expand_more
True Multi-Network
No PLMN restrictions
Remote Steering
Switch networks post-deployment
Private APN & Fixed IP
Secure, isolated traffic
Flexible PAYG
No contracts or minimums

Unlike consumer SIM cards which are designed for phones, IoT SIMs are built for long-term deployments where reliability, remote management and predictable costs matter.

They are commonly used in routers, CCTV systems, payment terminals, telemetry devices, alarms, vehicle tracking systems and industrial equipment mainly for low volume data but in some cases can utilise voice and SMS.

The network architecture behind the SIM is a major driver of coverage, performance and longevity.

KeySIM IoT SIM Card

The Four Types of IoT SIM Cards

Not all IoT SIMs work the same way. Understanding how each type selects a network — and where they break down — is the difference between a deployment that "just works" and one that fails on weak signal.

01

Single-Network IoT SIMs

One network only — best for high-data, fixed installations

Single-network IoT SIMs connect to one mobile network only. In areas with strong signal from that network they can work very well, particularly in fixed installations with high monthly data usage.

They are often used in applications consuming large amounts of data because pricing can sometimes be more cost effective than multi-network connectivity.

The downside is that if the network experiences congestion, maintenance issues or weak signal in a specific area, the device has no alternative network available.

Watch out for consumer SIM terms.

When procuring single network SIM cards for connected machines it is prudent to verify the contractual terms cover IoT as business use and resale can be prohibited. For example, giffgaff states its services are intended for "private, Personal Use and non-commercial purposes", while Three UK states resale is not permitted unless the customer becomes an approved Three reseller.

02

Steered Multi-Network SIMs

Multiple networks with a preferred-network list (PLMN)

Steered multi-network SIMs can access more than one mobile network but use a preferred network list (PLMN) to prioritise certain operators.

PLMN lists are described in detail in the 3GPP TS 23.122 document.

This approach is commonly used to reduce roaming costs while still allowing fallback access to alternative networks if the preferred network is unavailable.

In many deployments this works well, but problems can occur when the preferred network still has a weak usable signal. In these situations, the modem may continue trying to use the prioritised network even when another available network would perform significantly better.

03
KeySIM core offering

Unsteered Multi-Network IoT SIMs

No PLMN list — the device picks the strongest signal in real time

Unsteered multi-network SIMs do not use a preferred network list. Instead, the modem is free to select from all available mobile networks based on signal conditions and standard 3GPP network selection behaviour.

This gives the router or device greater control over network selection and can improve resilience in areas where signal conditions regularly change.

At KeySIM, the average monthly usage across our multi-network SIM deployments is around 800 MB per SIM, making this type of connectivity well suited to remote infrastructure, backup connectivity and business-critical IoT applications where uptime is more important than achieving the absolute lowest cost per gigabyte.

KeySIM offers unsteered connectivity across 400+ networks through official IoT agreements with Tele2 IoT.

04
KeySIM core offering

Manually Steerable Multi-Network IoT SIMs

Remotely pin a SIM to a specific network — no site visit required

Some multi-network IoT SIMs allow devices to be remotely pinned to a specific mobile network at SIM level. This makes it possible to override the modem's automatic network selection behaviour without requiring physical access to the router or device.

This can be useful in deployments where signal conditions, congestion or network performance change over time, particularly in remote or difficult-to-access locations.

KeySIM supports remote network steering directly through the KeySIM portal, allowing users to remotely pin devices to available mobile networks without reconfiguring hardware on site. This capability was independently covered by Mobile News following KeySIM's partnership with Wired Broadcast.

Case study — HFM SmartFarm

"We spent weeks trying to get the machine connected and couldn't understand why it wasn't working, especially as we'd been told the SIM was multi-network. It just wouldn't establish a reliable connection.

After speaking to KeySIM, we tried one of their SIMs and it connected straight away. There was nothing else to change — it just worked. It resolved the issue immediately."

Tim Crombie Managing Director, HFM SmartFarm

Internet Breakout Infrastructure

Internet breakout architecture determines where traffic leaves the mobile network and reaches the internet or private infrastructure. Some providers use direct mobile operator breakout, while others use privately managed breakout infrastructure.

When private breakout is used, IoT SIM performance becomes dependent on the routing, resilience, latency and availability of the breakout platform and underlying datacentre infrastructure.

KeySIM operates UK-based network infrastructure with direct management of routing, performance and support. Traffic breaks out through multiple Tier 1 datacentre locations including Equinix facilities in Manchester, Leeds and London through FAELIX.

KeySIM is a registered RIPE NCC member operating Autonomous System AS207652 with allocated IP address space and independent routing control.

RIPE NCC Member AS207652 — independent routing control
Tier 1 Datacentres Equinix Manchester, Leeds & London via FAELIX
Tele2 IoT Partnership Official agreement covering 400+ global networks
UK-Based Operations Routing, performance and support managed in the UK

Fixed IP Connectivity Through Private Breakout Infrastructure

KeySIM fixed IP services are delivered through private breakout infrastructure designed for industrial IoT and remote access applications. Rather than relying on heavily shared public mobile internet routing, compatible deployments can maintain consistent addressing for VPN connectivity, telemetry and secure remote device access.

The quality of the breakout infrastructure can directly affect latency, routing consistency and long-term connectivity stability across IoT deployments.

Real-world examples of fixed IP connectivity in industrial environments can be seen in smart surveillance and remote monitoring deployments such as this Teltonika smart city video surveillance deployment.

Fixed IP IoT SIM for industrial remote access and surveillance

Industrial eUICC IoT SIM Cards

Unlike standard IoT SIM cards, eUICC-enabled industrial SIM cards can be remotely re-provisioned to an alternative mobile operator without physically replacing the SIM.

Standard IoT SIMs are normally tied permanently to a single operator profile for the life of the deployment. eUICC technology allows approved network profiles to be securely downloaded or replaced over the air. This gives businesses greater long-term flexibility and reduces supplier lock-in across large deployments.

eUICC is particularly valuable in long-life industrial installations where physical access to devices may be difficult or expensive. It is increasingly used within industrial routers, telemetry equipment, remote monitoring systems and critical infrastructure where operational continuity is important.

KeySIM supports industrial-grade eUICC IoT SIM cards for deployments requiring remote provisioning capability and long-term network flexibility.

Industrial eUICC IoT SIM with remote provisioning across global networks

eSIM for IoT: SGP.22 & SGP.32

KeySIM supports SGP.22 and emerging SGP.32 eSIM architectures. These GSMA standards allow compatible devices to remotely download and manage mobile network profiles without physically replacing the SIM card.

Similar to eUICC, eSIM technology presents an opportunity for businesses to take full control of their connected estate — by virtue of the fact they will not need to physically swap SIM cards to migrate suppliers.

SGP.22 is currently the most widely adopted eSIM standard in industrial routers and connected business devices. Hardware including the Teltonika Networks RUT241 industrial 4G eSIM router uses the GSMA SGP.22 architecture to support remote eSIM profile management through the router interface or remote management platforms.

SGP.32 is a newer GSMA standard developed specifically for large-scale IoT deployments such as sensors, industrial monitoring, asset tracking and smart infrastructure. It is designed to simplify remote SIM provisioning for connected devices deployed at scale and is expected to become increasingly important as the IoT eSIM ecosystem matures.

SGP.22 — Business & Industrial Widely adopted in industrial routers and connected business devices. Supports remote eSIM profile management.
SGP.32 — Large-Scale IoT Designed for sensors, industrial monitoring and asset tracking deployed at scale. Emerging standard.
No Physical SIM Swap Remote profile download means supplier migration without site visits or hardware changes.
KeySIM SGP Support KeySIM supports both SGP.22 and SGP.32 architectures for compatible hardware deployments.

KeySIM Foundation

KeySIM Foundation — IoT SIM's for good

The KeySIM Foundation is our community support programme, providing free and discounted connectivity, SIM card donations and technical expertise to charities and community organisations across the UK.

KeySecure Specialist Network Services

KeySecure Specialist Network Services are optional, bespoke solutions developed to each customer's exact requirements. As KeySIM owns and operates its own mobile IP core, routing infrastructure, and RIPE IP address allocations, we can develop virtually any technically achievable IP networking solution. The services below are examples of our capabilities. Bespoke service development is £1,000 + VAT, with ongoing hosting and support £100 + VAT per month. If you have a specific requirement, please contact us.

01
KeySecure Specialist Service

Guaranteed Public IPv4 Source Address

A dedicated, static outbound IPv4 address exclusively assigned to your deployment

KeySecure Services Guaranteed Public IPv4 Source Address provides organisations with a dedicated, static outbound IPv4 address that is exclusively assigned to their deployment. Every outbound connection established by the organisation's KeySIM IoT SIM cards is presented to external services using the same guaranteed public IPv4 address, regardless of which mobile network the device is connected to or where it is deployed.

Unlike standard mobile broadband services, where outbound Network Address Translation (NAT) addresses are dynamically allocated from a shared carrier pool and may change without notice, KeySIM allocates a dedicated public IPv4 address that is reserved exclusively for a single customer. KeySIM guarantees that no other customer or SIM card will ever present this source IP address, providing complete separation between organisations.

This enables administrators to implement simple yet highly effective IP-based access control. Rather than maintaining extensive firewall rules or continually updating changing carrier IP ranges, organisations need only create a single firewall or Access Control List (ACL) entry permitting connections from their dedicated KeySIM public IPv4 address. Any connection originating from an alternative source IP can be automatically rejected.

The service is particularly valuable for organisations operating APIs, application servers, cloud infrastructure, industrial control systems, SCADA platforms, telemetry servers, payment gateways, databases and other business-critical systems that require trusted inbound connectivity from remote IoT devices. By restricting access to a single known source IP address, organisations can significantly reduce their external attack surface while simplifying firewall administration.

The guaranteed public IPv4 address is allocated at the KeySIM mobile core and is completely independent of the underlying Radio Access Network (RAN). Whether devices are attached to Vodafone, O2, EE or Three within the United Kingdom, or operating internationally under roaming agreements, outbound connections continue to present the same dedicated public IPv4 address. Changes in serving cell site, radio technology or mobile operator have no impact on the source IP address presented to external services.

For large-scale deployments, this architecture provides predictable networking behaviour across thousands of devices. Firewall policies remain unchanged as SIMs are added, replaced or moved between networks, eliminating the operational complexity associated with dynamic carrier NAT pools and frequently changing IP address allocations.

Guaranteed Public IPv4 Source Address is frequently deployed alongside enterprise firewall policies, IP allowlisting, API authentication, cloud security controls, Zero Trust network architectures and intrusion prevention systems, providing an additional layer of network identity that complements application-level authentication.

For organisations requiring secure, predictable and scalable connectivity, Guaranteed Public IPv4 Source Address delivers a trusted network identity that enables servers to confidently distinguish legitimate customer traffic from all other Internet connections. The result is simplified firewall management, enhanced security and the assurance that only the organisation's authorised KeySIM IoT SIM cards can establish trusted connections using their dedicated public IPv4 address.

02
KeySecure Specialist Service

Website & Domain Access Filtering

Selectively block specific websites and domains while keeping everything else online

KeySecure Services Website & Domain Access Filtering enables organisations to control exactly which Internet services their IoT deployments can access. Rather than restricting connectivity to a predefined list of permitted destinations, this service allows specific websites, domains, IP addresses and online services to be selectively blocked while permitting access to all other Internet resources.

Security policies are enforced centrally within the KeySIM mobile core, meaning devices remain protected regardless of whether they are connected via Vodafone, O2, EE or Three, or operating anywhere in the world under international roaming agreements. Filtering is completely independent of the serving Radio Access Network (RAN), ensuring a consistent security policy across every deployment.

The service supports the blocking of individual IPv4 addresses, Fully Qualified Domain Names (FQDNs), website categories and application endpoints, allowing organisations to create highly granular Internet access policies without deploying additional on-site security appliances or firewall infrastructure.

A common enterprise use case is the deployment of business-critical connectivity for payment terminals, CCTV systems, digital signage, telemetry equipment and remote management devices. While these devices often require Internet connectivity for normal operation, organisations may wish to prevent users from consuming unnecessary bandwidth or accessing non-business services.

For example, a large enterprise deploying payment terminals and security cameras may prohibit access to streaming and social media platforms such as Netflix, YouTube, TikTok, Snapchat, Instagram, Facebook, X (formerly Twitter), LinkedIn, Twitch and Vimeo. These services can generate significant bandwidth consumption, increase operational costs and introduce unnecessary network traffic, despite having no relevance to the primary business application.

By selectively blocking these destinations while permitting access to all other required Internet services, organisations can maintain operational flexibility without unnecessarily restricting legitimate business traffic. Critical cloud platforms, payment gateways, remote management portals, software update services and application servers continue to operate normally while bandwidth-intensive or non-essential services remain inaccessible.

Unlike blanket Internet restrictions, selective domain filtering allows security policies to be aligned with business requirements. Devices retain Internet access where required, but connections to known non-productive or high-bandwidth destinations are denied before they are established. This helps optimise mobile data usage, reduce unnecessary operating costs and improve the overall efficiency of large-scale IoT deployments.

Filtering policies can be updated as operational requirements evolve, allowing new domains or IP addresses to be added or removed without changing SIM cards, device firmware or field configurations. Centralised policy management enables rapid deployment of security changes across thousands of connected devices from a single point of administration.

KeySecure Website & Domain Access Filtering is particularly suited to enterprise IoT, retail, financial services, transport, utilities, digital signage, surveillance, smart infrastructure and managed service providers seeking to balance Internet accessibility with network governance, cybersecurity and bandwidth optimisation.

03
KeySecure Specialist Service

Enterprise IPsec L2TP VPN

A standards-based, encrypted Layer 3 tunnel between the KeySIM core and your infrastructure

KeySecure Services enables secure private connectivity between the KeySIM mobile core network and customer infrastructure using standards-based IPsec L2TP Virtual Private Network (VPN) technology. The service establishes an authenticated, encrypted Layer 3 tunnel between the KeySIM private ISP and the customer's firewall, router or VPN concentrator, creating a secure extension of the customer's enterprise network.

Unlike conventional mobile broadband services where traffic is broken out directly onto the public Internet, all subscriber traffic remains within the KeySIM private IP infrastructure before being securely encapsulated and forwarded through the IPsec tunnel. This creates a private routed environment for IoT devices, industrial control systems, telemetry equipment, SCADA infrastructure, PLCs, RTUs, CCTV systems, edge gateways and enterprise networking applications.

Every KeySIM Private Fixed IP SIM is allocated a permanently routable private IPv4 address, enabling deterministic addressing and direct host-to-host communication without requiring Dynamic DNS, inbound NAT, public IP addressing or application-layer relay services. Devices remain reachable across the VPN regardless of their serving mobile network.

The IPsec tunnel terminates at the KeySIM mobile core and is completely independent of the Radio Access Network (RAN). Whether the SIM is registered on Vodafone, O2, EE or Three, the encrypted tunnel architecture remains identical. Likewise, the VPN operates consistently whether devices are deployed within the United Kingdom or internationally, providing a uniform networking architecture across global IoT deployments. Cellular network selection, roaming agreements and serving base stations have no impact on the operation of the IPsec tunnel once traffic reaches the KeySIM core.

Customers maintain complete administrative control over traffic once it reaches their network perimeter. Internet breakout, static routing, firewall policies, VLAN segmentation, DNS resolution, proxy services, web filtering, IDS/IPS inspection, SIEM integration and Zero Trust security policies can all be managed entirely within the customer's own infrastructure. This allows enterprise security standards to be applied consistently across both fixed and mobile assets.

For organisations connected to the London Internet Exchange (LINX), KeySIM can exchange traffic across the LINX peering fabric, providing a highly efficient routing path between the KeySIM private core and customer infrastructure. This minimises unnecessary upstream transit while maintaining encrypted end-to-end transport between the KeySIM network and the customer's VPN gateway.

The architecture provides secure bidirectional communications, allowing authorised systems within the customer's network to initiate connections directly to remote devices using their assigned Private Fixed IP addresses. This enables secure remote management, firmware updates, telemetry collection, industrial automation, remote diagnostics, configuration management and machine-to-machine (M2M) communications without exposing field devices to the public Internet.

KeySecure Services has been designed for enterprise IoT, Industry 4.0, utilities, transportation, security, telemetry and mission-critical infrastructure where predictable routing, network isolation, private addressing and secure remote access are fundamental operational requirements.

IoT SIM — Frequently Asked Questions

An IoT SIM card connects devices to the internet over cellular mobile networks. Unlike consumer SIMs designed for phones, IoT SIMs are built for long-term deployments where reliability, remote management and predictable costs matter. They are commonly used in routers, CCTV systems, payment terminals, telemetry devices, alarms, vehicle tracking systems and industrial equipment.

Steered multi-network SIMs use a preferred network list (PLMN) to prioritise certain operators, which can hold a device on a weak signal even when a stronger network is available. Unsteered SIMs have no PLMN list, so the modem freely selects the strongest network at any time using standard 3GPP behaviour.

An eUICC (sometimes called eSIM) is an industrial SIM card that can be remotely re-provisioned to an alternative mobile operator over the air, without physically replacing the SIM. It is particularly valuable for long-life industrial deployments where physical access is difficult or expensive.

Internet breakout is the point where mobile data traffic leaves the cellular network and reaches the public internet or private infrastructure. KeySIM operates UK-based private breakout through Tier 1 datacentre locations including Equinix Manchester, Leeds and London via FAELIX, with independent routing as a RIPE NCC member (AS207652).

No. KeySIM operates on a flexible PAYG basis with no minimum terms. SIMs can be activated, paused or stopped as needed without long-term commitment, and dormant SIMs are not purged from the network. View PAYG pricing.

Yes. KeySIM SIMs can be remotely pinned to a specific UK mobile network at SIM level via the KeySIM portal — without any physical access to the device.

A private APN (Access Point Name) creates an isolated network for your devices, keeping traffic off the public internet. This improves security and enables remote access via VPN using private IP addresses. Learn about Fixed IP SIM.

Get Started with KeySIM IoT SIM

If your deployment relies on connectivity, you need a SIM that won't fail. Speak to our team or request your trial SIMs today.