Kigen, the Cambridge eSIM company spun out of Arm in 2020, says its automotive eSIM is the first to be certified under the GSMA's eUICC Security Assurance scheme while supporting SGP.32 version 1.3, the most recent release of the IoT eSIM specification. The announcement on 23 September is aimed at carmakers and their tier one suppliers, with sampling in the MFF2 solderable package beginning this month and GSMA interoperability testing scheduled for the same period.
The product runs Kigen's eSIM operating system on Infineon's TEGRION SLI22 automotive security controller, part of a family that also covers consumer and industrial variants. The certification covers the eSIM software together with the GSMA's manufacturing and subscription management audits and Kigen's hosted eSIM IoT Manager.
Security assurance here means something specific. The eSA scheme is built on the Common Criteria framework and its evaluation methodology, adapted for eSIMs through GSMA documentation and assessed against protection profiles by accredited certification bodies. It is a laboratory evaluation of the product rather than a self-declaration.
Why This Certificate Matters To Carmakers
A vehicle is the hardest case in IoT connectivity. It is built in one country, sold in another, driven across borders for a decade or more, and nobody is going to open the dashboard to swap a SIM. Carmakers have handled that with regional hardware variants and operator contracts signed before the vehicle was built, which locks a connectivity decision in place for the life of the car.
SGP.32 removes the technical basis for that. A single hardware build ships worldwide and the operator profile is assigned afterwards, then changed remotely when contracts or coverage change. Version 1.3 adds direct and indirect profile downloads, digital activation codes and emergency profile handling, the last of which matters when a vehicle loses its working profile somewhere inconvenient.
The scale behind the interest is substantial. More than 400M connected cars are on the road, some generating up to 25 gigabytes of data an hour, and Rivian has said its R2 will support SGP.32. Deloitte expects 81% of manufacturer fleets to be software-defined by 2030.
The Trust Anchor Has To Outlast The Contract
"Vehicles are becoming long-lived software platforms, so their connectivity trust anchor must remain secure and manageable long after production," Kigen chief executive Vincent Korstanje said, which is the argument for certifying this component rather than treating it as a commodity part.
The eSIM holds the credentials that authenticate a car to a mobile network. If it cannot be updated securely, a vulnerability found in year three of a fifteen-year service life has no remedy short of a recall, which is the problem that has made connected vehicle architecture a security question rather than a features question.
Regulation Is Turning Certificates Into Evidence
The commercial driver behind this is procurement. European rules now require manufacturers placing products on the market to support security updates across a product's expected lifetime, and a carmaker answering that for a vehicle needs its suppliers to have answered it for every component inside.
Kigen added secure updates for the eSIM operating system to its IoT products earlier this year for that reason. A certificate from an accredited laboratory is something an OEM can put in front of an auditor, which is a different kind of value from anything in a datasheet.
Gloria Trujillo, the GSMA's eSIM technical director, framed it as translating specifications into interoperable technology, which is the gap the industry has been working through all year as SGP.32 moved from standard to shipping product.
What The Certificate Does Not Cover
Two things in the announcement sit outside the certified scope and should be read accordingly.
Post-quantum cryptography is the first. Kigen says it supports manufacturers implementing hybrid key encapsulation that combines classical and quantum-safe algorithms, and provides a development kit for testing it. The company is also clear that post-quantum cryptography is not yet part of GSMA specifications, so this is preparation rather than a certified capability.
The second is maturity. Interoperability testing with the GSMA is scheduled for October, samples go to manufacturers this month, and no customer has been named. A first certification is a starting position in a procurement cycle that runs for years in automotive, not a design win.
A Field Competing On Certificates
Kigen is not alone in automotive eSIM, where Thales, Giesecke+Devrient and IDEMIA all supply carmakers, and the specific claim here is being first to this certification for this version of the specification.
The distribution work around it is arguably more telling. Kigen has partnered with China Mobile International, whose IoT and automotive head Katherine Diao described the arrangement as bringing SGP.32-based security to Chinese automakers, and lists more than 20 network providers ready for digital activation codes and over 60 modules carrying its software.
That is the shape of competition now that the standard itself is settled. Vendors are differentiating on certification, on orchestration software and on which operators and module makers they have already integrated with, a contest over who controls the provisioning layer rather than over the specification.
Certification Is The Easy Part
Getting a certificate for an eSIM that supports the newest specification is a real engineering achievement and a modest commercial one. What follows is harder: interoperability testing, design wins at manufacturers with multi-year validation cycles, and proving that the secure update path works when it is needed in eight years rather than when it is demonstrated today.
Carmakers evaluating this should take the certificate as evidence that the component meets a defined security bar, and ask separately about everything the scheme does not assess, starting with what happens to a fleet when the specification moves on again.