The Story of the SIM Card

Story Of The SIM Card
eSIM & SIM  ·  From GSM to SGP.32

Which Came First, the Mobile Phone or the SIM? And How We Ended Up at SGP.32

There is a clear answer, and it is the least interesting part of the story. Follow the question through shrinking cards, industrial deployments and eUICC, and it turns into a better one: what actually needs to move? That has changed three times in thirty-five years.

In short

This is the story of the SIM card in one paragraph. The mobile phone came first. GSM then split the subscriber from the handset and put the subscriber on a removable card. IoT made that card physically awkward to reach, so the industry embedded the secure chip and made the operator profile the thing that moves instead. SGP.32 is the latest version of that same idea, rebuilt for devices with no screen and no engineer on site.

A 1980s telecoms engineer at a cluttered desk with a TACS brick phone, studying a 1988 GSM blueprint of a Subscriber Identity Module noting that network identity belongs to the user, not the device.
A GSM design document, dated 1988. Analogue networks such as TACS were still the working technology, but the idea that would define the next three decades was already on the drawing board: the subscription should belong to the user, not the handset.

Before the SIM, the telephone was the important thing

Ask which came first, the chicken or the egg, and you can lose an afternoon to a question with no answer. Ask the cellular version, which came first, the mobile phone or the SIM, and there is an answer: the phone came first. That is exactly where the two puzzles part company. The barnyard riddle is a loop with no beginning. Ours has a clear beginning and then does something far more interesting. It keeps swapping which part is the chicken and which is the egg, and it is still swapping them today.

The earliest cellular networks did not work like the GSM systems most of us grew up with. First generation analogue networks, AMPS, TACS and NMT, arrived before the familiar removable SIM. The network effectively identified the equipment, and subscriber details were tied to identifiers programmed into the terminal.

There was no little piece of plastic you casually pulled from one telephone and pushed into another. Person, subscription, network and handset were all bound tightly together. Change your handset and the operator had to be involved. Worse, cloning those handset identifiers became a serious fraud problem.

None of that seemed unreasonable at the time. Mobile telephones were expensive specialist equipment. Nobody was designing for billions of two pound sensors reporting the temperature of shipping containers. Then Europe began designing GSM, and somebody made a decision that still sits underneath modern networks.

GSM made a deliberate decision: the phone is not the subscriber

GSM separated two things that feel obvious to us today: the mobile equipment, and the mobile subscriber. The handset would carry its own equipment identity, which became the familiar IMEI. The subscriber would be represented separately, through the IMSI and the cryptographic key needed to authenticate to the network. And those subscriber credentials would live not inside the telephone, but in a separate secure module. The Subscriber Identity Module. The SIM.

The network could now ask two different questions. What equipment is this? The IMEI answers that. Which subscriber is using it? The SIM answers that. The clever part was never the plastic. It was the separation. Your subscription had become independent of your telephone, so you could buy a Nokia, an Ericsson or a Motorola without the handset maker owning your subscription, and your operator did not have to build your phone.

This shipped in 1991. The first commercial GSM network launched in Finland on 1 July that year, run by Radiolinja (now Elisa), after the first successful test call in March. The Munich smart card maker Giesecke and Devrient delivered the first commercial SIMs the same year, a first batch of just 300, to that same operator. And here is the detail people forget: the original SIM was the size of a credit card. G and D had already standardised the snap out plug in back in 1989, so you broke the small module out of a card the size of a Barclaycard and posted the whole thing into the phone.

The principle in one line

Authenticate the subscriber, not the telephone. That single idea gave GSM portability, tamper resistant security for the secret key, operator control, equipment independence, and roaming across any compatible handset.

Thirty years of cutting away the plastic

Anyone under a certain age assumes SIM cards were always tiny. They were not. As phones shrank, carrying something the size of a credit card inside them became absurd, so we started trimming the plastic away. Full size became mini, mini became micro, micro became nano. Every generation made the card smaller, and every generation was doing exactly the same job: physically moving the subscriber credentials between devices.

The SIM card generations shown largest to smallest, from the full-size 1FF through mini, micro and nano to the soldered MFF2 eSIM chip, with the gold contact staying roughly the same size as the plastic around it shrinks.
Thirty years of cutting away the plastic. From the credit-card-sized 1FF to the soldered MFF2, the gold contact at the centre barely changed. What shrank was the plastic around it, and eventually the need to remove it at all.
Form factorAlso calledArrivedSizeDesigned around
1FFFull size SIM199185.6 x 53.98 mmA person swapping a subscription between phones
2FFMini SIMLate 1990s25 x 15 mmSmaller handsets, still a human task
3FFMicro SIM2003 (mainstream 2010)15 x 12 mmSlimmer smartphones
4FFNano SIM201212.3 x 8.8 mmReclaiming almost all the plastic
MFF2Embedded, soldered eUICC2010s onwardAbout 6 x 5 mm, solderedA machine nobody expects to open

Notice the last row breaks the pattern. The moment you solder the chip to the board, you have quietly killed the reason it was ever removable. Nobody pops a soldered chip out of a field device. Which is exactly the problem IoT walked into.

Then IoT arrived and exposed the weakness

This is where our chicken and egg starts to misbehave. For a decade the roles had been settled: the handset was the bird, and the SIM was the egg you moved from one nest to the next. IoT quietly broke that arrangement.

Changing a SIM in a mobile phone is trivial. Changing one in an industrial device is not. Picture a router in a roadside cabinet, a smart meter, a sealed tracker halfway up a pole, a monitoring unit on an offshore asset, or tens of thousands of devices spread across several countries. Someone has to travel to it, open the enclosure, remove one card and insert another. When the device is weatherproof, safety critical, remote or deployed in enormous numbers, the cost of changing a two pound part can run into hundreds of pounds.

This forced the industry to notice a distinction it had glossed over for twenty years. We wanted the subscription to stay independent of the device. But we did not necessarily want the SIM itself to remain physically removable. Those are not the same thing. The removable card had been standing in for the real requirement, and in IoT the stand in had become a liability.

eUICC: soldering the wallet, not the card

Here the old question turns over completely. For thirty years the SIM was the egg you carried between birds. Embed it, and the egg never leaves the nest again. So has the chicken finally swallowed the egg for good? Not quite, and the reason it is not quite is the whole point.

The important development was not simply swapping a plastic SIM for a soldered chip. If that were all we had done, we would have travelled backwards. Instead came the eUICC, an embedded Universal Integrated Circuit Card that can securely receive and manage downloadable operator profiles. Now the secure SIM environment can stay with the device for its entire working life, while the mobile subscription no longer has to. The thing that moves has changed. With a traditional SIM you moved the card. With an eUICC you change the profile, and no screwdriver is required.

So in a sense, yes, we have tied the SIM back to the device. But look closer. An embedded eUICC has its own permanent identifier, the EID, and if it is a soldered MFF2 part it may sit inside the same unit for fifteen years. We now have several separate layers of identity that no longer have to be synonymous.

THE EQUIPMENT IMEI and serial number: which piece of hardware is this? THE CONTAINER EID: which secure eUICC is this? Stays with the device. THE SUBSCRIPTION IMSI and operator profile: this is now the part that moves.
Three layers that used to travel together. Today only the bottom one has to move, and it can move over the air.

We did not solder the subscription into the device. We soldered the wallet into the device and made the cards inside replaceable remotely.

That distinction matters far more in IoT than in consumer mobile. A person changes phones every few years. An industrial device can stay installed for ten, fifteen, even twenty years, and during that time almost everything around it changes. Operators merge. Commercial agreements expire. Roaming rules change. Deployments cross borders. 2G and 3G networks switch off. A better tariff appears, and the connectivity supplier you started with may not even exist a decade later. Traditionally the SIM could quietly become one of the things deciding the commercial life of an otherwise perfectly serviceable device. Remote provisioning breaks that link: the hardware stays put while the connectivity relationship changes around it.

Why the first IoT eSIM was not enough

Remote provisioning is older than SGP.32. The GSMA M2M architecture, usually associated with SGP.02, already let you manage profiles on deployed devices. But it leaned on a heavyweight push model built around a server called the SM-SR, and switching operator meant an SM-SR to SM-SR handover that required a bilateral agreement between two competing carriers. Manageable for a single large integrated fleet. Operationally impossible across ten million devices needing operator changes in ten different countries.

The consumer standard, SGP.22, solved operator independence beautifully with an elegant pull model, but it assumed a human with a screen scanning a QR code. A turbine sensor has no thumbs. IoT sat awkwardly between the two worlds, too large and too headless for either.

 SGP.02 (M2M)SGP.22 (Consumer)SGP.32 (IoT)
Built forEarly machine to machine fleetsPhones, tablets, wearablesLarge scale, headless IoT
Trigger modelPush, operator drivenPull, user initiatedPull, remotely orchestrated
Human neededNo, but heavy integrationYes, a screen and usually a QR scanNo
OrchestratorSM-SRLPA on the deviceeIM (portable)
Profile serverSM-DPSM-DP+SM-DP+ (reused)
Switching operatorSM-SR to SM-SR handover, bilateral dealUser re-provisionseIM re-points, no hardware change
Main limitationLock in at scaleNeeds a personEcosystem still maturing

SGP.32: the same idea, with the human removed

SGP.32 is the GSMA IoT eSIM technical specification, published in 2023, with SGP.31 as its matching architecture. It keeps the pull model and reuses the same SM-DP+ profile server that consumer eSIM already deploys, which lowers the barrier to adoption. What it changes is the orchestration. The SM-SR is replaced by the eIM, the eSIM IoT Remote Manager, and a new component called the IPA, the IoT Profile Assistant, sits on the device or inside the eUICC and carries out the eIM instructions. Crucially, the eIM is portable: you can change eIM provider without touching hardware, which breaks precisely the lock in that defined SGP.02. It is built to work over constrained networks such as NB-IoT and LTE-M, with no user interaction at all.

Through the first half of 2026 this stopped being slideware. Certified hardware and commercial SIMs began shipping, and orchestration platforms moved to general availability. Worth knowing if you are specifying now: v1.2 remains the baseline that GSMA certification is issued against, while the GSMA published SGP.32 v1.3 on 28 May 2026, so certification programmes and vendor documentation will catch up over the coming months rather than overnight, and the two versions will coexist for a while.

The remaining work is less about the specification and more about the ecosystem. A deployment only benefits when the eUICC vendor, the eIM provider and operator coverage all line up in the country you care about. Certification has to catch up to v1.3. And the questions that decide a project are increasingly commercial rather than technical: who runs the eIM, and whose coverage sits behind the profiles. For where that stands right now, we track the SGP.32 state of play across the UK and Europe, and the practical selection questions sit in the IoT eSIM buyer's guide. For the architecture in depth, sgp32.co.uk is the dedicated reference, with euicc.co.uk covering the eUICC and EID layer.

The chicken, the egg, and what actually needs to move

So which came first? The cellular telephone came before the SIM. Then GSM separated the subscriber from the telephone. The physical SIM gave us a wonderfully simple way to carry that identity around. Then devices shrank and the SIM shrank with them. Then IoT put cellular connections into things where swapping a card became expensive, difficult or effectively impossible, so we embedded the secure element into the equipment.

At first glance that looks like undoing the original GSM idea. It is actually the idea taken further. For decades we treated the SIM as the thing that made a subscriber portable, and physically it was. But the plastic was never the point. The point was that owning the equipment and holding the network subscription did not have to be the same relationship. GSM achieved that by making the identity physically portable. Modern eSIM achieves it by making the profile digitally portable. SGP.32 makes that model practical for the billions of devices where nobody wants to open a SIM tray in the first place.

Which is why the cellular version of the chicken and egg question was never really about which came first. We settled that on the first page. The barnyard riddle loops forever; ours resolved, and then kept flipping which piece was the chicken and which was the egg until the labels stopped being the point. The point is which piece has to move. In 1991, the answer was the SIM. In the SGP.32 era, increasingly, it is just the subscription.

Frequently asked questions

Which came first, the mobile phone or the SIM?

The mobile phone. First generation analogue networks ran without a removable subscriber module; the SIM arrived with GSM, whose first commercial network launched in Finland in 1991. The interesting part is why GSM then chose to separate the subscriber from the handset at all.

Is an eSIM the same thing as an eUICC?

Not quite. The eUICC is the secure chip that can hold and switch operator profiles. eSIM is the broader idea of a SIM you provision remotely rather than insert. In IoT the eUICC is often the soldered MFF2 form, while the profile it carries is the part that actually changes.

Did IoT reverse the original GSM idea?

No, it extended it. Embedding the secure element looks like tying the SIM back to the device, but the subscription is no longer fixed: the hardware stays put while the operator profile moves. The separation GSM introduced in 1991 is stronger now, not weaker.

What is SGP.32 in one sentence?

SGP.32 is the GSMA IoT eSIM architecture that lets a device download and change its operator profile remotely with no human involved, using an eIM to orchestrate the fleet and an IPA on the device, over networks such as NB-IoT and LTE-M.

Sources: GSMA eSIM specifications (SGP.02 M2M, SGP.22 consumer, SGP.31 and SGP.32 for IoT; v1.2 certification baseline, v1.3 published 28 May 2026). Giesecke and Devrient historical accounts of the first commercial SIM (1991, delivered to Radiolinja). Ericsson and Nokia historical records of the first GSM call (Radiolinja, Finland, 1991). SIM form factor dimensions per ETSI and GSMA. Commercial and version status reflects the market as of September 2026 and should be reviewed before any procurement decision.