This application describes techniques for postponed
certificate credential installation to
wireless devices, including generation and storage of secured scripts to be used for subsequent
certificate credential installation on an eUICC of a
wireless device after manufacturing. Management of
certificate credentials, including installation on, modification to, and removal from, an eUICC can occur post-manufacturing, such as during a device activation procedure or as part of remote electronic
subscriber identity module (eSIM) provisioning to the eUICC of the
wireless device. Updating certificate credentials on an eUICC can allow for wireless device operation in different
geographic regions that use different public key infrastructures (PKIs) with distinct
root certificate issuers. The secured scripts can be pre-generated by an eUICC manufacturer (EUM) for the particular eUICC and stored at an OEM networked
server and later used to install the certificate credentials on the eUICC of the wireless device.