Government Affairs Commentary

CALEA for Small ISPs and WISPs: What You Must Do

By the Subsentio Compliance Team. Reviewed for accuracy against CALEA (47 U.S.C. 1001 et seq.) and the FCC's implementing rules.

TL;DR: If you run a small internet service provider or a wireless ISP, CALEA very likely applies to you. Facilities-based broadband providers have been covered since 2005, and there is no exemption for being small, rural, or new. The good news is that what you actually have to do is manageable: confirm you are covered, put a conforming lawful intercept capability in place, file and maintain a System Security and Integrity plan with the FCC, and be able to respond to an order quickly. Most small providers meet all of that through a trusted third party, an option the FCC created specifically because compliance is heavy for smaller operators.

"We're Too Small for CALEA" Is the Myth

The single most common belief among small ISPs and WISPs is that CALEA is a big-carrier problem. It is not. When the FCC extended CALEA to facilities-based broadband providers, that reached the whole field, cable, DSL, fiber, and fixed wireless alike, and a federal appeals court upheld it. The industry's own wireless ISP association has told its members the same thing: small wireless ISPs are required to be CALEA compliant.

Coverage does not scale with your size. A ten-thousand-subscriber rural WISP has the same basic obligation as a national carrier, because CALEA was written to be technology-neutral and turns on what you do, provide broadband to the public, not on how big you are. So the first step is not to assume you are too small to be covered. You very probably are covered.

The Myths That Get Small Providers in Trouble

A handful of specific misreadings are what actually cause the trouble.

"We're just an ISP, not a phone company." CALEA stopped being only about phone companies in 2005. If you provide facilities-based broadband, you are in, regardless of whether you offer voice at all.

"Our upstream provider handles it." This is the costly one. Getting your IP addresses or transit from an upstream ISP does not relieve you of your own obligation. Each covered provider remains responsible for the information it holds, and the fact that someone upstream might also be able to help does not release you from responding to an order directed at you.

"It's built into our equipment." Maybe your gear has an interception feature, but having a feature is not the same as a validated, conforming solution that you can actually operate under a live order. Capability is not conformance, and an untested feature is a guess, not a compliance posture.

"We've never gotten an order, so we're fine." The obligation exists before any order arrives. The point of CALEA is to be ready in advance, so the day an order lands is not the day you start building.

What a Small ISP or WISP Actually Has to Do

Stripped down, the obligation is a short list:

  1. Confirm you are covered. Settle the question in writing rather than assuming either way.
  2. Put a conforming solution in place. You need the ability to isolate and deliver a target's communications and call-identifying information, conforming to the recognized standard for your network type.
  3. File and maintain an SSI plan. Every covered carrier must file a System Security and Integrity plan with the FCC, name a person responsible for compliance who is reachable around the clock, and keep it current.
  4. Be able to respond quickly. When an order arrives, you generally need to stand up the intercept promptly, often within a few days. That is only realistic if the capability and the process already exist.

None of these require you to become a surveillance expert. They require that the capability, the paperwork, and a person who knows what to do are all in place before you need them.

The Real Problem for Small Providers, and the Realistic Fix

Here is the honest tension. Everything on that list is manageable in principle, and genuinely hard for a small operator to carry alone. A regional WISP usually does not have spare engineers to build and maintain a conforming intercept solution, staff to be reachable at 2 a.m., or a compliance officer with lawful intercept experience on payroll. Standing all of that up in-house, for a capability you may use rarely, is expensive and slow.

That is exactly why the FCC created a third path. Alongside building your own solution or buying equipment, a covered provider may meet CALEA through a trusted third party, and the Commission allowed it specifically because of the resources and complexity involved, especially for smaller and mid-sized operators. A trusted third party carries the technical solution and the compliance program together, and spreads that cost across many providers, so a small ISP or WISP gets the capability, the around-the-clock coverage, and the standards expertise without hiring for all of it.

The responsibility still stays with you, that never transfers, but the work does not have to.

A Quick Self-Check

To see where you stand:

  1. Have you confirmed, in writing, whether CALEA applies to your network?
  2. If an order arrived this week, could you isolate one subscriber's traffic and deliver it in the required form?
  3. Do you have a current SSI plan on file, with a contact reachable 24/7?
  4. Does anyone on your team actually know the steps, or would the first order be the first time?

If those questions make you uneasy, that is the gap to close, and it is very closable.

Frequently Asked Questions

Does CALEA really apply to a small WISP? Yes. Facilities-based broadband providers, including fixed wireless ISPs, are covered, and there is no small-provider exemption. The size of your network does not change the obligation.

Our upstream ISP could perform the intercept. Are we off the hook? No. Each covered provider is responsible for what it holds. Another provider also being able to help does not relieve you of responding to an order directed at you.

We have never received a lawful order. Do we still have to comply? Yes. The obligation is to be ready before an order arrives, not to react after one does.

Isn't compliance too expensive for a provider our size? It does not have to be. The trusted third party path exists precisely so smaller providers can meet CALEA without building and staffing the whole program in-house.

Get Compliant Without Building It Alone

For a small ISP or WISP, CALEA is not a reason to panic, and not something to wish away either. It is a manageable obligation that is far easier to meet before an order arrives than after. Subsentio provides the trusted third party path for providers of exactly your size, the conforming solution, the around-the-clock coverage, the SSI plan, and the expertise, so compliance is handled without pulling your small team off the work that grows your business. Request a small-provider CALEA assessment and find out precisely what your network needs.

About Subsentio: Subsentio helps communications providers meet their law enforcement assistance obligations as a trusted third party. It determines CALEA coverage, implements and validates lawful intercept solutions, files and maintains System Security and Integrity plans, and reviews legal demands and manages records production for carriers, broadband providers, and VoIP operators of every size.

Share

Compliance questions? Ask the experts.

No hype, no lobbying, just the law, real answers to specific compliance questions.

All commentary