Summary
- RIPE NCC’s February-to-August member updates report 293, 256, 256, 242, 240, 237 and 275 Assisted Registry Checks for January through July 2026. The exact sum is 1,799.
- The 2026 Activity Plan commits to 2,400 checks. The seven-month total is 74.96% of that number and 399 above a simple seven-twelfths comparator of 1,400; this is not a forecast or a prescribed work schedule.
- RIPE-694 allows an ARC to begin at a member’s request, by random selection or because of a specific matter. Audit scope may be restricted or extended, and duration depends on complexity. One completed operation therefore cannot be read automatically as one unique LIR or one uniform risk review.
- A privacy-safe cohort receipt should publish unique and repeat coverage, initiation and scope bands, correction and closure states, recurrence, snapshot date and provisional/final status—without naming members or exposing case details.
Seven monthly lines make a convincing numerator
The February member update supplies the first number: 293 Assisted Registry Checks completed in January. The March update reports 256 for February. The April update reports another 256 for March. Then come 242 in April’s activity, published in May, 240 for May in the June update, 237 for June in the July update, and 275 for July in the August update.
Add the seven figures and the result is 1,799. The arithmetic is useful because the RIPE NCC Activity Plan and Budget 2026 contains an explicit commitment: complete 2,400 Assisted Registry Checks during 2026, remotely and in person at RIPE NCC events. By the end of the published July series, the cumulative count was 74.9583% of that annual number.
An even monthly pace would place seven-twelfths of 2,400 at 1,400. The public total is 399 above that comparator. It is tempting to turn this into a year-end projection. The sources do not justify one. They do not say work is scheduled evenly; event-based reviews, member demand, complex cases, staffing and automation can move work between months. The honest conclusion is narrower: the reported output was ahead of a straight-line reference at this point in the series.
That is already valuable. A target without periodic observations is a promise waiting for an annual retrospective. Seven observations make pace inspectable. Yet the numerator becomes ambiguous as soon as it is used to answer a different question: how much of the registry’s member population or risk surface has actually been covered?
An ARC is not one standard unit
The current Assisted Registry Check service page describes a wide operating surface. It includes registry-data accuracy, inconsistencies between routing-registry entries and BGP announcements, reverse-DNS delegation problems, RPKI guidance and an option to test IPv4 or IPv6 reachability with RIPE Atlas. Those are not five names for the same task. They are different evidence objects and different forms of remediation.
The procedural document RIPE-694 makes the variation clearer. It says an ARC may be initiated at a member’s request, after RIPE NCC selects a member randomly, or because of a specific matter concerning that member. It also says the audit need not cover every registration record or every policy obligation. RIPE NCC may keep the scope to the triggering issue or extend it to other matters.
Time varies too. RIPE-694 says the duration depends on case complexity, while concrete response timeframes are set for the resource holder. Once the appropriate actions requested of RIPE NCC or the holder have been taken, the audit is concluded. Failure to provide requested information may be treated as failure to cooperate and may lead to termination of the relevant agreement. That is a possible contractual consequence of non-cooperation, not the ordinary meaning of every completed ARC.
These distinctions break the factory metaphor. One ARC can be requested and constructive; another can be randomly selected; a third can begin with a particular concern. One may remain narrow. Another may grow. One may end after simple data correction. Another may demand more documents and time. Counting each as one is perfectly reasonable for a production tally. Treating each as an interchangeable unit of coverage is not.
The missing denominator is a cohort, not another target
The monthly lines report completed ARC operations. They do not state that the operations correspond to 1,799 different LIRs. A member checked in one month could appear again later. A repeat could be routine follow-up, a fresh request, a new matter or recurrence of an earlier inconsistency. The frozen public source set does not distinguish those possibilities.
This is not an accusation that RIPE NCC lacks internal case records. It is not proof that no other public document contains any relevant detail. It is a bounded reading of the eleven sources supporting this article: the seven updates, the service page, RIPE-694, the activity plan and the 2025 annual report. Beside the monthly count, these sources do not publish the number of unique LIRs, first and repeat reviews, initiation-mode mix, scope distribution, correction classes, open and concluded cohorts, conclusion times or recurrence.
Without those fields, two very different programmes can produce the same 1,799. One could distribute first reviews broadly across the membership. Another could devote more work to repeat or extended reviews of a smaller cohort. Neither is inherently better. Repetition may be exactly what risk demands. Broad, shallow coverage may discover little. Concentrated follow-up may close serious inconsistencies. The point is not to reward one pattern in advance. It is to stop a single numerator from silently choosing the interpretation.
The relevant denominator is therefore plural. How many distinct LIRs appeared? How many had not been checked in the defined look-back period? How many returned? What share began by request, random selection or a specific matter? How often did scope stay narrow or extend? Which classes of correction were opened and concluded? Did the same class recur?
Those questions measure coverage and learning. They do not turn ARC into an enforcement league table. They make the public target legible in the units that its own procedure says can vary.
The 2025 totals show why snapshot state matters
The activity plan dated December 2025 displays 2,529 Assisted Registry Checks for 2025. The later RIPE NCC Annual Report 2025 displays 2,825 and says that total exceeded the 2,400 target. The two official publications therefore carry different values for the same labelled year.
The evidence does not establish that either value is wrong. A December planning document can capture work before the year is fully closed; a later annual report can carry the final total. The inspected pages do not provide a reconciliation or label the earlier value with a cutoff date. The safe lesson is about status, not error.
A monthly series needs an observation date. A year-to-date value needs a cutoff. A provisional count should become final through a visible transition, not silent replacement. If scope or counting rules change, the series needs a definition version. These fields are small, but they prevent an analyst from comparing a live operational snapshot with a closed annual total as if both were the same state.
The difference also explains why the July cumulative count should remain a cumulative observation. It is not the final 2026 result. Later completions, corrections or definition changes may alter what an annual report records. The public record should preserve both states and the route between them.
A cohort receipt can stay small and private
The remedy does not require publishing an audit database. A compact aggregate receipt can sit beside each monthly ARC number.
Start with time and status: calendar month, cumulative operations, snapshot date, definition version and provisional or final state. This preserves the exact observation being reported.
Then separate operations from organisations: distinct LIRs in the period, first checks under a declared look-back window, and repeat checks. Publish only totals or sufficiently broad bands. No member name, registry identifier or case narrative belongs in the receipt.
Next publish the initiation mix in aggregate: member-requested, randomly selected and specific-matter. These labels come from RIPE-694 and explain why the queue exists. They should not be presented as risk scores. A requested check is not a weak check; a specific-matter check is not a public finding.
Scope needs a small vocabulary. A report might distinguish trigger-limited, standard multi-area and extended review, with the definitions versioned. The current service page’s areas—registry records, routing/BGP consistency, reverse DNS, RPKI support and optional reachability—can inform the dictionary, but the receipt must not assume every ARC touches every area.
Closure needs state rather than a celebratory total. Show how many operations opened corrections, how many were concluded, the distribution of time to conclusion and how many remained open at the snapshot. Correction classes can be broad: identity/contact, resource registration, routing consistency, reverse DNS or another declared class. Sensitive evidence stays restricted.
Finally, record recurrence in aggregate. A repeated finding class within a defined period is not automatically failure; it may reflect changing networks, new records or deeper checking. But it changes what “repeat” means and tells members whether completed volume is also producing durable correction.
Every figure should be suppressible below a privacy threshold. Small cells can be combined or withheld with an explicit privacy marker. The receipt’s job is to expose programme shape, not participants.
What 1,799 does prove
The absence of a cohort ledger does not empty the count of meaning. Seven public updates show that RIPE NCC completed substantial ARC work month after month. The total can be reproduced. Its relation to the annual commitment can be calculated. The activity plan identifies automation and improved experience as part of the 2026 programme. Those are inspectable facts.
The number also creates a useful monitoring baseline. Future updates can extend the series. The annual report can close it. If the final total differs from the last monthly cumulative figure, a snapshot and reconciliation field can explain why. If unique coverage or repeats are later published, the series can acquire a denominator without changing its historical numerator.
What 1,799 cannot do is decide whether coverage was broad, concentrated, shallow, extended, corrective or recurrent. Those are not criticisms hidden inside a demand for more data. They are different questions with different units.
The public target counts work. A cohort receipt would show where that work travelled. RIPE NCC has already published the numerator. The next useful object is the map behind it.
Sources
- RIPE NCC Member Update February 2026
- RIPE NCC Member Update March 2026
- RIPE NCC Member Update April 2026
- RIPE NCC Member Update May 2026
- RIPE NCC Member Update June 2026
- RIPE NCC Member Update July 2026
- RIPE NCC Member Update August 2026
- RIPE NCC — Assisted Registry Check
- RIPE-694 — RIPE NCC Audit Activity
- RIPE NCC Activity Plan and Budget 2026
- RIPE NCC Annual Report 2025
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
