ESA: GSMA eUICC Security Assurance Scheme
ESA is GSMA’s eUICC Security Assurance (eSA) scheme, the industry security certification programme for embedded UICC (eUICC) products. Evaluations use the Common Criteria framework with eUICC-specific optimisations defined by GSMA. NenkinTracker indexes eSA certificates alongside CCRA, EUCC, SESIP, PSA Certified, EMVCo, and MIFARE so eSIM-related assurance surfaces in the same product view.
Summary: ESA (eSA) is GSMA’s industry security certification scheme for embedded UICC products, operated by TrustCB. The scheme uses Common Criteria with eUICC optimisations from SGP.06 and SGP.07, and Protection Profiles SGP.05 and SGP.25.
Key facts
- Authorising body: GSMA (Global System for Mobile Communications Association)
- Certification body: TrustCB (selected by GSMA)
- Scheme name spellings: “eSA” in GSMA / TrustCB documentation; “ESA” in NenkinTracker’s data model
- Region: Global; eSIM products from vendors worldwide
- Methodology: Common Criteria (CC) + Common Evaluation Methodology (CEM), plus eUICC-specific optimisations from GSMA SGP.07
- Conformity model: Type Examination (testing)
- Scheme governance documents: GSMA SGP.06 (eUICC Security Assurance Principles), GSMA SGP.07 (eUICC Security Assurance Methodology)
- Protection Profiles: GSMA SGP.05 (Embedded UICC PP for M2M architecture, designed for SGP.01) and GSMA SGP.25 (Embedded UICC PP for Consumer and IoT-device architecture, designed for SGP.21)
- Product types: eUICC chips and platforms
- CCRA status: Not part of CCRA mutual recognition; the scheme is governed by GSMA, not by a CCRA national authority
- Canonical registry: https://trustcb.com/gsma/esa/esa-certificates/
Overview
The eUICC Security Assurance scheme provides industry-level security assurance for the eSIM ecosystem. Mobile network operators rely on eSIM technology to provision and manage subscriber profiles remotely on a chip soldered into the device, replacing the removable plastic SIM. eSA certifies that eUICCs meet GSMA’s security requirements for that role: principally, secure access to networks and protection of the subscriber’s account.
How evaluations work under this scheme
Applicants register with GSMA and then submit a TrustCB eSA application. Evaluation is performed by accredited security laboratories against one of the GSMA Protection Profiles (SGP.05 for M2M eUICCs, SGP.25 for Consumer and IoT-device eUICCs). The methodology is Common Criteria plus CEM, with eUICC-specific testing optimisations described in SGP.07. TrustCB issues the certificate and publishes it in the GSMA eSA registry, which is also listed on the GSMA website.
Each certificate lists the certified product, the sponsor (the vendor whose product was evaluated), the evaluator (the lab), the Protection Profile claimed, and links to the certificate document and Security Target.
Notable product categories
- M2M eUICCs evaluated against SGP.05, designed for the GSMA SGP.01 eSIM architecture
- Consumer and IoT-device eUICCs evaluated against SGP.25, designed for the GSMA SGP.21 eSIM architecture
- Underlying secure-element chips evaluated against the standard Security IC Platform Protection Profile, used as the silicon basis for eUICC platforms
Relationship to CC baseline
eSA is built on Common Criteria, not parallel to it. The scheme framework is CC plus CEM, layered with eUICC-specific optimisations (SGP.07) and eUICC-specific Protection Profiles (SGP.05 and SGP.25). The practical difference from a CCRA-issued certificate is governance: eSA is industry-governed by GSMA, not under the CCRA mutual-recognition arrangement, so eSA certificates do not carry CCRA recognition by themselves. Many eSA-evaluated products are also referenced by CCRA Common Criteria certificates for the underlying secure-element silicon.
Where to find official records
- eSA certificate registry (TrustCB): https://trustcb.com/gsma/esa/esa-certificates/
- GSMA eSIM and eSA specifications: https://www.gsma.com/esim/
- For Common Criteria certificates on the underlying secure-element silicon, see the issuing CCRA national scheme via the Common Criteria Portal.
- NenkinTracker normalises eSA records alongside CCRA, EUCC, SESIP, and other sources.
See also: Certification Schemes Overview, Beyond Common Criteria, Glossary.