Frameworks
Stay connected, stay compliant with RVIT
Telecom networks exposed to security gaps invite regulatory sanctions and put critical services at risk.
Tidal secures your telecom infrastructure. Implement sector-specific controls, manage incidents systematically, and exceed RDI expectations with proven compliance.

RVIT in depth
RVIT stands for Regeling veiligheid en integriteit telecommunicatie, a ministerial regulation based on article 11a.1 of the Dutch Telecommunications Act and the Besluit veiligheid en integriteit telecommunicatie. It sets out 19 organisational and technical security measures for network providers: providers of a public mobile electronic communications network that hold licences for harmonised radio spectrum awarded by auction.
In practice RVIT is often treated as another generic security checklist. That underestimates it, because the measures are prescriptive, they reach into network architecture and supplier contracts, and an exemption has to be requested from the Minister of Economic Affairs per implementation requirement.
By treating RVIT as a baseline rather than a one-off project, clarity emerges. Every measure has an owner, an implementation status, and evidence behind it, so you can show the RDI what is in place and why.
How Tidal helps you get certified
Hit the ground running
Start with our pre-built controls, policies, and risk assessment templates.
Our platform guides you through establishing your ISMS scope, identifying assets, and implementing right-sized controls that match your business needs.


Why Tidal Control
We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.
Made in Europe
Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.
Continuous automation
Automated evidence collection from cloud providers and development tools working 24/7 for you.
Real security
Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.
Go beyond RVIT
Explore complementary frameworks that strengthen your telecom security strategy.
ISO 27001
Building foundational telecom security? ISO 27001 provides security controls that support RVIT compliance for telecommunications providers.
NIS2
Meeting broader essential services requirements? NIS2 complements RVIT by applying to telecommunications as critical infrastructure across the EU.
DORA
Securing telecom-dependent financial services? DORA requirements extend to telecom providers supporting financial institutions.
CIS Controls
Implementing practical telecom security controls? CIS Controls provide prioritised security measures that enhance RVIT compliance.
Integrate with your existing tools

Testimonials
What our customers say
With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.
Frequently asked questions
RVIT (Regeling veiligheid en integriteit telecommunicatie) is a Dutch ministerial regulation that sets 19 organisational and technical security measures under article 11a.1 of the Telecommunications Act. It applies to network providers: providers of a public mobile electronic communications network that hold licences for harmonised radio spectrum awarded by auction. Those measures had to be implemented by 1 October 2022.
RVIT is sector-specific regulation for telecommunications in the Netherlands, whilst NIS2 applies more broadly to essential and important entities. Many telecom providers need to comply with both. Our platform helps you address overlapping requirements efficiently.
RVIT groups its measures into five domains: secure configuration of technical equipment, secure network configuration, monitoring of the infrastructure, security assurance on software and services from suppliers, and personnel security. Concrete requirements include network segmentation, timely deployment of critical security patches, isolated management workstations, encryption of critical data in transit, near real-time incident detection, independent security evaluation of software before it goes into production, and screening of third-party personnel. Our platform guides you through all required measures systematically.
Our platform helps you establish the detection and response processes RVIT requires, including near real-time detection of security incidents and retention of historical data for investigating advanced threats. We support incident documentation and help you prepare the notifications the Telecommunications Act requires towards the RDI and, where applicable, affected subscribers.
No. RVIT is aimed at network providers that hold auctioned licences for harmonised radio spectrum, so an MVNO without its own spectrum falls outside its scope. MVNOs do remain subject to the general duty of care in article 11a.1 of the Telecommunications Act and, depending on their size and role, to NIS2. Our platform helps you implement proportionate controls appropriate to your role.
We actively monitor changes to RVIT and telecommunications security guidance from the RDI and the Ministry of Economic Affairs. Our controls and frameworks are regularly updated to reflect new requirements, ensuring your compliance remains current.


























