Charging and Rating: How Usage Becomes Revenue
Charging and rating architecture is how usage becomes money. Mediation collects the records, rating decides what a unit costs under the subscriber's plan, and charging either controls the session in real time or records it for later billing. Which of those two paths a service takes decides what you can sell: real-time control makes prepaid possible, batch processing makes it cheap.
Every call your subscriber makes, every message they send, every megabyte of data they consume needs to be measured, valued, and billed. This is the domain of charging and rating architecture, and it is one of the most consequential technical decisions you make when building your MVNO. Your charging architecture determines what business models you can operate, how accurately you capture revenue, how quickly you can launch new products, and how effectively you prevent fraud and revenue leakage.
Charging is not simply a billing function. It is a real-time system that sits at the intersection of your network, your product catalog, and your subscriber accounts. When it works well, it is invisible to everyone. When it fails, it generates revenue leakage, customer complaints, and regulatory risk simultaneously.
This guide explains how charging and rating architecture works in an MVNO context, the key components involved, the choices you need to make, and how to design a charging system that supports your business model today and scales as you grow.
On this page
- Why Charging Architecture is Central to Your MVNO Business
- Online vs. Offline Charging: The Fundamental Choice
- Online Charging: Real-Time Control
- Offline Charging: Batch Processing
- Convergent Charging: The Best of Both
- The Rating Engine: Turning Usage Into Revenue
- How Rating Works
- Rating Complexity: Bundles, Promotions, and Tiered Pricing
- Policy Control and Charging: The PCRF and PCF
Why Charging Architecture is Central to Your MVNO Business
Your charging architecture is your revenue engine. Every business model you want to operate, whether prepaid or postpaid, bundle-based or pay-as-you-go, wholesale or retail, requires specific charging capabilities. A charging architecture that cannot support your target business model forces you to compromise your product design or invest in expensive workarounds.
Charging architecture also determines your exposure to revenue leakage. Industry estimates consistently show that telecoms operators lose between one and three percent of revenue to leakage caused by rating errors, unmetered usage, provisioning failures, and fraud. For an MVNO with tight margins, even one percent leakage is the difference between profitability and loss.
Understanding your charging requirements starts with understanding your MVNO business model. A discount MVNO competing on price needs a highly automated, low-cost charging platform that handles high volumes of simple prepaid transactions. A business MVNO serving enterprise customers needs a charging system that handles complex postpaid billing, multi-line account management, and detailed usage reporting. An IoT MVNO managing millions of connected devices needs a charging system that scales to extreme transaction volumes at very low per-event costs.
Define your charging requirements from your business model outward, not from the technical capabilities of available products inward.
Online vs. Offline Charging: The Fundamental Choice
Online, offline and convergent compared
| Feature | Online | Offline | Convergent |
|---|---|---|---|
| When it decides | Before and during the session | After the event | Both, in one system |
| Can it stop a session | Yes | No | Yes |
| Makes prepaid possible | Yes | No | Yes |
| Signalling load | High | Low | Depends on configuration |
| Typical interface | Gy in 4G, Nchf in 5G | Rf in 4G, Nchf in 5G | One service, both modes |
| Main risk | Latency and quota tuning | Overspend goes unnoticed | Complexity, and a single point of failure |
Online Charging: Real-Time Control
Online charging, managed by the Online Charging System (OCS), controls service access in real time. Before a subscriber's session begins, or at regular intervals during the session, the network queries the OCS to check whether the subscriber has sufficient credit or allowance. The OCS authorizes the session, grants a quota of usage, and the network enforces that quota. When the quota is exhausted, the network queries the OCS again.
This real-time control model is essential for prepaid subscribers. Without online charging, a prepaid subscriber can consume services beyond their balance, creating debt that is difficult or impossible to collect. Online charging also enables real-time spend controls for postpaid subscribers, preventing bill shock from unexpected usage spikes such as roaming.
The technical standard for online charging uses the Diameter Ro interface between the network and the OCS. In 5G, this function is handled through the CHF (Charging Function) using HTTP/2-based service interfaces. Your OCS must respond to quota grants within tight latency bounds (typically under 200 milliseconds) to avoid impacting the subscriber experience during session setup.
Offline Charging: Batch Processing
Offline charging, managed by the Offline Charging System (OFCS), collects usage records after the fact for subsequent rating and billing. The network generates Charging Data Records (CDRs) for each usage event and forwards them to the OFCS for processing. The OFCS accumulates these records and passes them to the rating engine for valuation and invoice generation.
Offline charging suits postpaid billing models where the subscriber is invoiced at the end of a billing period. It is simpler to implement than online charging and adds no latency to session setup. However, it provides no real-time control, meaning a subscriber can accumulate unlimited usage before the billing cycle ends.
Most MVNO platforms implement both online and offline charging to support their full range of products and subscribers. The Diameter Rf interface carries offline charging data from the network to the OFCS.
Convergent Charging: The Best of Both
Convergent charging combines online and offline charging in a single unified platform, enabling the MVNO to manage all subscriber types, all service types, and all revenue streams through one charging system. A convergent charging platform applies real-time control where needed (prepaid subscribers, roaming sessions, high-value data passes) and batch processing where appropriate (postpaid monthly billing, wholesale settlement).
Modern MVNO platforms increasingly adopt convergent charging as the standard approach. It reduces platform complexity, simplifies operations, and provides a single source of truth for subscriber balances and usage across all products and channels. When selecting your BSS solution, verify whether its charging capabilities are genuinely convergent or whether separate online and offline charging systems must be integrated.

The Rating Engine: Turning Usage Into Revenue
How Rating Works
Rating is the process of applying financial values to raw usage data. The network generates usage events: a voice call of 3 minutes and 24 seconds, a data session consuming 47 megabytes, an SMS sent. The rating engine takes these raw events, looks up the applicable tariff in your product catalog, applies any relevant discounts or bundle deductions, and produces a monetary value or a deduction from a bundled allowance.
This sounds straightforward, but in practice rating logic is highly complex. The applicable tariff depends on who the subscriber is, which plan they are on, what time of day the usage occurred, whether the subscriber is roaming, whether the usage is on-net or off-net, and whether any active promotions apply. The rating engine must evaluate all of these variables for every usage event, correctly and at high speed.
The accuracy of your rating engine directly determines your revenue capture. Rating errors in either direction cost you money: under-rating means you give away revenue, over-rating generates customer complaints, regulatory investigations, and potential fines. Test your rating engine exhaustively against your complete product catalog before launch, and retest every time you introduce a new product or promotion.
Rating Complexity: Bundles, Promotions, and Tiered Pricing
Modern MVNO products are designed around bundles: fixed allowances of voice minutes, SMS, and data packaged together at a single price. Bundle rating requires the rating engine to track the subscriber's consumption against each allowance in real time, apply the bundled rate until the allowance is exhausted, and then apply out-of-bundle rates for any excess usage.
Promotions add further complexity. A promotional double-data offer, a friends-and-family discount, or a loyalty bonus all require the rating engine to apply different values to usage depending on conditions that may be time-limited, subscriber-specific, or usage-dependent.
Tiered pricing, used widely in data MVNO products, applies different per-unit rates at different consumption levels. The rating engine must track cumulative consumption and apply the correct tier rate at each threshold crossing, which requires stateful rating logic rather than simple per-event calculation.
Your product design team and your rating engine must work in close alignment. If your rating engine cannot handle the product logic your commercial team wants to launch, either the product must be simplified or the rating engine must be upgraded. Discover this constraint early, not on the day of a product launch.
Policy Control and Charging: The PCRF and PCF
The Policy and Charging Rules Function (PCRF) is the component of your 4G core network that applies policy rules to subscriber sessions. It works in close coordination with the OCS to enforce subscriber entitlements at the network level: determining the quality of service a subscriber receives, throttling speeds when data allowances are exhausted, and triggering notifications when usage thresholds are reached.
In 5G, the Policy Control Function (PCF) takes over this role, using the service-based architecture of the 5G Core to communicate with other network functions through APIs.
The integration between your charging system and your policy control function is critical for delivering the subscriber experience your products promise. When a subscriber exhausts their data allowance, you may want to throttle their speed to a lower tier rather than cutting service entirely. When they top up their account, you want speed to be restored instantly. These behaviors require real-time coordination between your OCS, your PCRF or PCF, and your product catalog.
Design the integration between charging and policy control as a core architectural requirement, not as an integration to be worked out after the main components are deployed.
Charging for Roaming Subscribers
Roaming creates specific charging challenges. When your subscriber uses services on a foreign network, the visited network generates usage records that reach your charging system through TAP (Transferred Account Procedure) batch files or NRTRDE (Near Real Time Roaming Data Exchange) feeds. Your rating engine must apply your roaming tariffs (which are typically different from your domestic tariffs) and correctly deduct from or charge against the subscriber's account.
Real-time charging for roaming requires your OCS to be accessible from the visited network through your IPX connectivity. The visited network's Packet Gateway queries your OCS before granting data access to your roaming subscriber, just as it would for any online-charged session. This real-time control prevents your subscriber from running up large roaming bills before you have visibility of the usage.
For MVNOs offering inclusive roaming (where roaming usage is deducted from the same bundle as domestic usage, as required under EU roaming regulations), your rating engine must implement fair use policy logic that prevents abuse while delivering the promised inclusive roaming benefit to legitimate travelers.
Prepaid vs. Postpaid Charging Architecture
Prepaid and postpaid charging have fundamentally different architectures and operational characteristics. Understanding these differences helps you design a platform that serves both subscriber types efficiently.
Prepaid charging is real-time and balance-based. The OCS holds a credit balance for each prepaid subscriber and deducts from it as usage occurs. Session access is refused when the balance reaches zero. Prepaid charging eliminates bad debt risk but requires a robust, low-latency OCS and a reliable top-up mechanism.
Postpaid charging is deferred and invoice-based. Usage accumulates throughout the billing period, the rating engine values it at period close, and an invoice is generated for payment. Postpaid charging carries bad debt risk but allows subscribers to use services without upfront payment, which suits higher-value customer segments.
Hybrid products, such as postpaid plans with a prepaid data bolt-on or a hard spending cap on postpaid accounts, combine elements of both architectures and require your charging system to apply different charging logic to different service components for the same subscriber simultaneously.
When selecting your charging platform, verify that it handles your complete mix of prepaid, postpaid, and hybrid products natively. Platforms that handle one model well but require custom development for the other create ongoing cost and risk.
Revenue Assurance and Leakage Prevention
Where the money actually leaks
| Leak | How it happens | How you would notice |
|---|---|---|
| Records never collected | Mediation drops or never receives them | Usage volume lower than network counters |
| Rating rules out of step with the price list | A tariff changed in one system but not the other | Revenue per subscriber moves without a reason |
| Roaming priced wrongly | TAP records rated at the wrong rate | Host operator invoice exceeds your own records |
| Promotions that never end | No expiry on a temporary bundle | A cohort of subscribers paying less than their plan |
| Active but unbilled subscribers | Provisioned in the network, missing in the BSS | Subscriber count differs between OSS and BSS |
| Unexplained balance movements | Adjustments without an audit trail | Balance changes nobody can trace to an event |
Revenue assurance is the discipline of ensuring that all revenue your network generates is correctly captured, rated, and billed. Every gap in this chain is a source of revenue leakage.
Common sources of leakage in MVNO charging architectures include CDR loss (usage events generated by the network that never reach the rating engine), rating errors (usage events that are rated at the wrong price or not rated at all), provisioning failures (subscribers activated on the network but not in the BSS, or vice versa), and roaming settlement discrepancies (differences between what the visited network charges you and what you charge your subscriber).
Design revenue assurance controls into your charging architecture from the start. Implement CDR reconciliation processes that detect and recover missing usage records. Run regular audits comparing your network's subscriber records with your BSS. Monitor your rating engine's output for anomalies that indicate rating errors. Reconcile your roaming TAP costs against your subscriber billing to detect margin erosion.
Revenue assurance is supported by your OSS and is closely related to the synergy between OSS and BSS. Integrate revenue assurance tooling into your platform from launch rather than adding it reactively when you discover a leakage problem.
Designing Your Charging Architecture for Growth
Scalability and Performance Requirements
Your charging architecture must scale with your subscriber base without requiring architectural redesign. Define your target transaction volumes at launch and at your three-year and five-year growth targets, and verify that your chosen charging platform can handle those volumes with acceptable latency.
The key performance metrics for online charging are transactions per second (TPS) and response latency. An MVNO with 100,000 active subscribers may generate several hundred OCS transactions per second during peak hours. At 1,000,000 subscribers, this scales proportionally. Your OCS must handle peak load with response times under 200 milliseconds to avoid impacting session setup performance.
For offline charging and rating, the key metric is CDR processing throughput: how quickly can your rating engine process the volume of CDRs your network generates during peak periods? Backlogs in CDR processing delay invoice generation and create uncertainty in subscriber balance calculations.
Charging Architecture for 5G Services
The 5G Core introduces new charging capabilities that MVNOs need to understand and plan for. The 5G Charging Function (CHF) consolidates online and offline charging into a single function using the HTTP/2-based service-based architecture of the 5G Core. This simplifies the charging interface compared to 4G, where separate Ro (online) and Rf (offline) Diameter interfaces were used.
5G also introduces network slicing, which creates new charging dimensions. Different network slices may carry different charging rates, requiring your rating engine to handle slice-aware charging logic. For MVNOs targeting enterprise customers with dedicated network slices, this capability is a genuine revenue opportunity that requires charging architecture preparation today.
The potential of 5G for MVNOs extends beyond speed improvements to new service models, including ultra-reliable low-latency services and massive IoT connectivity, each with distinct charging requirements. Build your charging architecture to accommodate these new dimensions rather than treating 5G as simply a faster version of 4G.
Frequently Asked Questions
Why do MVNOs need dedicated cybersecurity solutions?
MVNOs process highly sensitive subscriber data and operate network infrastructure that is exposed to well-documented telecom-specific attack vectors, including SS7 fraud, SIM swap attacks, and Diameter signaling exploits. Dedicated solutions are required to detect and prevent these threats and to meet regulatory obligations.
What is the biggest cybersecurity threat for MVNOs today?
SIM swap fraud and SS7/Diameter signaling attacks remain among the most impactful threats. Both allow attackers to take over subscriber accounts or intercept communications, leading to financial fraud, data breaches, and severe reputational damage.
Are MVNOs subject to GDPR?
Yes. Any MVNO operating in or processing the personal data of individuals in the European Union is subject to GDPR. This includes obligations around lawful processing, data subject rights, breach notification, and the security of processing.
How does 5G affect cybersecurity requirements?
The 5G Core introduces stronger built-in security mechanisms, including SUPI/SUCI privacy protection and mutual authentication. However, 5G also expands the attack surface through network slicing, edge computing, and massive IoT connectivity, requiring updated security strategies and tools.
What should an MVNO look for in a cybersecurity solution provider?
Operators should look for providers with proven telecom-specific expertise, coverage of signaling security (SS7, Diameter, GTP), fraud management, SIEM capabilities, and demonstrated experience with GDPR and 3GPP security standards. Use the MVNO Index Solution Provider directory to identify and shortlist qualified vendors.
How do cybersecurity solutions integrate with BSS and OSS?
Security solutions integrate with BSS and OSS platforms via APIs and log-forwarding mechanisms, feeding event data into the SIEM and enabling automated fraud response actions such as service suspension or alert escalation.
What is the role of Artificial Intelligence in telecom cybersecurity?
AI and machine learning are increasingly used to detect anomalous behavior patterns in subscriber usage, signaling traffic, and network operations that would be impossible to identify through manual analysis or static rule-based systems. Learn more about how AI is transforming MVNO operations on the Artificial Intelligence and a Mobile Brand page.
Summary
Cybersecurity and Privacy Solutions are the foundational protective framework that every MVNO, IoT operator, MVNE, and MVNA must put in place to protect its subscribers, infrastructure, revenue, and regulatory standing. From securing the signaling plane managed by the DRA and STP, to protecting subscriber identities in the HLR and HSS, to hardening the modern 5G Core and securing vast IoT device deployments, the scope of cybersecurity in mobile telecoms is broad and continually expanding.
Investing in the right cybersecurity and privacy capabilities is not merely a compliance exercise. It is a direct investment in subscriber trust, operational resilience, and sustainable business growth. Operators who build security into the foundations of their business from day one, whether they are starting a new MVNO or scaling an existing IoT platform, will be better positioned to grow with confidence, win enterprise customers, and navigate an increasingly regulated and threat-rich environment.
Use the MVNO Index Solution Provider directory to find qualified cybersecurity and privacy vendors for your mobile or IoT business, or explore the Consultancy section to find expert partners who can help you design and implement a security and compliance strategy tailored to your specific needs.










