Alternative & migration · Custom Software

IDEMIA Alternatives for Credential Issuance and eSIM Operations: The Certified Core and the Layer Above It

Custom Software Development workflow illustration for IDEMIA Alternatives for Credential Issuance and eSIM Operations.
The short answer

Keep the certified core. Physical credential production, biometric matching, and GSMA accredited eSIM provisioning are secured, audited, and certified for reasons you do not want to relearn the hard way. The workflow above them is where you are actually stuck: a custom orchestration and entitlement layer runs $60k to $150k in 12 to 20 weeks, and a full self service and exception platform runs $150k to $350k. Do not build if you are proposing to reproduce card personalisation, secure element provisioning, or biometric matching.

Why organisations start looking for an IDEMIA alternative

IDEMIA sits in two very different procurement conversations, and the frustration in each has a different shape. On the government side, a motor vehicle agency or identity programme is dealing with credential issuance: driver licences and identity cards, central production, biometrics, and increasingly mobile credentials. On the telecom side, an operator or a virtual network operator is dealing with SIM and eSIM lifecycle: profile production, remote provisioning, activation, and swaps.

In both cases the trigger is rarely the certified component failing. It is the workflow around it. A DMV cannot change an exception process without a change request because the vendor owns the issuance workflow as well as the card. An operator wants a device trade in journey that activates an eSIM in three taps, and discovers the constraint is the ordering and entitlement layer rather than the provisioning platform. Somebody then types the vendor's name plus alternative into a search bar, when the actual question is which parts of the stack they should own.

What IDEMIA genuinely does well

Start with what is genuinely difficult. Producing a secure physical credential means substrates, laser engraving, optically variable features, tamper evidence, a controlled production facility, and a supply chain that survives audit. Biometric matching at national scale is a specialist discipline with decades of research behind it. On the connectivity side, eSIM provisioning runs on infrastructure that must be certified under GSMA security accreditation, hold operator credentials, and interoperate with a device ecosystem that changes constantly.

IDEMIA, formed from the merger of Oberthur Technologies and Safran Identity and Security, operates across both of those worlds, which is unusual. If your requirement is a credential that must resist counterfeiting or a provisioning platform that must satisfy accreditation and device compatibility across dozens of manufacturers, that capability is the product and it is not reproducible with a development budget. Anyone telling you otherwise is selling you a very expensive lesson.

Where the surrounding stack actually strains

Certification is a strength and a constraint at the same time. Systems that must remain accredited change slowly and deliberately, which is correct for the secure core and frustrating when it governs the customer journey attached to it. Release cadence in a certified environment is not something a customer negotiates.

The second strain is the bundle. When issuance workflow, exception handling, appointment logic, and reprint rules ship with the credential contract, an agency ends up paying for a change request every time policy shifts. The same pattern appears in telecom, where activation journeys, dealer tooling, and entitlement rules travel with the provisioning platform and cannot easily be reshaped to match a new commercial offer. Third is per credential and per profile economics. Costs track volume, which is fine when volume is flat and uncomfortable when a mobile credential programme or an eSIM push succeeds faster than forecast. Fourth is integration burden into systems the vendor does not own: the agency's core registration and titling platform on one side, the operator's business and operations support stack on the other. Fifth is data portability, which in this domain means enrolment records, credential history, and profile state, all of which are regulated and none of which should ever be trapped in an undocumented format.

Your realistic options, competitors included

For government identity and credential issuance, Thales, Veridos, and Valid are the names that appear in most competitive procurements, and several jurisdictions split the contract, buying card production from one supplier and issuance software from another or from a systems integrator. That split is worth pricing even if you end up rejecting it, because it reveals how much of your cost is the card and how much is the workflow.

For eSIM and SIM lifecycle, Thales and Giesecke and Devrient are the established alternatives, with Kigen and Workz among the providers serving operators and device makers who want more flexible arrangements. Multi-vendor eSIM setups are increasingly normal. The interfaces are standardised by GSMA specifications precisely so operators are not locked to one provisioning vendor, which gives you more room to move here than in most enterprise software categories.

When staying is the right call

Stay if your credential or profile production is reliable, audited, and accepted, because those outcomes are the entire point and replacing a certified supplier consumes years. Stay if your volumes are modest, since certification and accreditation costs are fixed and small programmes get the best value by sharing a supplier's infrastructure. Stay if you are mid-contract on a programme with statutory deadlines, such as a mobile driver licence rollout or a network migration, because vendor changes and deadlines do not coexist happily. And stay if your complaint is about the customer journey, because you can fix that without touching the vendor at all.

When a custom layer pays back

Build the orchestration layer. For an agency that means the parts of issuance that encode your policy rather than the vendor's: eligibility checks, document verification workflow, appointment and queue management, exception and fraud review queues, reprint and correction handling, and a status service so a resident can find out where their credential is without calling. All of that sits above the production interface and none of it requires touching the secure core.

For an operator it means activation and entitlement orchestration: the ordering journey, device eligibility and compatibility rules, dealer and retail tooling, eSIM transfer and device change flows, self service swap and replacement, and the analytics that tell you where activations fail. The provisioning platform performs the profile operation; your layer decides who is allowed to ask for it, what happens when the device is unsupported, and how a failed activation gets recovered without a call centre. That decision logic is your commercial product, and it changes every quarter, which is exactly why it should not live inside a certified system on someone else's release cycle.

Migration reality in a regulated stack

If you are genuinely changing a certified supplier, plan in years and phases rather than months. Enrolment and credential records are regulated data with retention obligations, so export scope, format, and chain of custody need to be settled before anything else. Run production in parallel with a low volume segment first, verify credential acceptance in the field, and only then scale. In telecom, profile state is the equivalent sensitive asset, and any transition needs to preserve the ability to service subscribers whose profiles were issued under the previous arrangement.

If you are building a layer instead, the migration is much smaller but the discipline is the same. Define the interface to the certified system, build validation that fails loudly rather than silently, and run the new journey alongside the existing one for a subset of traffic. Retraining is significant for counter staff and dealer channels, and those groups need the new flow to be faster than the old one within the first week or they will route around it.

Plan the accreditation conversation early. Anything your layer touches near the certified core will be reviewed, and the questions are predictable: what data crosses the boundary, where it is stored, who can see it, and how access is logged. Teams that design for that from the first sprint pass review with minor findings. Teams that treat it as a launch task discover that a security review can add months to a project that was otherwise finished.

What each path costs

Credential and provisioning contracts are quoted per unit against committed volumes over multi-year terms, with production infrastructure, certification, and support built in. Those numbers are large because the underlying capability is capital intensive, and they are usually defensible. On the custom side, from Digital Heroes delivery experience: an orchestration layer covering eligibility, exception queues, status services, and dealer or counter tooling above an existing certified platform runs roughly $60k to $150k in 12 to 20 weeks. A fuller self service, entitlement, and analytics platform with several integrations runs roughly $150k to $350k. Card personalisation, secure element provisioning, and biometric matching are not on that menu at any budget.

The honest recommendation

Split the stack in your head before you split it in procurement. The certified core is a buy decision and will stay one. The policy layer, the customer journey, the exception handling, and the analytics are yours, and every quarter you leave them inside a vendor contract is a quarter you pay change request pricing for decisions that are properly your own. Change certified suppliers only when quality, cost against benchmark, or accreditation status genuinely justifies a multi-year programme. Otherwise, keep the core, take back the workflow, and get your bargaining position from the standardised interfaces that exist precisely so buyers are not trapped.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
  2. Retailers improving Core Web Vitals saw measurable gains: Vodafone improved LCP by 31% for 8% more sales, Lazada saw a 16.9% mobile conversion increase, and Cdiscount saw a 6% Black Friday revenue uplift. Source: web.dev (Google Chrome team) (2021) →
  3. SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
  4. In an RCT, the no-show rate was 23.5% for patients receiving a text-message reminder versus 38.1% for the control group - a 14.6 percentage-point reduction (p = 0.04). Source: Clinical Pediatrics / PubMed Central (Lin et al.) (2016) →
Olivia R. · Senior Product Designer · Sydney

Olivia is a senior product designer working on the software side of Digital Heroes: dashboards, admin tools, internal systems and the screens people use all day rather than once. She writes about designing for repeat use, where speed and clarity matter more than a striking first impression.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

What are the alternatives to IDEMIA for identity credentials?
Thales, Veridos, and Valid appear in most government credential procurements. Some jurisdictions split the contract, buying card production from one supplier and issuance workflow software from another or from an integrator. Pricing that split is worthwhile even if you reject it, because it shows how much of your cost is the credential and how much is the workflow.
What are the alternatives to IDEMIA for eSIM management?
Thales and Giesecke and Devrient are the established alternatives, with Kigen and Workz serving operators and device makers seeking more flexible arrangements. Because GSMA specifications standardise the interfaces, multi-vendor eSIM setups are common and operators generally have more switching freedom here than in typical enterprise software.
Can we build our own eSIM provisioning platform?
Realistically no. Remote provisioning infrastructure must hold GSMA security accreditation, manage operator credentials, and interoperate with a constantly changing device ecosystem. The sensible build is the layer above it: ordering journeys, device eligibility rules, entitlement decisions, dealer tooling, and activation recovery.
How much does a custom orchestration layer cost?
An orchestration layer covering eligibility, exception queues, status services, and counter or dealer tooling above an existing certified platform typically runs $60k to $150k. A fuller self service, entitlement, and analytics platform with several integrations runs $150k to $350k. Credential production and secure provisioning remain purchased capabilities.
Why is our credential issuance workflow so hard to change?
Usually because it was bought as part of the credential contract rather than separately, so every policy change becomes a vendor change request. Certified systems also change slowly by design, which is correct for the secure core and limiting when it governs eligibility rules and exception handling that belong to you.
Should a DMV separate card production from issuance software?
It is worth evaluating. Card production is capital intensive, security certified, and a genuine buy decision. Issuance workflow encodes state policy, changes with legislation, and benefits from being owned. Separating them adds integration responsibility but removes change request pricing on decisions that are properly the agency's.
What data must we be able to export from a credential system?
Enrolment records, credential issuance history and status, biometric references subject to legal constraints, and any exception or fraud review history. Specify the format and the chain of custody in the contract, because this is regulated data with long retention obligations and a vague export clause becomes a serious problem years later.
How long does it take to change a certified supplier?
Plan in years, not months, with phased rollout. Run production in parallel for a low volume segment, verify field acceptance of the credential or profile, then scale. Any programme with a statutory deadline, such as a mobile credential launch or a network migration, is the wrong moment to start a supplier change.
Where do custom builds fail in this domain?
When someone proposes reproducing the certified core. Card personalisation, secure element provisioning, and biometric matching are capital intensive, audited, and accredited, and a development budget does not substitute for that. Custom work succeeds above the interface, where the rules are yours and change frequently.
If an agency builds my software, who actually owns the code?
You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.
How do I work out whether custom software will pay for itself?
Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.
What does a $50,000 custom software budget actually buy?
One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
Why do agencies charge for a discovery phase instead of quoting for free?
Because an accurate quote requires real work: mapping your workflows, finding the edge cases, and writing a specification, which typically takes 1 to 3 weeks and costs $2,000 to $10,000 at Digital Heroes depending on system complexity. You leave discovery owning a written spec and a fixed price you can take to any vendor, so the money is not locked into one agency. Free estimates are guesses, and the guess usually becomes your budget overrun six months later.
How many people should be working on my software project?
Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.
Will custom software work with the tools we already use, like QuickBooks and Stripe?
Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?