Compliance

Configuration compliance for service providers

Hold a national, multi-vendor estate to one policy standard, and prove it to auditors continuously, not reconstructed at audit time.

multi-vendor estatecontinuous policy sweep
rConfigCOREcurrent coreEDGEinherited edgeACQUIREDnext acquisitionEVERY DEVICEEVERY PASSONE STANDARD
COMPLIANCE PROOF

A service-provider estate, held to one policy standard and proven continuously, not reconstructed at audit time.

  • 100%of collected configs policy-checked

    every device, every collection

  • 24/7continuous checking

    on change, not at audit time

  • 1estate-wide policy standard

    across every region and vendor

  • 0silent changes

    every change captured and attributed

Figures describe how rConfig operates; deployment-specific results are published with customer permission.

THE CHALLENGE

Prove it continuously, not at audit time

For a service provider, compliance is a permanent state the network has to hold and the business has to prove. A national, multi-vendor estate drifts constantly: thousands of changes a week, dozens of engineers, and regulators who expect one consistent standard across all of it.

The expensive failure mode is audit-time archaeology: reconstructing months of change to answer a question that should already have an answer. rConfig inverts that, measuring every config against policy as it is collected, so the evidence exists before anyone asks for it, proven at the scale of a Tier 1 ISP estate.

  • A policy result for every config, every collection
  • Drift events, timestamped and diffed
  • Change attribution: who, what, where, when
  • An exportable evidence trail for the regulator
HOW IT WORKS

Continuous compliance

The controls a carrier has to demonstrate, running automatically across the whole estate rather than a sampled subset at audit time, the same estate covered in managing 100,000 network devices.

INDEPENDENCE

Compliance across every vendor

A standard that only holds on one vendor's kit is not a standard. A service-provider estate is multi-vendor by necessity, and compliance has to span all of it: the current core, the inherited edge, and whatever the next acquisition brings in. Because rConfig sells no network hardware, its neutrality is structural, and policy checks, drift detection, and audit run the same way across every platform. See multi-vendor configuration management for how that neutrality is built.

FRAMEWORKS

The regimes your network is in scope for

A service provider's network configuration sits inside sector-specific security regulation. rConfig does not make you compliant; it produces the continuous configuration control and evidence those regimes require, mapped to the standard you are held to.

  1. United Kingdom

    The Telecommunications (Security) Act 2021 places overarching security duties on public telecoms providers, with specific measures in the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice, overseen by Ofcom. They cover network architecture, access control, monitoring, and remediation, all of which turn on configuration, and the evidence they expect is what rConfig captures on every collection.

  2. European Union

    NIS2 brings electronic-communications and other essential-service operators under stronger network and information security obligations, with configuration security, change control, and incident readiness among them. See NIS2 compliance.

  3. United States

    US carriers map configuration and security posture to NIST: the Cybersecurity Framework (CSF 2.0) for governance, and the NIST SP 800-53 Configuration Management controls for baselines, change control, and component inventory, alongside the FCC's CSRIC best practices and CISA's cross-sector Cybersecurity Performance Goals for the communications sector.

Make compliance the network's default state

See rConfig prove continuous compliance against a multi-vendor, service-provider estate. Book a working demo, or talk to our team about your audit obligations.