PrahiX

Network operations

How to evaluate NOC service providers.

Choosing a NOC (network operations centre) service provider is harder than the brochures make it look, because every proposal promises 24x7 monitoring, multi-vendor support and an SLA — words that describe operations which behave very differently at 3am. The separation shows up in a handful of questions: whether the SLA commits to restoring or merely to informing, what the provider may remediate without waking you, what an escalation actually contains, who owns the monitoring platform, and what leaving would take. This guide walks through those questions and ends with the full checklist.

First, which NOC we mean

In India the letters NOC usually mean a no-objection certificate — the document an RTO issues for a vehicle transfer, or the clearance a fire-safety consultant obtains for a building. This guide is about the other NOC: the network operations centre, the team and platform that watch an organisation's network and infrastructure around the clock. If you were searching for certificate services, this is not that page. The collision matters commercially too: searches for NOC providers in Indian cities surface fire consultants ahead of network operators, which is why the network kind is usually found under the fuller phrases — NOC as a Service, managed NOC, outsourced NOC.

Why provider lists don't settle it

Ranked lists of NOC providers are useful for building a longlist and useless for choosing, because they rank marketing reach rather than what happens when a core switch dies at 2am. Two providers can sit side by side on the same list while one runs genuine diagnosis and remediation and the other forwards alerts from a tool you could have licensed yourself. The only way to separate them is to put the same operational questions to every shortlisted provider and compare the answers in writing.

The SLA verb: restore, respond, or notify?

Read the SLA for the verb it commits to. Many network monitoring services are contractually complete once they have told you something is down — the clock stops at notification, and the fault is yours at whatever hour it lands. A response SLA keeps the clock running until a defined action has been taken; a restoration target goes further and commits to time-to-fix for defined fault classes. None of these is wrong to buy, but they are very different services sold under the same name, and the price should differ accordingly. If the commitment is to inform, the overnight shift you are paying for is a messenger.

Multi-vendor coverage, tested rather than claimed

Every provider claims multi-vendor support. The test is specific: hand over your actual device inventory — makes, models, firmware — and ask which devices are monitored natively, which need custom work, and which are visible only as up-or-down. Estates are never single-vendor, and a NOC that can only diagnose deeply on one manufacturer will quietly degrade to ping-monitoring on everything else.

  • Which of our exact device models are supported out of the box?
  • Is discovery agentless, and how long does mapping a new site take?
  • What telemetry is collected — SNMP, syslog, flow, API — per device class?
  • Are configuration changes and drift visible, or only availability?

What may the provider fix without asking?

Remediation authority is agreed, not assumed. A capable provider will ask, during onboarding, which corrective actions may run unattended — restarting a hung service, failing over a degraded link, clearing a saturated queue — which need approval, and which stay advisory, per action and per environment. Be wary of both extremes: a provider that wants no authority is planning to notify and step back, and one that wants blanket authority on day one has not thought about your change control. Ask to see the authority matrix from a live engagement, redacted, and ask how every automated run is recorded.

What does an escalation actually contain?

Ask for a sample escalation from a real incident. A good one arrives diagnosed: what failed, what was correlated and suppressed behind it, what was already tried, and a recommended next action with the vendor-specific detail attached. A poor one is a forwarded alert with a timestamp. The difference is the whole value of a NOC — an alert storm summarised into one diagnosed fault is exactly what you are paying for, and providers who do it well are proud to show the artefact.

Who owns the tooling — and the exit

In some engagements you license the NMS and the provider staffs it; in others the platform is the provider's and you subscribe to the outcome. Both models work, but they fail differently at exit. If the tooling is yours, you keep the monitoring history and the integrations but must re-staff the watch. If it is the provider's, ask before signing: what leaves with you — device inventory, baselines, incident history, runbooks — and in what format? An engagement you cannot leave without starting monitoring from zero has the lock-in priced in, whether or not it appears on the quote.

Co-managed: your engineers inside the loop

If you have network engineers you want to keep close to the estate — working on the provider's platform in daylight, holding approvals and business context in-house while the provider carries the nights, weekends and the platform — you are describing a co-managed NOC. Evaluate providers on how well they actually support that model: real console access for your team, not a read-only dashboard and a monthly PDF.

The checklist, in one place

Put every shortlisted provider through the same ten questions and score the answers side by side.

  • Does the SLA commit to restoration, response, or only notification?
  • Which remediations may run unattended, and how is that authority agreed and recorded?
  • Which of our exact device models are diagnosed natively, not just pinged?
  • Is discovery agentless, and how quickly is a new site mapped?
  • What does a real escalation contain — show one, redacted?
  • Who owns the monitoring platform, and what leaves with us at exit?
  • Is co-managed console access available for our engineers?
  • How are sites with no local IT presence handled overnight?
  • Can network, security and physical devices be watched on one platform?
  • What exactly drives the price up or down as the estate changes?

Where a platform-led provider differs

One structural difference worth mapping as you compare: some providers assemble their service from licensed tools, while others run their own platform. PrahiX sits in the second camp — monitoring, diagnosis and self-healing automation are one system, there is no separate NMS licence inside the price, and network, security and camera telemetry share a single timeline. That model is not automatically better for every buyer, and it sharpens one checklist question in particular: at exit, what you take with you is your data and history rather than a licence you already own. Whoever you evaluate, make them place themselves on this map in writing.

Have Questions? We've Got Answers.

Three is usually enough to see the range of the market. Use published lists to build the longlist, then cut to the providers willing to answer the operational questions — SLA verb, remediation authority, escalation samples — in writing before a demo.

Whether the SLA commits to restoring service or only to notifying you. It is the fastest way to separate an operation from an alert-forwarding service, and the answer reframes everything else in the proposal, including the price.

No. The tool raises alerts; the service includes the people watching them at 3am, the diagnosis, the remediation runbooks and the escalation paths. Some providers bundle their own platform, others operate a tool you license — both are NOC services, but the ownership difference matters at exit.

Location matters less than coverage and accountability: whether escalations reach the right people in your hours, where your telemetry and history are stored, and whether support commitments hold across time zones. Indian estates with sites in smaller cities should also test how the provider handles locations with no local IT presence.

Normalise them on the same variables: number of sites and devices, depth of monitoring per device class, whether remediation is included or advisory, SLA tightness, and platform licence costs — included or extra. Cheap quotes usually differ on remediation scope or licence exclusions rather than on efficiency.

Keep reading

Want our answers to these ten questions?

Put the checklist to us. Send your device inventory and we will answer every question in writing — then run a POC on a real slice of your estate so you are scoring results, not promises.