What changed

The UK Department for Science, Innovation and Technology published version 1.1 of the Telecommunications Security Code of Practice on 14 July 2026. eSIM is named among the technologies that require updated security controls.

A digital profile can be added, changed or removed remotely. That convenience also creates additional risks for networks and subscriber confidentiality.

Who the code applies to

The code is aimed at large and medium public telecom providers operating networks and services across the United Kingdom.

It is not a separate instruction for smartphone owners, tourists or travel-eSIM buyers. It explains how providers should protect infrastructure and meet telecom-security obligations.

Which eSIM risks the government identifies

The guidance addresses compromised remote-management keys, misuse of eSIM and Remote SIM Provisioning functions, unauthorized profile changes, weak algorithms and compromised authentication keys.

It gives particular attention to the eUICC that stores eSIM profiles. Unlike a removable SIM, this secure component may be difficult or impossible to replace physically.

What operators are expected to control

Providers should assess SIM and eSIM profiles against current GSMA recommendations and prepare risk-reduction plans where weaknesses are found. Management messages must come only from authorized sources.

Where profiles can be changed remotely, only trusted services should be able to add, remove or edit them, and those operations must be monitored and logged.

Why certificate pinning is used

For operator-issued eSIMs, the code recommends certificate pinning. This establishes which servers and certificates are allowed to manage the profile.

A request from an unapproved service should be blocked, reducing the chance that an attacker or compromised third party can alter profiles remotely.

How eSIM suppliers should be assessed

Operators must look beyond their own network and assess external suppliers involved in SIM manufacture, personalization and remote profile delivery.

The code refers to supplier certification through sites accredited under the GSMA Security Accreditation Scheme. The requirement covers the wider SIM supply chain, not only eSIM.

What needs to be logged

Security records should identify who or what service performed an action, what changed, when it happened and where the request originated. Failed or unauthorized attempts and interruptions in security-event reporting also need attention.

Logging supports both incident investigation and earlier detection of unusual profile-management activity.

What this means for eSIM users

The update does not require users to reinstall an eSIM, replace a phone or stop using travel eSIMs. Most changes should happen in operator and supplier infrastructure.

Users should still install profiles only through trusted instructions, keep QR and activation details private, protect operator and email accounts, and verify reinstall rules before deleting a profile.

Does it restrict travel eSIMs?

No. The code does not ban overseas eSIM services or prevent travellers from buying mobile data.

It recognizes that global profile-management services can create network and privacy risks at scale and requires operators to manage those risks. That is an infrastructure-security obligation, not a consumer prohibition.

Why it matters

As eSIM adoption grows, mobile security depends increasingly on software platforms, certificates, cryptographic keys and remote-management servers rather than a removable plastic card.

The revised code shows regulators treating eSIM as part of critical telecom infrastructure as well as a convenient consumer feature. A compromised management platform could affect many connections at once.