Consider a team eighteen months into an asset tracking deployment. Six hundred units are live in one country, the hardware is finished, and a distributor has just asked for the same product in a second market. The commercial model assumed the second country would behave like the first. It did not. Local rules on long-term roaming meant those devices needed a local operator profile, and the SIMs already sitting inside sealed enclosures could not accept one over the air. Every unit turned into a site visit.
Nothing in that story is exotic. It is the ordinary result of choosing a supplier on price per megabyte and a coverage map, then finding out later that the parts of the contract nobody read are the parts that decide what the deployment costs. What follows is not a ranking. It is the set of questions worth putting to any prospective supplier, with a note on what a good answer sounds like.
The Short Version
If you only have twenty minutes with a supplier, spend it here:
- Ask for a country-by-country answer on your real deployment list, not a headline country count.
- Ask which GSMA specification their eSIM implements, by number.
- Ask what you can do through the API without emailing anyone.
- Ask for the environmental class letters on the SIM hardware, not the word “industrial”.
- Ask which radio technologies they will still support once 2G and 3G are gone in your markets.
- Ask to see a redacted invoice from month fourteen of a real account.
- Ask who answers at two in the morning, and whether the response time is contractual.
Question One: Where Will These Devices Actually Live, And Can You Cover Every One Of Those Countries?
Give the supplier your real country list, including the markets you expect to enter in three years, and ask them to answer country by country. A good supplier comes back with a list that has some awkward entries on it. A weak one sends a world map.
Country counts are the least useful number in this industry. A provider claiming coverage in 180 countries is describing roaming agreements, not the quality of service in the specific towns where your devices will sit. What matters is which operator you land on in each market, and what happens when it stops answering.
Two terms carry most of the weight here.
Permanent roaming is the practice of leaving a device connected to a foreign network indefinitely, rather than for the short visits roaming agreements were designed around. Some regulators and operators restrict it, and the European regulators’ body BEREC documented both the restrictions and the difficulty smaller operators face negotiating permanent roaming access for M2M devices in its December 2024 report.
Multi-IMSI is a SIM carrying two or more network identities, with an applet on the card selecting the profile that performs best in that location. It lets a device behave like a local subscriber in a market where a foreign identity would be blocked or billed as international traffic.
A multi-network SIM, by contrast, keeps one identity and roams onto whichever partner network is strongest. It is simpler, usually cheaper, and the right answer across most of North America and Western Europe. It is the wrong answer in the markets that police permanent roaming, which is exactly where the two approaches stop being interchangeable.
If You Are Buying For Fleet Tracking Specifically
Fleet and telematics deployments have a narrower priority list than the general checklist suggests. In rough order:
- Automatic failover between networks, because a vehicle crosses coverage boundaries several times a day.
- SMS as well as data, and voice if the device has a duress or SOS function.
- Cross-border profile handling, because vehicles leave the country eventually.
- A SIM form factor that survives vibration and engine bay temperatures.
- Predictable per-vehicle cost, since fleet economics are quoted per asset per month.
Video telematics changes the arithmetic again. Upload volumes are an order of magnitude larger, so the pricing model matters more than the coverage map.
Question Two: Is the eSIM Genuinely Reprovisionable, and Under Which Specification?
Ask for the specification number. “We support eSIM” is a marketing sentence. “Our cards are eUICC to SGP.22, and here is our SGP.32 roadmap” is an engineering one.
An eUICC is a SIM whose operator profile can be changed remotely after manufacture. The physical card can be a plug-in or a soldered chip, because the word describes the software capability rather than the shape. That is the most common confusion in these conversations.
SGP.32 is the GSMA specification for remote SIM provisioning on IoT devices that have no screen and no user to tap through a menu. It introduces an eSIM IoT Remote Manager and an on-device provisioning agent so profiles can be pushed to network-constrained equipment. Version 1.1 was published in April 2024 and is available from the GSMA directly.
Underneath all of this sits a question about ownership. If the subscription management platform belongs to your supplier alone, then “you can change operator later” means “you can change operator later, with our cooperation”. Ask what the exit process looks like, in writing.
Question Three: What Can I Do Through Your API Without Sending Anyone An Email?
The honest test of a management platform is not the screenshot on the website. It is the list of actions that require a human on the supplier’s side. Ask for the API documentation before you sign, and check that all of these are available programmatically:
- Activate, suspend, and reactivate a SIM.
- Set and change a data cap on one SIM or a group.
- Pull session history and last known network for diagnostics.
- Receive threshold alerts as a webhook rather than an email.
- Create sub-accounts if you resell connectivity to your own customers.
The single pane of glass idea is worth taking literally. If SIM state lives in one system, APN configuration in a second, and billing in a third, somebody on your team becomes the integration layer. That person is expensive, and they will leave.
Question Four: Will The SIM Outlive The Device It Is Fitted Into?
This is the question that gets skipped, and it is the one that produces truck rolls.
A SIM in a consumer phone gets replaced every three years by a human with fingers. A SIM in a trailer tracker or a roadside cabinet has to survive heat cycling, condensation, salt, vibration, and a decade of not being touched. Usefully, none of this is a matter of opinion. ETSI TS 102 671 defines environmental classes for machine-to-machine secure elements, and a supplier who builds real hardware can quote the class letters without hesitating.
The classes that matter to a buyer:
- Temperature: TS covers -25C to +85C, TA covers -40C to +85C, TB covers -40C to +105C, and TC covers -40C to +125C.
- Data retention: classes RA, RB, and RC correspond to 10, 12, and 15-year retention periods.
- Update endurance: classes UA, UB, and UC correspond to 100,000, 500,000, and 1,000,000 write cycles.
- Mechanical and chemical: vibration testing follows JESD22-B103, salt atmosphere testing follows JESD22-A107, and temperature cycling requires 500 cycles across the full supported range.
The full text is published by ETSI as a free download, so there is no excuse for answering this question with an adjective. When a data sheet says “industrial grade” and nothing else, that is a claim about the marketing department.
One of the providers that publishes this level of hardware detail rather than a single ruggedized label is Trafalgar Wireless, whose industrial SIM cards are rated from -40C to 105C with a stated service life of over 17 years, against the decade it quotes for a standard M2M card. If you are buying industrial SIM cards for equipment that will sit in an engine bay, a utility cabinet, or an unheated enclosure through a northern winter, that pairing of a temperature range with a service life figure is the shape of specification worth demanding from every supplier on the shortlist, in writing, before the purchase order goes out.
Two follow-on decisions come from the same place.
The first is form factor. A removable card in a 2FF, 3FF, or 4FF socket can be swapped by a technician, which helps during development and during a supplier change. It is also the part of the assembly most likely to work loose, because sockets and vibration are old enemies. An MFF2 chip soldered to the board removes that failure mode and removes the swap option with it, which is precisely why MFF2 is normally paired with eUICC. You give up physical access, so you buy back remote provisioning.
The second is arithmetic. If the device is designed for a ten-year field life and the card is rated for ten years, there is no margin at all. Match the card to the enclosure, then keep the paperwork, because in five years nobody will remember which variant went into which production batch.
Question Five: Which Radio Technologies Will Still Be There In Ten Years?
Ask the supplier to state, per market, which technologies they will support at the end of your device’s expected life rather than today.
Legacy fallback is disappearing faster than most hardware roadmaps assume. In the United Kingdom, Ofcom reports that all four mobile network operators have completed their 3G switch-offs, with 2G shutdowns beginning in 2029 and running into 2030, and O2 began withdrawing inbound roaming access to its 2G network on 1 October 2025. A roaming SIM that quietly depends on 2G in a given country is on a clock, and the clock is visible.
For low-bandwidth sensor work, LTE-M suits anything that moves or needs low latency, and NB-IoT suits stationary meters and deep indoor placements. Neither is available everywhere. Availability depends on the local carrier having deployed it and on the roaming agreement covering it, and roaming support for these technologies is patchier than domestic coverage. Ask for the country list where the technology you designed around is genuinely usable on their SIM.
One more distinction: 5G in an IoT context usually means non-standalone 5G riding on an LTE core. That is fine for most applications, but it is not the same product as standalone 5G.
Question Six: How Does My Traffic Get Off The Public Internet?
A private APN is a dedicated access point name that routes your devices’ traffic into your own network rather than out to the open internet. Devices on it are not reachable from the public internet by default, which removes a whole category of attack before you configure anything else.
That is the foundation. The rest of the security conversation is about what sits on top:
- A site-to-site IPSec VPN, or equivalent tunnel, between the operator core and your data center or cloud environment.
- Static or fixed IP addressing, if your platform needs to initiate connections to devices rather than only receive them.
- IMEI locking, which binds a SIM to a specific device so a card pulled out of a tracker and put into a phone stops working.
- A private interconnect off the public internet entirely, offered by some providers through regional points of presence for latency-sensitive or regulated traffic.
Two practical warnings. Ask what the private APN costs and what the lead time is, because on some networks it is a heavy multi-week piece of work and on others it is a configuration change. Then ask whether the APN is genuinely private to you or shared among that provider’s customers under a private-sounding name. Those are different products.
Question Seven: Show Me What My Bill Looks Like In Month Fourteen
Pricing models here fall into a small number of shapes, and the shape matters more than the rate. Per SIM per month with an allowance is predictable and wasteful when most devices sit far below the allowance. Per megabyte, usually with a small monthly SIM or platform fee, is efficient for lumpy usage and harder to forecast. Pooled plans sit between the two.
Data pooling means the monthly allowance is held in common across all SIMs on the account, so a device using 40 MB offsets one using 4 MB and you are billed against the total. Where usage varies device by device, pooling is usually the cheaper structure and always the calmer one.
The questions that decide the bill:
- What happens at the pool limit: an overage rate, a throttle, a hard stop, or an automatic step up?
- Are suspended and unactivated SIMs billed?
- Is there a pre-activation or testing period before billing starts?
- What is the minimum term per SIM, and can a SIM be cancelled independently of the contract?
- Are activation, portal access, and API calls charged separately?
Then ask for a redacted invoice from an account in its second year. Sales quotes describe the best case. Invoices describe the product.
Question Eight: Who Answers At Two In The Morning, And When Should I Commit?
Support is the criterion buyers rank last during evaluation and first during an outage. Establish whether you get a named account contact or a shared inbox, whether that contact can see your account data or has to raise an internal ticket, what the target response time is for a service-affecting fault, and whether any of it is contractual. A written service level agreement with credits attached is a different commitment from a support page that promises to care.
On timing, the common mistake is engaging a connectivity provider after the hardware is finalized. By then, the form factor is fixed, the modem’s band support is fixed, and whether the design can accept a remote profile is fixed. A more workable sequence:
- During hardware design, discuss form factor, eUICC capability, and band support.
- During prototyping, test real SIMs from at least two suppliers in the actual enclosure, in the actual country.
- Before the first production run, settle profile provisioning, APN configuration, and commercial terms.
- After deployment, review pooled usage at three months and again at twelve, because the first plan you buy is rarely the right one.
Most suppliers will run a trial batch. Take it, and test in the worst location you have rather than the office car park.
Frequently Asked Questions
What is the most important factor when choosing an IoT SIM provider?
Coverage quality in the specific places your devices will operate, verified with real SIMs in the real enclosure. Most other items on the checklist are recoverable. Poor signal at the installation site is not, and no commercial term fixes it.
Should I choose a multi-network SIM or a multi-IMSI SIM?
Choose a multi-network roaming SIM when your devices stay in markets where permanent roaming is accepted, and you want operational simplicity. Choose multi-IMSI, or an eUICC with local profiles, when deploying into countries that restrict permanent roaming or where local rates are materially cheaper. Several providers offer both and will recommend based on your country mix.
Do I need SGP.32, or is SGP.22 enough?
SGP.22 remains workable for devices with a user interface, or that can be provisioned in a controlled environment. SGP.32 was written for devices with neither, and it is the sensible target for equipment with a long field life. If you are designing today for a ten-year deployment, ask about SGP.32 support and treat the roadmap answer as informative in itself.
When should I lock in an IoT connectivity provider?
Earlier than most teams do, and provisionally rather than permanently. Choose during hardware design so the form factor and eUICC decisions are informed, but keep a second SIM tested and a documented exit process, and prefer short contract terms in the first year.
Is a private APN worth it for a small deployment?
Often yes, and the deciding factor is usually the data rather than the device count. If your devices carry personal, medical, financial, or operational control traffic, a private APN is a reasonable baseline at almost any scale. If you are shipping temperature readings, standard routing with encryption at the application layer may be sufficient.
How long should an IoT SIM card last?
A standard M2M card is generally specified for around a decade of service, while industrial and embedded variants are specified well beyond that, with published figures of 17 years and more. The number that matters is the relationship between the card’s rating and the device’s expected field life, plus a margin.
The Eight Questions, In Order
- Can you cover every country on my actual deployment list, market by market?
- Which GSMA specification does your eSIM implement, by number?
- What can I do through the API without contacting a human?
- What environmental class is the SIM hardware graded to, and what is its service life?
- Which radio technologies will you still support in my markets in ten years?
- How does my traffic get off the public internet, and at what cost and lead time?
- What does a real invoice look like in month fourteen?
- Who answers during an outage, and is the response time contractual?
Take the answers in writing. A supplier who is comfortable putting the awkward ones on paper has usually done this before.