What GSMA SAS actually certifies
The GSMA Security Accreditation Scheme exists so mobile operators can trust the suppliers that hold their cryptographic keys and subscriber credentials. It has two arms. SAS-UP accredits UICC, SIM and eSIM production sites, covering personalisation, key generation, data handling, transport and destruction. SAS-SM accredits subscription management platforms, both SM-DP+ and SM-SR/SM-DS operations, covering the data centres, the platform and the people who run it.
Accreditation is site-specific and platform-specific, not company-wide. Each production location or hosting environment is audited and listed separately, and adding a site, a data centre or a materially new process means an extension audit rather than an update to your existing certificate.
Audits are carried out by GSMA-appointed auditors against a published set of requirements and a consolidated security controls checklist. There is no scoring curve. Either a control is implemented and evidenced or it is a finding.
The timeline that works
Organisations that succeed first time typically start twelve to eighteen months before they need the certificate. That sounds long until you cost out the physical works. A compliant high-security area usually needs construction, intrusion-resistant walls, a certified vault or safe, access control with anti-passback, CCTV with retention that satisfies the checklist, and an alarm system with monitored response. Those lead times, not documentation, drive the plan.
A realistic sequence is: gap assessment and scope definition (weeks 1 to 6), control design and procurement (weeks 6 to 16), physical works and system commissioning (weeks 12 to 36), documentation, training and process embedding in parallel, then a mock audit at least eight weeks before the real one so there is time to close what it finds.
Book the GSMA audit slot early. Auditor availability, not your readiness, is often the binding constraint on the date.
Where first-time applicants lose points
Physical security assumptions. Teams assume an existing factory perimeter counts as the secure area. The scheme expects layered zones with defined entry controls between each, and evidence that the layering works in practice, including out of hours.
Personnel controls. Screening must be documented, repeatable and applied to contractors and cleaners as well as employees, with defined re-screening intervals and a documented process for role changes and terminations. Verbal assurance that people are trusted is not evidence.
Key management. Dual control and split knowledge have to be visible in ceremony records, not just written in a procedure. Auditors will ask to see completed ceremony logs, HSM configuration, key component custody records and destruction certificates.
Logistics and transport. Secure courier arrangements, tamper-evident packaging, chain-of-custody records and reconciliation between what was produced, shipped and received are examined closely, including reject and scrap flows.
Destruction and reconciliation. Scrap, rejected cards, test data and returned material must be accounted for numerically. Unexplained quantity variances are one of the fastest routes to a serious finding.
Logging and monitoring. Access control and CCTV logs are frequently retained but never reviewed. The scheme expects evidence of review, with names, dates and outcomes.
Building an evidence pack the auditor can follow
Structure your evidence one-to-one against the GSMA consolidated controls list rather than against your internal document tree. For each control, hold the policy or procedure, the record that proves it operates, and the name of the owner who can speak to it in the interview.
Keep the records recent. A procedure signed off two years ago with no operational records since reads as shelfware. Three to six months of live records, logs, reviews, training completions and ceremony documents demonstrate a working system.
Prepare your people, not just your paperwork. Auditors interview operators, security staff and process owners. The most common failure mode we see is a well-documented control that the person performing it describes differently.
Renewal audits are not a formality
Accreditation is maintained through periodic re-audit, and renewal audits examine change. New products, eSIM introduction, cloud migration of a supporting service, a new subcontractor, revised shift patterns or a change of security integrator all attract scrutiny. Maintain a change register that records the security assessment of each change and you turn the renewal into a review rather than a re-run.
Between audits, keep the annual rhythm going: internal audit against the SAS checklist, management review, screening refresh, key ceremony practice, CCTV and access log reviews, and a physical control test.
How AACL Global supports SAS programmes
We support both first-time applications and renewal cycles for SAS-UP and SAS-SM, working with SIM and eSIM manufacturers, security printers, subscription management providers and their hosting partners. Engagements typically combine a gap assessment against the current GSMA requirements, control and facility design support with your architects and security integrators, evidence engineering, personnel and key management process design, staff readiness coaching, an independent mock audit, and onsite or remote support during the scheme audit and finding closure.
Delivery is available onsite or remote, wherever you operate. If you are scoping a first SAS audit or preparing for renewal, talk to us early. The cheapest time to fix a physical control is on a drawing.
To discuss this subject with our practitioners, write to info@aacl.co.ke.
