BSG utilizes HTTP cookies (and similar or complementary technologies) to 1) make this website safe, functional, and accessible (through the use of mandatory cookies) and 2) understand how you use our website (through the use of optional cookies) in order to improve your experience and to provide you with personalized content.

The information in the cookie text files may be related to your personal preferences or your device and is intended to make the site operate according to your expectations. The information contained in cookies does not usually identify your identity directly but is helpful in providing you with a more personalized user experience.

In accordance with the requirements of the General Data Protection Regulation (GDPR) privacy and security law that governs how the personal data of individuals in the EU may be processed and transferred, we provide you the possibility to prohibit the use of certain types of cookies when you use our website.

Read our Cookie Notice and the Privacy Policy for detailed information on how BGS collects and uses cookies. Please note that prohibiting the use of certain types of cookies may affect your interaction with the website and limit the accessibility of services we offer you. Choose the appropriate category below to learn more and to disable cookies.

Accept All cookies*
*Recommended for comfortable use of the site
Accept only necessary cookies
Accept only selected cookies
Necessary cookies
Social media
Analytics
Marketing

Messaging Layer Security (MLS)

What is Messaging Layer Security (MLS)?

Messaging Layer Security (MLS) is an IETF standard for encrypting group and one-to-one messaging that RCS Universal Profile 3.0 uses to deliver interoperable E2EE between iPhone and Android.

Messaging Layer Security (MLS) is an open encryption protocol standardised by the IETF (RFC 9420) for securing conversations between two or more devices, with efficient key management for group chats. The GSMA built MLS into RCS Universal Profile 3.0 so that encrypted RCS would work across vendors, instead of relying on Google's earlier Signal-based layer that only protected Android-to-Android chats. Apple adopted this profile in iOS 26.5 (May 2026), which is why RCS between iPhone and Android can now be E2EE — as long as both carriers in the conversation have upgraded to Universal Profile 3.0; otherwise the chat silently falls back to unencrypted RCS or SMS.

For business senders the practical point is what MLS does not cover. RCS for Business (A2P) traffic travels from the brand's RBM platform through the operator to the handset; the MLS session exists between end-user devices, not between a brand's API and a customer. A2P RCS is therefore encrypted in transit but not device-to-device, and it should be treated like any other operator channel for sensitive content such as OTP or account data.

Example: a bank can show a verified sender, rich card and read receipt on an EE iPhone in 2026, but the encryption lock icon customers see in personal chats does not apply to that campaign message.

Related terms

Related BSG products

Further reading

Interested in a special offer?

Ready to reach further?
Let’s talk

I agree to BSG privacy policy
Submit

Useful Materials

Apple RCS on iPhone: What Changes for Business Messaging in EU and UK

Apple RCS is live on iPhone. Which EU and UK carriers support it and how to plan campaigns with SMS fallback.

Sender ID Registration in the EU and UK: Why Your SMS Gets Filtered

Why unregistered senders get filtered in the EU and UK, and what each country requires for sender ID registration.

RCS in Brazil: Carriers, Coverage and What Works for Brands in 2026

Vivo, Claro and TIM coverage, iPhone status, where RCS beats SMS in Brazil and how to launch with SMS fallback.