FCC & Telecom Compliance News

    Plain-language summaries of FCC rulemakings, enforcement actions, AI calling rules and network security decisions — with what each one actually means for a carrier running traffic on its own switch. Every entry links to the official source.

    FCC tightens the Robocall Mitigation Database again

    A further FCC action on the effectiveness of the Robocall Mitigation Database, tied to the Call Authentication Trust Anchor and unlawful robocall proceedings, was published in the Federal Register.

    The Commission continues to treat the Robocall Mitigation Database as an enforcement instrument rather than a filing formality. This item sits in the same line of proceedings as the earlier filing-requirement rules and the Call Authentication Trust Anchor docket (WC Docket No. 17-97).

    The practical direction of travel has not changed since 2024: certifications must be accurate, current, and backed by a robocall mitigation plan the provider can actually demonstrate. Stale or copy-pasted filings are the ones drawing attention.

    What it means for your switch

    If your RMD certification still describes a mitigation program you no longer run, update it before someone else reads it for you. Downstream carriers are entitled to refuse traffic from providers whose filings are deficient or removed.

    Source: Federal Register — Improving the Effectiveness of the Robocall Mitigation Database

    FCC removes 14 voice providers from the Robocall Mitigation Database

    In a single sweep, the Commission struck 14 named companies from the Robocall Mitigation Database for violating robocall rules.

    Removal from the RMD is not a paperwork penalty. Once a provider is off the list, other US carriers are required to stop accepting its traffic — the commercial effect is immediate and total.

    The action follows the pattern the Enforcement Bureau has used repeatedly: warning letters and requests for information first, then removal for providers that do not respond or cannot show a real mitigation program.

    What it means for your switch

    Two jobs for an originating or intermediate provider. First, keep your own certification defensible. Second, check the RMD status of every upstream partner you accept traffic from — accepting traffic from a removed provider puts your own registration at risk.

    Source: National Law Review — FCC removes 14 companies from the RMD

    Know-Your-Upstream-Provider rules and stronger STIR/SHAKEN

    The Commission moved to strengthen know-your-upstream-provider obligations alongside STIR/SHAKEN call authentication requirements.

    The regulatory logic is straightforward: illegal traffic usually enters the US network through a provider that did not look closely at who handed it the calls. Tightening upstream diligence pushes responsibility back up the chain instead of leaving it entirely with terminating carriers.

    For carriers this converts what used to be a commercial judgement — who you peer with — into a compliance obligation you may have to evidence.

    What it means for your switch

    Keep documented KYC records for every upstream and customer: legal entity, contacts, expected traffic profile, and what you did when the traffic did not match that profile. Records created after an inquiry arrives carry little weight.

    Source: Federal Register — Enhancing Know-Your-Upstream-Provider Requirements

    FCC proposes enhancements to STIR/SHAKEN

    A Further Notice of Proposed Rulemaking set out measures to make STIR/SHAKEN a sharper tool against illegal calls, including improved know-your-upstream-provider requirements (WC Docket No. 17-97; CG Docket No. 17-59).

    The FNPRM signals that attestation quality itself is under review. A-level attestation is meant to mean the provider knows the customer and the customer's right to use the number — not simply that the call originated on its own switch.

    Proposals at this stage are not yet binding rules, but they are the clearest available preview of where compliance expectations are heading.

    What it means for your switch

    If your platform hands out A attestation broadly, start measuring how much of that traffic you could actually justify. Getting attestation logic right before it becomes mandatory is far cheaper than retrofitting under an inquiry.

    Source: FCC Fact Sheet — Enhancing STIR/SHAKEN to Combat Illegal Robocalls

    FCC cuts off a provider from US networks over robocall rules

    The Commission acted to immediately prevent a provider that violated robocall rules from connecting to US networks.

    Actions of this kind end a carrier's US business overnight. There is no phased wind-down: other providers are directed to stop accepting the traffic.

    The trigger is usually the same — high volumes of illegal traffic, a mitigation program that exists only on paper, and slow or incomplete responses to the Enforcement Bureau.

    What it means for your switch

    Respond to traceback requests quickly and completely. A provider that can show call detail, attestation decisions, and the action it took on a flagged customer is in a fundamentally different position from one that cannot.

    Source: FCC News Release — FCC Cuts Off Provider for Violating Robocall Rules

    Stricter Robocall Mitigation Database filing requirements take effect

    Rules tightening RMD filing requirements — including registration through CORES — were published in the Federal Register.

    The changes are aimed at the long-standing weakness of the database: filings that were incomplete, anonymous, or plainly fictional. Tying registrations to verified entity records makes accountability traceable.

    Providers that filed years ago and never revisited the entry are the most exposed, because a certification that no longer describes the business is a defective filing.

    What it means for your switch

    Re-open your RMD entry and read it as an investigator would. Confirm the entity details, contact, and mitigation description still match what you actually do on your switch.

    Source: Federal Register — Improving the Effectiveness of the Robocall Mitigation Database; CORES

    Direct access to numbers now requires robocall and national security compliance

    The Commission adopted rule changes so that VoIP providers with direct access to numbering resources must certify robocall, public safety, and national security compliance and disclose ownership information.

    Numbers are the raw material of illegal calling campaigns. By attaching compliance certification and disclosure conditions to direct access, the FCC closed a route that let bad actors obtain numbering resources with little scrutiny.

    The order sits alongside the STIR/SHAKEN framework rather than replacing it: authentication tells you who signed a call, numbering rules govern who was allowed to hold the number in the first place.

    What it means for your switch

    If you hold direct access authorisation, review your certifications and ownership disclosures now. If you buy numbers wholesale, expect your supplier to push new diligence questions down to you.

    Source: FCC News — FCC Combats Robocallers' Abuse of Phone Numbering Resources

    National security cited for the first time in RMD removals

    The Enforcement Bureau issued orders removing three Chinese telecommunications providers from the Robocall Mitigation Database, the first time national security grounds were used for removal.

    Until this point, removals from the database followed robocall-mitigation failures: bad certifications, unanswered inquiries, illegal traffic. This action introduced a second, separate basis for exclusion.

    It matters for risk assessment because it means a partner can lose US network access for reasons unrelated to its call quality or traffic profile.

    What it means for your switch

    Screen upstream partners for ownership and control, not only for traffic behaviour. Monitor RMD status continuously — a partner can go from valid to removed between two invoices.

    Source: Wiley — FCC First: National Security Cited for Removal from the RMD

    FCC reconsiders its telecom cybersecurity ruling after Salt Typhoon

    An Order on Reconsideration revisited the Commission's January 2025 cybersecurity action in PS Docket No. 22-329, the proceeding opened in response to the Salt Typhoon intrusions into US carrier networks.

    The underlying question is how far the Commission's authority reaches into how carriers secure their own networks, as opposed to what they must report after an incident. The reconsideration narrowed the mandatory reading adopted earlier in the year.

    The security expectation itself did not go away. Carriers remain the target: signalling systems, provisioning portals and lawful-intercept infrastructure were all in scope of the intrusions that started this proceeding.

    What it means for your switch

    Regardless of where the rule lands, treat switch and portal access as a security perimeter: unique credentials per person, MFA on provisioning, logged configuration changes, and alerting on unusual route or trunk edits.

    Source: FCC Fact Sheet — Protecting the Nation's Communications Systems (Order on Reconsideration)

    FCC opens a proceeding on branded calling and caller ID presentation

    A Further Notice of Proposed Rulemaking asked how caller identification information should be verified and displayed, covering branded calling (CG Docket Nos. 17-59, 02-278, 25-307; WC Docket No. 17-97).

    Branded calling puts a verified name and logo on the called party's screen. The proceeding examines what verification should sit behind that display so branding does not become a new spoofing surface.

    For originating providers this is the constructive half of the robocall agenda: not just blocking bad calls, but making legitimate enterprise calls identifiable enough to be answered.

    What it means for your switch

    If you sell enterprise voice, track this docket. Verified branding will depend on the same KYC and attestation records the enforcement rules already demand of you.

    Source: FCC Fact Sheet — Call Branding FNPRM

    Staying ahead of the next enforcement sweep

    SipShield scores live SIP signaling with patented AI so attestation, blocking and traceback evidence are already in place when a request arrives.