eSIM: a potential tool for digital sovereignty
When digital sovereignty comes up, the discussion generally centers on data, the cloud, software, artificial intelligence, critical infrastructure, or the location of data centers. These issues are important, but they can obscure a far more discreet reality: technology dependence is sometimes built out of minuscule components. The SIM card is an excellent example. In a personal phone, switching telecom providers is generally a relatively simple operation. When a company operates thousands of connected sensors, vehicles, machines, or devices spread across several regions or several countries, the situation becomes entirely different. Physically changing the connectivity of each of those devices can become a lengthy, costly, and sometimes practically unfeasible operation.
The question then goes far beyond the price of a cellular plan. It touches the organization’s ability to evolve its infrastructure, to change suppliers, to negotiate its terms, to adapt to the networks available, and to keep its equipment in service for several years. The new generations of eSIM designed for the Internet of Things aim precisely to make this connectivity more programmable and remotely manageable. Behind this technical evolution lies a far broader strategic issue: if being sovereign means retaining the ability to choose, then being able to change the connectivity of thousands of devices without having to physically modify them can become an important component of digital sovereignty.
The SIM card has a fundamental function: it allows a device to identify itself to a mobile network and to use the services it is authorized to access. For a consumer, this infrastructure remains largely invisible. In the Internet of Things, its importance becomes far greater. A company can manufacture a device in one country, sell it in another, and have to keep it connected for ten or fifteen years. An automaker can have vehicles on the road all over the world, an energy company can operate equipment in hard-to-reach regions, and a logistics organization can manage thousands of devices scattered across a vast territory. If the connectivity of these devices depends on a configuration that requires physical intervention to change, each one gradually becomes a small point of dependency. Multiplied by a few tens or hundreds of thousands of units, this technical detail can become a major strategic constraint.
This reality challenges the way we calculate the cost of a technology decision. When an organization selects a technology, it naturally analyzes its price, its features, its performance, and its ability to meet the current need. It far less often considers what it will cost to replace it several years later. Imagine a fleet of 50,000 devices spread across several countries where changing connectivity providers requires physically replacing every SIM card. The migration no longer consists simply of negotiating a new contract. You have to locate the equipment, gain physical access, coordinate the interventions, replace the cards, verify the configurations, and handle hard-to-reach devices separately. Even when another provider offers better terms, the operational cost of migration can be enough to make the change economically unjustifiable.
The dependency then stems from no contractual prohibition. It was created by the architecture. The organization theoretically remains free to change providers while having lost much of its operational freedom to do so. This distinction is central when we talk about digital sovereignty. A freedom that requires several years, considerable investment, or the premature replacement of thousands of perfectly functional devices remains legally real, but it becomes far less useful in the company’s day-to-day decisions. We already see this phenomenon in the cloud, in enterprise software, in data formats, and across several digital platforms. IoT can amplify it considerably, since IT infrastructure is no longer concentrated in a few data centers: it is physically distributed across machines, vehicles, buildings, and equipment that may be thousands of kilometers away.
This is precisely where the eSIM becomes strategically interesting. With traditional architectures, the identity that allows a device to access the mobile network is tightly bound to a physical card and a fixed configuration. eSIM architectures make it possible to render certain elements of that relationship more programmable and to provision profiles remotely. At the scale of a single phone, the change may seem relatively modest. At the scale of an international fleet of devices, its impact is considerable: a decision that previously required physical intervention on each device can increasingly be managed remotely. Part of the physical connectivity thus becomes programmable, with everything that programmability can bring in terms of agility, automation, resilience, and governance.
This capability becomes all the more important because the lifespan of IoT devices often exceeds that of the communication technologies surrounding them. A piece of industrial equipment can operate for fifteen years, as can some vehicles, while energy, medical, or municipal infrastructure can stay in service even longer. Over that period, cellular technologies will be retired, suppliers will change their offerings, new standards will appear, economic conditions will shift, and new regulatory requirements may come into force. A company may also change strategy, exit a market, or decide that another supplier now better matches its needs. An architecture entirely determined by the connectivity choice made at the time of manufacture therefore implicitly obliges the company to predict a technology environment that does not yet exist. The ability to modify certain parameters remotely, by contrast, introduces a form of agility into an infrastructure that has historically been far harder to evolve.
This logic connects to a broader conception of digital sovereignty. Being sovereign does not necessarily mean owning all your infrastructure or using only locally developed technologies. A modern organization inevitably depends on suppliers, networks, software, cloud services, and specialized partners. The decisive question becomes how much control it retains over its decisions. Can it change suppliers, move its data or its workloads, modify its security mechanisms, replace a component, or adopt a different technology without having to rebuild its entire environment? From this perspective, relying on an external supplier remains perfectly compatible with sovereignty when the architecture preserves enough options for the future.
Sovereignty thus becomes a property of the architecture as much as a characteristic of the suppliers used. An infrastructure fully controlled today but extremely difficult to modify tomorrow may ultimately offer less freedom than an architecture that draws on several partners while preserving interoperability and reversibility. That is why standards and the ability of systems to work with different environments carry strategic value. A proprietary technology can be excellent, high-performing, and perfectly suited to the organization’s needs. The real question arises when the needs change: can the devices use other networks, can the identities evolve, can the data be moved, and can operations continue during a migration?
Interoperability creates options, and those options have economic value. A company able to change suppliers retains more negotiating power. It can more easily adopt an innovation offered by a new player and react when a partner’s prices, service levels, or commercial strategy no longer match its needs. Technology architecture thus becomes directly tied to sourcing strategy. The cost of entry remains important, but the cost of exit and the real ability to exercise that exit should also be part of the investment analysis.
This ability to change also has value in terms of resilience. A network can suffer a major outage, offer insufficient coverage in certain regions, or become unavailable. A cellular technology can be progressively phased out. For a device that occasionally transmits non-critical information, a temporary interruption may be acceptable. For a device taking part directly in a supply chain, an energy infrastructure, or an industrial process, the consequences can be far more significant. An architecture able to use different connectivity options or to modify certain profiles can then help keep operations running when the environment changes. Sovereignty and resilience converge on a single principle: keeping alternatives realistic enough that you can actually use them when they become necessary.
Making connectivity programmable does, however, bring its own responsibilities. An infrastructure that allows thousands of devices to be reconfigured remotely holds considerable operational power, which also makes it a particularly sensitive function. The organization must know who holds the authority to modify that connectivity, under what circumstances a change is authorized, and how each operation can be authenticated and traced. Orchestration platforms themselves become critical infrastructure components and must be protected accordingly. Identity, permission control, Zero Trust, and cybersecurity therefore necessarily accompany this evolution. The more programmable an infrastructure becomes, the more important the governance of that programmability becomes.
Artificial intelligence and agents could eventually add a new layer to this orchestration. A distributed infrastructure can analyze network quality, availability, costs, device locations, and operational requirements in order to recommend different connectivity strategies. In clearly bounded situations, automated mechanisms could select an option based on policies defined by the organization. Connectivity would then become a more dynamic resource, adjusted according to context, the performance sought, cost, or the required level of security. Here we find an evolution already observed in other areas of computing: physical infrastructures gradually come to be managed by software layers capable of adapting them to needs.
This evolution should also change the questions asked when making an IoT investment. Beyond network coverage or the immediate cost of connectivity, an organization should seek to understand the options it will retain throughout the lifespan of its equipment. What will happen if the current supplier no longer meets its needs in five years? Will it be possible to change networks without replacing the devices? Will the identities associated with the equipment remain under its control? Will a proprietary dependency make migration particularly complex? What physical intervention would be required, and how much would an exit really cost? These questions go far beyond the work of IT architects. They also concern operations, finance, procurement, risk management, and strategy, since a technology choice made today can determine the freedom of decision available for a decade or more.
This perspective ultimately gives a very concrete definition to digital sovereignty. A sovereign organization is not necessarily one that owns every component of its infrastructure. It is one that knows its dependencies well enough, understands the consequences of its choices, and retains enough control and enough options to make its own decisions when its environment changes. In IoT, the eSIM can contribute to that capability by turning a historically physical decision into one that can largely be managed remotely. It obviously does not guarantee sovereignty on its own: the platforms used to manage profiles, the standards, the contracts, the available networks, and the control mechanisms all create dependencies of their own. The technology opens a possibility; the architecture determines whether that possibility genuinely becomes a freedom.
A SIM card seems insignificant when compared with a data center, a cloud platform, or an artificial intelligence model. Yet when it is embedded in tens of thousands of devices meant to stay in service for many years, it can profoundly influence an organization’s ability to evolve its infrastructure. The eSIM and new remote provisioning approaches change this dynamic by progressively making it possible to decouple a device’s physical lifespan from certain connectivity choices made at the time of manufacture.
This flexibility can improve resilience, facilitate international deployments, reduce certain physical interventions, and above all preserve more options for the future. It is also a reminder of a principle that extends well beyond mobile connectivity: technology decisions should be assessed not only by what they make possible today, but also by the freedom they will leave the organization tomorrow. Modularity, interoperability, reversibility, and knowledge of dependencies thus become concrete dimensions of digital sovereignty.
For Quantum Beyond, this reflection fits directly into our approach to sovereign architectures, Edge infrastructures, Qb OS Edge, Hypersecurity, and digital resilience. Our experts work alongside technology and operations teams to identify the dependencies liable to limit the organization’s future evolution and to design architectures capable of retaining enough modularity, interoperability, and control to evolve along with technologies, suppliers, and operational needs.
Digital sovereignty is therefore not decided solely in the large, visible infrastructures. It is also built through far more discreet technical choices that will determine what an organization can still change in five, ten, or fifteen years. A component a few millimeters across can seem insignificant when a device is being designed; multiplied by thousands of units and several years of operation, it can determine the economic and operational feasibility of a change of direction.
Being sovereign means retaining the real ability to choose. In a world where millions of machines will stay connected for years, preserving the ability to evolve their connectivity may prove far more strategic than it appears today.
