industry.
  • Promotes ongoing improvement and risk reduction – encouraging a security by design culture across the supplier community.
  • Adherence to SAS standards can serve as a key differentiator – especially in a market where security is a critical decision factor.

Resources

Further information and insights in the form of blogs, case studies and videos. 


Register your interest

Please get in touch if you need more information, would like to book a meeting, have a product demo or want to talk to us about your particular use case.