industry

SPRS Score Calculator for Telecommunications & Network Providers

Score CMMC / NIST SP 800-171 readiness for SPRS — for telecom and network providers in the defense supply chain.

Telecommunications and network providers that transmit or store a DoD customer's CUI — or provide security-protection capabilities for it — are pulled into assessment scope as External Service Providers. Segregating the services that carry CUI is the key to a manageable scope.

Categorize each service under §170.19: links and systems that carry CUI are CUI Assets, while monitoring and security capabilities are Security Protection Assets. Document the relationship and boundary in the customer's SSP and a Customer Responsibility Matrix.

What's typically in scope for Telecommunications & Network Providers

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
Network services / systems that transmit or store customer CUI
CUI
Assessed against all Level 2 requirements; CUI-handling cloud needs FedRAMP Moderate or equivalency.
Monitoring / security capabilities you provide for the CUI
Security Protection
Assessed against the capability provided.
Network OT / elements that can't be fully secured
Specialized
Reviewed via the SSP, not assessed against every requirement.
General commercial network with no DoD CUI, separated
Out-of-Scope
Out of scope with justified separation.

Where Telecommunications & Network Providers teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Segregating the services that carry CUI
  • FIPS-validated encryption of CUI in transit
  • Access control + MFA for network management
  • Audit logging across delivered services
  • The ESP boundary in the customer SSP + CRM
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

Your in-scope services are assessed within the customer's Level 2 assessment; if you hold CUI under your own DoD contract you carry your own SPRS obligation.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
DFARS 252.204-7020
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Are telecom providers in CMMC scope?
If you transmit or store a DoD customer's CUI, or provide security-protection capabilities for it, the relevant services are in scope as an External Service Provider.
What level do we need?
Handling CUI points to Level 2 as the minimum; the self-assessment versus C3PAO question depends on the CUI category.
How do we limit scope?
Segregate the services and systems that carry CUI and document the boundary; assets with no CUI and proper separation can be Out-of-Scope.
Are we in scope if we only carry encrypted traffic?
If you transmit or store the customer's CUI — even encrypted — the carrying services are in scope as an ESP. Whether you also see the plaintext affects which requirements apply; categorize each service under §170.19.
Does our managed-network cloud need FedRAMP?
If it stores or transmits the customer's CUI, the cloud must meet FedRAMP Moderate or equivalency under DFARS 252.204-7012.

Need a provider?

As an External Service Provider, the right MSP/MSSP, vCISO, or C3PAO can shorten the path. Browse vetted providers — free, no account.

Explore the provider marketplace

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.