Skip to content
Nenkin

ESA: GSMA eUICC Security Assurance Scheme

ESA is GSMA’s eUICC Security Assurance (eSA) scheme, the industry security certification programme for embedded UICC (eUICC) products. Evaluations use the Common Criteria framework with eUICC-specific optimisations defined by GSMA. NenkinTracker indexes eSA certificates alongside CCRA, EUCC, SESIP, PSA Certified, EMVCo, and MIFARE so eSIM-related assurance surfaces in the same product view.

Summary: ESA (eSA) is GSMA’s industry security certification scheme for embedded UICC products, operated by TrustCB. The scheme uses Common Criteria with eUICC optimisations from SGP.06 and SGP.07, and Protection Profiles SGP.05 and SGP.25.

Key facts

  • Authorising body: GSMA (Global System for Mobile Communications Association)
  • Certification body: TrustCB (selected by GSMA)
  • Scheme name spellings: “eSA” in GSMA / TrustCB documentation; “ESA” in NenkinTracker’s data model
  • Region: Global; eSIM products from vendors worldwide
  • Methodology: Common Criteria (CC) + Common Evaluation Methodology (CEM), plus eUICC-specific optimisations from GSMA SGP.07
  • Conformity model: Type Examination (testing)
  • Scheme governance documents: GSMA SGP.06 (eUICC Security Assurance Principles), GSMA SGP.07 (eUICC Security Assurance Methodology)
  • Protection Profiles: GSMA SGP.05 (Embedded UICC PP for M2M architecture, designed for SGP.01) and GSMA SGP.25 (Embedded UICC PP for Consumer and IoT-device architecture, designed for SGP.21)
  • Product types: eUICC chips and platforms
  • CCRA status: Not part of CCRA mutual recognition; the scheme is governed by GSMA, not by a CCRA national authority
  • Canonical registry: https://trustcb.com/gsma/esa/esa-certificates/

Overview

The eUICC Security Assurance scheme provides industry-level security assurance for the eSIM ecosystem. Mobile network operators rely on eSIM technology to provision and manage subscriber profiles remotely on a chip soldered into the device, replacing the removable plastic SIM. eSA certifies that eUICCs meet GSMA’s security requirements for that role: principally, secure access to networks and protection of the subscriber’s account.

How evaluations work under this scheme

Applicants register with GSMA and then submit a TrustCB eSA application. Evaluation is performed by accredited security laboratories against one of the GSMA Protection Profiles (SGP.05 for M2M eUICCs, SGP.25 for Consumer and IoT-device eUICCs). The methodology is Common Criteria plus CEM, with eUICC-specific testing optimisations described in SGP.07. TrustCB issues the certificate and publishes it in the GSMA eSA registry, which is also listed on the GSMA website.

Each certificate lists the certified product, the sponsor (the vendor whose product was evaluated), the evaluator (the lab), the Protection Profile claimed, and links to the certificate document and Security Target.

Notable product categories

  • M2M eUICCs evaluated against SGP.05, designed for the GSMA SGP.01 eSIM architecture
  • Consumer and IoT-device eUICCs evaluated against SGP.25, designed for the GSMA SGP.21 eSIM architecture
  • Underlying secure-element chips evaluated against the standard Security IC Platform Protection Profile, used as the silicon basis for eUICC platforms

Relationship to CC baseline

eSA is built on Common Criteria, not parallel to it. The scheme framework is CC plus CEM, layered with eUICC-specific optimisations (SGP.07) and eUICC-specific Protection Profiles (SGP.05 and SGP.25). The practical difference from a CCRA-issued certificate is governance: eSA is industry-governed by GSMA, not under the CCRA mutual-recognition arrangement, so eSA certificates do not carry CCRA recognition by themselves. Many eSA-evaluated products are also referenced by CCRA Common Criteria certificates for the underlying secure-element silicon.

Where to find official records

See also: Certification Schemes Overview, Beyond Common Criteria, Glossary.

Frequently asked questions

What is ESA in security certification?
ESA, written by GSMA as eSA, is GSMA's eUICC Security Assurance scheme. It is the industry security certification programme for embedded UICC (eUICC) products: the secure chips and platforms that hold subscriber profiles in modern phones, smartwatches, tablets, automotive units, and IoT devices. GSMA has selected TrustCB as the eSA Certification Body, and TrustCB issues the certificates.
What does ESA certify?
eSA certifies eUICC products: the embedded UICC chips and platforms that securely hold and manage subscriber profiles for mobile network operators. The scheme covers both M2M eUICCs (under the SGP.05 Protection Profile, designed for the SGP.01 architecture) and Consumer or IoT-device eUICCs (under the SGP.25 Protection Profile, designed for the SGP.21 architecture).
Who issues ESA certificates?
TrustCB issues eSA certificates as the GSMA-selected certification body. The certificate registry is published at trustcb.com/gsma/esa/esa-certificates and is also listed on the GSMA website. Each entry shows the certificate ID, issue date, product, sponsor (the vendor), evaluator (the lab), the Protection Profile claimed, and links to the certificate document and Security Target.
Is ESA a CCRA member?
No. eSA is not a Common Criteria scheme in the CCRA sense and is not part of CCRA mutual recognition. It is an industry certification programme governed by GSMA and operated by TrustCB. The scheme framework is Common Criteria (CC) and the Common Evaluation Methodology (CEM), plus eUICC-specific optimisations described in GSMA's SGP.07 methodology document.
What standards does ESA reference?
The eSA scheme requirements are specified in GSMA SGP.06 (eUICC Security Assurance Principles), with conformity assessed by Type Examination (testing). The methodology is Common Criteria and CEM, augmented with eUICC-specific optimisations described in GSMA SGP.07. Protection Profiles used in evaluations are SGP.05 (M2M eUICCs) and SGP.25 (Consumer and IoT-device eUICCs).
How does ESA relate to Common Criteria?
eSA is built on Common Criteria. The scheme framework is CC plus CEM, with eUICC-specific optimisations layered on top through GSMA SGP.07. The Protection Profiles (SGP.05 and SGP.25) are written in the standard Common Criteria format. The difference from a CCRA-issued certificate is that eSA is industry-governed by GSMA rather than under the CCRA mutual-recognition arrangement.