STIR/SHAKEN Certificate Revocation and the Trusted CA List Explained
June 25, 2026 · 6 min read
A STIR/SHAKEN certificate is only trustworthy as long as it's valid, properly maintained, and recognized by every party in the call path. Understanding certificate revocation and the Trusted CA List is essential for any provider running their own signing infrastructure — and for anyone evaluating why a partner's calls might suddenly start failing verification.
What Is the Trusted CA List?
The Trusted CA List is the master registry of Certificate Authorities approved by the STI-PA (Iconectiv) to issue STIR/SHAKEN certificates. Verification services check incoming call signatures against certificates issued by CAs on this list — if a certificate wasn't issued by an authority on the Trusted CA List, the call cannot be verified, regardless of how the call was actually signed.
Why Certificates Get Revoked
A certificate can be revoked for several reasons, including the provider's SPC token expiring or being revoked, the provider going out of business or losing its FCC registration status, evidence of certificate misuse or compromised private keys, or the Certificate Authority itself losing its approved status.
What Happens When a Certificate Is Revoked
Once a certificate is revoked, any calls signed with it will fail verification on the receiving end. Depending on the terminating carrier's policies, this can mean the call is delivered without any attestation indicator, flagged as "Unverified," or in stricter configurations, blocked entirely.
Certificate Revocation Lists (CRLs)
Certificate Authorities maintain Certificate Revocation Lists — records of certificates that have been revoked before their natural expiration date. Verification services are expected to check against current CRLs (or use OCSP, the Online Certificate Status Protocol) to confirm a certificate hasn't been revoked since issuance.
Monitoring Your Own Certificate Status
Providers running their own STI certificates should proactively monitor expiration dates, since certificates typically need annual renewal alongside the SPC token. Letting a certificate lapse — even unintentionally — has the same practical effect on call delivery as having it revoked: your outbound calls suddenly lose their attestation and become far more likely to be flagged or blocked.
What This Means If You Use a Hosted/Partial Implementation
If you rely on an upstream provider's certificate (registered as "Hosted" in the RMD), your call deliverability is directly tied to that provider's certificate status. It's worth periodically confirming your upstream partner's certificate remains valid and that they haven't had any compliance issues that could result in revocation.
Best Practices
- Track your SPC token and certificate expiration dates with calendar reminders well before the renewal window closes
- Maintain a direct relationship with your Certificate Authority so renewal notices don't go to an outdated contact
- If you're a reseller, confirm your upstream provider's compliance status periodically rather than assuming it's stable indefinitely
- Keep documentation of your certificate chain in case you ever need to dispute a call-blocking decision with a terminating carrier
Conclusion
Certificate revocation and trust list management are the less-discussed but equally critical half of STIR/SHAKEN compliance. A valid implementation today can become a deliverability problem tomorrow if certificate maintenance isn't treated as an ongoing responsibility.
Need help with this?
Our specialists handle the filings discussed in this article end-to-end.
Start Your Application →