Status 01 is the most common security rejection mid-campaign. The card recomputed the cryptographic checksum or redundancy check and got a different value. In mixed estates the operational cause is often inventory drift — MSISDN and IMSI no longer match the key the server used. The other frequent cause is the checksum byte range: for SMS-PP, whether CPI, CPL and CHL are included is implementation-dependent, so a server that includes the wrong prefix produces packets every card rejects identically.
Usual cause
The card recomputed the cryptographic checksum or redundancy check and got a different value. Either the key is wrong, or the checksum was computed over the wrong byte range. In live estates a frequent operational cause is the wrong key for that subscriber: MSISDN and IMSI in inventory no longer match. The other common cause is the checksum byte range: whether CPI, CPL and CHL are included in the CC calculation is implementation-dependent for SMS, so a server that includes the wrong prefix produces a valid-looking packet that every card rejects.
What to do
If inventory is stale, update the MSISDN–IMSI mapping and try again. Also confirm the KID key value and key version, the algorithm and checksum length on the card, and the byte range: for SMS-PP, compute over CPL onward and compare against a known-good packet from the card vendor.
TS 102 225 §5.1.3, table 2 note 2 and note 3