Your devices worked in testing. They worked for the first six months in the field. Then a batch in one country dropped off the network, and the operator's answer was short: permanent roaming is not permitted here.
Permanent roaming is the default model for most global IoT SIMs. A device carries a SIM from a home operator in one country and roams indefinitely on a visited network somewhere else. It is simple to deploy. It is also the model most exposed to regulators and operators who never agreed to host your fleet for ten years.
This guide covers where permanent roaming creates compliance risk, how to assess it by market, and when to use local breakout, multi-IMSI, or eUICC instead.
What this guide covers, and what it does not
This is a practical guide for IoT architects and connectivity buyers planning international deployments in 2026. It explains the types of restriction you will meet and the technical options for each.
It is not legal advice. Roaming rules change, national regulators interpret them differently, and operator contracts add restrictions that no regulation mentions. Verify the current position in each target market with your provider and your legal team before you ship.
Why permanent roaming creates risk
Roaming agreements between operators were designed for travellers: phones that visit a country for a week and go home. An IoT device that never leaves the visited network breaks that assumption.
Three parties have reasons to object.
- Regulators, who want devices operating in their country registered with a local operator, subject to local lawful intercept, data rules, and numbering plans.
- Visited operators, who carry the traffic at wholesale rates and see little return from a device that never pays a local subscription.
- Home operators, whose roaming agreements set limits on how long a SIM roams before the visited operator raises a dispute or blocks it.
Any one of them is enough to cut a device off.
Three types of restriction
Regulatory bans
Some countries restrict or prohibit permanent roaming for IoT by regulation. Brazil, Turkey, China, and India are among the markets most widely cited as requiring local connectivity for devices operating long term. Others require device registration, local numbering, or local data storage that permanent roaming does not satisfy. Enforcement varies. Some markets block at the network, others act on complaint.
Operator and contractual limits
In markets with no regulatory ban, operators still limit permanent roaming through their bilateral agreements. North America and Australia are frequently named as markets where operators restrict long-term IoT roaming by contract. These limits are invisible until they are enforced, and they change when agreements are renegotiated.
Fair use rules
Inside the EU, the Roam Like at Home regulation removed retail roaming charges for travellers. The same regulation lets operators apply a fair use policy where a SIM spends more time and data abroad than at home over a four month observation window. IoT devices with foreign SIMs fit that profile exactly. Most IoT traffic runs on wholesale agreements outside the retail rules, but the principle shapes how operators treat permanently roaming SIMs across Europe.
How to assess risk by market
Build a simple market register before deployment. For each country, record four things.
- Regulatory position: banned, restricted, registration required, or permitted.
- Operator position: whether the networks you plan to use accept permanent roaming from your provider's home network.
- Device lifetime in market: a two month pilot carries different risk from a fifteen year meter installation.
- Replacement cost: what it costs to reach every device if the SIM has to change.
High regulatory risk plus long lifetime plus high replacement cost means permanent roaming is the wrong model for that market, no matter how attractive it looks at launch.
The alternatives, and when to use each
Local connectivity and local breakout
A local subscription on a domestic operator is the most compliant option. The device is not roaming, so roaming rules do not apply. The traditional cost is operational: one contract, one SIM type, and one portal per country. Local breakout, where traffic exits to the internet or your cloud in the country of operation, also answers data residency and latency requirements.
Multi-IMSI
A multi-IMSI SIM holds several operator identities on one card. In markets where the provider holds a local IMSI, the device presents as a domestic subscriber instead of a roamer. The switch happens in the SIM applet or the core network, with no change in the field. Multi-IMSI fits fleets spread across many countries where you want one SIM stock-keeping unit and local identity where it matters.
eUICC
An eUICC lets you download a new operator profile over the air. Under GSMA SGP.32, the standard for IoT devices, the profile change is driven by your platform, not by the user. eUICC fits long-lived devices in markets where rules change, or where you expect to add a local operator profile after deployment. It is the most flexible option and the one that asks the most of your hardware and provisioning process.
Choosing between them
Choose local connectivity for a small number of high-volume markets with strict rules. Choose multi-IMSI for broad multi-country coverage with local identity in key markets. Choose eUICC for long device lifetimes and markets where you need a path to change operator without a site visit. Most global fleets use a combination.
How IXT approaches roaming compliance
IXT runs a dedicated mobile core built for IoT. One SIM covers 600+ mobile networks across 190+ countries, available as SIM, eSIM, or iSIM. IXT supports local IMSI options in key markets to reduce permanent roaming risk, so a device presents as a local subscriber where the market requires it.
TheIXT CMP shows every SIM by country and network in real time. You see which devices sit in restricted markets and which network each one uses, before an operator decides for you.
IXT does not guarantee coverage on every network in every country. Availability depends on the agreements in place at the time of deployment, and regional support for NB-IoT and LTE-M varies. Confirm the position for your target markets before you commit.
Frequently asked questions
Is permanent roaming illegal?
Not in most countries. It is restricted by regulation in a minority of markets and by operator agreements in many more. The risk is disconnection, not prosecution.
Does an eSIM solve permanent roaming?
Only if the eSIM loads a local profile. An eSIM carrying a foreign operator profile roams in the same way as a physical SIM.
How long before permanent roaming is detected?
It depends on the operator and the agreement. Some act within weeks, others after months, and some only when traffic volume draws attention.
Do I need a local SIM in every country?
No. Most fleets need local identity only in the markets with strict rules or long device lifetimes. Multi-IMSI covers the rest from one SIM.
For a shorter introduction to the options, read What to use instead of permanent roaming for IoT. To map roaming risk across your target markets, book a demo at ixt.io.
Why trust this guide
This guidance is based on real IoT and OT deployments in regulated industries including energy, utilities, and industrial environments.
IXT designs and operates secure connectivity architectures where:
- devices are deployed across multiple countries and networks
- SIM-level identity is enforced at the network edge
- third-party access is controlled without VPNs
- audit trails are required for regulatory compliance (including NIS2)
The patterns described here reflect how these environments are secured in practice, not theoretical models.
About the author
This article was written by the IXT Connectivity and Security team.
IXT operates a full MVNO core network and delivers secure IoT connectivity across 190+ countries and 600+ mobile networks. The team works directly with industrial, utilities, and infrastructure operators to design and secure large-scale IoT and OT deployments.
Their focus is on network-level Zero Trust architecture, SIM-based identity, and secure device communication without relying on VPNs or endpoint agents.
Related articles