Singapore: New eSIM Compliance Framework Released

Home / Country Update / Singapore: New eSIM Compliance Framework Released

Singapore’s Info-communications Media Development Authority (IMDA) has published three new Technical Specifications, all dated August 2026, that together set out the country’s complete compliance framework for eSIM-enabled products. IMDA TS eUICC SMT – CE Device covers eUICC requirements for consumer products, IMDA TS eUICC SMT – M2M Device covers machine to machine and IoT equipment, and IMDA TS Provisioning of eUICC Subscription Management covers the server infrastructure that provisions and manages profiles for both.

For manufacturers, the key takeaway is that a product’s architecture, not simply the presence of eSIM, determines which specification applies. Companies preparing Singapore equipment registrations should classify each eUICC implementation before compiling their compliance evidence.

Singapore on map device regulatory update

Why IMDA Split eUICC Requirements Across Three Documents

eUICC technology lets a device’s SIM profile be provisioned and changed remotely over the air rather than through a physical SIM swap. Consumer smartphones and wearables rely on a fundamentally different provisioning model than industrial, automotive, or metering equipment, so IMDA structured its framework around the two GSMA architectures that already separate these use cases.

Consumer devices pull subscription management through a Local Profile Assistant after the end user agrees terms with a service provider, while M2M devices have profiles pushed to them by an off-device server component. That architectural split is why IMDA issued a dedicated device-side specification for each category, alongside the server-side specification governing the infrastructure both rely on.

Classifying eUICC Products as Consumer Device or M2M Device

Manufacturers need to determine which framework applies based on how a product receives, manages, and changes its operator profile, not on cellular capability alone. A product only falls under one of these specifications if it actually implements eUICC or eSIM functionality; a device with a conventional removable SIM is out of scope regardless of its other cellular features. This distinction also matters for product families that share the same radio hardware: two SKUs on the same platform can fall under different specifications if one uses a removable SIM and the other an eUICC, or if one uses a consumer remote-provisioning implementation and another an M2M implementation.

Compliance Requirements for Consumer Devices

Under IMDA TS eUICC SMT – CE Device, a consumer device must at minimum hold PTCRB or GCF certification as proof of compliance with the GSMA Remote SIM Provisioning specifications, GSMA SGP.21 and SGP.22, and must meet the mandatory functional requirements in Annex C of SGP.22.

Vendors of consumer devices and their eUICC suppliers must also ensure that eUICC compliance declarations and certifications meet GSMA’s RSP Compliance Process under SGP.24, covering eUICC functional testing per the RSP Test Specification, security evaluations against the eUICC for Consumer Devices Protection Profile, hardware platform certification to the relevant Security IC Platform Protection Profile, and production sites accredited under the GSMA Security Accreditation Scheme for UICC Production (SAS-UP).

Compliance Requirements for M2M Devices

Under IMDA TS eUICC SMT – M2M Device, an M2M or IoT device must comply with the mandatory interoperability requirements in Annex G of GSMA SGP.02, ensuring the device works across different mobile network operator deployments, network equipment makes, and eUICC platforms. The eUICC used in the device must also be certified to the Protection Profile specified by GSMA under SGP.01. Vendors of M2M devices must ensure eUICC compliance declarations are submitted to and verified by GSMA under the M2M Compliance Process, SGP.16, covering functional testing per the M2M Test Specification, security evaluations against the eUICC Protection Profile, hardware platform certification, and SAS-UP accredited production sites.

Compliance Requirements for the Subscription Management Servers

The third specification, IMDA TS Provisioning of eUICC Subscription Management, governs the infrastructure behind both device categories. For M2M deployments, vendors of SM-DP and SM-SR servers must submit compliance declarations verified by GSMA under the M2M Compliance Process, covering the GSMA M2M architecture, functional testing, and SAS-SM accredited production sites. For consumer deployments, vendors of SM-DP+ and SM-DS servers must meet the equivalent RSP Compliance Process requirements under SGP.24. Data centres hosting any of these servers must carry SAS-SM accreditation and ISO 27001 certification.

A New Safeguard Against Permanent SIM Locking

The framework builds in consumer protection at both the device and server level. On the device side, IMDA TS eUICC SMT – CE Device requires that a consumer device support new profile downloads and profile swapping by the end user, and if the device ships with a pre-loaded profile, it must not prevent the user from downloading and enabling a different one. On the server side, IMDA has amended the GSMA Profile Policy Management rules so that no consumer eSIM profile provisioned in Singapore may carry Profile Policy Rules tied to itself, and profile owners can no longer set their own Profile Policy Rules in the profile metadata. Together, these provisions mean a consumer device cannot be permanently locked to a single eSIM profile.

For this article’s source information and any product certification guidance, please contact Global Validity. 

Quick Country Facts

Singapore

Certification Body: Infocomm Media Development Authority (IMDA)

Certification Type: Mandatory

License Validity: 60 Months

Application Language: English

Legal License Holder: Local Representative

In-Country Testing Requirement: Testing Not Required

The regulatory information above is based on radio type approval certification. Access additional certification requirements in over 200 countries and territories with Global Validity’s free proprietary product certification management software, Access Manager. Learn more about the platform here or fill our quick contact form! 

Global Validity is your partner for global certification success

Want to learn more about regulatory compliance and how we can help? Simply fill out the form below and we’ll be in touch!