|
시장보고서
상품코드
2119268
통신사업자용 IDaaS(Identity-as-a-Service) : 시장 점유율 분석, 업계 동향 및 통계, 성장 예측(2026-2031년)Telecom Identity-as-a-Service - Market Share Analysis, Industry Trends & Statistics, Growth Forecasts (2026 - 2031) |
||||||
Mordor Intelligence에 의하면, 통신사업자용 IDaaS(Identity-as-a-Service) 시장 규모는 2025년 21억 4,000만 달러로 평가되었습니다. 2026년 28억 4,000만 달러에서 2031년까지 68억 9,000만 달러로 확대되고 2026년부터 2031년까지 연평균 복합 성장률(CAGR)은 19.39%를 나타낼 전망입니다.

본 보고서는 구성 요소(솔루션 및 서비스), 배포 방식(클라우드, On-Premise, 하이브리드), 인증 방식(SMS 기반 일회용 비밀번호, 모바일 생체 인증 등), 최종 사용자(모바일 네트워크 사업자 등), 산업 분야(금융 서비스, 전자상거래·소매, 의료 등), 지역별로 분류되어 있습니다. 시장 전망은 금액(달러) 기준으로 제시되어 있습니다.
Cifas에 따르면, 2026년 상반기 불법 SIM 스왑 건수는 2025년 같은 기간에 비해 402% 증가했습니다. 이러한 증가는 단발성 피싱 공격이 아니라, 조직적이고 자동화된 SIM 번호 이전 기법이 널리 활용되고 있음을 시사합니다. SMS를 통한 일회용 비밀번호는 휴대전화 번호가 본래의 사용자와 연결되어 있다는 전제에 기반을 두고 있습니다. 그러나 사기꾼이 재할당되거나 번호 이동된 SIM 카드를 장악하게 되면 이 전제는 약화됩니다. 이러한 위험으로 인해 통신사업자용 IDaaS(Identity-as-a-Service) 시장에서 통신 사업자에 의한 소유권 확인이 은행, 소매업체, 디지털 플랫폼에 있어 더욱 중요해지고 있습니다. 또한 여전히 SMS를 주요 인증 수단으로 사용하는 조직의 경우, 계정 복구 시나 고액 거래 시 신원 확인이 더욱 중요해지고 있습니다.
규제로 인해 지식 기반 인증 정보에만 의존하지 않는 인증의 필요성이 높아지고 있습니다. 규정(EU) 2024/1183에 따라 모든 EU 회원국은 2026년 12월 6일까지 최소 1개의 유럽 디지털 ID 지갑을 제공해야 할 의무가 부과되었습니다. 이 프레임워크에서는 규제 대상 의존 당사자에게 해당 일정에 따라 해당 지갑을 수용할 의무도 규정하고 있습니다. 이러한 규정으로 인해 금융 기관, 통신 사업자 및 디지털 서비스 사업자에게 ID 프로세스를 현대화해야 할 명확한 이유가 생겼습니다. 통신사업자용 IDaaS(Identity-as-a-Service) 시장은 캐리어 신호가 지갑 기반 인증 및 기타 강력한 인증 기법을 보완함으로써 이러한 전환을 지원할 수 있습니다. 또한, 잉글랜드 국민건강서비스(NHS England)의 DAPB3051 표준에서는 2026년 12월 31일까지 디지털 헬스 ID 표준을 완전히 준수할 것을 요구하고 있어, 검증된 환자 접근 제어의 중요성이 더욱 강조되고 있습니다.
통신 사업자는 귀중한 가입자 데이터를 보유하고 있지만, 개인정보 보호 관련 법률에 따라 해당 데이터의 재사용에는 제한이 부과됩니다. Connect Europe은 유럽 데이터 보호 위원회(EDPB)의 지침에 대한 2025년 답변에서 현재의 e-프라이버시 프레임워크 하에서는 사업자가 트래픽 데이터나 위치 정보에 대해 GDPR(EU 개인정보보호규정)의 호환성 조항을 근거로 삼을 수 없다고 밝혔습니다. 이로 인해 중앙 집중형 ID 모델에서 행동 정보 및 위치 정보의 활용이 제한됩니다. 따라서 통신 사업자는 번호 일치나 SIM 스왑 플래그와 같은 미리 정의된 신호에 더 중점을 두어야 합니다. 이러한 신호는 유용하지만, 보다 광범위한 행동 위험 모델에 비해 맥락 정보가 부족하다는 한계가 있습니다. 통신사업자용 IDaaS(Identity-as-a-Service) 플랫폼이 네트워크 정보를 보다 폭넓게 활용하기 위해서는 동의 기반 접근 방식이나 개인정보 보호형 접근 방식의 활용을 확대해야 합니다.
2025년에는 솔루션이 매출의 71.23%를 차지하며 통신사업자용 IDaaS(Identity-as-a-Service) 시장의 최대 구성 요소가 되었습니다. 이 범주에는 전화번호 검증 API, SIM 스왑 감지, 디지털 ID API 및 사일런트 네트워크 인증 제품이 포함됩니다. 기업들은 통신 사업자와 개별적인 관계를 구축하지 않고도 통신사 기반 검증을 도입할 수 있기 때문에 이러한 사전 통합된 제품을 선택하는 경우가 많습니다. 패키지화된 솔루션은 API 액세스와 워크플로 제어가 결합되어 있어, 기존의 사기 방지 시스템이나 고객 액세스 시스템 내에 도입할 수 있습니다. GSMA Open Gateway의 표준화로 인해 기본적인 API 접근 방식의 차이는 점차 줄어들고 있습니다. 그 결과, 제공업체들은 네트워크 신호와 관련된 오케스트레이션, 리스크 스코어링, 동의 관리 및 보고 기능의 가치를 더욱 중요시하게 되었습니다.
서비스 시장은 2026년부터 2031년까지 연평균 성장률(CAGR) 21.61%로 확대될 것으로 예측됩니다. 이는 도입 지원, 통신 사업자와의 관계 관리, 규제 관련 자문, 그리고 지속적인 부정 행위 감시에 대한 수요 증가를 반영한 것입니다. 기업의 ID 환경에서는 여러 인증 방법이 결합되는 경우가 많아, 이에 따라 설계 및 설정 작업의 중요성이 커지고 있습니다. 이 서비스는 조직이 통신사로부터 받은 신호를 내부 부정 방지 대책, 고객 경험 요건 및 국가별 규정 준수 의무와 조화시키는 데 도움이 됩니다. AI 에이전트의 부상으로 인해 인간이 아닌 행위자에 대한 신뢰성 관리를 설계할 필요성도 대두되고 있습니다. Prove사는 2026년 4월, 통합된 환경 내에서 개인, 기업 및 AI 에이전트의 검증을 지원하는 ID 플랫폼을 출시했습니다. 구매자가 에이전트의 권한을 어떻게 검증하고 모니터링해야 할지 검토함에 따라, 이러한 요구 사항은 전문 서비스 수요를 뒷받침할 것입니다.
2025년에는 클라우드 배포가 매출의 82.36%를 차지했으며, 2031년까지 연평균 성장률(CAGR) 21.73%로 확대될 것으로 전망됩니다. 이 부문의 규모는 많은 구매자가 전용 인프라보다 소프트웨어를 통해 제공되는 ID 서비스를 선호하고 있음을 보여줍니다. 클라우드 시스템을 통해 기업은 현지 통신 사업자와의 연결을 관리할 필요 없이 API를 통해 검증 및 인증 기능을 활용할 수 있습니다. 또한 여러 국가와 고객 채널에 걸친 대량의 트랜잭션도 처리할 수 있습니다. 클라우드 네이티브 네트워크 기능과 디지털 고객 여정의 확산이 클라우드 기반 통신사업자용 IDaaS(Identity-as-a-Service) 시장 규모 확대를 주도하고 있습니다. ITU-T 권고안 M.3411은 통신 관리 네트워크 내의 ID 및 액세스 관리를 위한 표준 기반의 지침을 제공합니다. 이로 인해 분산 환경 전반에 걸친 통합 거버넌스의 필요성이 더욱 높아지고 있습니다.
On-Premise 및 하이브리드 배포는 엄격한 데이터 상주 요건, 보안 요건 또는 인프라 요건을 가진 사용자에게 계속해서 서비스를 제공합니다. 정부 기관, 일부 금융 기관 및 의료 기관은 규제 대상 데이터에 대해 로컬 관리를 유지할 수 있습니다. 하이브리드 설계는 5G 클라우드 네이티브 기능과 병행하여 구형 가상 네트워크 기능을 관리하는 통신 사업자에게도 관련성이 있습니다. 공통 ID 정책을 채택하면 레거시 시스템을 즉시 교체하지 않고도 두 환경을 모두 포괄할 수 있습니다. 이러한 설계는 현대화에 따른 업무에 미치는 영향을 완화할 수 있지만, 클라우드 우선 접근 방식에 비해 더 많은 통합 작업이 필요할 수 있습니다. 통신사업자용 IDaaS(Identity-as-a-Service) 시장에서는 업종별로 보안 및 규제 요구 사항이 다르기 때문에 이러한 선택지가 계속해서 포함되고 있습니다. 따라서 하이브리드 배포는 많은 사용자에게 보편적인 최종 형태라기보다는 전환의 경로에 가깝습니다.
북미는 대기업 구매자, 성숙한 모바일 네트워크, 그리고 높은 사기 위험에 힘입어 2025년 매출의 33.12%를 차지했습니다. 미국에서는 2025년 소비자 대상 사기 피해액이 159억 달러에 달하면서, 보다 강력한 고객 인증의 필요성이 더욱 대두되었습니다. 이 지역의 통신 사업자와 애그리게이터는 단일 엔터프라이즈 연결을 통해 통합 가능한 네트워크 API 서비스를 구축하고 있습니다. 이를 통해 은행, 전자상거래 기업, 디지털 플랫폼이 전화번호 검증 및 SIM 스왑 감지를 보다 쉽게 수행할 수 있게 됩니다. 북미가 매출액에서 1위를 차지한 배경에는 클라우드 소프트웨어 및 통신 사업자의 폭넓은 기반이 반영되어 있습니다. 캐나다와 멕시코에서는 금융 서비스 및 정부 주도의 디지털 ID 이니셔티브를 통해 관련 이용 사례가 개발되고 있습니다.
디지털 ID 및 개인정보 보호 관련 규제의 도입은 유럽에 큰 영향을 미치고 있습니다. 유럽의 디지털 ID 프레임워크에서는 회원국들에게 2026년 12월까지 최소 한 가지의 디지털 지갑을 제공하도록 의무화하고 있습니다. 이에 따라 금융 기관, 통신 사업자, 온라인 서비스 사업자들은 인증 인프라를 공통된 ID 요건에 부합하도록 조정해야 합니다. 영국의 통신 사업자들은 2025년 9월 GSMA Open Gateway를 통해 KYC 연령 확인 및 KYC 이용 기간 확인 API 제공을 시작했습니다. Infobip은 2025년에 SIM 스왑 및 번호 검증 API에 대해 GSMA Open Gateway 인증을 획득하여 통신 사업자 네트워크 간의 상호 운용성을 지원하고 있습니다. 이 지역의 개인정보 보호 규제로 인해 통합된 가입자 데이터의 이용이 제한될 가능성이 있으므로, 동의 및 규정 준수를 고려한 설계는 여전히 공급자의 전략에서 핵심적인 위치를 차지하고 있습니다.
아시아태평양은 2026년부터 2031년까지 연평균 성장률(CAGR) 21.71%로 확대될 것으로 예상되며, 이는 지역별 부문 중 가장 높은 성장률입니다. 이 지역은 모바일 우선의 거대한 인구, 디지털 서비스 이용 확대, 그리고 활발한 규제 정비가 맞물려 성장을 이루고 있습니다. 인도와 아랍에미리트(UAE)에서는 금융 서비스 분야에서 보다 강력한 인증 수단의 필요성을 높이는 요건이 도입되었습니다. 아시아태평양의 통신사업자용 IDaaS(Identity-as-a-Service) 시장 규모는 대용량 디지털 플랫폼을 지원할 수 있는 네트워크 API의 도입에 힘입어 성장하고 있습니다. 남미는 신흥 수요 지역으로, 특히 네트워크 API가 이미 대량의 트랜잭션을 처리하고 있는 지역에서 수요가 증가하고 있습니다. 아프리카와 중동은 높은 모바일 보급률과 각국의 디지털 ID 프로그램 덕분에 장기적인 잠재력이 큰 지역입니다. 이 지역에서는 제공업체가 ID 서비스를 현지 통신 사업자의 서비스 지역, 동의 관련 규정 및 기업의 기술 예산에 맞추어 조정함으로써 혜택을 얻을 수 있습니다.
According to Mordor Intelligence, the telecom identity-as-a-Service market size is projected to expand from USD 2.14 billion in 2025 and USD 2.84 billion in 2026 to USD 6.89 billion by 2031, registering a CAGR of 19.39% between 2026 to 2031.

This report is Segmented by Component (Solutions, and Services), Deployment (Cloud, On-Premise, and Hybrid), Authentication Type (SMS-Based One-Time Password, Mobile Biometrics, and More), End User (Mobile Network Operators, and More), Industry Vertical (Financial Services, E-Commerce and Retail, Healthcare, and More), and Geography. The Market Forecasts are Provided in Terms of Value (USD).
Unauthorized SIM-swap cases rose 402% in the first half of 2026 compared with the same period in 2025, according to Cifas. The increase points to the wider use of organized, automated SIM-porting methods rather than isolated phishing attempts. SMS one-time passwords depend on the assumption that a mobile number remains tied to the intended user. That assumption weakens when a fraudster can obtain control of a reassigned or ported SIM. This exposure is making carrier-verified possession checks more relevant to banks, retailers, and digital platforms in the Telecom Identity-as-a-Service Market. It also makes verification at account recovery and high-value transactions more important for organizations that still use SMS as their primary authentication step.
Regulation is increasing the need for authentication that does not rely solely on knowledge-based credentials. Regulation (EU) 2024/1183 required every EU member state to provide at least 1 European Digital Identity Wallet by December 6, 2026. The framework also establishes obligations for regulated relying parties to accept the wallet within its implementation timetable. These rules give financial institutions, telecommunications providers, and digital services a clearer reason to modernize identity flows. The Telecom Identity-as-a-Service Market can support this transition when carrier signals complement wallet-based or other strong authentication methods. NHS England's DAPB3051 standard also required full conformance with digital health identity standards by December 31, 2026, reinforcing the importance of verified patient access controls.
Telecom operators hold valuable subscriber data, but privacy law limits how that data can be reused. Connect Europe stated in its 2025 response to European Data Protection Board guidance that operators could not rely on the GDPR's compatibility provisions for traffic and location data under the current ePrivacy framework. This restricts the use of behavioral and location information in centralized identity models. Providers must therefore rely more heavily on defined signals such as a number match or a SIM-swap flag. Such signals can be useful, but they offer less context than a broader behavioral risk model. The Telecom Identity-as-a-Service Market must expand its use of consent-based and privacy-preserving approaches if it is to use network information more broadly.
Other drivers and restraints analyzed in the detailed report include:
For complete list of drivers and restraints, kindly check the Table Of Contents.
Solutions held 71.23% of revenue in 2025, making them the largest component of the Telecom Identity-as-a-Service Market. This category includes number-verification APIs, SIM-swap detection, digital-identity APIs, and silent network authentication products. Enterprises often choose these pre-integrated products because they can introduce carrier-based checks without building individual relationships with operators. A packaged solution also combines API access with workflow controls that can be deployed within existing fraud and customer-access systems. GSMA Open Gateway standardization is narrowing differences in basic API access. As a result, providers are placing greater value on orchestration, risk scoring, consent management, and reporting capabilities related to the network signal.
Services are projected to expand at a 21.61% CAGR from 2026 to 2031. This reflects growing demand for implementation support, carrier relationship management, regulatory advice, and continuous fraud monitoring. Enterprise identity environments often combine several authentication methods, which raises the importance of design and configuration work. Services can help organizations align carrier signals with internal fraud controls, customer-experience requirements, and country-specific compliance obligations. The rise of AI agents also creates a need to design trust controls for nonhuman actors. Prove launched its identity platform in April 2026 to support verification of people, businesses, and AI agents within a unified environment. This requirement can support professional services as buyers test how agent permissions should be verified and monitored.
Cloud deployment accounted for 82.36% of revenue in 2025 and is projected to expand at a 21.73% CAGR through 2031. The segment's scale indicates that many buyers prefer software-delivered identity services over dedicated infrastructure. Cloud systems allow enterprises to invoke verification and authentication functions via APIs without managing local carrier connections. They can also support high transaction volumes across several countries and customer channels. The wider adoption of cloud-native network functions and digital customer journeys drives the Telecom Identity-as-a-Service Market size for cloud delivery. ITU-T Recommendation M.3411 provides a standards-based reference for identity and access management in telecom management networks. This strengthens the case for centralized governance across distributed environments.
On-premise and hybrid deployments continue to serve users with strict data residency, security, or infrastructure requirements. Government agencies, certain financial institutions, and healthcare organizations may retain local controls for regulated data. Hybrid designs are also relevant to operators that manage older virtual network functions alongside 5G cloud-native functions. A common identity policy can cover both environments without requiring immediate replacement of legacy systems. These designs can reduce disruption during modernization, but they may require more integration work than a cloud-first approach. The Telecom Identity-as-a-Service Market continues to include these options because security and regulatory needs are not uniform across verticals. Hybrid deployment is therefore a transition path for many users rather than a universal end state.
North America held 33.12% of revenue in 2025, supported by large enterprise buyers, mature mobile networks, and high fraud exposure. The United States recorded USD 15.9 billion in consumer fraud losses in 2025, which reinforced the need for stronger customer authentication. The region's operators and aggregators are establishing network API services that can be integrated through a single enterprise connection. This makes number verification and SIM-swap detection more accessible to banks, e-commerce firms, and digital platforms. North American revenue leadership also reflects a broad base of cloud software and communications providers. Canada and Mexico are developing related use cases through financial services and government digital identity initiatives.
The implementation of digital identity and privacy rules strongly influences Europe. The European Digital Identity framework requires member states to offer at least 1 wallet by December 2026. This encourages financial institutions, operators, and online services to align authentication infrastructure with common identity requirements. United Kingdom operators launched KYC age-verification and KYC tenure APIs under GSMA Open Gateway in September 2025. Infobip received GSMA Open Gateway certifications for SIM Swap and Number Verification APIs in 2025, supporting interoperability across operator networks. The region's privacy restrictions can limit the use of centralized subscriber data, so consent and compliance design remain central to provider strategy.
Asia-Pacific is projected to expand at a 21.71% CAGR from 2026 to 2031, the fastest rate across geographic segments. The region combines large mobile-first populations, rising use of digital services, and active regulatory development. India and the United Arab Emirates introduced requirements that increase the need for stronger forms of authentication in financial services. The Telecom Identity-as-a-Service Market size in Asia-Pacific is also supported by network API deployments that can serve high-volume digital platforms. South America is an emerging demand area, particularly where network APIs are already processing high transaction volumes. Africa and the Middle East have strong long-term potential because of high mobile usage and national digital identity programs. These regions can benefit when providers adapt identity services to local operator coverage, consent rules, and enterprise technology budgets.