As 5G FWA deployments scale from thousands to millions of CPE units per operator, the economics of device provisioning have shifted from a manageable operational expense to a strategic bottleneck. The cost of dispatching a field technician to install and configure a single CPE — estimated at $75–$180 per truck roll across major markets — becomes untenable at scale. Zero-Touch Provisioning (ZTP), enabled by the Broadband Forum’s TR-369 User Services Platform (USP) standard, has emerged as the definitive answer. For B2B buyers and system integrators sourcing 5G CPE in 2026, understanding ZTP architecture is a prerequisite for operator certification and large-scale deployment eligibility.
From TR-069 to TR-369: The Management Protocol Transition
The broadband industry’s CPE management backbone has been TR-069 (CWMP) for nearly two decades. While TR-069 served DSL, cable, and early LTE FWA deployments adequately, its limitations in a 5G context are well documented:
- HTTP-based polling model introduces latency and overhead unsuitable for real-time 5G service orchestration
- Single CPE-to-ACS relationship cannot support multi-tenant, multi-service architectures required by network slicing and private 5G
- Limited data model extensibility makes it difficult to expose 5G-specific parameters (CSI-RS measurements, beam management state, slice configuration) without proprietary vendor extensions
- No native IoT device proxy capability — TR-069 assumes every managed endpoint is a CPE, whereas TR-369 USP can proxy manage connected IoT sensors, mesh nodes, and enterprise LAN equipment
TR-369 USP (User Services Platform), standardized by the Broadband Forum as USP 1.3 in 2024 and USP 1.4 targeted for H2 2026, addresses these limitations through a fundamentally modern architecture:
- WebSocket and CoAP transport with MQTT broker integration for real-time, bidirectional communication
- Multi-controller architecture allowing a single CPE to be simultaneously managed by an operator ACS, enterprise IT controller, and security analytics platform
- USP Services model that cleanly separates device management, firmware lifecycle, network diagnostics, and IoT proxy functions
- End-to-end security with TLS 1.3 mutual authentication and USP Endpoint Identity certificates
Zero-Touch Provisioning Architecture
Phase 1: Bootstrap and Discovery
When a CPE powers on for the first time, it must autonomously discover its management controller without any prior configuration. The bootstrap sequence typically follows DHCP/DHCPv6 option-based discovery (the most common method in carrier deployments), DNS-SD/mDNS fallback for enterprise deployments, or a pre-configured bootstrap URL for managed service providers.
The key evaluation criterion for buyers: how many bootstrap discovery methods does the CPE support, and can they be prioritized in a configurable fallback chain?
Phase 2: Secure Onboarding and Identity
Once the controller URL is discovered, the CPE establishes a mutually authenticated TLS 1.3 session. The device identity model is critical: factory-installed X.509 device certificates (IEEE 802.1AR DevID) burned into secure storage (TEE or TPM) during manufacturing provide cryptographic device identity — the gold standard mandatory for operator-grade ZTP. Buyers should verify that the CPE supports hardware-backed key storage (TrustZone, Secure Enclave, or discrete TPM) for device certificates and can perform CSR generation for operator PKI integration.
Phase 3: Parameter Provisioning
After secure onboarding, the controller pushes the full service configuration via USP Set messages: WAN configuration (APN/DNN, PDU session parameters, URSP rules), LAN configuration (DHCP pools, VLANs, SSIDs, firewall rules), voice configuration (SIP proxy, codec preferences), and QoS mapping (DSCP-to-QFI mapping tables). The entire provisioning sequence — from power-on to fully configured service — should complete in under 90 seconds for typical FWA deployments and under 3 minutes for complex enterprise configurations.
Phase 4: Ongoing Lifecycle Management
ZTP is not a one-time event; it extends across the CPE lifecycle with firmware lifecycle management via segmented, scheduled, and conditional USP upgrades; telemetry and performance monitoring with real-time KPI streaming; remote diagnostics with ping, traceroute, packet capture, and modem log collection; and secure decommissioning with factory reset, certificate revocation, and secure wipe.
Evaluation Criteria for CPE ZTP Capability
1. USP Protocol Compliance
Verify USP 1.3 (or later) with WebSocket transport and TLS 1.3 mutual authentication, MQTT transport support, CoAP transport with DTLS for constrained IoT scenarios, at least 15 concurrent controller connections, and USP MTP with fragmentation and reassembly for large payloads.
2. Bootstrap Mechanism Flexibility
The CPE should support all three bootstrap discovery methods (DHCP options, DNS-SD/mDNS, pre-configured URL) with configurable priority and timeout parameters.
3. Hardware-Backed Security
Mandatory: X.509 device certificate in factory-secured storage, secure boot chain, TLS 1.3 with PFS cipher suites, and certificate renewal without factory reset.
4. Data Model Coverage
The CPE must expose a comprehensive TR-181 Device:2 data model covering Device.Cellular (5G modem parameters, cell measurements), Device.WiFi (SSID, band steering, client statistics), Device.Routing (static routes, policy routing, VRF instances), Device.Bridging (VLANs, IGMP/MLD snooping), and Device.QoS (classification, queuing, DSCP marking).
5. Multi-Tenant and Slicing Support
For private 5G and network slicing deployments, the CPE must support multiple PDU sessions with independent USP controller associations, URSP rule provisioning via USP, and per-slice telemetry and QoS monitoring.
Honlly’s ZTP Implementation
Honlly Telecom’s 5G CPE portfolio implements TR-369 USP 1.3 across all current-generation devices, with a field-upgradable path to USP 1.4. Key differentiators include factory-installed X.509 device certificates with hardware-backed key storage in ARM TrustZone, a multi-controller architecture supporting simultaneous operator, enterprise, and cloud management connections, comprehensive TR-181 Device:2 data model coverage, conditional firmware upgrade engine, and zero-touch bootstrap time under 75 seconds for typical FWA deployments.
The ZTP Imperative for 2026–2027
Operators issuing RFPs for 5G CPE in H2 2026 are increasingly making TR-369 USP compliance a mandatory gate criterion — not a “nice-to-have.” The days of TR-069 as an acceptable minimum are ending. For CPE buyers serving operator channels, ZTP readiness determines whether a device can be listed on an operator’s approved CPE roster at all.
When evaluating 5G CPE for ZTP capability, treat USP compliance as a pass/fail gate. Devices that pass should then be scored on bootstrap flexibility, security architecture, and data model depth. The CPE that provisions fastest, most securely, and with the richest data model will deliver the lowest operational cost over a 3–5 year deployment lifecycle.
For detailed technical documentation on Honlly’s TR-369 USP implementation and ZTP capabilities, visit honllytelecom.com/products or contact the Honlly B2B solutions engineering team.

