RCS End-to-End Encryption on iPhone: What Brands Should Know
iOS 26.5 adds end-to-end encrypted RCS on iPhone. The lock marks a personal chat. RCS for Business uses a different security model.

On May 11, 2026, Apple started rolling out RCS end-to-end encryption in beta. iPhone users on iOS 26.5 see a lock in a personal RCS chat when their carrier, and the other person’s carrier, both support it. That lock marks a person-to-person conversation. Google’s RCS for Business security docs, updated May 14, 2026, say the business product does not offer end-to-end encryption. It is also a different product from Apple Messages for Business.
Apple’s newsroom note describes chats between an iPhone on iOS 26.5 and an Android phone on the latest Google Messages. Brands sending verified business messages need a separate security story, and a separate channel decision.
What iOS 26.5 Changed
Apple and Google led the cross-industry work to add end-to-end encryption to RCS, the carrier standard that carries texts, high-resolution media, read receipts, and typing indicators when a conversation is not iMessage. Apple says encryption is on by default and turns on over time for new and existing RCS conversations on supported carriers. When a chat is encrypted, the messages cannot be read while they travel between the devices.
iMessage has its own end-to-end encryption, and Apple’s newsroom still points people to iMessage for conversations between Apple devices. RCS on iPhone shows up in green bubbles. A lock on a green bubble is new. It does not turn that thread into iMessage, and it does not turn it into a branded business conversation.
The GSMA, which publishes the RCS Universal Profile, marked the same day. Chief technology officer Alex Sinclair described the rollout as encrypted chats between iOS 26.5 and current Google Messages, and encouraged operators to enable more secure RCS for personal and business users. That encouragement is aimed at mobile networks. Google’s business-messaging product has its own documentation, and that documentation still says the product is not end-to-end encrypted.
- iOS 18
RCS arrives on iPhone
Apple’s support docs require iOS 18 and a carrier that supports RCS on iPhone. Messages use green bubbles and include richer media than SMS.
- May 11, 2026
iOS 26.5 encryption beta
Apple begins rolling out end-to-end encrypted RCS for personal chats on supported carriers. The GSMA announces the same day.
- May 14, 2026
Google restates the business model
Google’s RCS for Business data-security page says RBM does not offer end-to-end encryption and will not show a lock icon.
- September 15, 2026
Apple’s carrier page
The US and Canada carrier-support page lists end-to-end encrypted RCS (beta) as its own feature, separate from plain RCS messaging.
When the Encrypted Label Appears
Apple’s article on the difference between iMessage, RCS, and SMS/MMS, published May 11, 2026, sets the conditions. The iPhone needs iOS 26.5. The carrier has to support end-to-end encryption for RCS. Every participant’s carrier has to support it too. When that lines up, the conversation shows “Encrypted” and a lock at the top.
If the indicator is missing, Apple says those RCS messages are not protected from a third party reading them while they are sent between devices. One side of the chat can be on AT&T, T-Mobile, or Verizon and still see no lock, because the other person’s carrier has not enabled the feature.
People manage this in Settings → Apps → Messages → RCS Messaging. Apple’s setup guide says End-to-End Encryption (Beta) is on by default. Basic RCS still needs iOS 18 and a supporting plan. Carrier fees can apply. If the RCS Messaging row never appears, the carrier has not turned RCS on for that iPhone.
Which Carriers Apple Lists
The live list is Apple’s wireless carrier support page for the United States and Canada, updated September 15, 2026. On that page, end-to-end encrypted RCS messaging (beta) is listed for AT&T, T-Mobile, and Verizon, and for many other US brands, including Boost Mobile, Cricket, Metro by T-Mobile, Mint Mobile, US Cellular, Visible, Xfinity Mobile, and Spectrum. In Canada the same feature is listed for Bell, Rogers, and Telus, and for brands such as Fido, Koodo, Freedom Mobile, and Virgin Mobile.
RCS and encrypted RCS are separate lines. H2O Wireless and Total Wireless list RCS messaging on that page and do not list the encryption feature. Tbaytel in Canada lists RCS messaging the same way. A customer on one of those networks can exchange RCS texts and still have no lock.
Use Apple’s page for the market you actually message, including Europe and Asia-Pacific, before a privacy FAQ names a carrier. The rows move with carrier launches. A May 2026 news recap will already be incomplete.
RCS Business Messages Are a Separate Switch
On that same RCS screen, Apple includes RCS Business Messages. The support article says some businesses can send alerts and updates about orders and other transactions through RCS, and that people can turn those messages off. They can also tap Report Junk, then delete the thread.
That switch is the business-message control. The encryption toggle is the personal-chat control. Turning one on does not describe how a brand is verified, what a message costs, or whether an agent can read the thread. For the product definition, see What Is RCS Business Messaging? For the iPhone channel choice, see Apple Messages for Business vs RCS Business Messaging.
RCS for Business Is Not End-to-End Encrypted
No, RBM doesn't offer end-to-end encryption. This is why you won't see a lock icon displayed within the Messages UI for RBM conversations.
GoogleData security for RCS for Business, updated May 14, 2026
Google’s page explains the model it does use. Messages are encrypted between the phone and Google’s servers, and between Google and the messaging partner, through the RCS Business Messaging API. Google holds the keys. Those keys let Google’s systems inspect traffic for policy compliance, including spam, phishing, and malware links. A business cannot take control of the keys.
A few operational details matter if legal or security is reviewing a rollout. Google says it may process the content of messages a business sends, to detect abuse, and that it does not have access to the contents of messages users send to the business unless the user reports the thread as spam. To open the conversation, Google shares the customer’s phone number with the business and no other personal information. Undelivered business messages can sit on Google’s servers for up to 30 days. RBM is not HIPAA compliant, and messages that contain protected health information are out of scope. An OTP sent over RBM can count as a “possession” factor for EU PSD2 strong customer authentication, because it is tied to a verified number and SIM. That is a regulatory property of the channel. It is not end-to-end encryption.
Google’s RCS for Business FAQ draws the product line in plain language. RCS is the messaging standard on Android and on iOS where carriers support it. RCS for Business is the branded product for marketing, transactions, authentication, and customer support. Brands send it through a partner or aggregator. Features include a verified sender profile, rich cards, carousels, and suggested replies. International delivery depends on the carrier and on local rules. If RCS cannot deliver, Google’s product marketing says the message falls back to SMS or MMS.
If a vendor slide says “RCS is now end-to-end encrypted, including campaigns,” ask which product they mean. Personal RCS on iOS 26.5 and RCS for Business do not share that control. The GSMA’s note to operators about business users does not override Google’s own answer.
How the Three Channels Differ
Personal RCS, RCS for Business, and Apple Messages for Business
| Question | Personal RCS | RCS for Business | Apple Messages for Business |
|---|---|---|---|
| Who the chat is between | People, in the Messages app | A verified brand agent and a customer | A registered brand and a customer, through an MSP |
| End-to-end encryption | Yes, on iOS 26.5 when every carrier supports it | No. Google documents point-to-point encryption | The MSP and live agents read the thread in order to reply |
| Lock icon | “Encrypted” plus a lock, when active | Google says there is no lock icon | Apple does not describe this channel with the RCS lock |
| How a brand participates | It doesn’t. This is person-to-person | Through a messaging partner and carrier launch | Through an Apple-approved MSP and Experience Review |
| Customer control | RCS and the encryption beta can be turned off | RCS Business Messages can be turned off; junk can be reported | Customers open the chat from an approved entry point |
Where Apple Messages for Business Fits
Apple Messages for Business is Apple’s business channel inside Messages. A customer reaches a brand that has registered with Apple. An Apple-approved Messaging Service Provider runs the software, the automation, and the live agents. Apple’s FAQ says deployments need a path to a human, and that bots have to connect through an approved MSP rather than a direct integration. The MSP directory lists providers that operate that program. The brands directory shows companies already using the channel.
That model assumes the provider can read the conversation. A support agent, a payment request, and an order lookup all require it. A lock-icon personal RCS chat is the other arrangement: Apple says those messages cannot be read in transit between the two devices. A service team cannot staff a thread it cannot read.
Treat the May 2026 encryption launch as a change in what customers see on green-bubble chats with friends. Treat RCS for Business as the carrier business channel, with verified branding and SMS fallback, under Google’s point-to-point model. Treat Apple Messages for Business as the reviewed path for customer-initiated service on Apple devices, including Apple Pay in the thread and entry points such as Safari, Maps, and QR codes. Privacy copy for that program should follow Apple’s PII rules for Messages for Business, not the wording of the iOS 26.5 lock.
What to Do With the Rollout
Check Apple’s carrier page for every market you care about before anyone writes “encrypted on iPhone” into a help center. Encryption is per carrier, and every participant’s carrier has to support it.
Split the language in policies, sales decks, and security reviews. “RCS end-to-end encryption” means personal chats on iOS 26.5 with supporting carriers. RCS for Business is the product Google says has no lock icon. Using one phrase for both will fail a questionnaire.
If an agent has to see the message — an order update, a payment, a sign-in handoff — choose a business channel on purpose. RCS for Business runs through a messaging partner. Apple Messages for Business runs through an approved MSP, from registration to Experience Review. A2P 10DLC remains the US carrier path for business SMS on 10-digit numbers where RCS is unavailable.
Expect some customers to hide business RCS. Apple gives them an off switch and a junk report on the same screen as the encryption control. A program that assumes every iPhone will accept branded RCS will over-count reach.
Keep the fallback honest. Google’s RCS for Business materials describe SMS/MMS fallback when RCS cannot deliver. Apple Messages for Business reaches people in Messages on Apple devices. It does not cover an Android inbox. Most brands that want both still run more than one channel, with one team reading the threads.
Sources
End-to-end encrypted RCS messaging begins rolling out today in beta — Apple Newsroom, May 11, 2026.
What is the difference between iMessage, RCS, and SMS/MMS? — Apple Support, published May 11, 2026.
Turn on RCS messaging on your iPhone — Apple Support, including RCS Business Messages and the encryption toggle, published May 11, 2026.
Wireless carrier support and features for iPhone in the United States and Canada — Apple Support, published September 15, 2026.
iOS 26.5 brings E2EE for RCS — GSMA Newsroom, May 11, 2026.
Data security for RCS for Business — Google for Developers, last updated May 14, 2026.
RCS for Business FAQ — Google.
RCS end-to-end encryption FAQ
Is RCS end-to-end encrypted on iPhone?
Personal RCS can be. Starting with iOS 26.5, Apple rolls out end-to-end encrypted RCS in beta when the iPhone’s carrier supports it and every other participant’s carrier supports it too. The chat then shows “Encrypted” and a lock. If the lock is missing, Apple says the messages are not protected from a third party reading them in transit.
Does RCS for Business have end-to-end encryption?
No. Google’s data-security page for RCS for Business, updated May 14, 2026, says RBM does not offer end-to-end encryption and will not show a lock icon. Messages are encrypted in transit between the phone and Google, and between Google and the messaging partner. Google holds the keys so it can scan for spam and abuse.
Which US carriers support encrypted RCS on iPhone?
Apple’s US and Canada carrier page, published September 15, 2026, lists end-to-end encrypted RCS messaging (beta) for AT&T, T-Mobile, and Verizon, plus many other brands including Boost Mobile, Cricket, Metro by T-Mobile, Mint Mobile, US Cellular, Visible, Xfinity Mobile, and Spectrum. Some carriers list RCS messaging without the encryption feature, including H2O Wireless and Total Wireless. Check Apple’s page for the current row.
Is Apple Messages for Business the same as encrypted RCS?
No. Apple Messages for Business is Apple’s registered business channel inside Messages, operated through an Apple-approved Messaging Service Provider, with a required path to a live agent. The iOS 26.5 lock applies to personal RCS chats between people. A business thread has to be readable by the provider and the agents who reply.
Can customers turn off business RCS messages?
Yes. Apple’s RCS settings include a separate RCS Business Messages switch. Apple says some businesses send alerts and order updates through RCS, and that people can turn those messages off or report a conversation as junk.