Which Came First, the Mobile Phone or the SIM? And How We Ended Up at SGP.32
There is a clear answer, and it is the least interesting part of the story. Follow the question through shrinking cards, industrial deployments and eUICC, and it turns into a better one: what actually needs to move? That has changed three times in thirty-five years.
This is the story of the SIM card in one paragraph. The mobile phone came first. GSM then split the subscriber from the handset and put the subscriber on a removable card. IoT made that card physically awkward to reach, so the industry embedded the secure chip and made the operator profile the thing that moves instead. SGP.32 is the latest version of that same idea, rebuilt for devices with no screen and no engineer on site.

Before the SIM, the telephone was the important thing
Ask which came first, the chicken or the egg, and you can lose an afternoon to a question with no answer. Ask the cellular version, which came first, the mobile phone or the SIM, and there is an answer: the phone came first. That is exactly where the two puzzles part company. The barnyard riddle is a loop with no beginning. Ours has a clear beginning and then does something far more interesting. It keeps swapping which part is the chicken and which is the egg, and it is still swapping them today.
The earliest cellular networks did not work like the GSM systems most of us grew up with. First generation analogue networks, AMPS, TACS and NMT, arrived before the familiar removable SIM. The network effectively identified the equipment, and subscriber details were tied to identifiers programmed into the terminal.
There was no little piece of plastic you casually pulled from one telephone and pushed into another. Person, subscription, network and handset were all bound tightly together. Change your handset and the operator had to be involved. Worse, cloning those handset identifiers became a serious fraud problem.
None of that seemed unreasonable at the time. Mobile telephones were expensive specialist equipment. Nobody was designing for billions of two pound sensors reporting the temperature of shipping containers. Then Europe began designing GSM, and somebody made a decision that still sits underneath modern networks.
GSM made a deliberate decision: the phone is not the subscriber
GSM separated two things that feel obvious to us today: the mobile equipment, and the mobile subscriber. The handset would carry its own equipment identity, which became the familiar IMEI. The subscriber would be represented separately, through the IMSI and the cryptographic key needed to authenticate to the network. And those subscriber credentials would live not inside the telephone, but in a separate secure module. The Subscriber Identity Module. The SIM.
The network could now ask two different questions. What equipment is this? The IMEI answers that. Which subscriber is using it? The SIM answers that. The clever part was never the plastic. It was the separation. Your subscription had become independent of your telephone, so you could buy a Nokia, an Ericsson or a Motorola without the handset maker owning your subscription, and your operator did not have to build your phone.
This shipped in 1991. The first commercial GSM network launched in Finland on 1 July that year, run by Radiolinja (now Elisa), after the first successful test call in March. The Munich smart card maker Giesecke and Devrient delivered the first commercial SIMs the same year, a first batch of just 300, to that same operator. And here is the detail people forget: the original SIM was the size of a credit card. G and D had already standardised the snap out plug in back in 1989, so you broke the small module out of a card the size of a Barclaycard and posted the whole thing into the phone.
Authenticate the subscriber, not the telephone. That single idea gave GSM portability, tamper resistant security for the secret key, operator control, equipment independence, and roaming across any compatible handset.
Thirty years of cutting away the plastic
Anyone under a certain age assumes SIM cards were always tiny. They were not. As phones shrank, carrying something the size of a credit card inside them became absurd, so we started trimming the plastic away. Full size became mini, mini became micro, micro became nano. Every generation made the card smaller, and every generation was doing exactly the same job: physically moving the subscriber credentials between devices.

| Form factor | Also called | Arrived | Size | Designed around |
|---|---|---|---|---|
| 1FF | Full size SIM | 1991 | 85.6 x 53.98 mm | A person swapping a subscription between phones |
| 2FF | Mini SIM | Late 1990s | 25 x 15 mm | Smaller handsets, still a human task |
| 3FF | Micro SIM | 2003 (mainstream 2010) | 15 x 12 mm | Slimmer smartphones |
| 4FF | Nano SIM | 2012 | 12.3 x 8.8 mm | Reclaiming almost all the plastic |
| MFF2 | Embedded, soldered eUICC | 2010s onward | About 6 x 5 mm, soldered | A machine nobody expects to open |
Notice the last row breaks the pattern. The moment you solder the chip to the board, you have quietly killed the reason it was ever removable. Nobody pops a soldered chip out of a field device. Which is exactly the problem IoT walked into.
Then IoT arrived and exposed the weakness
This is where our chicken and egg starts to misbehave. For a decade the roles had been settled: the handset was the bird, and the SIM was the egg you moved from one nest to the next. IoT quietly broke that arrangement.
Changing a SIM in a mobile phone is trivial. Changing one in an industrial device is not. Picture a router in a roadside cabinet, a smart meter, a sealed tracker halfway up a pole, a monitoring unit on an offshore asset, or tens of thousands of devices spread across several countries. Someone has to travel to it, open the enclosure, remove one card and insert another. When the device is weatherproof, safety critical, remote or deployed in enormous numbers, the cost of changing a two pound part can run into hundreds of pounds.
This forced the industry to notice a distinction it had glossed over for twenty years. We wanted the subscription to stay independent of the device. But we did not necessarily want the SIM itself to remain physically removable. Those are not the same thing. The removable card had been standing in for the real requirement, and in IoT the stand in had become a liability.
eUICC: soldering the wallet, not the card
Here the old question turns over completely. For thirty years the SIM was the egg you carried between birds. Embed it, and the egg never leaves the nest again. So has the chicken finally swallowed the egg for good? Not quite, and the reason it is not quite is the whole point.
The important development was not simply swapping a plastic SIM for a soldered chip. If that were all we had done, we would have travelled backwards. Instead came the eUICC, an embedded Universal Integrated Circuit Card that can securely receive and manage downloadable operator profiles. Now the secure SIM environment can stay with the device for its entire working life, while the mobile subscription no longer has to. The thing that moves has changed. With a traditional SIM you moved the card. With an eUICC you change the profile, and no screwdriver is required.
So in a sense, yes, we have tied the SIM back to the device. But look closer. An embedded eUICC has its own permanent identifier, the EID, and if it is a soldered MFF2 part it may sit inside the same unit for fifteen years. We now have several separate layers of identity that no longer have to be synonymous.
We did not solder the subscription into the device. We soldered the wallet into the device and made the cards inside replaceable remotely.
That distinction matters far more in IoT than in consumer mobile. A person changes phones every few years. An industrial device can stay installed for ten, fifteen, even twenty years, and during that time almost everything around it changes. Operators merge. Commercial agreements expire. Roaming rules change. Deployments cross borders. 2G and 3G networks switch off. A better tariff appears, and the connectivity supplier you started with may not even exist a decade later. Traditionally the SIM could quietly become one of the things deciding the commercial life of an otherwise perfectly serviceable device. Remote provisioning breaks that link: the hardware stays put while the connectivity relationship changes around it.
Why the first IoT eSIM was not enough
Remote provisioning is older than SGP.32. The GSMA M2M architecture, usually associated with SGP.02, already let you manage profiles on deployed devices. But it leaned on a heavyweight push model built around a server called the SM-SR, and switching operator meant an SM-SR to SM-SR handover that required a bilateral agreement between two competing carriers. Manageable for a single large integrated fleet. Operationally impossible across ten million devices needing operator changes in ten different countries.
The consumer standard, SGP.22, solved operator independence beautifully with an elegant pull model, but it assumed a human with a screen scanning a QR code. A turbine sensor has no thumbs. IoT sat awkwardly between the two worlds, too large and too headless for either.
| SGP.02 (M2M) | SGP.22 (Consumer) | SGP.32 (IoT) | |
|---|---|---|---|
| Built for | Early machine to machine fleets | Phones, tablets, wearables | Large scale, headless IoT |
| Trigger model | Push, operator driven | Pull, user initiated | Pull, remotely orchestrated |
| Human needed | No, but heavy integration | Yes, a screen and usually a QR scan | No |
| Orchestrator | SM-SR | LPA on the device | eIM (portable) |
| Profile server | SM-DP | SM-DP+ | SM-DP+ (reused) |
| Switching operator | SM-SR to SM-SR handover, bilateral deal | User re-provisions | eIM re-points, no hardware change |
| Main limitation | Lock in at scale | Needs a person | Ecosystem still maturing |
SGP.32: the same idea, with the human removed
SGP.32 is the GSMA IoT eSIM technical specification, published in 2023, with SGP.31 as its matching architecture. It keeps the pull model and reuses the same SM-DP+ profile server that consumer eSIM already deploys, which lowers the barrier to adoption. What it changes is the orchestration. The SM-SR is replaced by the eIM, the eSIM IoT Remote Manager, and a new component called the IPA, the IoT Profile Assistant, sits on the device or inside the eUICC and carries out the eIM instructions. Crucially, the eIM is portable: you can change eIM provider without touching hardware, which breaks precisely the lock in that defined SGP.02. It is built to work over constrained networks such as NB-IoT and LTE-M, with no user interaction at all.
Through the first half of 2026 this stopped being slideware. Certified hardware and commercial SIMs began shipping, and orchestration platforms moved to general availability. Worth knowing if you are specifying now: v1.2 remains the baseline that GSMA certification is issued against, while the GSMA published SGP.32 v1.3 on 28 May 2026, so certification programmes and vendor documentation will catch up over the coming months rather than overnight, and the two versions will coexist for a while.
The remaining work is less about the specification and more about the ecosystem. A deployment only benefits when the eUICC vendor, the eIM provider and operator coverage all line up in the country you care about. Certification has to catch up to v1.3. And the questions that decide a project are increasingly commercial rather than technical: who runs the eIM, and whose coverage sits behind the profiles. For where that stands right now, we track the SGP.32 state of play across the UK and Europe, and the practical selection questions sit in the IoT eSIM buyer's guide. For the architecture in depth, sgp32.co.uk is the dedicated reference, with euicc.co.uk covering the eUICC and EID layer.
The chicken, the egg, and what actually needs to move
So which came first? The cellular telephone came before the SIM. Then GSM separated the subscriber from the telephone. The physical SIM gave us a wonderfully simple way to carry that identity around. Then devices shrank and the SIM shrank with them. Then IoT put cellular connections into things where swapping a card became expensive, difficult or effectively impossible, so we embedded the secure element into the equipment.
At first glance that looks like undoing the original GSM idea. It is actually the idea taken further. For decades we treated the SIM as the thing that made a subscriber portable, and physically it was. But the plastic was never the point. The point was that owning the equipment and holding the network subscription did not have to be the same relationship. GSM achieved that by making the identity physically portable. Modern eSIM achieves it by making the profile digitally portable. SGP.32 makes that model practical for the billions of devices where nobody wants to open a SIM tray in the first place.
Which is why the cellular version of the chicken and egg question was never really about which came first. We settled that on the first page. The barnyard riddle loops forever; ours resolved, and then kept flipping which piece was the chicken and which was the egg until the labels stopped being the point. The point is which piece has to move. In 1991, the answer was the SIM. In the SGP.32 era, increasingly, it is just the subscription.
Frequently asked questions
Which came first, the mobile phone or the SIM?
The mobile phone. First generation analogue networks ran without a removable subscriber module; the SIM arrived with GSM, whose first commercial network launched in Finland in 1991. The interesting part is why GSM then chose to separate the subscriber from the handset at all.
Is an eSIM the same thing as an eUICC?
Not quite. The eUICC is the secure chip that can hold and switch operator profiles. eSIM is the broader idea of a SIM you provision remotely rather than insert. In IoT the eUICC is often the soldered MFF2 form, while the profile it carries is the part that actually changes.
Did IoT reverse the original GSM idea?
No, it extended it. Embedding the secure element looks like tying the SIM back to the device, but the subscription is no longer fixed: the hardware stays put while the operator profile moves. The separation GSM introduced in 1991 is stronger now, not weaker.
What is SGP.32 in one sentence?
SGP.32 is the GSMA IoT eSIM architecture that lets a device download and change its operator profile remotely with no human involved, using an eIM to orchestrate the fleet and an IPA on the device, over networks such as NB-IoT and LTE-M.



