As discussed in our previous client advisory, the Federal Communications Commission (FCC) has adopted new rules requiring all Robocall Mitigation Database (RMD) filers to recertify their filings on an annual basis. This initiative is part of the agency’s continued effort to strengthen industry accountability and enhance consumer protection against illegal robocalls.
This year, providers must recertify their RMD filings by March 1, 2026.
Risks for Noncompliance
Failure to recertify by the March 1 deadline may result in removal from the Robocall Mitigation Database, which would obligate other providers to block all traffic from the noncompliant entity. Providers removed from the RMD may face significant business disruption, as reinstatement requires a new filing, FCC review, and can take up to a year (or more) to complete. Noncompliance also exposes providers to potential enforcement action and monetary penalties.
Multi-Factor Authentication
The FCC has also implemented multi-factor authentication for RMD access. Specifically, the new rules require each filer to authenticate its identity, as opposed to simply providing a username and password, by one of two methods: (1) obtain and enter a temporary code generated from the Google Authenticator app; or (2) utilize the Okta Verify authenticator app. The RMD provides links to set up and activate those apps.
Key Action Items
- Appoint a person to manage multi-factor authentication, with CORES credentials linked to their device.
- Coordinate internally among legal, compliance, and technical teams to ensure consistency between the RMD filing and actual operational practices.
- Review your existing RMD filing carefully. Verify that all fields, particularly corporate identifiers, contact details, and robocall mitigation plans, reflect current information and practices.
- Update your robocall mitigation plan, if changes were made since your most recent filing.
- Recertify the RMD filing through the FCC portal by March 1, 2026.
- Engage outside counsel or compliance experts early to avoid last-minute issues.
Conclusion
Recertification is now a mandatory annual obligation for all RMD filers. Providers that fail to act promptly risk substantial operational and regulatory consequences. Our firm assists numerous clients with RMD recertification, STIR/SHAKEN compliance, and ongoing robocall mitigation strategy development.
Contact us for support in reviewing your filing, updating your mitigation plan, or addressing FCC compliance requirements.
NEED HELP WITH ROBOCALL MITIGATION, COMPLIANCE AND LITIGATION SUPPORT/DEFENSE AGAINST BUSINESS & LEGAL CHALLENGES?
The CommLaw Group Can Help!
Given the complexity and evolving nature of the FCC’s rules, regulations and industry policies & procedures around Robocall Mitigation and Compliance issues (e.g., Stir/Shaken, TRACED Act, FCC Rules & Regulations, US Telecom Industry group, ATIS, NECA, VoIP Numbering Waivers, Know Your Customer and the private sector ecosystem), as well as the increased risk of business disputes, consumer protection enforcement by state attorneys general, and even civil litigation, and anticipating the potential torrent of client questions and concerns, The CommLaw Group formed a “Robocall Mitigation Response Team” to help clients (old and new) tackle their unique responsibilities.
CONTACT US NOW, WE ARE STANDING BY TO GUIDE YOUR COMPANY’S COMPLIANCE EFFORTS
Michael Donahue — Tel: 703-714-1319 / E-mail: mpd@CommLawGroup.com
Susan Duarte – Tel: 703-714-1318 / E-mail:sfd@CommLawGroup.com
Rob Jackson – Tel: 703-714-1316 / E-mail: rhj@CommLawGroup.com
Ron Quirk – Tel: 703-714-1305 / E-mail: req@CommLawGroup.com
Diana James – Tel: 703-663-6757 / E-mail: daj@CommLawGroup.com