The short version: SGP.32 frees the operator profile, but the lock-in does not vanish – it scatters up and down the stack. Four UK companies each own a different layer, and each layer is a different kind of lock. This is the whole map on one page: where Kigen, 1GLOBAL, Eseye and Wireless Logic sit, the networks underneath them, and the enterprise buyer on top who quietly ends up locked at several layers at once.
The four orange markers are where a UK vendor’s lock-in concentrates once SGP.32 frees the operator profile. The dark bands are the two fixed poles: the buyer at the top, and the networks the whole stack runs on at the bottom.
How to read the stack
Two things do not move. At the top is the buyer – the enterprise deploying the fleet. At the bottom are the mobile networks that carry the traffic. Everything in between is where SGP.32 relocated the lock. The old world had one obvious lock, the operator profile welded to the SIM. SGP.32 dissolved that. What this map shows is that the dissolving did not remove the lock so much as break it into four smaller ones, each held by a different company, each with a different escape cost. Read from the bottom up and you move from the most permanent lock (set in silicon) to the softest-looking one (a service contract) – which, counter-intuitively, is often the hardest to leave.
The four locks at a glance
| Vendor | Layer it owns | The lock | Core product | Hardest part to leave |
|---|---|---|---|---|
| Kigen | eUICC operating system | Chosen at design time, fixed in silicon, no over-the-air path to a different OS | Kigen eSIM OS, eIM, Pulse | You cannot – it needs new hardware |
| 1GLOBAL | Bootstrap profile | Burned in at the factory; every device phones home to it on first boot | eSIM IoT Manager + Bootstrap | Hard – re-bootstrapping a deployed fleet |
| Eseye | eIM / orchestration control plane | Your fleet’s provisioning logic and fallback rules live in their platform | AnyNet+ eSIM, Infinity | Painful – re-platforming the orchestration |
| Wireless Logic | Managed-service relationship | You outsource the whole operation and never build the capability in-house | Conexa managed connectivity | Heaviest in practice – rebuilding a department |
Each of those has a full profile behind it. In short: Kigen is the honest broker sitting on the deepest lock; 1GLOBAL owns the lock most easily mistaken for a free gift; Eseye holds the control plane and, through its own CTO, more or less argues the whole thesis for you; and Wireless Logic holds the one lock that is not a component at all.
The networks underneath
The whole stack runs on the mobile networks at the base of the diagram, and the UK network market itself has just been through a once-in-a-generation reshaping. After Vodafone and Three completed their merger, and Vodafone then moved to take full ownership of the combined business, the country is served by three host networks: VodafoneThree, now the largest with around 27 million connections; EE, part of BT Group; and Virgin Media O2. Everyone else – the MVNOs and IoT specialists – rides on top of those three.
All three are building SGP.32-native IoT offerings, and Vodafone has been the most vocal, having restructured its IoT unit around the eSIM and iSIM shift. There is an irony worth naming: SGP.32 is precisely the standard that erodes the operators’ historic, SIM-based grip on their IoT base. The rational response for an MNO is therefore not to sell radio and watch the value migrate upward, but to climb into the eIM and platform layers themselves – which is why the operators are increasingly competing with the very vendors that ride on their networks.
The MVNO and connectivity layer
Between the three host networks and the enterprise sits the connectivity layer, and this is where two of our four vendors actually live. Both Wireless Logic and 1GLOBAL are themselves MVNOs – they buy access wholesale from the MNOs and resell managed connectivity on top – while Eseye operates as the standardised global eSIM behind several tier-one operators. This layer is consolidating fast: Wireless Logic alone has rolled up Arqia, Webbing, Blue Wireless and, in July 2026, Simetry. The pattern across the market is the same one this whole map illustrates – the value, and the control, is migrating to whoever owns the management layer, and SGP.32 is what makes that layer decisive. (Our sister site IoTPortal has a fuller analysis of that consolidation.)
Where the customer actually sits
The buyer sits at the top of the diagram, and the trap is that the four locks are cumulative. Nothing stops an enterprise from being locked at the hardware OS (Kigen), the bootstrap (1GLOBAL), the orchestration (Eseye) and the managed-service relationship (Wireless Logic) all at once – and most never map it out, because each decision was made separately, by a different team, at a different point in the project. The device engineer picks the module and OS. Procurement picks the connectivity provider. Operations picks the managed service. Each choice is sensible in isolation. Stacked together, they can leave a fleet with four independent dependencies and no one who has looked at the whole picture.
The pattern: conservation of lock-in
This map is the evidence for a single idea we have argued across the site: SGP.32 did not end operator lock-in, it moved it. Look at the four orange markers and the claim becomes concrete. The standard genuinely removed the old lock – the operator profile is now portable, and that is a real gain. But the need for something to own the silicon, hold the bootstrap, run the orchestration and operate the fleet did not go away, and each of those is a place a vendor can stand. Lock-in is conserved. What SGP.32 changed is not whether you are locked in, but where, to whom, and at what cost to leave.
How to use this map as a buyer
The single most useful thing this diagram tells you is which decisions you can revisit and which you cannot. Draw a line through the middle of the stack. Below it – the eUICC OS and the bootstrap – the choices are set at design and manufacture, and you live with them for the life of the hardware. Above it – the orchestration and the managed service – the locks are contractual and operational: painful to unwind, but possible, because no one has to replace a physical device to do it.
So spend your scrutiny accordingly. Interrogate the permanent layers hardest, because a mistake there is a hardware refresh. Ask the reversible layers the exit questions instead – what leaves with you, what stays behind, and what it would cost to bring the capability in-house – because there the lock is only as strong as the price of leaving, and a lock you have costed an exit from is a much weaker lock. For the layer-by-layer detail, the individual profiles above go deeper, and the architecture guide explains how the pieces fit.
By Peter Green