SPRS Score Calculator for Telecommunications & Network Providers
Score CMMC / NIST SP 800-171 readiness for SPRS — for telecom and network providers in the defense supply chain.
Telecommunications and network providers that transmit or store a DoD customer's CUI — or provide security-protection capabilities for it — are pulled into assessment scope as External Service Providers. Segregating the services that carry CUI is the key to a manageable scope.
Categorize each service under §170.19: links and systems that carry CUI are CUI Assets, while monitoring and security capabilities are Security Protection Assets. Document the relationship and boundary in the customer's SSP and a Customer Responsibility Matrix.
What's typically in scope for Telecommunications & Network Providers
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| Network services / systems that transmit or store customer CUI | CUI | Assessed against all Level 2 requirements; CUI-handling cloud needs FedRAMP Moderate or equivalency. |
| Monitoring / security capabilities you provide for the CUI | Security Protection | Assessed against the capability provided. |
| Network OT / elements that can't be fully secured | Specialized | Reviewed via the SSP, not assessed against every requirement. |
| General commercial network with no DoD CUI, separated | Out-of-Scope | Out of scope with justified separation. |
Where Telecommunications & Network Providers teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Segregating the services that carry CUI
- FIPS-validated encryption of CUI in transit
- Access control + MFA for network management
- Audit logging across delivered services
- The ESP boundary in the customer SSP + CRM
Which CMMC level you need
Your in-scope services are assessed within the customer's Level 2 assessment; if you hold CUI under your own DoD contract you carry your own SPRS obligation.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Are telecom providers in CMMC scope?
- If you transmit or store a DoD customer's CUI, or provide security-protection capabilities for it, the relevant services are in scope as an External Service Provider.
- What level do we need?
- Handling CUI points to Level 2 as the minimum; the self-assessment versus C3PAO question depends on the CUI category.
- How do we limit scope?
- Segregate the services and systems that carry CUI and document the boundary; assets with no CUI and proper separation can be Out-of-Scope.
- Are we in scope if we only carry encrypted traffic?
- If you transmit or store the customer's CUI — even encrypted — the carrying services are in scope as an ESP. Whether you also see the plaintext affects which requirements apply; categorize each service under §170.19.
- Does our managed-network cloud need FedRAMP?
- If it stores or transmits the customer's CUI, the cloud must meet FedRAMP Moderate or equivalency under DFARS 252.204-7012.
Need a provider?
As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.
Explore the provider marketplaceRelated industries
Related guides
Go deeper on scoring, levels, and POA&Ms.