Home Research Russian Authorities Plan to Restrict eSIMs. Evading the Restrictions

Russian Authorities Plan to Restrict eSIMs. Evading the Restrictions

On June 23, 2026, Kommersant (a major Russian business daily) reported that the government is discussing new restrictions on two types of SIM cards: virtual eSIMs and M2M (machine-to-machine) cards, which run in sensors, ATMs, vehicles, and other equipment. The measures under discussion include:

  • banning Russians from remotely registering eSIMs from abroad,
  • placing M2M cards into a separate category,
  • additional identification of their users,
  • stripping such cards of the ability to carry voice calls and SMS.

The key point that gets lost in the news headlines: for now this is a discussion, not a law.

The Ministry of Digital Development (Mintsifry) confirms only that work on a third package is underway and declines to give any details. Sources say directly that no decision has been made and the measure may not end up in the third package at all. On top of that, two separate storylines (eSIMs for travel and remote issuance of Russian phone numbers) have been mixed together in press coverage, even though they are different things.

The consequences are also uneven. For eSIMs, experts estimate the effect will be narrow and will mostly hit individuals abroad. For M2M, it will be systemic: this is a market of roughly 60 million cards, a significant share of the country’s entire Internet of Things.

What’s happening

The status of the initiative is deliberately vague. One Kommersant source says the measures may be included in the third package of bills against cyberfraud (the anti-fraud package). Another person familiar with the ministry’s plans clarifies: “The task exists, but it’s not certain the measure will go into the third package specifically.” A third source says discussions are ongoing, but there has been no concrete decision yet.

Mintsifry responded with restraint. The ministry said it continued to fight online fraud, that the third package “is being discussed and will be presented soon,” and that it is too early to talk about details. VimpelCom (Beeline), MegaFon, and T2 declined to comment; MTS did not respond.

Amid a wave of clickbait reposts, the Telegram channel ZaTelecom rightly pointed out that the word “discussing” is already reason to pause. This is not about roaming for foreign SIM cards, but about a hypothetical restriction on remote issuance of Russian numbers for people who are abroad. How to implement that technically is a separate big question, and we will come back to it.

Anti-fraud packages

The measures under discussion continue a steady tightening of the rules for SIM card circulation:

  • The first package was adopted in March 2025, and its main provisions took effect in September 2025.
  • The second package has already been approved by the State Duma and the Federation Council (the two chambers of Russia’s parliament). It includes labeling of international calls and a self-imposed opt-out from receiving them, mandatory linking of a device’s IMEI to the subscriber contract along with a unified IMEI database, a “red button” service on Gosuslugi (the government services portal), and a limit of 20 bank cards per person.
  • We have already analyzed one of these measures in detail. The second package included a ban on hosting services for VPNs. That provision survived to the second reading, although some other measures (confirmation via Max, the state-backed Russian messenger, and registration only through Russian email services) were dropped. Read more about this in our earlier analysis.
  • A separate story: starting in September 2026, operators are set to be banned from purchasing foreign SIM cards, leaving only cards with Russian software and cryptography. The criteria for what counts as “domestic” still have not been clearly spelled out.

The eSIM and M2M restrictions under discussion fit into this same sequence, as yet another layer of control over how a subscriber gets connectivity.

What an eSIM is, and why the “border” is blurry here

An eSIM is a profile rather than a physical card. It is downloaded onto a special chip inside the device (called an eUICC). The technology is defined by a global GSMA industry standard and relies on Remote SIM Provisioning.

Simplified, the process involves four elements: the eUICC chip in the phone, which stores profiles; the SM-DP+ server, which prepares and delivers the operator’s profile; the SM-DS discovery server, which helps the device find the right SM-DP+; and the LPA, local software on the device that manages all of this. When you scan a QR code, it contains the SM-DP+ address and an activation code: the phone contacts the server, passes verification, and receives an encrypted profile with keys and network settings. The profile is encrypted specifically for your chip and cannot be installed on another device.

This is the source of the main technical problem with a ban. In this architecture, the “border” is not a controllable checkpoint: activation happens on the device side, and the profile arrives from a server over the internet. You can determine which country a person is in through geolocation or their IP address, but that is easy to circumvent.

In practice, the government has two options, and both are flawed.

The first option is to require a Russian operator (and its SM-DP+) to withhold the profile unless the person’s presence in Russia is confirmed. The second is to block foreign eSIM services at the network level, as India did. In the first case, legitimate users traveling abroad will suffer. In the second case, the ban is bypassed with a VPN or by buying a profile in advance.

Stripping M2M of voice and SMS

M2M cards provide communication between devices without human involvement: sensors, terminals, vehicle trackers, ATMs. Today, according to market participants, they are in a “gray zone”: one can purchase a card without registering it on Gosuslugi, and it is most often issued to a legal entity. At the same time, the operator can see on its network whether the card is inserted into a phone or some other device.

“The main goal of the amendments is to close a loophole for fraudsters who use M2M SIMs for spam calls. The idea is to strip them of voice and SMS so they work only for their intended purpose,” says Anastasia Bidzhelova of Telecom Birzha (a Russian SIM card marketplace). The logic is understandable, but it has its cost. In many devices, the voice channel or SMS is used not for conversations but as a backup or a control channel (for example, to transmit commands or emergency signals). The ban will hit exactly those devices.

Two different storylines, two different effects

Experts polled by Delovoy Peterburg (a St. Petersburg business newspaper) agree that the consequences for eSIM and M2M are fundamentally different.

ParameterBan on remote eSIM registrationRestrictions on M2M SIM cards
Whom it affectsIndividuals outside Russia: tourists, business travelers, emigrantsBusinesses: logistics, transport, smart homes, payment terminals, monitoring
ScaleeSIM’s share in Russia is still smallAround 60 million cards, ~20% of all SIM cards in the country
Main riskDifficulty with remotely issuing or restoring a Russian number while travelingBanning voice and SMS breaks devices where these serve as a backup or control channel
Effect on operatorsEstimated to be almost negligibleHigher administrative burden, possible migration of some SIM cards
Technical feasibilityLow: checking the country of activation is easy to bypassHigher: the operator can see the device type
Table 1. Differenced between esim and m2m sim cards

For eSIM, the outlook is fairly calm. Yuri Bryukvin, head of Rustelecom (a telecom research agency), notes that the number of eSIMs in Russia is still small, so the impact on operators’ revenue may be imperceptible, and the blow will land primarily on individuals outside the country. Denis Kuskov (Telecom Daily) adds that the number of tourists has dropped noticeably since 2022.

There is more concern about M2M. Analyst Eldar Murtazin warns that harsh restrictions will “cut off” a large number of devices already in operation, including those run by companies:

Beyond the anti-fraud framing

The stated goal is fighting fraud. According to the Central Bank of Russia, fraudsters stole 29.3 billion rubles (about $390 million) in 2025, and remote issuance of a phone number without reliable identification does create risks. But experts consider this explanation incomplete.

Banning remote eSIM registration will indeed complicate schemes built on mass registration of accounts with virtual numbers, but it will also restrict legitimate use of foreign services by Russians abroad. Given the parallel restrictions on VPNs and foreign messengers, this decision can also be seen as yet another tool for controlling the digital space.

Yaroslav Klimov, Financial University (in a comment to Delovoy Peterburg)

The same piece offers a substantive argument against the geographic approach: the problem is solved by the quality of identification and by monitoring suspicious operations, not by the country where the connection happens. Modern tools already make it possible to verify identities reliably at a distance, and it makes more sense to rely on them rather than on geography.

Other countries’ experience

According to an assessment by Transforma Insights (reviewed more than 80 jurisdictions), 83% of the countries studied have mandatory registration of phone SIM cards. On the other side, regulation of IoT SIM cards is far less developed. More than 70% of countries do not mention them particularly, and European regimes tend to set softer rules for IoT than for phones.

  • China is the closest parallel to Russia. There is no explicit eSIM ban: the restriction works through regulatory design. eSIM is allowed only in specific niches (wearables and IoT), where profiles are issued by domestic operators and registered to verified identities. Since 2021, connected cars have been subject to a separate real-name registration requirement.
  • India: in January 2024, the authorities required Apple and Google to remove the Airalo and Holafly eSIM apps from their local app stores. For export-oriented M2M/IoT devices, TRAI (India’s telecom regulator) proposed a separate authorization scheme with strict KYC.

For contrast, the UK, the EU, the US, Japan, South Korea, Australia, and most of Southeast Asia operate have opened eSIM ecosystems and operators compete to issue profiles. Control through infrastructure is a distinct model.

Mitigation of the consequences

Again, this has been a discussion only. We will update this analysis when an official document appears.

If your product uses mobile connectivity for devices, the M2M restrictions under discussion hit not the “frontend” but the communication architecture itself. Here is what you should check and build in ahead of time.

  1. Overall, you should reduce dependence on eSIM/SIM infrastructure. It already creates problems for users, and improvements will not come soon.nt.
  2. Audit your communication channels. Find every place where voice or SMS is used, not only as a primary function but also as a backup or control channel. Examples: SMS commands for rebooting a modem or changing its configuration, voice dial-up as a fallback when the data channel is unavailable, and SMS confirmation in the activation logic. These are the first things at risk.
  3. Move control logic to the data channel. If a device accepts commands via SMS, plan a transition to protocol-over-IP. This is the right move for reliability reasons anyway; the restrictions merely make the migration mandatory rather than desirable.
  4. Don’t lock yourself into a single profile at the design stage. Use an eUICC with remote profile switching (the SGP.32 standard for IoT). This is insurance not only against regulatory changes but also against operator switches, tariff changes, and coverage problems. Build in OTA (over-the-air) profile updates as a standard capability.
  5. Take inventory of your hardware and sort it by its age. Old devices where voice or SMS is baked into the firmware and cannot be updated over the air are the most painful case. You may have to replace them physically. Make a list of everything that cannot be reconfigured remotely. Estimate the replacement cost in advance, not at the moment the rule takes effect.
  6. Keep your cards “white.” Make sure your M2M cards are registered transparently: to a legal entity, with a clear purpose and proper accounting. Under any regulatory scenario, visible corporate connections are in a far better position than “gray” voice cards resold under the guise of M2M.

Don’t miss the next Riposte!

We don’t spam! Read more in our privacy policy