Plain-language summaries of FCC rulemakings, enforcement actions, AI calling rules and network security decisions — with what each one actually means for a carrier running traffic on its own switch. Every entry links to the official source.
FCC tightens the Robocall Mitigation Database again
A further FCC action on the effectiveness of the Robocall Mitigation Database, tied to the Call Authentication Trust Anchor and unlawful robocall proceedings, was published in the Federal Register.
The Commission continues to treat the Robocall Mitigation Database as an enforcement instrument rather than a filing formality. This item sits in the same line of proceedings as the earlier filing-requirement rules and the Call Authentication Trust Anchor docket (WC Docket No. 17-97).
The practical direction of travel has not changed since 2024: certifications must be accurate, current, and backed by a robocall mitigation plan the provider can actually demonstrate. Stale or copy-pasted filings are the ones drawing attention.
What it means for your switch
If your RMD certification still describes a mitigation program you no longer run, update it before someone else reads it for you. Downstream carriers are entitled to refuse traffic from providers whose filings are deficient or removed.
FCC removes 14 voice providers from the Robocall Mitigation Database
In a single sweep, the Commission struck 14 named companies from the Robocall Mitigation Database for violating robocall rules.
Removal from the RMD is not a paperwork penalty. Once a provider is off the list, other US carriers are required to stop accepting its traffic — the commercial effect is immediate and total.
The action follows the pattern the Enforcement Bureau has used repeatedly: warning letters and requests for information first, then removal for providers that do not respond or cannot show a real mitigation program.
What it means for your switch
Two jobs for an originating or intermediate provider. First, keep your own certification defensible. Second, check the RMD status of every upstream partner you accept traffic from — accepting traffic from a removed provider puts your own registration at risk.
Know-Your-Upstream-Provider rules and stronger STIR/SHAKEN
The Commission moved to strengthen know-your-upstream-provider obligations alongside STIR/SHAKEN call authentication requirements.
The regulatory logic is straightforward: illegal traffic usually enters the US network through a provider that did not look closely at who handed it the calls. Tightening upstream diligence pushes responsibility back up the chain instead of leaving it entirely with terminating carriers.
For carriers this converts what used to be a commercial judgement — who you peer with — into a compliance obligation you may have to evidence.
What it means for your switch
Keep documented KYC records for every upstream and customer: legal entity, contacts, expected traffic profile, and what you did when the traffic did not match that profile. Records created after an inquiry arrives carry little weight.
A Further Notice of Proposed Rulemaking set out measures to make STIR/SHAKEN a sharper tool against illegal calls, including improved know-your-upstream-provider requirements (WC Docket No. 17-97; CG Docket No. 17-59).
The FNPRM signals that attestation quality itself is under review. A-level attestation is meant to mean the provider knows the customer and the customer's right to use the number — not simply that the call originated on its own switch.
Proposals at this stage are not yet binding rules, but they are the clearest available preview of where compliance expectations are heading.
What it means for your switch
If your platform hands out A attestation broadly, start measuring how much of that traffic you could actually justify. Getting attestation logic right before it becomes mandatory is far cheaper than retrofitting under an inquiry.
FCC cuts off a provider from US networks over robocall rules
The Commission acted to immediately prevent a provider that violated robocall rules from connecting to US networks.
Actions of this kind end a carrier's US business overnight. There is no phased wind-down: other providers are directed to stop accepting the traffic.
The trigger is usually the same — high volumes of illegal traffic, a mitigation program that exists only on paper, and slow or incomplete responses to the Enforcement Bureau.
What it means for your switch
Respond to traceback requests quickly and completely. A provider that can show call detail, attestation decisions, and the action it took on a flagged customer is in a fundamentally different position from one that cannot.
Stricter Robocall Mitigation Database filing requirements take effect
Rules tightening RMD filing requirements — including registration through CORES — were published in the Federal Register.
The changes are aimed at the long-standing weakness of the database: filings that were incomplete, anonymous, or plainly fictional. Tying registrations to verified entity records makes accountability traceable.
Providers that filed years ago and never revisited the entry are the most exposed, because a certification that no longer describes the business is a defective filing.
What it means for your switch
Re-open your RMD entry and read it as an investigator would. Confirm the entity details, contact, and mitigation description still match what you actually do on your switch.
Direct access to numbers now requires robocall and national security compliance
The Commission adopted rule changes so that VoIP providers with direct access to numbering resources must certify robocall, public safety, and national security compliance and disclose ownership information.
Numbers are the raw material of illegal calling campaigns. By attaching compliance certification and disclosure conditions to direct access, the FCC closed a route that let bad actors obtain numbering resources with little scrutiny.
The order sits alongside the STIR/SHAKEN framework rather than replacing it: authentication tells you who signed a call, numbering rules govern who was allowed to hold the number in the first place.
What it means for your switch
If you hold direct access authorisation, review your certifications and ownership disclosures now. If you buy numbers wholesale, expect your supplier to push new diligence questions down to you.
National security cited for the first time in RMD removals
The Enforcement Bureau issued orders removing three Chinese telecommunications providers from the Robocall Mitigation Database, the first time national security grounds were used for removal.
Until this point, removals from the database followed robocall-mitigation failures: bad certifications, unanswered inquiries, illegal traffic. This action introduced a second, separate basis for exclusion.
It matters for risk assessment because it means a partner can lose US network access for reasons unrelated to its call quality or traffic profile.
What it means for your switch
Screen upstream partners for ownership and control, not only for traffic behaviour. Monitor RMD status continuously — a partner can go from valid to removed between two invoices.
FCC reconsiders its telecom cybersecurity ruling after Salt Typhoon
An Order on Reconsideration revisited the Commission's January 2025 cybersecurity action in PS Docket No. 22-329, the proceeding opened in response to the Salt Typhoon intrusions into US carrier networks.
The underlying question is how far the Commission's authority reaches into how carriers secure their own networks, as opposed to what they must report after an incident. The reconsideration narrowed the mandatory reading adopted earlier in the year.
The security expectation itself did not go away. Carriers remain the target: signalling systems, provisioning portals and lawful-intercept infrastructure were all in scope of the intrusions that started this proceeding.
What it means for your switch
Regardless of where the rule lands, treat switch and portal access as a security perimeter: unique credentials per person, MFA on provisioning, logged configuration changes, and alerting on unusual route or trunk edits.
FCC opens a proceeding on branded calling and caller ID presentation
A Further Notice of Proposed Rulemaking asked how caller identification information should be verified and displayed, covering branded calling (CG Docket Nos. 17-59, 02-278, 25-307; WC Docket No. 17-97).
Branded calling puts a verified name and logo on the called party's screen. The proceeding examines what verification should sit behind that display so branding does not become a new spoofing surface.
For originating providers this is the constructive half of the robocall agenda: not just blocking bad calls, but making legitimate enterprise calls identifiable enough to be answered.
What it means for your switch
If you sell enterprise voice, track this docket. Verified branding will depend on the same KYC and attestation records the enforcement rules already demand of you.