Certificate Authority — STIR/SHAKEN Registration

Navigating the STIR/SHAKEN certification journey can be intricate, time-consuming, and overwhelming. Our dedicated team takes charge of the entire registration and onboarding process, allowing you to concentrate on your business while we manage all regulatory requirements. Whether you are a VoIP provider, carrier, or telecommunications company, we will guide your organization through every necessary step to secure STIR/SHAKEN certification, enabling you to sign and verify calls.

Start Your Application → Free Compliance Check Talk to a Specialist

Comprehensive End-to-End Registration Service

Our all-inclusive STIR/SHAKEN registration package encompasses:

FRN Registration & Verification

We assist in obtaining and validating your FCC Registration Number (FRN), ensuring compliance with all regulatory standards.

RMD Filing & Compliance

Our team manages your Robocall Mitigation Database (RMD) registration and filing, ensuring adherence to FCC regulations.

OCN Acquisition & Validation

Need an Operating Company Number (OCN)? We facilitate the process and confirm that all necessary information is submitted correctly.

STI-PA Registration

Our experts oversee the complete registration with the Secure Telephone Identity Policy Administrator (STI-PA), ensuring all documentation is accurately completed.

Certificate Authority Registration

We coordinate your registration with the appropriate Certificate Authority (CA) and assist in procuring the certificates needed for STIR/SHAKEN implementation.

STI-PA Testing & Validation

We conduct all required STI-PA testing and validation on your behalf, ensuring your organization meets the technical requirements for certification.

Processing Options

Standard

Normal Processing

Estimated Timeline: 4–6 Weeks

Ideal for organizations with flexible deployment schedules. Our team manages the entire process and keeps you updated on progress.

Priority

Expedited Processing

Estimated Timeline: 2–3 Weeks

For those needing certification quickly, our expedited service prioritizes your application and speeds up processing whenever possible.

Why Choose Us?

Comprehensive Management

We take care of everything, from FRN and RMD registration to STI-PA onboarding and Certificate Authority setup.

No Need for Technical Expertise

You don't have to become a STIR/SHAKEN expert; we handle all paperwork, registrations, coordination, and testing.

Dedicated Support

Our specialists liaise directly with the relevant organizations and service providers to minimize delays and remove uncertainty.

Accelerated Time to Certification

With our experience navigating the certification process, we help you avoid common pitfalls that can delay approval times.

Simple Process

Submit Your Information — Provide basic company and telecommunications details.

We Handle the Registrations — Our team completes all necessary filings, registrations, and onboarding tasks.

We Perform Testing — We coordinate and execute STI-PA testing requirements.

Receive Your Certification — Once approved, you're ready to engage in the STIR/SHAKEN ecosystem.

Stop spending weeks trying to learn the STIR/SHAKEN process and juggling multiple registrations. Let our experts manage the entire certification journey — from FRN and RMD registration to STI-PA onboarding, Certificate Authority registration, and testing.

Sit back, relax, and allow us to get your organization STIR/SHAKEN certified.

💬 Not sure where to start? Our free compliance check → identifies exactly what your company needs.

Frequently Asked Questions

The Robocall Mitigation Database, maintained by USAC for the FCC. Every voice provider must register or risk having traffic blocked by downstream carriers.
Yes, licensed carriers need an OCN to participate in the network and complete STIR/SHAKEN enrollment.
The STI-PA (Secure Telephone Identity Policy Administrator) is the FCC-designated authority that vets voice service providers and authorizes them to receive STIR/SHAKEN certificates. Only approved providers may sign calls with a valid certificate. Eligibility review is strict, and applications are commonly delayed or rejected over incomplete registration data or documentation. STIRSHAKEN.AI manages the entire STI-PA approval process on your behalf, from eligibility review through approval.
Normal Processing: 4–6 Weeks. Expedited Processing: 2–3 Weeks, depending on OCN status and STI-PA review times.
We prioritize RMD registration to restore your standing, then complete the remaining steps.
If you're new to telecom, think of STIR/SHAKEN as the telephone industry's version of the padlock icon in your web browser, helping to prove that a phone call is genuinely coming from the phone number shown on your caller ID. For decades, phone networks trusted whatever caller ID information was provided. Imagine receiving a call where the caller ID says it's from your bank, the IRS, a local hospital, or even your own phone number. Before STIR/SHAKEN, scammers could easily make their calls appear to come from any number they wanted, a practice known as Caller ID Spoofing. A scammer in another country could call thousands of people while displaying a local number, a government agency, or a legitimate business, making people more likely to answer because they thought the call was genuine, leading to an increase in robocalls and phone fraud. STIR stands for Secure Telephone Identity Revisited, the technical standard that digitally signs a phone call, creating a digital signature that certifies the legitimacy of the caller ID. SHAKEN, which stands for Signature-based Handling of Asserted Information Using toKENs, is the framework carriers use to exchange and verify these digital signatures. In simple terms, STIR creates the signature, while SHAKEN verifies and manages it. Here’s a simple example of how it works: say your company owns the phone number 555-555-1234. When you place a call, your VoIP provider receives it and verifies you as a legitimate customer, checking if you own and are authorized to use that phone number. The provider then attaches a cryptographic signature to the call, verifying that you are authorized to use the number. As the call travels across networks, other carriers pass the signature along. When the call reaches the recipient, the receiving carrier checks the signature. If it is valid, the call is trusted; if not, it may be flagged as spam or suspicious. The real-world analogy is sending a package: before STIR/SHAKEN, anyone could label a box as being from Amazon without checks. After STIR/SHAKEN, only an authorized sender can apply a special verified seal, allowing the recipient to determine whether the package really came from Amazon. Attestation levels are assigned when a carrier signs a call, indicating the level of confidence. A-Level Attestation, the highest trust level, is when the carrier knows exactly who the customer is and that the customer owns the phone number. B-Level Attestation is partial, where the carrier knows who the customer is but cannot fully verify ownership of the number. C-Level Attestation, with the lowest trust level, is when the carrier received the call from another network and cannot verify the caller. Telecom companies need STIR/SHAKEN if they operate VoIP, CLEC, CPaaS, Wholesale Voice, or SIP Trunking, as U.S. regulations require voice service providers to authenticate and verify caller ID in their IP networks. Without it, calls may be blocked, labeled as "Spam Risk," have lower answer rates, or lead to regulatory issues. Businesses care because if a doctor’s office makes a call and the number is not properly authenticated, calls may be labeled as spam, and patients may not answer, causing appointment reminders to fail. With STIR/SHAKEN, calls are more trusted, leading to better answer rates and reduced spoofing of business numbers. However, STIR/SHAKEN does not stop all spam calls, a common misunderstanding. It does not determine whether a caller is honest; it only helps verify that the caller is authorized to use the displayed number. A legitimate call can be verified and good, while a scam call can also be verified if the scammer owns a real number. STIR/SHAKEN prevents fake caller IDs but does not eliminate fraud. For VoIP providers, STIR/SHAKEN is now part of basic telecom compliance, requiring them to obtain an SPC token, STIR/SHAKEN certificates, implement call signing, verify inbound calls, and maintain compliance records. Many new VoIP providers register with industry authorities and complete STIR/SHAKEN onboarding to effectively originate traffic. In summary, STIR/SHAKEN is a digital caller-ID authentication system that allows phone carriers to verify whether a caller is authorized to use the phone number shown on caller ID, reducing spoofing and increasing trust in phone calls. If you're working with telecom compliance and STIR/SHAKEN registration services, I can explain the entire ecosystem, including SPC tokens, certificate authorities, policy administrators, service providers, and how a new VoIP company becomes STIR/SHAKEN compliant from start to finish.
If a telecom company wants to place calls onto the U.S. telephone network, an RMD filing is often one of the most important regulatory requirements. It tells the FCC and other carriers that the company is following robocall rules, implementing STIR/SHAKEN, and actively working to prevent illegal calling. Without a valid RMD filing, carriers may block the company's traffic, customers may lose the ability to make calls, and the provider could face serious operational and regulatory consequences. An RMD (Robocall Mitigation Database) filing is a registration that voice service providers must submit to the Federal Communications Commission. The database tells the FCC and the telecom industry how a company is preventing illegal robocalls and whether it has implemented STIR/SHAKEN call authentication. Think of it like this: A driver's license allows you to legally drive. An RMD filing allows a telecom company to legally participate in the U.S. voice network. Without a valid RMD filing, many carriers are prohibited from carrying your calls.
Americans face billions of unwanted calls, including scams, impersonations, and spam, posing security risks. Notable tactics include caller ID spoofing, where scammers disguise their identity. In response, the FCC initiated the STIR/SHAKEN authentication requirements and the Robocall Mitigation Database to trace call origins and reduce fraud. These measures aim to enhance trust in phone communications and protect consumers.
The database is a public registry maintained by the FCC. It contains information about voice service providers, including: Company name Contact information FCC registration information STIR/SHAKEN implementation status Robocall mitigation program details Before many carriers will exchange traffic with another company, they check whether that company has a valid RMD filing.
In general, any company that generates voice traffic entering the U.S. telephone network should assess whether it is required to file a Required Minimum Disclosure (RMD). Common examples of such companies include: VoIP Providers: Hosted PBX providers Business phone service providers Residential VoIP providers SIP Trunk Providers: Companies offering SIP trunking services CLECs (Competitive Local Exchange Carriers): Providers of local exchange services Wholesale Voice Providers: Companies that facilitate voice traffic between other carriers CPaaS (Communications Platform as a Service) Providers: Numerous providers that enable voice calling through their platforms Telecom Resellers: Companies that resell voice services under their own branding If a company is not engaged in voice telecommunications, it generally does not need to file an RMD. Typically, this category includes: Software companies CRM (Customer Relationship Management) providers Web hosting companies E-commerce platforms Marketing agencies
For many telecom companies, the RMD is as crucial as a business license. Without the RMD, a telecom company may find itself unable to operate effectively. This essential document serves multiple purposes. Firstly, it acts as proof of the company's existence, affirming its legitimacy in the industry. Additionally, the RMD provides evidence that the company can be reached, ensuring transparency and accessibility. Compliance with FCC robocall rules is another critical aspect that the RMD addresses, demonstrating that the company adheres to necessary regulations. Lastly, it confirms that the company has implemented required mitigation measures, further emphasizing its commitment to responsible operations.
Imagine opening a trucking company without having a commercial driver's license. You might technically own the business, but you cannot legally operate it. A similar situation can arise in the telecommunications industry. If you are required to have an RMD filing and do not possess one, several issues can occur. Carriers may refuse your traffic, as many upstream providers are prohibited from accepting traffic from non-compliant providers. This could result in your calls being blocked and never reaching their intended destinations. Consequently, your customers might experience failures, such as outbound calls ceasing to function. Additionally, business relationships may be jeopardized, as wholesale carriers often insist on RMD compliance. Lastly, there is a risk of FCC enforcement, as the FCC may investigate instances of non-compliance.
This situation is even more critical than it appears. When a service provider is removed from the industry database, it can set off a cascading series of events that affect the entire telecommunications sector. Consequence 1: Your Removal Becomes Visible Once your status changes, other carriers will instantly notice that your filing is no longer active. This visibility can lead to immediate concerns about your compliance and operational status. Consequence 2: Upstream Providers Receive Notices Providers frequently keep a close watch on the compliance status of those they work with. When a removal is detected, they receive notifications alerting them to potential disruptions or non-compliance, prompting them to reassess their partnerships. Consequence 3: Traffic Restrictions Begin As a consequence of the alerts, carriers may decide to impose traffic restrictions. They might cease accepting calls or data from your network, aiming to protect their own operations from potential risks associated with your non-compliance. Consequence 4: Calls Start Failing The impact becomes evident to customers, who may start experiencing a range of issues such as: Outbound calls that fail to connect Disrupted or incomplete call routing A noticeable decline in the rate of successful call completions These problems can erode customer trust and satisfaction rapidly. Consequence 5: Revenue Loss The ultimate repercussion of these disruptions is financial. When customers find themselves unable to make calls, they are likely to seek more reliable services elsewhere. This migration results in a significant loss of revenue, as well as potential damage to your reputation in the market.
No, FCC rules require voice service providers and intermediate providers to verify that entities sending traffic are properly listed in the Robocall Mitigation Database. This means carriers will be required to block traffic from providers that are not properly registered and listed. Understanding the FCC CPNI Filing The FCC CPNI Filing is an annual certification that telecommunications providers must submit to prove they are safeguarding customer telecommunications information. This requirement serves as a privacy-compliance measure for phone companies, VoIP providers, CLECs, SIP trunk providers, and other telecommunications carriers. Key Points: Purpose: To ensure the protection of sensitive customer calling and account information. Protection Against: Misuse, unauthorized access, and disclosure of customer data.
A STI-PA Token functions as a cryptographically signed authorization document that informs a STIR/SHAKEN Certificate Authority (CA): “This company has been vetted and is authorized to receive a STIR/SHAKEN certificate.” The STI-PA Token provides the necessary authorization to obtain the certificate. Once the certificate is issued, the token is no longer involved in the signing or verification processes for calls. Instead, it is the certificate along with its corresponding private key that your network employs to sign outbound calls within the STIR/SHAKEN framework.
At a high level, a voice service provider must first be vetted and approved by the STI-PA, which confirms the company is a legitimate, properly registered US voice provider. Once approved, the provider is authorized to obtain a STIR/SHAKEN certificate, which is then used to digitally sign outbound calls so downstream carriers can verify the caller ID is legitimate. Each step depends on the one before it: registration must be accurate and consistent, authorization must be current, and certificates must be maintained and renewed or signing stops and calls begin failing verification. The details are technical, exacting, and unforgiving of small errors — which is why most providers have it handled for them. STIRSHAKEN.AI manages the full process end to end, including the registration, authorization, certificate setup and ongoing maintenance.
The STI-PA Token does not sign or authenticate calls, is not presented on live call traffic, and is not exchanged between carriers. It is solely utilized during the certificate issuance process. Simple Analogy Think of the system in this way: STI-PA — DMV | STI-PA Token — Authorization to receive a driver's license | STIR/SHAKEN Certificate — Driver's license | Private Key — Your signature | PASSporT — Signed document | Signed Call — Document you've signed | Verifying Carrier — Person checking your ID
Yes — in practice you do. The administrator portals used for STIR/SHAKEN authorization restrict account access by IP address as a security control, so the IP your company connects from matters. A dynamic IP (the kind most residential and basic business connections use) changes over time, which causes access failures and lockouts. A static IP does not change, and a dedicated IP is both static and not shared with anyone else, which is the strongest option for access control and auditability. Getting this wrong is a common cause of delays. STIRSHAKEN.AI reviews your network setup and configures the correct arrangement as part of onboarding.
Because access to the STIR/SHAKEN administrator portal is locked to your IP address as a security measure. A stable, company-controlled IP means that even if credentials were ever compromised, an unauthorized party still could not log in from elsewhere. It also gives you clean auditability of who accessed your compliance account and when — something regulators and carriers care about. A changing (dynamic) IP breaks that model and can lock you out of your own account at the worst possible moment. STIRSHAKEN.AI handles this configuration for you so it is right the first time.

Ready to Get Started with
STIR/SHAKEN Registration?

Our specialists handle every step so you stay compliant and connected.

Disclaimer: STIRSHAKEN.AI provides filing assistance, compliance guidance, and document preparation services only. We are not a law firm and do not provide legal representation or legal advice. Results may vary. For legal matters, please consult a qualified telecommunications attorney. All FCC, USAC, and regulatory filings are prepared on your behalf subject to your review and approval.