Skip to content
§
§ · build vs buy

eSIM Lifecycle Management: Keep the Vendor Platform, Decide About the Orchestration Layer

Two decisions here, and only one is open. Do not build a profile management server: Thales, IDEMIA, Giesecke and Devrient, Kigen and Workz already carry the security accreditation and key management, and duplicating that buys you nothing.

Custom Software Development software overview illustration for Esim Lifecycle Management Software Build vs Buy Guide.
The short answer

Two decisions here, and only one is open. Do not build a profile management server: Thales, IDEMIA, Giesecke and Devrient, Kigen and Workz already carry the security accreditation and key management, and duplicating that buys you nothing. The open decision is the orchestration layer above it, and the threshold is escalation volume. Below a handful of profile escalations to engineering a week, vendor tooling plus a manual release is genuinely cheaper. Most small operators reading this should stay where they are.

When is off the shelf genuinely the right call here?

Two things are off the shelf in this category and they need separating, because conflating them is how budgets double.

The first is the profile management server itself. Keep buying it, permanently. Running a certified platform means security accreditation, key management and industry compliance obligations that Thales, IDEMIA, Giesecke and Devrient, Kigen and Workz already hold. That is not a cost decision, it is a compliance and key management decision, and no operator improves its position by taking it in house.

The second is the operational layer above. Stay with vendor tooling alone if you are a small operator in one market, on one profile management vendor, at low activation volume, with an engineering team that can absorb an occasional manual profile release without anyone noticing. Below a certain volume the manual path is genuinely cheaper than the build, and we would say so on the call.

Some vendors also sell care tooling as a paid tier. It will not fit your retail journey and it will not hold your inventory, but if your only complaint is visibility, compare that annual fee against a six figure build before committing to anything.

The test that settles it: count how many times last month your care team escalated a profile problem to engineering. If the answer is single digits and none of them caused a hardware return, you do not have a build case yet.

When does a custom build actually pay off?

Two or more of these need to hold.

Your care team escalates profile issues to engineering more than a handful of times a week, which means every stranded customer costs an engineer's afternoon as well as the customer. You ship devices where a failed onboarding causes a return, so the cost of a stalled activation exceeds anything the connectivity earns. You operate in more than one market with different identity verification requirements and different profile release preconditions. You are moving from physical to embedded first and the retail journey is being designed now, which is the cheapest moment to get it right. Or you cannot produce a count of issued but unconsumed activation codes, which is an inventory leak you are paying for without being able to size it.

The structural reason is that a subscription split into three systems and nothing joins them. The commercial subscription lives in your business support systems. The secure profile lives on the vendor server. The physical embedded card lives in a device with its own identifier, its own operating system version and its own behaviour when a download fails. During an incident nobody can answer the only question that matters, which is what state this specific profile is in right now and what the safe next action is.

Vendor platforms expose primitives, not journeys. They do not know that your prepaid activation requires an identity check before profile release in one market and not another, or that your upgrade path should keep the old profile enabled until the new one is confirmed working. The gap between primitive and journey is exactly where customers get stranded.

How do they compare on the things that matter in this industry?

  • Profile state. Most operator stacks collapse a real lifecycle into an activated flag on the subscription. The actual states are issued, downloaded, installed, enabled, disabled and deleted, plus the unhappy paths where a customer swapped device mid download or the code expired between purchase and unboxing. Each needs a definition, a transition rule, a timeout and a safe care action.
  • Care resolution. Vendor portals are reachable by two engineers with access. An agent screen keyed on the card identifier and the device identifier, with guarded actions and an audit entry per action, is what converts an engineering escalation into a first contact resolution.
  • Device behaviour. Model and operating system version at the moment of a failed download is the data nobody captures, which is why a failure cluster on one device family looks like random noise across thousands of tickets. Owning eligibility as data rather than code means a rule change ships in a day rather than in an application release.
  • Inventory. Physical stock, embedded profile pools and activation state usually live in three places. Expiry policy on issued codes and an automated reclaim sweep turn a recurring manual audit into a dashboard.
  • Multi vendor position. Interfaces and notification behaviour differ in practice even where the specification is shared, and missed notifications are the normal case in production rather than the exception.
  • Consumer against connected devices. Consumer provisioning is user initiated with retries and a human present. Fleet provisioning runs with no human in the loop and must assume a device in the field cannot ask for help.

What does total cost of ownership look like at your scale?

In Digital Heroes delivery experience an orchestration layer over an existing profile management server is $70,000 to $160,000 over 12 to 18 weeks, covering the local profile state mirror, activation code issuance with expiry, download and installation tracking, device eligibility rules, retry and recovery flows, inventory with automated reclaim, and a care console showing profile state on one screen. Extending into device transfer, multi profile handling and retail activation is $200,000 to $320,000 over 7 to 10 months. Adding bulk provisioning for connected devices alongside the consumer model takes it to $320,000 to $450,000 over 9 to 12 months.

A mobile operator moving to an embedded first retail journey, one vendor, one market, three device families, prices out at $126,000 across 16 weeks: discovery and state model design $14,000, the state mirror with reconciliation $22,000, activation issuance, expiry and reclaim $16,000, download tracking, eligibility and retry logic $32,000, care console with guarded actions and audit $24,000, and device testing across three families with rollout $18,000. Adding in store activation at the same time would have pushed it toward $175,000.

Running cost is 15 to 20 per cent of build a year, so $19,000 to $25,000 on that example, plus two to three weeks of engineering and testing every autumn for the device compatibility refresh, and $4,000 to $18,000 for hosting and event retention. Vendor profile fees continue separately and are unaffected by anything you build. Care retraining each device season and periodic security review of anything touching activation credentials are real recurring lines that never appear on a feature priced quote.

What does the hybrid look like, and when is it the honest answer?

The hybrid is the default and it has two layers, the same way the buy decision does.

The outer layer is permanent: keep the vendor profile management server forever, and build only the operational layer that sits between your business support systems, your care tooling and that server. Profile release becomes a business action with preconditions rather than an interface call somebody makes from a portal. Retry gets a policy. Recovery gets an authorised path an ordinary agent can execute without escalating to engineering, and that last point is what changes support cost.

The inner layer is sequencing. Start with the state mirror and the care console only, at roughly $35,000 to $55,000. That combination is the cheapest slice of the full orchestration layer and it removes most escalations, which buys time to do the rest properly rather than in a panic. There is a cheaper option still if you only need visibility: a read only profile state dashboard at $18,000 to $30,000, with no actions, no retry logic and no inventory reclaim. For an operator with modest activation volume that is sometimes the whole answer.

The reason to go further is inventory and recovery. A dashboard tells you a profile is stuck. It does not reclaim the activation code, does not safely release the profile so the customer can retry, and does not stop the second support call. If stranded activations are producing hardware returns, both shortcuts stop being cheap quickly.

Sequence markets rather than launching them together. That alone typically saves 20 to 30 per cent on a first release.

Which should you choose, by operator size and stage?

Small operator, one market, one vendor, low activation volume: stay with vendor tooling. Absorb the occasional manual release and revisit when escalations become weekly rather than monthly.

Operator whose only complaint is care visibility: build the read only dashboard at $18,000 to $30,000, or price your vendor's care tier against it. Three or four weeks of work removes the majority of escalations currently landing on engineering, and it is an honest answer rather than a stepping stone you are being sold.

Operator moving to an embedded first retail journey: build the orchestration layer now, before the retail flow is designed around vendor primitives. One vendor, one market, one activation journey in release one, and expect roughly $126,000 across 16 weeks.

Device manufacturer shipping connected hardware: build, and decide which product you are before the first sprint. Fleet provisioning is a different trigger model from consumer, and building both journeys over one flow is a common and expensive mistake, though they can share one inventory model.

Operator running two profile management vendors, or likely to within two years: build, and make the state model vendor neutral from the start. A second vendor adds 25 to 40 per cent on top of the orchestration layer, and retrofitting one into a single vendor design usually means touching the whole provisioning path.

Anyone who cannot count their issued but unconsumed activation codes: fix that first at $8,000 to $16,000. It is the cheapest problem in this whole category and it is an inventory leak with a security edge, because a code sitting in an inbox for six months is a credential.

If you want a second opinion before signing anything, Digital Heroes contracts through India LLP, US LLC and UK LTD entities, so the agreement and the intellectual property assignment sit under law your own advisers already read. The document is yours whichever way you go.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. OECD research finds that digitalisation offers SMEs opportunities to improve performance, spur innovation, enhance productivity and compete more evenly with larger firms; it reports that increased use of online platforms produced significant multi-factor productivity gains in SME-heavy sectors such as hospitality and retail, while smaller firms lag in adoption due to skills, resource and financing gaps. Source: OECD (2021) →
  2. The share of tasks performed mainly by humans is projected to fall from 47% to 33% by 2030 as human-machine collaboration expands, with 170 million jobs created and 92 million displaced (a net gain of 78 million). Source: World Economic Forum (2025) →
  3. Qualtrics research (Q3 2023 survey of ~28,400 consumers across 26 countries) estimated bad customer experiences put roughly $3.7 trillion in global revenue at risk annually, a 19% jump from the prior year's $3.1 trillion; 64% of customers say they will switch companies over poor service regardless of how much they like the product. Source: Qualtrics XM Institute (via Forbes) (2024) →
  4. SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
FAQ

Frequently asked questions

What does it cost to move off vendor care tooling onto our own layer?

You do not move off the vendor at all, which is what makes this switching cost low. The profile management server stays, its fees continue, and the orchestration layer reads from it rather than replacing it.

The real switching cost is access rather than money: test credentials and a sandbox on your vendor, plus real devices across the model range you support. Start the vendor access request on day one, because it runs on their calendar rather than yours.

What happens if our profile management vendor changes its pricing or tiers?

Model it per profile at the activation volume you expect next year, and separately price any care tooling tier they sell. Those tiers are the part a build can displace. The core platform fee is not, and should not be, because you are keeping it.

If a repricing pushes you toward a second vendor, design the state model to be vendor neutral now. That costs little today and saves most of the 25 to 40 per cent a second vendor otherwise adds.

How long before care agents can see where a profile actually is?

Twelve to eighteen weeks for a full orchestration layer, and three to four weeks for a read only dashboard if visibility is the entire problem. In the sequence we recommend, the state mirror and care console land first because they remove escalations before any money moves through the system.

Device testing sits at the end and should not be compressed. The failures you do not find on real handsets are found by customers holding an unusable phone.

Do we need our own profile management server instead of Thales or IDEMIA?

No, and this is the one part of the category where the answer is not a judgement call. Running a certified server carries security accreditation and key management obligations that those vendors already hold, and duplicating them buys you nothing.

What is worth building is the layer above: the journeys, preconditions, retries, recovery paths and care visibility that vendor portals expose only as raw primitives. Keep buying the secure element and own the operational logic.

Why is device transfer the most expensive feature to build?

Because it spans two devices, two profile states and a recovery path that must never leave a customer with a working profile on neither. The safe design keeps the existing profile enabled until the new download is confirmed installed rather than releasing first and hoping.

Every failure mode has to be handled explicitly and tested on real hardware, which is why it is consistently the most expensive feature per screen here and why we usually sequence it into a second release.

Can we extend our existing subscriber systems instead of building a new layer?

Usually not, and the reason is the state model. Existing subscriber and inventory systems treat a profile as issued or not issued, and retrofitting a real lifecycle into them tends to cost more than building a purpose shaped layer that reads from them.

The exception is an inventory system that is already event driven and modern, where extending can save 20 to 30 per cent. Ask that question specifically before assuming either answer.

How much does supporting a second profile management vendor cost?

Typically 25 to 40 per cent on top of the orchestration layer. The specification is shared but notification behaviour, error semantics and timing are not, so each vendor becomes its own adapter with edge cases found during testing rather than in documentation.

Missed notifications are the normal case in production, so ask any developer how they reconcile state when a notification never arrives. A build that assumes they always arrive drifts out of sync within weeks.

Who owns the code and the orchestration logic if an agency builds this?

You should own the repository, the cloud accounts and the right to hire anyone else to continue the work, written into the contract before kickoff. At Digital Heroes the client keeps both from the first commit.

This matters more than usual here, because the orchestration layer sits between your business support systems and a vendor you already depend on. You do not want a third dependency in the middle of that relationship.

Should we build an MVP first or go straight to the full system?

MVP first, for almost everyone: ship the single workflow that carries the business value in 10 to 16 weeks, learn from real users, then fund phase two from evidence instead of guesses. The caveat is that an MVP is a small version of a well-built system, not a badly built version of a big one; the data model must already support what comes next. An agency that cannot tell you what they deliberately left out of your MVP has not designed one.

We run everything on Airtable and spreadsheets. When is it time to go custom?

The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.

What questions should I ask a development agency on the first call?

Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.

Is a solo freelancer enough for my project, or do I really need an agency?

A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.

What does a $50,000 custom software budget actually buy?

One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.

What should I have ready before I contact a development agency?

Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.

What happens if I stop paying for maintenance after launch?

Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.

If an agency builds my software, who actually owns the code?

You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.

Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?

For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply