When multi-IMSI failover happens in IoT connectivity
Multi-IMSI failover is not constant. Here are the six moments a switch actually triggers, what it fixes, what it does not fix, and what to ask a provider.
A fleet of 3,000 trackers works for two years. Then one morning 400 of them go quiet, all in the same country, all at once. Nothing changed on the devices. Nothing changed in your platform. A roaming agreement changed, and every unit that depended on it lost its only route to a network.
Multi-IMSI is the answer people reach for here, and it is the right one. It is also poorly explained. Most descriptions say a multi-IMSI SIM "switches networks automatically" and leave it there, which suggests the SIM is hopping between operators all day looking for a better signal. It is not. Failover fires in a small number of specific situations. Knowing which ones tells you what multi-IMSI actually protects you against, and what it leaves on your plate.
What an IMSI is and why a SIM holds more than one
The IMSI, or International Mobile Subscriber Identity, is the number a SIM presents when it asks a mobile network for permission to attach. It identifies the subscriber and, in its first digits, the home operator. That home operator is what makes roaming work: a visited network looks at the IMSI, finds a roaming agreement with the home operator, and admits the device on those terms.
A single network SIM has one IMSI and one home operator. Everywhere the device travels, it is a guest of that one operator's agreements. If the agreement in a given country is weak, so is the device.
A multi-IMSI SIM stores several operator identities on the same SIM. The SIM presents one, and where that identity is refused or unusable, it presents another. To your device, this is invisible. It sees one SIM and one connection. Inside the SIM, a different home operator relationship is being used.
eUICC solves a related problem differently. An eUICC SIM holds a full operator profile that is downloaded and swapped over the air, not just an identity. Profile swaps are slower and heavier, and they suit long-lived changes such as moving a device permanently onto a local operator. Multi-IMSI is the faster, lighter mechanism for reachability on a day to day basis. Many fleets end up using both.
The six moments failover actually triggers
1. The attach is refused
The device asks to attach and the network says no. Registration rejected, roaming not allowed, or the visited network has no usable agreement with that home operator. This is the cleanest failover case. The SIM presents a different IMSI, arrives as a subscriber of a different home operator, and the same visited network admits it.
2. A roaming agreement lapses or changes terms
This is the scenario in the opening paragraph, and it is the most commercially painful one because it hits a whole country at once and originates outside your control. A multi-IMSI SIM has other agreements to fall back on, so the blast radius is a subset of devices rather than every device in that market.
3. The visited network has an outage
A regional core failure or an extended cell outage on the operator the device is registered to. A single network SIM waits for the operator to recover. A multi-IMSI SIM presents an identity that gives it access to a different operator in the same country, so the device rides out the outage on somebody else's infrastructure.
4. Permanent roaming rules are enforced
Several markets restrict devices from roaming indefinitely on a foreign IMSI. Brazil, Turkey, Canada, India, China, and others each treat this differently, and enforcement tightens without much warning. A device installed in 2024 and never touched since is exactly the device that gets caught. Multi-IMSI with a local identity for that market removes the foreign roaming dependency. IXT supports local IMSI options in key markets to reduce permanent roaming risk.
5. Signal quality degrades below a usable threshold
The device is attached, the network says everything is fine, and the throughput is unusable. Weak signal, heavy congestion, or a cell the device should have released and did not. Where the SIM applies quality-based rules, a poor session triggers a switch rather than waiting for a hard failure. This is the case with the most variation between providers, so it is the one worth asking about specifically.
6. A network technology is retired
2G and 3G sunsets are still running through Europe on different national timetables. A device attached to a network that switches off a generation loses service in that market on that operator's schedule. Another IMSI with a different operator relationship gives the device somewhere else to land while you plan the hardware refresh.
What failover does not fix
Being precise about the limits is what makes the mechanism worth buying.
- No coverage is still no coverage. If no operator has a usable cell where the device sits, switching identity changes nothing. Multi-IMSI is a commercial and identity mechanism, not a radio one.
- Band support is fixed in hardware. An IMSI switch does not give the module bands it was never built for. A device that lacks the local band is out of reach regardless of which operator would have admitted it.
- Switching is not instant. A switch means detaching, presenting a new identity, and re-attaching. Expect seconds to minutes, and expect the application session on top to drop and reconnect. Firmware that assumes a permanent socket will notice.
- It does not reduce data cost on its own. Different identities carry different rates. Without pooling and usage control, more identities means more rate variation, not less spend.
- It adds nothing to security. Multi-IMSI is about reachability. Keeping traffic off the public internet is private routing. Checking whether a device should be talking to a system at all is a Zero Trust layer in the network and cloud. Three separate jobs.
What to ask a provider
Most connectivity providers offer multi-IMSI. The differences sit in operations, not in the datasheet.
- Which of the six triggers above cause a switch on your platform, and which do not?
- How long does a switch take, end to end, and what does the device see while it happens?
- Are switch events visible to me per device, and how quickly? A switch history that appears tomorrow is a report. One that appears now is an operational tool.
- Which markets do you hold a local IMSI in, rather than roaming into?
- Who owns the mobile core that makes the routing decision? A provider running its own dedicated IoT core changes policy directly. A provider virtualised on a partner platform raises a ticket.
That last question is where IXT differs from most of the market. IXT runs its own mobile core built for IoT, so routing, session policy, and identity selection are controlled in-house rather than requested from a partner. Switch events, session status, usage, and location appear in theIXT CMP in real time, not on a 24 to 48 hour delay, which matters when the question is whether a silent device is a network problem or a hardware failure.
The practical position
Multi-IMSI does not make a fleet faster and it does not fix a device parked in a signal shadow. What it removes is single-operator dependency: one lapsed agreement, one regional outage, one tightened roaming rule taking out a whole market at once. For cross-border fleets with a 10-year service life, that dependency is the risk worth engineering out, because it is the one that arrives without notice and lands on every device at the same moment.
Ask us how it works for your deployment.
Why trust this guide
This guidance is based on real IoT and OT deployments in regulated industries including energy, utilities, and industrial environments.
IXT designs and operates secure connectivity architectures where:
- devices are deployed across multiple countries and networks
- SIM-level identity is enforced at the network edge
- third-party access is controlled without VPNs
- audit trails are required for regulatory compliance (including NIS2)
The patterns described here reflect how these environments are secured in practice, not theoretical models.
About the author
This article was written by the IXT Connectivity and Security team.
IXT operates a full MVNO core network and delivers secure IoT connectivity across 190+ countries and 600+ mobile networks. The team works directly with industrial, utilities, and infrastructure operators to design and secure large-scale IoT and OT deployments.
Their focus is on network-level Zero Trust architecture, SIM-based identity, and secure device communication without relying on VPNs or endpoint agents.
Related articles