Embedded connectivity for IoT products
Embedded connectivity integrates cellular hardware, subscriber identity, firmware and lifecycle operations into a product. Decisions made before layout and certification—technology, bands, antenna, SIM form, profile architecture and security—determine where the product can operate and how it can be maintained.
Connected Assets
Cellular modems, antennas and SIM or eSIM components built directly into original equipment manufacturer products are connected.
Recommended Tech
Key Takeaways
- A embedded connectivity design should start with the device's real locations, traffic pattern, power source and expected service life.
- Coverage must be validated on the intended radio technology and operator networks at representative sites; a coverage map is a planning input, not proof of indoor or device-level performance.
- Data use varies with payloads, protocol overhead, reporting frequency, retries, diagnostics and firmware updates, so measurements from representative hardware are more useful than generic averages.
- SIM form factor, remote profile management, security controls and network-sunset exposure should be decided before hardware certification and large production orders.
- Atomic Pulse may support deployments with multi-network SIMs, eSIM options, data pooling and connectivity management delivered by Atomic Mobile.
Deployment Checklist
- 1List launch and future target markets
- 2Choose technologies and bands from verified availability
- 3Reserve antenna volume and ground plane early
- 4Select SIM architecture before board layout
- 5Define factory provisioning and identifier reconciliation
- 6Measure every firmware traffic state
- 7Plan radio, regulatory and operator certification
- 8Implement secure boot and signed updates
- 9Validate profile failure and recovery
- 10Align supplier and network lifecycles with product support
What is connected in a embedded deployment?
Cellular modems, antennas and SIM or eSIM components built directly into original equipment manufacturer products are connected. The cellular link normally carries application telemetry and device-management traffic between field hardware and a cloud or enterprise endpoint. It does not by itself define the application, sensor accuracy or operational workflow.
A production design should document every communicating component: the modem, subscriber identity module (SIM), antenna, device firmware, application protocol, backend endpoint and management platform. If a gateway aggregates local Bluetooth, Wi-Fi, wired or low-power sensor traffic, size the cellular connection for the gateway's combined load and failure behavior. Treat remote diagnostics, certificate renewal, time synchronization and firmware delivery as first-class traffic rather than incidental overhead.
What business problem does embedded connectivity solve?
Manufacturers embed cellular to make products usable without customer network setup and to support remote monitoring or service. The connectivity supply chain then becomes part of the product lifecycle, requiring coordination between hardware, firmware, certification, manufacturing and support.
Cellular is generally considered when equipment moves, sits at third-party premises, or cannot depend on local Wi-Fi or wired access. It can shorten site installation by removing local-network credentials and firewall changes. That is a design benefit, not a guarantee of availability: service still depends on compatible hardware, an active subscription, radio conditions and the operator network.
Define the commercial outcome before choosing a modem. Useful measures might include the share of devices reporting on schedule, time to detect a fault, truck rolls avoided, transaction completion, or recovery time after a primary-link outage. Connectivity metrics such as successful attaches and session failures should support those outcomes rather than replace them.
What is the typical deployment environment?
The product may be worn, installed in vehicles, enclosed in metal, placed outdoors or sold into unknown premises. Industrial design, battery, ground plane, coexisting radios, user handling and regional variants all influence radio performance.
Survey representative locations, including the difficult ones, with the production module, antenna and enclosure. Radio performance can change when the antenna is mounted beside metal, behind coated glass, underground, inside machinery or close to electrical noise. Temperature, moisture, vibration and tampering also affect enclosure, connector and SIM-form-factor choices.
Document who installs the unit, how they confirm service, and what happens when no approved network is available. A technician should have a deterministic commissioning process: identify the device and SIM, verify antenna installation, confirm registration and data exchange, and record the result against the asset. For unattended equipment, include an out-of-band recovery or safe local service procedure.
How much cellular data will the deployment consume?
Estimate every product state: onboarding, normal operation, alarms, diagnostics, failed connections, certificate renewal, firmware and factory testing. Early firmware often logs more than release builds. Establish version-specific measurements and guardrails before launch.
There is no universal usage figure. Build a byte budget from payload size and frequency, then add Transmission Control Protocol/Internet Protocol (TCP/IP), Transport Layer Security (TLS), messaging and cellular-session overhead. Include unsuccessful retries, keepalives, domain name lookups, logs, remote commands and staged firmware images. A small telemetry payload can be outweighed by protocol setup; conversely, compression and batching can reduce repeated overhead.
Measure on production-like firmware across normal, degraded and recovery scenarios. Model a typical month and a high-use month rather than relying only on an average. The IoT data usage calculator can structure an estimate, but packet captures and connectivity-platform records should validate it. Set alerts that distinguish expected maintenance events from leaks or compromised devices.
What coverage does the use case require?
Define target countries, operators, technologies and bands before module selection. Test total radiated performance and sensitivity through the final enclosure using qualified laboratories where required. Network certification and local regulatory approval are distinct planning tracks.
Check coverage by country, operator, radio access technology and frequency band. “LTE coverage” does not prove LTE-M, Narrowband Internet of Things (NB-IoT), 5G or a particular roaming relationship is available. The device module and antenna must support bands actually used in each market. Moving or cross-border equipment also needs tested handover, roaming and network-selection behavior.
For stationary units, survey the exact installation position and consider external or diversity antennas where the design permits. For mobile units, test complete routes and dwell locations rather than one depot. Multi-network access can reduce dependence on a single operator, but it cannot create coverage where no compatible network is present. Countries may also restrict permanent roaming, so long-lived international deployments need a regulatory and profile-localization plan.
Which cellular technologies are recommended?
The following are technologies to evaluate, not universal prescriptions:
| Technology | Planning role |
|---|---|
| LTE-M | Evaluate against coverage, power, throughput, mobility and module lifecycle requirements. |
| NB-IoT | Evaluate against coverage, power, throughput, mobility and module lifecycle requirements. |
| LTE Cat-1 bis | Evaluate against coverage, power, throughput, mobility and module lifecycle requirements. |
| 5G RedCap | Evaluate against coverage, power, throughput, mobility and module lifecycle requirements. |
LTE-M and NB-IoT fit low-power designs under different mobility and coverage conditions. Cat-1 bis can simplify moderate-data LTE products. 5G RedCap may suit products needing more capability than low-power wide-area options, subject to ecosystem availability.
Confirm operator support in every target market before fixing the bill of materials. LTE-M and NB-IoT are Third Generation Partnership Project (3GPP) low-power wide-area technologies, but deployment differs by operator. LTE Cat-1 bis uses conventional LTE coverage and one receive antenna, while higher LTE categories and 5G suit greater throughput. Review the LTE-M versus NB-IoT comparison and the network sunset tracker. Avoid a new 2G- or 3G-only design unless a documented market-specific lifecycle justifies it.
Should the device use a SIM or eSIM?
Choose removable SIM, MFF2, eUICC or integrated SIM (iSIM) from mechanical, security, provisioning and supply-chain needs. eSIM is not merely a component choice: define bootstrap, profile download, ownership, recovery, entitlement and end-of-life processes.
A removable SIM is convenient for prototypes and serviceable equipment. A soldered machine-form-factor SIM (MFF2) resists vibration, moisture and casual removal. An embedded Universal Integrated Circuit Card (eUICC), commonly called eSIM, can store remotely managed operator profiles when the device, platform and commercial arrangements support the relevant architecture. GSMA SGP.32 defines an eSIM architecture aimed at Internet of Things devices; adoption and feature support must be confirmed with suppliers.
Decide before certification because the holder, eUICC, secure element and profile workflow affect hardware and operations. Specify bootstrap behavior, profile ownership, failed-download recovery and what happens at contract end. See IoT SIM versus eSIM versus iSIM and what SGP.32 is.
What security controls should be included?
Build a hardware root of trust where appropriate, unique factory identity, secure boot, signed rollback-protected updates and protected manufacturing injection. Separate SIM identity from application authorization. Maintain a vulnerability response process for the product's supported lifetime.
SIM authentication and radio encryption protect part of the path, not the whole product. Use device-unique credentials, TLS for application traffic, certificate rotation, signed firmware, secure boot where supported, least-privilege backend authorization and protected debug interfaces. Never use one shared application password across a fleet.
Segment devices from public inbound access where the application allows it. A private Access Point Name (APN), virtual private network (VPN), Internet Protocol allowlist or private routing arrangement can narrow exposure, but each requires resilient routing and operational ownership. Monitor unusual destinations, repeated authentication failures and data spikes. Define vulnerability intake, patch timelines, key revocation and secure decommissioning. For regulated environments, map controls to the applicable law and organizational policy rather than assuming cellular connectivity supplies compliance.
What deployment risks should teams plan for?
- Late radio decisions. antenna or band changes force redesign
- Certification gaps. approval in one market is assumed elsewhere
- Supply discontinuity. modem, eUICC or profile dependencies change
- Provisioning failure. factory identity and subscription records diverge
- Lifecycle mismatch. connectivity and security support end before product use
Run a pilot that represents geography, enclosure, firmware, operators and installation methods. Record acceptance criteria before the pilot starts and retain failure evidence rather than swapping hardware without diagnosis. Test loss of coverage, rejected registration, exhausted allowance, backend outage, certificate expiry, power interruption and interrupted firmware updates.
Operational ownership is another risk. Assign teams for subscription inventory, billing anomalies, carrier escalation, firmware, security response and device retirement. Keep International Mobile Equipment Identity (IMEI), integrated circuit card identifier (ICCID), eUICC identifier where applicable, hardware revision and installed asset records linked. A deployment is not complete until support staff can locate and safely suspend a missing or compromised unit.
How may Atomic Pulse support the deployment?
Atomic Pulse may support this use case with multi-network SIMs, eSIM and GSMA SGP.32 options where compatible, data pooling, and connectivity management through Atomic Mobile. Those capabilities can help teams provision subscriptions, inspect usage, apply controls and reduce operational fragmentation across a device estate.
The appropriate design depends on countries, operator availability, device certification, expected traffic and roaming rules. A deployment review should therefore use an actual device list, market list and measured usage profile; it should not assume every technology or network is available everywhere. Atomic Pulse supplies connectivity rather than owning radio networks. Mobile network operators operate the underlying networks.
GlobalIoT.com is an Atomic Mobile company. Connectivity solutions are provided through Atomic Pulse, the IoT connectivity offering from Atomic Mobile.
