Skip to content
§
§ · hiring guide

How to Hire an eSIM Lifecycle Management Development Company

Hire for the orchestration layer, never for the SM-DP+ itself. Keep the certified platform with your SIM vendor and buy the journeys, preconditions, retries, recovery paths and care visibility they do not own.

Custom Software Development code editor and API illustration for Esim Lifecycle Management Software.
The short answer

Hire for the orchestration layer, never for the SM-DP+ itself. Keep the certified platform with your SIM vendor and buy the journeys, preconditions, retries, recovery paths and care visibility they do not own. An orchestration build over an existing SM-DP+ runs $70,000 to $160,000 over 12 to 18 weeks. Test the shortlist with one question: what happens when a result notification never arrives.

Choosing a developer for eSIM work is like hiring an electrician to wire a building whose fuse box belongs to somebody else. The secure profile lives on an SM-DP+ operated by Thales, IDEMIA, Giesecke+Devrient, Kigen or Workz. The subscription lives in your BSS. The eUICC lives in a device with its own EID and its own opinions about failed downloads. Your developer owns none of those three things, and the customer standing in a store on Monday with a phone that cannot make calls does not care. They only know that nobody can tell them what happened on Saturday.

That is what makes this hard to buy. The specification is public and the vendor APIs look tidy in a proposal, so almost any competent integrator will quote confidently. What separates them shows up only in production, in the ordinary case where a result notification is missed and the local state drifts out of sync within weeks, or where a September device release changes download behaviour and your activation flow was written against last year's assumptions. Ask about those two situations early, because a firm that has run this in production answers immediately and a firm that has not talks about QR codes.

What an eSIM lifecycle development company actually does

The care console is the visible piece. Everything that makes it useful sits behind it.

They mirror the profile state machine locally as a first class object keyed on ICCID and EID, with every transition timestamped and attributed to whoever caused it, fed from the SM-DP+ result notification path. That mirror is what makes support possible at all, because your BSS collapses the whole lifecycle into an activated flag while the device disagrees and the truth sits in a third system. They build reconciliation for missed notifications, which is the normal case rather than the exception.

They encode your journeys as business actions with preconditions rather than raw API calls somebody makes from a vendor portal: identity checks before profile release where a market requires it, keeping the old profile enabled until a transfer is confirmed installed, retry with a policy, and a recovery path an ordinary agent can execute without escalating to engineering. They make device eligibility data driven, capturing model, OS version and EID with every attempt and failure so a new device family becomes a rule change rather than an app release. And they build one inventory model spanning physical and embedded stock, with expiry on issued activation codes and an automated sweep that returns abandoned profiles to the pool.

What it really costs in 2026

Digital Heroes delivery bands. Vendor count and market count move the number more than subscriber volume does.

Project tierCostTimeline
Orchestration over an existing SM-DP+: state mirror, activation issuance, eligibility rules, retry and recovery, inventory, care console$70,000 to $160,00012 to 18 weeks
Full platform: device to device transfer, multi profile handling, retail and dealer activation, IoT bulk provisioning$200,000 to $450,0007 to 12 months
Each additional SM-DP+ vendor adapter$25,000 to $60,0004 to 7 weeks
Support, device rule updates and vendor change handling15% to 20% of build per yearOngoing

Two costs sit outside most quotes. The first is vendor access. Test credentials and a sandbox on your SM-DP+ run entirely on your SIM vendor's calendar, and test profiles are frequently chargeable. Raise the request on day one of the engagement, before any code exists, because it is the single most common reason an eSIM schedule slips and no developer can accelerate it for you.

The second is a real device lab. Download and transfer behaviour differs by model family and OS build, and every autumn brings a new generation that changes the assumptions your flow was written against. That means buying handsets across the range you support and refreshing them annually, plus the time to retest eligibility rules against each. Emulators do not surface this. Firms that have shipped eSIM say so early. Firms that have not will price a purely API level test plan.

Signals of a strong partner

  • They refuse to build an SM-DP+. Security accreditation and key management belong with your vendor, and a firm that offers to replicate that is either inexperienced or selling you a compliance problem.
  • They raise missed notifications unprompted. Production reconciliation between the local mirror and the vendor state is the difference between a system that works in week one and one that works in month six.
  • They name the SM-DP+ platforms they have integrated. Interfaces converge on the specification and diverge in notification behaviour and error semantics, which only shows up in real work.
  • They design the care agent screen early. Who may release a profile, what preconditions apply, what gets logged. That answer reveals whether they think in state and permissions or just in endpoints.
  • They separate consumer from IoT. User initiated retries and fleet initiated orchestration are different trigger models, and building one flow for both is a common and expensive mistake.
  • They ask about markets before features. Identity verification requirements and release preconditions vary by country, and that shapes the precondition engine rather than being configuration added later.
  • They put the repository and the eligibility data in your accounts. This layer sits between your BSS and a vendor you already depend on, and a third dependency in the middle is exactly what you are trying to avoid.

Red flags

  • They cannot cleanly explain EID versus ICCID. If the difference and its consequence for a wrongly downloaded profile is not immediate, keep looking.
  • Profile state is modelled as a boolean. Released, downloaded, installed, enabled, disabled and deleted are not interchangeable, and some transitions are not reversible.
  • Device eligibility is hard coded. Every autumn you will wait on an app release to fix a device family that broke, while support absorbs the tickets.
  • No expiry or reclaim on activation codes. Unconsumed codes are an inventory leak and a credential sitting in somebody's inbox for months.
  • The test plan is API only. Without real handsets across the supported range, you will discover device specific failures through your care queue.

Questions to ask on the first call

  1. Explain what happens when a profile downloads to the wrong EID, and when release and reissue is not possible.
  2. Which SM-DP+ platforms have you integrated by name, and how did you reconcile a missed result notification?
  3. Design the care agent screen out loud. Who may release a profile, under what preconditions, and what is logged?
  4. How do you keep a customer connected during a device to device transfer if the new download fails halfway?
  5. Where do device model and OS version get captured, and how do we change an eligibility rule without shipping an app?
  6. What is your expiry and reclaim policy for issued activation codes, and how would you report outstanding ones today?
  7. How would you support a second SM-DP+ vendor later without touching the whole provisioning path?
  8. What does your device test lab contain, and who buys and refreshes the handsets?
  9. Who requests the vendor sandbox, when, and what happens to the schedule if it takes six weeks?

A simple way to decide

Do not choose from a proposal. Pay your two strongest candidates for a three to five week discovery on the same brief, and require the same written specification from each: the local profile state machine with transitions and permissions, the reconciliation design for missed notifications, the precondition rules per market, the device eligibility data model, the inventory and reclaim policy, the care console permissions, and a phased cost. You own both documents. Take the better one to whoever you appoint. Bring them your activation failure tickets from the last month as the brief, because that file describes your real problem far more accurately than any requirements list you could write in a meeting.

Digital Heroes is PRD first by default, with more than 2,000 delivered projects and a 50 plus team, and contracts through an India LLP, a US LLC or a UK LTD so IP assigns under your own jurisdiction rather than a vendor's. The client holds the repository and the orchestration logic from the first commit, and the firm is verifiable through D-U-N-S, Clutch and Trustpilot before anything is signed.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. 76% of developers are using or planning to use AI tools in their development process in 2024 (up from 70% in 2023), with current active use rising to 62% from 44%; 81% agree increasing productivity is the biggest benefit of AI tools. Source: Stack Overflow (2024) →
  2. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  3. PMI's Pulse of the Profession research found organizations waste an average of roughly 9.9% of every dollar invested in projects due to poor performance - equivalent to about $1 million wasted every 20 seconds collectively worldwide. Source: Project Management Institute (PMI) (2018) →
  4. Independent reporting of Gartner's 2025 survey confirms 59% of finance leaders use AI, up from 37% in 2023, with error and anomaly detection (34%) and accounts payable automation (37%) among the leading use cases. Source: CPA Practice Advisor (reporting Gartner) (2025) →
FAQ

Frequently asked questions

How much does it cost to hire an eSIM lifecycle management development company?

An orchestration layer over an existing SM-DP+, covering the local profile state mirror, activation code issuance, device eligibility, retry and recovery, inventory and a care console, runs $70,000 to $160,000 over 12 to 18 weeks. Extending into device transfer journeys, retail activation and IoT bulk provisioning runs $200,000 to $450,000 across seven to twelve months. Each additional SM-DP+ vendor adapter typically adds $25,000 to $60,000.

Should a developer build our SM-DP+ as well?

No. Running a certified SM-DP+ carries security accreditation and key management obligations that Thales, IDEMIA, Giesecke+Devrient, Kigen and Workz already hold, and duplicating that buys you nothing but risk. What is worth building is the layer above: journeys with preconditions, retry policies, recovery paths an ordinary agent can execute, and the care visibility that vendor portals expose only as raw primitives.

What question best tests real eSIM experience?

Ask what happens when a result notification from the SM-DP+ never arrives. Missed notifications are the normal case in production, and a build that assumes they always land will drift out of sync within weeks. A firm that has run this answers with a reconciliation design immediately. Follow up by asking them to explain EID versus ICCID and what happens when a profile downloads to the wrong device.

What costs are usually missing from eSIM quotes?

Vendor sandbox access and a real device lab. Test credentials and test profiles come from your SIM vendor on their calendar and are often chargeable, so the request has to go in on day one. Separately, download and transfer behaviour differs by model family and OS build and changes every autumn, so handsets across your supported range must be bought, refreshed and retested against eligibility rules.

Can one build cover both consumer and IoT eSIM?

They can share one inventory model, but they should be scoped as two journeys. Consumer provisioning is user initiated and can rely on retries with a person present. IoT provisioning is fleet initiated, runs with no human in the loop and must assume a device in the field cannot ask for help, which is why the GSMA published a separate IoT remote provisioning specification. Squeezing both into one flow is expensive.

How do we get years of data out of our old system and into the new one?

Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.

If an agency builds my software, who actually owns the code?

You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.

How much should a small business budget for its first custom app or website?

For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.

Will custom software work with the tools we already use, like QuickBooks and Stripe?

Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.

How much should a small business expect to pay for custom software?

Across 2,000+ Digital Heroes projects, a small business system that replaces spreadsheets or one core workflow typically lands between $40,000 and $80,000, with more complex first versions running up to $150,000. The two levers that move the number most are integrations and user roles, not the team's hourly rate. Any quote under $15,000 for a full production system means the vendor has not understood your scope yet.

How many SaaS seats do we need before building custom becomes cheaper?

The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

Does the tech stack matter, and which one should I ask for?

It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.

Should I hire a freelancer or an agency for my software project?

A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.

How many people should be working on my software project?

A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.

What does it cost to keep custom software running after launch?

Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.

Should I ask for a fixed price or pay the agency hourly?

Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.

What is the biggest mistake first-time software buyers make?

Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply