Guide
M2M vs Consumer eSIM: SGP.31 vs SGP.22 Explained
TravelGo
2026-08-16
M2M vs Consumer eSIM: SGP.31 vs SGP.22 Explained
Two Parallel Worlds
Not all eSIMs are alike. GSMA defines two families of embedded SIM specs. Consumer eSIMs follow SGP.22, used in phones, tablets and laptops, where a user scans a QR code and switches profiles on demand. M2M eSIMs follow the older SGP.02 and the newer SGP.31 and SGP.32, serving devices never touched by a human: meters, trackers, sensors and vehicle modules. The key difference is control flow. The consumer model is device-driven; the M2M model is server-driven. That single distinction shapes security, provisioning and how a profile reaches the chip.
Consumer Pull Model
The consumer standard is a pull model. A local profile assistant (LPA) inside the device handles profile download, enabling, disabling and deletion. When you scan an activation code, the LPA contacts the operator's SM-DP+ server, retrieves the encrypted profile and installs it into the eUICC. Nothing happens until the user or device initiates it, which suits interactive use: the owner approves the download and controls which profile is active. The trade-off is that someone must be present, with data and battery available.
M2M Push Model
Older M2M used SGP.02, where a subscription manager for secure routing (SM-SR) pushed profiles with little local involvement. Modern SGP.32 replaces this with the eSIM IoT Manager (eIM) and an IoT Profile Assistant (IPA). The operator triggers provisioning server-side, and the profile travels over the network to the eUICC with no human action. This push model supports bulk operations and silent switching, and suits devices without screens or reliable power. The trade-off is complexity: devices need bootstrap credentials and eIM integration.
Making the Choice
If a device has a screen, a nearby user and frequent operator changes, SGP.22 is usually right; it is simpler and matches the smartphone ecosystem. If the device is unattended, sealed or deployed in the thousands, SGP.31/SGP.32 fits better, since server-driven control avoids manual intervention. Real deployments blur the line: some automotive and router vendors ship consumer eSIMs managed by server tools. The decision hinges on who initiates changes, how many devices are involved, and the available power and processing budget.
Convergence Ahead
The two tracks are converging. SGP.32 brings M2M closer to consumer flexibility while keeping server-side control, making it the default IoT roadmap. Meanwhile, consumer eSIMs gain enterprise management as operators expose LPA functions to device-management platforms. iSIM takes the next step by integrating the eUICC into the system-on-chip, shrinking cost and size for tiny devices. The practical lesson is simple: choose the architecture that matches who controls connectivity, not the newest acronym.