Configuration compliance for service providers
Hold a national, multi-vendor estate to one policy standard, and prove it to auditors continuously, not reconstructed at audit time.
CORE current corechecked every passEDGE inherited edgechecked every passACQUIRED next acquisitionchecked every pass
A service-provider estate, held to one policy standard and proven continuously, not reconstructed at audit time.
- 100%of collected configs policy-checked
every device, every collection
- 24/7continuous checking
on change, not at audit time
- 1estate-wide policy standard
across every region and vendor
- 0silent changes
every change captured and attributed
Figures describe how rConfig operates; deployment-specific results are published with customer permission.
Prove it continuously, not at audit time
For a service provider, compliance is a permanent state the network has to hold and the business has to prove. A national, multi-vendor estate drifts constantly: thousands of changes a week, dozens of engineers, and regulators who expect one consistent standard across all of it.
The expensive failure mode is audit-time archaeology: reconstructing months of change to answer a question that should already have an answer. rConfig inverts that, measuring every config against policy as it is collected, so the evidence exists before anyone asks for it, proven at the scale of a Tier 1 ISP estate.
- A policy result for every config, every collection
- Drift events, timestamped and diffed
- Change attribution: who, what, where, when
- An exportable evidence trail for the regulator
Continuous compliance
The controls a carrier has to demonstrate, running automatically across the whole estate rather than a sampled subset at audit time, the same estate covered in managing 100,000 network devices.
Continuous policy checks
Every collected config is checked against policy on every collection, not sampled once a quarter. CIS benchmarks, regulatory controls, and your own internal standards run as code against the whole estate.
Drift detection on change
A config that moves out of policy is flagged the moment it changes, with the exact diff and the line that broke compliance. Silent drift stops being something you discover during an audit.
RBAC and segregation of duties
Role-scoped access, change approval, and separation of duties, the controls auditors look for first. Who can see, who can change, and who signs off are enforced, not documented in a policy nobody reads.
Full, exportable audit trail
Who changed what, where, and when, captured for every device and every change. Evidence is already assembled when the auditor asks, instead of reconstructed from memory and scattered logs.
Remediation and rollback
When a config breaks policy, push the fix or roll back to the last compliant version in a controlled change, with the action captured for the audit trail. Drift gets closed, not just logged.
Read-only AI that explains findings
Read-only, grounded AI helps triage and explain compliance findings in plain language, so an engineer understands why a config failed faster. Assistive today, never an unattended change to production.
Compliance across every vendor
A standard that only holds on one vendor's kit is not a standard. A service-provider estate is multi-vendor by necessity, and compliance has to span all of it: the current core, the inherited edge, and whatever the next acquisition brings in. Because rConfig sells no network hardware, its neutrality is structural, and policy checks, drift detection, and audit run the same way across every platform. See multi-vendor configuration management for how that neutrality is built.
The regimes your network is in scope for
A service provider's network configuration sits inside sector-specific security regulation. rConfig does not make you compliant; it produces the continuous configuration control and evidence those regimes require, mapped to the standard you are held to.
United Kingdom
The Telecommunications (Security) Act 2021 places overarching security duties on public telecoms providers, with specific measures in the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice, overseen by Ofcom. They cover network architecture, access control, monitoring, and remediation, all of which turn on configuration, and the evidence they expect is what rConfig captures on every collection.
European Union
NIS2 brings electronic-communications and other essential-service operators under stronger network and information security obligations, with configuration security, change control, and incident readiness among them. See NIS2 compliance.
United States
US carriers map configuration and security posture to NIST: the Cybersecurity Framework (CSF 2.0) for governance, and the NIST SP 800-53 Configuration Management controls for baselines, change control, and component inventory, alongside the FCC's CSRIC best practices and CISA's cross-sector Cybersecurity Performance Goals for the communications sector.
Make compliance the network's default state
See rConfig prove continuous compliance against a multi-vendor, service-provider estate. Book a working demo, or talk to our team about your audit obligations.