Kigen and the SGP.32 Revolution: How an Arm Spin-Out Quietly Rewired IoT eSIM


IoT UK Investigates the SIM that finally grew up

Cellular IoT has spent two decades tripping over the same small square of plastic. The device engineering got extraordinary. Modules shrank, power budgets tightened, silicon got clever, and firmware learned to sleep for months and wake on a schedule measured in years. Then the whole clever edifice would arrive at a customer site, and somebody would have to walk out to it with a SIM card in a little jiffy bag.

That was the state of play for far too long. The physical SIM demanded physical access. The first machine-to-machine eSIM standard, GSMA SGP.02, replaced the plastic but not the pain, wrapping profile management in an operator-led control framework that enterprises found rigid and slow. The consumer eSIM standard, SGP.22, assumed the one thing an industrial device almost never has: a human being, a screen, and the patience to scan a QR code. None of that describes a water meter in a chamber under a pavement, an asset tracker crossing three continents, or a sensor bolted to a wind turbine.

Kigen eSIM SGP.32 Company Overview

The fix arrived in the shape of a new GSMA specification, SGP.32, and the single company most responsible for turning that specification from a PDF into working infrastructure is Kigen. Born out of Arm, quietly backed by some of the largest names in technology investment, and chaired into existence at the standards level by one of its own people, Kigen has made itself the trust layer that a great deal of the cellular IoT world now runs on, whether the end customer has ever heard the name or not.

This is a long read, because the subject deserves one. We will cover where Kigen came from, who runs it, what it actually sells, how it drives the SGP.32 movement, how it powered Robustel’s move into eSIM, who it competes with, and what all of this means for the UK IoT market in 2026 and beyond. If you want the shorter version first: SGP.32 is the standard that lets you change a device’s mobile network over the air, with no human, no screen, and no truck roll, and Kigen built the first widely adopted engine for doing it.

1. Who is Kigen? Background and origins

Kigen did not appear from nowhere. It was incubated inside Arm, the Cambridge company whose processor architecture sits in billions of chips worldwide, and it inherited a very Arm way of thinking about a problem: solve it once, in silicon, in a way everyone else can build on, and do not try to own the whole stack yourself.

The problem Kigen was spun out to solve was a specific and awkward one. How do you anchor trust and cellular connectivity directly into a connected device without adding cost, without draining the battery, and without tying the customer to a single network for the fifteen years the device is in the field? Answering that meant treating the SIM not as a consumable but as a secure operating system, one that could live on a removable card, on a soldered chip, or fused into the main processor itself.

Two features of Kigen’s position matter more than any product detail. The first is independence. Kigen does not run a mobile network, does not sell connectivity, and does not compete with the module makers or the operators. That neutrality is the entire point. It can act as an honest broker of trust across an ecosystem whose members are otherwise busy competing with each other, and it can do so without a customer worrying that the SIM vendor is quietly steering them toward a particular carrier.

The second is pedigree and backing. Kigen is Arm-founded, and its investors include SoftBank Vision Fund 2 and SBI Group, which is not the sort of cap table you assemble for a science project. The company positions itself among the top five SIM vendors globally, and its security accreditations sit in the places that matter: GSMA-accredited SAS-SM data centres for subscription management, and SAS-UP certified production sites in Dublin and Noida. In a market where “secure” is a word everyone uses and few can evidence, that certification depth is the difference between a pilot and a production deployment.

The mission, stripped of marketing gloss, is straightforward. Make cellular security something that is designed into a device from the silicon up, so that an OEM can ship one product anywhere on earth and manage its connectivity for its entire life without ever touching it again. Everything else Kigen does is in service of that single sentence.

2. The people behind the company

Standards bodies and security companies are not glamorous places, and Kigen’s leadership reflects that. These are mobile-standards veterans and semiconductor security people, not growth-hackers.

Vincent Korstanje, Chief Executive Officer. Korstanje has run Kigen through its transition from an Arm business unit into an independent market leader. His public argument, repeated consistently, is that IoT connectivity should be treated with the same programmatic discipline as cloud software, and that SGP.32 matters precisely because it removes the complexity that has kept enterprise IoT stuck at pilot scale. He has described the standard as a defining milestone for the industry, on the grounds that it finally makes connectivity flexible, resilient and secure by design rather than by heroic manual effort.

Dr Saรฏd Gharout, Head of Standards and VP of Standardisation. If any single person can be said to have authored the framework this whole article rests on, it is Gharout. He chairs the GSMA eSIM Working Group 2, which owns the technical specifications, and he also chairs the TCA IoT Remote SIM Provisioning working group. He has been building standards across GSMA, ETSI, GlobalPlatform and TCA for years. His guiding principle for SGP.32 was refreshingly plain: make it interoperable and simple without compromising the one job the secure element exists to do, which is security. That balance, comprehensive without being complex, is why the standard reads the way it does.

Bee Hayes-Thakore, VP of Marketing. Hayes-Thakore has shaped how Kigen tells its story, which in a standards-driven business is less about slogans and more about translation, turning dense cryptographic architecture into something a product manager or an operations lead can actually act on. Much of Kigen’s ecosystem-building narrative, the interoperability events and multi-vendor testing, runs through her function.

Loรฏc Bonvarlet, SVP of Solutions and Marketing. Bonvarlet speaks for the demand side, articulating why enterprises are pushing for the new standard rather than waiting to be sold it. His public commentary has leaned on a point that keeps proving true: the pull for SGP.32 is coming from buyers who have been burned by single-network SIMs and permanent-roaming crackdowns, not from vendors inventing a problem.

It is a team assembled for credibility in rooms full of engineers and regulators, which is exactly the room where the future of IoT connectivity is being decided.

3. What SGP.32 actually is, and why it changes everything

It is worth being precise here, because a lot of coverage of SGP.32 is vague to the point of uselessness. If you want the fuller standards explainer, our friends over at euicc.co.uk have a clean write-up of what SGP.32 is, and sgp32.co.uk goes deeper still on the multi-operator deployment mechanics. Here is the working version.

There are three GSMA eSIM standards, and they solve three different problems:

  • SGP.02 (M2M) was the original machine-to-machine eSIM standard. It works, but it is a push model controlled by the operator’s subscription management platform, and it is heavy and inflexible for modern fleet management.
  • SGP.22 (Consumer) is the standard in your phone and smartwatch. It is elegant, but it assumes a Local Profile Assistant with a user interface, someone to tap “yes”, and reliable connectivity and power. Useless for a headless sensor.
  • SGP.32 (IoT) was published in first form in May 2023, refined to the current v1.2, and built specifically for constrained, headless, long-life devices. It borrows the remote provisioning from SGP.02 and the pull model from SGP.22, then adapts both for the realities of NB-IoT, LTE-M and industrial connectivity.

The clever bit of SGP.32 is a piece of architecture called the eIM, the eSIM IoT remote Manager. This is the server-side orchestration component that lets an administrator download, enable, disable, switch and delete operator profiles on a fleet of devices remotely and at scale. It is a dramatic simplification of the machinery that came before, and crucially it can drive low-power devices that only wake up occasionally and cannot hold a rich local interface.

On the device sits the IPA, the IoT Profile Assistant, the lightweight on-device agent that talks to the eIM and to the operator’s SM-DP+ (the server that actually prepares and delivers profiles). Together, eIM plus IPA plus a certified eUICC give you the thing enterprises have wanted for a decade: the ability to decide, or change, which mobile network a device uses, over the air, after it has already been manufactured, shipped and installed.

That is the whole game. Change the network without touching the device. Everything about the commercial case for SGP.32, and everything about Kigen’s business, flows from that one capability.

4. Kigen’s products and services

Kigen sells the layer between the silicon and the cloud. Its portfolio is best understood as a stack, from the secure operating system on the chip up to the console a network administrator logs into.

Kigen eSIM and iSIM operating systems. At the base is a carrier-agnostic secure OS, described by Kigen as the industry’s most compact secure SIM OS. It can live on a traditional removable SIM, on a soldered MFF2 chip for devices that will never be opened again, or integrated directly into the cellular modem or main processor as an iSIM, which removes the discrete SIM component entirely and saves board space, cost and power. It supports the full spread of cellular technologies an IoT device might use, from 2G through LTE-M and NB-IoT, across more than two hundred countries.

The Kigen eIM. Announced in October 2024 and positioned as the first market-ready eIM fully compliant with GSMA SGP.32 v1.2, this is the flagship. It was the first eIM certified as GSMA-compliant, and Kigen operated the first GSMA SAS-SM certified site with an eIM. It ships with flexible deployment: fully managed inside Kigen’s accredited data centres, hosted on AWS, or self-managed on the customer’s own infrastructure. That deployment flexibility matters enormously to enterprises with data-residency or sovereignty requirements, which in the UK and Europe is an increasing number of them.

Kigen Pulse. The human-facing console. Pulse gives administrators visibility, auditing and control over profile operations, downloading, enabling, switching and auditing profiles across a fleet from a single pane of glass, with real-time device and profile status. It is the difference between “the standard supports this” and “an operations person can actually do this before lunch”.

Kigen APIs and device SDK. For teams that want the capability inside their own platform rather than a separate console, Kigen exposes developer-ready APIs for lifecycle workflows, plus an embedded-C device SDK for integrating the IPA into device firmware. This is the Arm inheritance showing through: give developers proper tools and documentation, and adoption follows.

In-Factory Profile Provisioning (IFPP). This solves the “first connect” problem. Rather than shipping a blank device that has to negotiate its first connection in the field, burning power and time, an initial bootstrap or operational profile is injected securely during manufacturing. The device arrives ready to connect the moment it powers on, with local connectivity assigned later over the air when it reaches its destination market.

The IoT eSIM Starter Kit. Recognising that most SGP.32 projects stall at the seams between vendors rather than inside any single component, Kigen packaged the whole thing: pre-certified hardware, hosted eIM access via Pulse, the device-side SDK, and pre-cleared activation profiles from a roster of connectivity partners. It compresses an integration project that used to take months of vendor wrangling into a single evaluation flow. That, more than any spec sheet, is what accelerates migration from concept to commercial reality.

5. How Kigen is leading the SGP.32 revolution

Plenty of companies claim to lead a standard. Kigen has a stronger claim than most, and it rests on four things.

It helped author the standard. With Saรฏd Gharout chairing GSMA eSIM Working Group 2, Kigen was in the room, pen in hand, as SGP.32 was drafted. The eIM and IPA architecture that the entire ecosystem now builds against did not descend from the heavens; it was shaped by people who then had to go and build the first working implementation of it. That is a rare and powerful position: setting the rules and shipping the reference product.

It shipped first, and shipped certified. Being first to a GSMA-compliant eIM, and first to a SAS-SM certified eIM site, is not a vanity metric. In this market, certification is procurement. A buyer specifying SGP.32 for a fifteen-year smart-metering rollout is not going to accept “compliant soon”. Kigen turned up with the certifications already in hand.

It proved interoperability in public. The genuine risk with any new standard is that it looks great on paper and falls apart the moment two vendors’ kit has to talk to each other. Kigen has attacked that head-on with multi-vendor testing and public “reality check” demonstrations, showing its certified eSIMs, eIM, Pulse and APIs working across diverse hardware and multiple connectivity providers. Gharout himself has pushed for industry-wide interoperability events precisely because SGP.32 is an open standard: one company can build only the eIM, another only the eUICC, another only the device, and they all have to work together. Proving that in the open is how you move a market from “interesting” to “safe to deploy”.

It built the ecosystem rather than a walled garden. This is the strategic masterstroke. Kigen’s business model rewards it for being the common trust engine underneath everyone else, so it has partnered widely instead of competing narrowly. KORE has aligned an SGP.32 connectivity portfolio around Kigen’s certified eSIM and eIM technology. Nordic Semiconductor built SGP.32 IoT capability into its nRF9151 and Thingy:91 X platforms with Kigen. floLIVE announced operational SGP.32 support using Kigen’s eIM and eSIM OS for a factory-to-field experience. TEAL preloaded its cloud platforms alongside Kigen’s SGP.32-ready OS. 1NCE, Onomondo and others sit in the same orbit. Many of the connectivity players who might, on paper, have built their own core cryptographic engines chose instead to build on Kigen’s. That is what leadership of a standard actually looks like: not owning the market, but being the thing the market is built on.

6. Case study: how Kigen powered Robustel’s move into eSIM

If you want a concrete example of the strategy in action rather than the abstract version, look at Robustel. This one is worth dwelling on, and we have covered the technical detail separately in our sister-site write-up of the Robustel and Kigen eSIM partnership over on euicc.co.uk.

Robustel is a serious industrial router and edge gateway manufacturer, the sort of hardware that ends up in utilities, transport and heavy industry where a device is expected to sit in a cabinet for a decade. In November 2025 Robustel announced it had adopted Kigen’s eSIM operating system, eIM and LPA developer enablement tools to bring eSIM flexibility and interoperability to its 4G and 5G router and edge gateway portfolio.

The elegance of the arrangement is in the detail. Robustel already had its own Smart Roaming technology, giving customers fine control over multi-network SIMs. Rather than rip that up, the Kigen integration extended the same capability to orchestrating eSIM profiles, adding zero-touch provisioning and over-the-air profile switching on top of what Robustel customers already understood. Better still, the plastic Kigen eSIM allowed a practical retrofit across Robustel’s existing single and dual-SIM routers, delivering eSIM functionality without changing the bill of materials. For a hardware maker, that phrase is close to magic: new capability, no board respin, no fresh certification cycle, reduced risk and testing effort.

There is also a compliance story riding underneath it. Public tenders and multinational deployments increasingly mandate eSIM readiness, and regulation like the EU Cyber Resilience Act is pushing security up the procurement checklist. By embedding a certified, standards-based eSIM stack, Robustel could answer those requirements with a straight face rather than a slide deck.

The Robustel deployment is the template for what is about to happen across the industrial hardware sector. A capable manufacturer with proven kit in the field, a customer base demanding network flexibility and regulatory cover, and a neutral trust engine that lets them add it all without reinventing their product line. Expect a lot more announcements that rhyme with this one.

7. Kigen’s competitors in the IoT eSIM space

Kigen does not operate in a vacuum, and it is fairer to the reader to say who else is in the ring. The competitive picture splits into two groups: the established secure-element heavyweights, and the connectivity players who could theoretically build their own core.

Among the traditional security vendors, three names come up repeatedly. Thales is a global digital-security and aerospace giant with a deep footprint in telecom and automotive, offering subscription management and IoT remote management alongside a very large legacy M2M and consumer business. Giesecke+Devrient (G+D), a security-technology company more than a century old, has transitioned successfully into eSIM and connectivity management and competes hard for tier-one automotive and industrial accounts. IDEMIA, best known for identity and secure transactions, brings strong eSIM operating systems and remote provisioning with a bias toward high-security government, financial and industrial deployments. All three are serious, well-resourced and entrenched. Where Kigen differentiates is neutrality and silicon-deep focus: it is not carrying a large legacy M2M book, it does not sell into competing parts of the value chain, and it built its reputation specifically on the IoT-constrained end of the problem.

The second group is more interesting strategically. Connectivity enablers and MVNO aggregators such as KORE, floLIVE, Soracom and 1NCE are the companies you might expect to compete with Kigen, and a few are building their own SGP.32 orchestration wrappers. But the recurring pattern across 2025 and 2026 has been these players partnering with Kigen rather than replicating its certified crypto core. Building an eSIM operating system and getting it through GSMA security accreditation is expensive, slow and unforgiving, and the commercial logic of standing on a neutral, already-certified foundation is compelling. That partner-not-compete dynamic is arguably Kigen’s strongest competitive moat, because it turns potential rivals into distribution.

If you are choosing between all of this from the buyer’s seat, the honest advice is that the SIM operating system is only one variable. The connectivity, the profile strategy and the day-two operations matter just as much, which is exactly the sort of decision we pull apart in more detail over at simwise.co.uk.

8. The UK IoT eSIM and SGP.32 market: now and next

Britain is one of Europe’s more mature and inventive enterprise IoT markets, from Midlands manufacturing to smart-energy rollouts, fintech and autonomous-transport trials. SGP.32 lands into that market at an unusually well-timed moment, and four forces are shaping where it goes.

Permanent roaming has become a real constraint. UK firms deploying devices internationally have spent years fighting regulatory and operator crackdowns on permanent roaming, where a foreign-issued SIM gets throttled or blocked after a set period. SGP.32 is close to a direct answer: download a local operator profile over the air, stay compliant, and never dispatch a technician to do it. For any UK business shipping hardware abroad, this alone justifies a hard look at the standard.

Energy and utilities are driving the demand. The UK’s smart-metering programme and its distributed-energy build-out need connectivity that survives a device lifecycle of ten to fifteen years and a couple of shifts in the network landscape along the way. Utilities and their OEMs are exactly the buyers who cannot afford to be locked to one network for that long, and they are actively piloting SGP.32 for fleet resilience. This is the anchor demand that pulls a standard into the mainstream.

Regulation has made SIM security a procurement baseline. The UK’s Product Security and Telecommunications Infrastructure regime, alongside broader alignment with the EU Cyber Resilience Act, has ended the era of treating the SIM as an afterthought. Cryptographic assurance and formal certification, the things Kigen leads on, are moving from “nice to have” to “tick this box or you are out of the tender”. That regulatory tailwind favours certified, standards-based approaches over homebrew ones.

Looking forward, three shifts look close to inevitable.

The first is the death of the single-SKU logistics headache. UK hardware exporters will increasingly manufacture one device variant carrying a universal secure eSIM, then assign local network connectivity only once the crate lands in its destination market. In-factory provisioning plus SGP.32 makes region-splitting your hardware for connectivity reasons an obsolete practice. That is a genuine cost and inventory saving, not a marketing line.

The second is autonomous, policy-driven connectivity at the edge. As edge AI spreads through UK logistics, smart cities and healthcare, devices will start making their own connectivity decisions, switching carrier profiles based on real-time latency, cost or coverage without a human in the loop. The eIM orchestration layer is the natural place for that machine-to-machine policy logic to live, and it will evolve to handle it.

The third is simply the commercial tipping point. If 2024 and 2025 were about finalising the standard and proving it worked on the bench, 2026 is the year it moves to mass rollout, a view ABI Research shares in forecasting that SGP.32 adoption accelerates sharply from here. As more UK connectivity providers bake the standard natively into their platforms, the foundational infrastructure underneath a great deal of it will be Kigen’s, whether the badge on the device says so or not.

Frequently asked questions

What is SGP.32 in simple terms? SGP.32 is the GSMA’s eSIM standard built specifically for IoT devices. It lets you download, switch and manage a device’s mobile network profile remotely and over the air, with no human, no screen and no site visit. It is the IoT-focused successor to the earlier M2M (SGP.02) and consumer (SGP.22) standards.

What is an eIM? The eIM, or eSIM IoT remote Manager, is the server-side component introduced by SGP.32 that orchestrates profile operations across a whole fleet of devices. It is paired with an on-device agent called the IPA (IoT Profile Assistant). Kigen shipped the first widely adopted, GSMA-compliant eIM in October 2024.

Is Kigen a network operator? No, and that is the point. Kigen is a neutral security and eSIM software company, founded out of Arm. It does not sell connectivity or run a network, which is what lets it act as a trusted foundation across the whole ecosystem, including for connectivity providers who are otherwise competitors.

Do I need new hardware to use SGP.32? Not always. As the Robustel deployment showed, a plastic SGP.32-capable eSIM can retrofit into existing single or dual-SIM routers without changing the bill of materials. New designs can go further and use soldered MFF2 chips or integrated iSIM, but retrofit is a genuine option.

How does SGP.32 help with permanent roaming rules? Instead of shipping a device abroad on a foreign SIM that risks being blocked, SGP.32 lets you download a local operator profile over the air once the device is in place, keeping the deployment compliant without sending anyone to swap SIMs.

Who are Kigen’s main competitors? The established secure-element vendors Thales, Giesecke+Devrient and IDEMIA compete at the SIM and provisioning layer. Many connectivity players who might compete, such as KORE, floLIVE and Soracom, have instead chosen to partner with Kigen rather than build their own certified cryptographic core.

The independent take

Strip away the acronyms and Kigen’s story is unusually clean. It found a real bottleneck, helped write the standard that removes it, shipped the first certified product against that standard, and then made itself indispensable by being the neutral thing everyone else builds on rather than a competitor to fear. That is a difficult position to attack and an easy one to underestimate, precisely because most of the time you will never see the name.

For UK enterprises, the practical message is less about Kigen and more about timing. The regulatory pressure is real, the permanent-roaming problem is real, the fifteen-year connectivity question in utilities is real, and for the first time there is a mature, certified, interoperable standard that answers all three at once. Whether you buy Kigen directly or through one of its many partners, SGP.32 has moved from something to watch to something to plan for. The truck rolls are ending. It only took the SIM twenty years to grow up.


Written by James Hatton for IoT UK. IoTUK is an independent technology publication.


Leave a Comment