STIR/SHAKEN Compliance in 2026: What VoIP Providers Must Know Now

August 2, 2026 · 6 min read

STIR/SHAKEN Compliance in 2026: What VoIP Providers Must Know Now

STIR/SHAKEN compliance has moved well past the implementation phase. As of mid-2026, the FCC is actively enforcing call authentication rules, cutting off non-compliant providers from U.S. voice networks, and proposing new upstream accountability mandates that will affect every layer of the call chain — from originating carrier to terminating gateway.

If you operate a VoIP platform, wholesale voice network, CPaaS service, or SIP trunk business, your compliance posture directly affects your ability to pass traffic. This guide covers the current framework, active enforcement trends, and the concrete steps you need to take.

What STIR/SHAKEN Actually Requires

STIR (Secure Telephone Identity Revisited) and SHAKEN (Signature-based Handling of Asserted information using toKENs) is a framework for digitally signing and verifying caller ID information on IP networks. The FCC mandated implementation under 47 CFR Part 64, Subpart CC.

At its core, the framework requires originating providers to attach a cryptographic token — a PASSporT — to SIP INVITE messages. That token carries an attestation level:

  • A (Full Attestation): The provider authenticates the calling party and confirms they are authorized to use the number.
  • B (Partial Attestation): The provider authenticates the call origin but cannot verify the number assignment.
  • C (Gateway Attestation): The provider received the call from outside its network and cannot verify the source.

Terminating providers must verify the signature. If no valid token is present, the call may be labeled as "Unverified" or flagged by downstream analytics engines — which directly affects answer rates for your customers.

Who Must Comply — and Who Gets an Extension

The FCC's implementation timeline distinguished between provider types:

  • Large voice service providers (over 100,000 subscriber lines): Full STIR/SHAKEN implementation was required by June 30, 2021.
  • Small voice service providers (under 100,000 lines): Deadline was June 30, 2023, with extensions available for providers that filed robocall mitigation plans in the Robocall Mitigation Database (RMD).
  • Non-IP networks: Providers operating legacy TDM infrastructure that cannot natively support STIR/SHAKEN may use alternative robocall mitigation measures, but must document this in their RMD filing.

The extension window has closed. Any provider that has not implemented STIR/SHAKEN or filed a compliant RMD entry is currently operating out of compliance and is exposed to enforcement action.

FCC Enforcement Is Escalating in 2026

The enforcement picture in 2026 is materially different from 2021. The FCC is no longer issuing warnings — it is taking operational action.

In June 2026, the FCC cut SK Teleco's access to U.S. voice networks, a direct consequence of robocall compliance failures. Earlier in July 2026, Law360 reported the FCC placing another voice provider on a formal robocall compliance plan — a step that precedes potential network access termination.

Critically, a July 2026 analysis from Mintz noted that enforcement is shifting upstream. The FCC is pushing mitigation responsibility toward providers higher in the call chain, not just the originating carrier closest to the bad actor. This means wholesale carriers and intermediate providers face real liability for traffic they transit.

The FCC also opened comment in July 2026 on a robocall vetting mandate, and separately is weighing a "know your upstream provider" proposal that would require carriers to verify the identity and compliance status of providers they accept traffic from. These proposals, if adopted, will create new due diligence obligations across the entire interconnection ecosystem.

The Robocall Mitigation Database: Your Public Compliance Record

Every voice service provider that originates, carries, or terminates calls on U.S. networks must have an active filing in the FCC's Robocall Mitigation Database registration. This is not optional — downstream providers are required to block traffic from any provider not listed in the RMD.

Your RMD filing must accurately describe:

  • Whether you have fully implemented STIR/SHAKEN or are relying on alternative mitigation measures
  • The specific steps you take to mitigate illegal robocalls
  • Your contact information for traceback requests

Inaccurate or outdated RMD filings are themselves an enforcement risk. If your network has changed — new SIP trunking arrangements, acquired customer base, new international interconnects — your RMD entry needs to reflect current operations.

Compliance Checklist for VoIP Providers and Carriers

Requirement Applies To Status Check
STIR/SHAKEN implementation (signing) All IP-based originating providers Active STI certificate from approved CA?
STIR/SHAKEN verification (terminating) All IP-based terminating providers Verifying PASSporT tokens on inbound SIP?
RMD filing — active and accurate All U.S. voice service providers Filed and current at fcc.gov/robocall-mitigation-database?
Traceback cooperation All providers Responding to USTelecom traceback requests within required timeframe?
Upstream provider vetting Wholesale carriers, aggregators Verifying RMD status of providers you accept traffic from?
FCC Form 499-Q (Q3) Providers with reportable revenue Due August 3, 2026
FCC Form 499-Q (Q4) Providers with reportable revenue Due November 2, 2026
CPNI Certification (annual) All telecommunications carriers Due March 1, 2027
FCC Form 499-A (annual) Providers with reportable revenue Due April 1, 2027

International Operators Entering the U.S. Market

Foreign carriers and international VoIP operators routing calls into the U.S. PSTN face the same STIR/SHAKEN framework at the point of interconnection. A U.S.-based gateway provider accepting your traffic must be able to attest to its origin — if you cannot provide verifiable call source information, your traffic will receive C-level attestation at best, and may be blocked entirely.

The proposed "know your upstream provider" rule would formalize this. International operators should expect U.S. interconnect partners to request compliance documentation, RMD verification, and potentially contractual representations about traffic sources before accepting new volume.

What Comes Next: Identity Mandates and Branded Calling

A June 2026 analysis in Telecom Ramblings raised a structural point worth understanding: as the FCC's identity mandates mature, verified caller ID becomes a commodity rather than a differentiator. Providers who have built revenue around branded calling services need to monitor how FCC identity rules interact with analytics-layer products — the regulatory floor is rising.

The FCC's open comment proceeding on robocall vetting, initiated in July 2026, is the next rulemaking to watch. Providers should consider filing comments or at minimum tracking the docket, as the outcome will directly shape upstream liability standards.

How STIRSHAKEN.AI Supports Your Compliance Program

Maintaining STIR/SHAKEN compliance services requires more than a one-time implementation. Certificate management, RMD accuracy, traceback response procedures, and evolving FCC rulemaking all require ongoing attention from people who understand both the technical stack and the regulatory framework.

STIRSHAKEN.AI provides telecommunications compliance services built specifically for VoIP providers, wholesale carriers, CPaaS platforms, and international operators navigating U.S. requirements. Our work covers STIR/SHAKEN implementation support, RMD filing preparation, 499 filing assistance, and compliance program review — grounded in the actual FCC rules, not generic advice.

If you have questions about your current compliance posture or upcoming deadlines, contact STIRSHAKEN.AI. We will give you a straight answer based on what the rules actually say.

Need help with this?

Our specialists handle the filings discussed in this article end-to-end.

Start Your Application →

Disclaimer: STIRSHAKEN.AI provides filing assistance, compliance guidance, and document preparation services only. We are not a law firm and do not provide legal representation or legal advice. Checker results and SHIELD scores are preliminary decision-support outputs, not regulator determinations, certifications, or guarantees. For legal matters, please consult a qualified telecommunications attorney. All FCC, USAC, and regulatory filings are prepared on your behalf subject to your review and approval.