{"id":5373,"date":"2014-10-09T15:41:28","date_gmt":"2014-10-09T15:41:28","guid":{"rendered":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/?page_id=5373"},"modified":"2025-10-30T16:14:12","modified_gmt":"2025-10-30T16:14:12","slug":"compliance","status":"publish","type":"page","link":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/","title":{"rendered":"Ensuring compliance with the specification"},"content":{"rendered":"<p>The technical basis for GSMA M2M Remote Provisioning for embedded UICC (eUICC) is described by GSMA SGP.01 and SGP.02.\u00a0 These technical specifications provide the necessary details to enable remote provisioning solution providers to develop GSMA compliant Remote Provisioning product, and Subscription Management services.<\/p>\n<p>Aside from the specifications describing technical implementation, it is beneficial for a technology to have a commonly agreed means to recognise the compliance of developed products.<\/p>\n<p>GSMA has developed such a compliance programme for M2M Remote Provisioning for eUICC.\u00a0 Its purpose is to describe the key test and accreditation expectations for eUICC and Subscription Management solutions that have been designed to SGP.01 and SGP.02.<\/p>\n<p>Products that successfully fulfil the compliance requirements are eligible to purchase GSMA Digital Certificates, used to authenticate with other M2M remote provisioning system elements.<\/p>\n<h2>Compliance Process Overview<\/h2>\n<p>The GSMA M2M compliance process is <u><a href=\"https:\/\/www.gsma.com\/newsroom\/gsma_resources\/sgp-16-m2m-compliance-process-v1-0\/\">SGP.16<\/a><\/u>, and lists the following areas for compliance with the GSMA M2M specifications:<\/p>\n<ul>\n<li>Functional interoperability of all entities<\/li>\n<li>Security of provisioning entities\n<ul>\n<li>By design (for eUICC)<\/li>\n<li>In production (for eUICC)<\/li>\n<li>At the operational location (for SM-DP and SM-SR)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The outcome of a successful compliance submission is eligibility for the Digital Certificate (PKI), needed for system authentication between the eUICC and M2M remote provisioning subscription management entities, SM-DP and SM-SR.<\/p>\n<p><a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-21495\" src=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218.png\" alt=\"\" width=\"1283\" height=\"546\" srcset=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218.png 1283w, https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218-300x128.png 300w, https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218-768x327.png 768w, https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2018\/12\/esim_IoT_1218-1024x436.png 1024w\" sizes=\"auto, (max-width: 1283px) 100vw, 1283px\" \/><\/a><\/p>\n<h2>Demonstrating compliance<\/h2>\n<p>In order to benefit from industry best practice for certification, GSMA has worked with specific global certification bodies that are:<\/p>\n<ul>\n<li>Recognised in the eUICC industry for test and certification expertise in either <strong>functional interoperability<\/strong> or <strong>security<\/strong>,<\/li>\n<li>Accessible to all organisations planning to operate in the GSMA defined M2M remote provisioning environment.<\/li>\n<\/ul>\n<p>The test and certification from these organisations, together with defined areas of vendor owned testing, form the basis for an M2M remote provisioning product to declare compliance with the M2M specifications.<\/p>\n<h3><strong>Functional interoperability<\/strong><\/h3>\n<p>GSMA has developed an M2M test specification, <a href=\"https:\/\/www.gsma.com\/newsroom\/gsma_resources\/sgp-11-remote-provisioning-architecture-for-embedded-uicc-test-specification\/\">SGP.11<\/a>.\u00a0 This provides test cases for each of the entities defined in the eUICC remote provisioning ecosystem, and for all test scenarios judged as key for a compliant product. Each test case references one or more requirements from the SGP.02 technical specification, with testing scopes covering:<\/p>\n<ul>\n<li>Interface interoperability<\/li>\n<li>System behaviour testing<\/li>\n<\/ul>\n<p><u>For eUICC:<\/u> \u00a0The SGP.11 requirements applicable to eUICC have been integrated into the test &amp; certification programme of <a href=\"https:\/\/globalplatform.org\/\">GlobalPlatform<\/a>.<\/p>\n<ul>\n<li>GlobalPlatform has developed an SGP.11 based M2M test plan and certification programme for functional interoperability testing.<\/li>\n<li>Embedded UICC wishing to declare SGP.16 compliance must first be GP qualified to the GlobalPlatform M2M test suite.<\/li>\n<\/ul>\n<p><u>For SM-DP and SM-SR<\/u>: In order to declare SGP.16 compliance, vendors are required to develop and execute their own SGP.11 based test plans.<\/p>\n<ul>\n<li>These vendor owned test plans will typically use either simulated testing via commercially available test equipment, or MNO based interoperability testing.<\/li>\n<li>Whichever methodology is selected the vendor owned test plan must reference the SM-DP and SM-SR test requirements from SGP.11.<\/li>\n<\/ul>\n<h3><strong>Security of provisioning entities<\/strong><\/h3>\n<h4>Product Security by design<\/h4>\n<p>The security of the embedded UICC design is required to be assured on two levels:<\/p>\n<p><u>At the hardware level<\/u>: certification to BS-CC-PP-0084, or its predecessor, BS-CC-PP-0035.\u00a0 This is the industry recognised security IC Protection Profile.<\/p>\n<p><u>At the embedded UICC functional level<\/u>: BSI-CC-PP-0089.\u00a0 This is a protection profile developed specifically for the embedded UICC.<\/p>\n<p>Methodologies and certification are available through <a href=\"https:\/\/www.commoncriteriaportal.org\/\">Common Criteria<\/a> laboratories and Certification Bodies with competence in the <a href=\"https:\/\/www.sogis.org\/uk\/tech_domain_en.html\">SOG-IS Smartcard technical domain<\/a>.<\/p>\n<h4><strong>Security in operation<\/strong><\/h4>\n<p>GSMA\u2019s long established, industry respected, <u>Security Accreditation Scheme<\/u> (SAS) has been adopted as the required security accreditation for M2M entities handling sensitive assets, and provisioning assets; including MNO profile information and Digital Certificates.\u00a0 SAS is an audit based scheme and the preparation time for audit should be taken into account when planning a compliance campaign for eUICC, SM-SR and SM-DP.<\/p>\n<p><u>For eUICC production:<\/u> a SAS-UP audit comprehensively reviews the handling of sensitive data during eUICC production.\u00a0 A valid GSMA SAS-UP accreditation is required in order to declare SGP.16 compliance.<\/p>\n<p><u>For SM-DP and SM-SR operational location<\/u>: a SAS-SM audit assesses the robustness of processes affecting secure data management at the Subscription Management datacentre.\u00a0 A valid GSMA SAS-SM accreditation is required in order to declare SGP.16 compliance.<\/p>\n<h2>Connecting to M2M remote provisioning<\/h2>\n<p>Assurance and authentication for operational M2M remote provisioning is based on a GSMA root public key interface (PKI), as defined in the M2M specifications. eUICC, SM-DP and SM-SR all need a PKI Digital Certificate to operate within GSMA M2M remote provisioning.<\/p>\n<p>The end result of a successful SGP.16 compliance declaration is a GSMA confirmation for PKI issuance.\u00a0 This is accepted by the GSMA M2M CI as proof of eligibility for a Root PKI certificate.\u00a0 Details of the M2M Root CI can be found\u00a0at this link.<\/p>\n<p><em>Note: <\/em><\/p>\n<ul>\n<li><em>The PKI certificate will not be issued by the Root CI without proof of eligibility. <\/em><\/li>\n<li><em>Organisations intending to apply for a PKI certificate are advised to initiate contract discussions with the M2M Root CI in advance, in order to avoid delays once their compliance process is successfully completed. <\/em><\/li>\n<li><em>The CI is generally able to issue test certificates for test purposes, contact the CI for details. <\/em><\/li>\n<\/ul>\n<h2>Find out more<\/h2>\n<p><a href=\"https:\/\/www.gsma.com\/newsroom\/gsma_resources\/sgp-16-m2m-compliance-process-v1-0\/\">Download<\/a>\u00a0SGP.16, the eSIM Compliance Process.\u00a0 This GSMA PRD, and its associated annexes provides full details of compliance requirements and current valid specification versions for compliance.\u00a0 It also includes the declaration templates necessary to make a compliance declaration.<\/p>\n<span class=\"shortcode_button_wrapper\"><a class=\"shortcode_button gsmacolor_red size_medium\" href=\"https:\/\/www.gsma.com\/newsroom\/gsma_resources\/sgp-16-m2m-compliance-process-v1-0\/\" target=\"_blank\">Download Document<\/a><\/span>\n<p>For further information or in case of any questions on the GSMA M2M compliance process, please contact M2MCompliance@gsma.com<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The technical basis for GSMA M2M Remote Provisioning for embedded UICC (eUICC) is described by GSMA SGP.01 and SGP.02.\u00a0 These technical specifications provide the necessary details to enable remote provisioning solution providers to develop GSMA compliant Remote Provisioning product, and Subscription Management services. Aside from the specifications describing technical implementation, it is beneficial for a [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":3417,"parent":81,"menu_order":4,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","footnotes":""},"tags":[54],"class_list":["post-5373","page","type-page","status-publish","has-post-thumbnail","hentry","tag-home"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Ensuring compliance with the specification | Internet of Things<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ensuring compliance with the specification\" \/>\n<meta property=\"og:description\" content=\"The technical basis for GSMA M2M Remote Provisioning for embedded UICC (eUICC) is described by GSMA SGP.01 and SGP.02.\u00a0 These technical specifications provide the necessary details to enable remote provisioning solution providers to develop GSMA compliant Remote Provisioning product, and Subscription Management services. Aside from the specifications describing technical implementation, it is beneficial for a [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Internet of Things\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/gsma\/\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-30T16:14:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2012\/03\/hero_embedsim.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"650\" \/>\n\t<meta property=\"og:image:height\" content=\"320\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@GSMA\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Ensuring compliance with the specification | Internet of Things","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/","og_locale":"en_US","og_type":"article","og_title":"Ensuring compliance with the specification","og_description":"The technical basis for GSMA M2M Remote Provisioning for embedded UICC (eUICC) is described by GSMA SGP.01 and SGP.02.\u00a0 These technical specifications provide the necessary details to enable remote provisioning solution providers to develop GSMA compliant Remote Provisioning product, and Subscription Management services. Aside from the specifications describing technical implementation, it is beneficial for a [&hellip;]","og_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/","og_site_name":"Internet of Things","article_publisher":"https:\/\/www.facebook.com\/gsma\/","article_modified_time":"2025-10-30T16:14:12+00:00","og_image":[{"width":650,"height":320,"url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2012\/03\/hero_embedsim.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@GSMA","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/","name":"Ensuring compliance with the specification | Internet of Things","isPartOf":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/#primaryimage"},"image":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2012\/03\/hero_embedsim.jpg","datePublished":"2014-10-09T15:41:28+00:00","dateModified":"2025-10-30T16:14:12+00:00","breadcrumb":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/#primaryimage","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2012\/03\/hero_embedsim.jpg","contentUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2012\/03\/hero_embedsim.jpg","width":"650","height":"320"},{"@type":"BreadcrumbList","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/"},{"@type":"ListItem","position":2,"name":"Remote SIM Provisioning for Machine to Machine","item":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/embedded-sim\/"},{"@type":"ListItem","position":3,"name":"Ensuring compliance with the specification"}]},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#website","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/","name":"Internet of Things","description":"To enable the IoT, a world in which consumers and businesses enjoy rich new services, connected by an intelligent and secure mobile network.","publisher":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#organization","name":"GSMA","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#\/schema\/logo\/image\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2024\/06\/GSMA-Logo-Red-RGB_square.jpg","contentUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-content\/uploads\/2024\/06\/GSMA-Logo-Red-RGB_square.jpg","width":600,"height":600,"caption":"GSMA"},"image":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/gsma\/","https:\/\/x.com\/GSMA","https:\/\/www.instagram.com\/gsmaonline\/","https:\/\/www.linkedin.com\/company\/12380","https:\/\/www.youtube.com\/user\/GSMAOnline","https:\/\/en.wikipedia.org\/wiki\/GSMA"]}]}},"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/pages\/5373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/comments?post=5373"}],"version-history":[{"count":34,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/pages\/5373\/revisions"}],"predecessor-version":[{"id":46675,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/pages\/5373\/revisions\/46675"}],"up":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/pages\/81"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/media\/3417"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/media?parent=5373"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/internet-of-things\/wp-json\/wp\/v2\/tags?post=5373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}