Print Article
SHARE

Today, the Federal Communications Commission (“FCC” or “Commission”) published in the Federal Register its recently adopted Further Notice of Proposed Rulemaking (“FNPRM”), which seeks to enhance the STIR/SHAKEN framework by imposing more specific “Know-Your-Upstream-Provider” (“KYUP”) obligations. The comments are due on August 10, and the reply comments are due on September 8, 2026 

As discussed in our previous client advisorythe proposed rules would require providers to thoroughly vet and monitor the companies that send them call traffic, verify their information, and cut off those found to be facilitating fraud or illegal activity. 

The proposal should be viewed together with the Commission’sseparate “Know-Your-Customer” (“KYC”) rulemaking, in which our firm has recently represented the Consumer Access & Choice Coalition (“CACC”). Together, the two items reflect a coordinated FCC push to move robocall compliance from a largely policy-and-certification regime toward a more prescriptive verification, monitoring, documentation, and refusal-of-service framework. 

Key Proposals in the FNPRM 

The most consequential proposals center on making “Know Your Upstream Provider” a formal, prescriptive compliance program, expanding it beyond just highvolume robocalls, and tying it tightly to STIR/SHAKEN attestation practices. 

Big-picture shifts 

  • The FNPRM would move KYUP from flexible guidance to a detailed, mandatory program for any provider that accepts traffic from an upstream partner, especially intermediate and transit providers. 
  • Obligations would apply to all illegal calls, not only obviously highvolume robocall campaigns, significantly broadening risk and compliance scope.  

Core KYUP program elements 

The FNPRM frames KYUP around five “baseline” compliance categories: Information Collection, Compliance Review, Verification, Monitoring, and Responsive Action.  

Key proposals include: 

  • Requiring structured, documented procedures to vet upstream providers at onboarding, contract renewal, and whenever new risk information emerges. 
  • Mandating collection and verification of specified business data about each upstream provider, with multiyear recordkeeping. 
  • Expecting continuous monitoring of upstream traffic using call analytics and periodic compliance checks, not just onetime due diligence. 
  • Imposing an “objectively reasonable” standard for when providers must refuse or discontinue service to problematic upstream partners, and requiring those actions to be documented.  

These elements effectively turn KYUP into an ongoing riskmanagement and documentation regime for all transit and intermediate providers, not just a boxchecking exercise. 

STIR/SHAKEN and attestation changes 

Several proposals are particularly consequential for how upstream relationships interact with call authentication: 

  • Codifying the A/B/C attestation standards in the FCC’s rules, including explicit prohibitions on “improper attestation.” 
  • Clarifying and expanding STIR/SHAKEN definitions in the rules to reduce ambiguity about responsibilities along the call path.  
  • Proposing that the provider with the direct relationship to the end user (the “initiating provider,” including resellers) should be the one that determines attestation level, obtains an SPC token or delegate certificate, and effectively drives the attestation decision for its traffic.  

This last change is one of the most crucial ones because it pulls accountability and attestation decisions closer to the actual call originator, which may significantly alter commercial and technical arrangements between resellers, originating carriers, and transit providers. 

Broader scope and ecosystem impact 

  • The FNPRM indicates that KYUP requirements would apply across the entire transit chain, not just to originating or terminating providers, with a particular focus on leastcost routing operators and other intermediaries that accept traffic from multiple upstream sources.  
  • The Commission signals an intent to close remaining STIR/SHAKEN “loopholes,” including by proposing to end certain implementation exemptions (for example for some satellite or tokenineligible providers) and to push toward more universal participation. 
  • Providers would be expected to formalize KYUP as an enterpriselevel compliance function, with coordination between business, legal, and technical teams and retention of evidence of their diligence for multiple years.  

Why these proposals matter in practice 

For upstreamfacing providers, the most consequential aspects to focus on are: 

  • The need for a formal KYUP policy, with specific procedures, thresholds, and documentation for each of the five baseline categories. 
  • Stronger expectations around analyticsbased monitoring of each upstream partner’s traffic, and the obligation to take timely remedial action when patterns suggest illegal calls. 
  • The new alignment between KYUP obligations and attestation decisions, which may force changes in who holds certificates, how calls are signed, and what information resellers must provide to originating providers. 

Comment Opportunities 

The comments are due on August 10, and the reply comments are due on September 8, 2026. Providers may wish to develop comments addressing whether the proposed KYUP categories are workable, how much diligence is reasonable before service initiation or renewal, how providers should handle incomplete upstream-provider responses, how to protect sensitive ownership and financial information, and how the Commission should calibrate enforcement for providers acting in good faith. 

Next Steps 

The CommLaw Group will continue monitoring the Commission’s robocall proceedings closely. Providers should evaluate their current upstream-provider diligence practices, caller ID authentication operations, and RMD disclosures, identifying gaps before the Commission converts these proposals into enforceable compliance obligations. 

Our firm is actively assisting voice service providers, VoIP providers, resellers, gateway providers, intermediate providers, and enterprise communications platforms in assessing robocall mitigation, KYC/KYUP, STIR/ SHAKEN, RMD, and traceback compliance obligations. Providers interested in filing comments, participating in industry advocacy, or evaluating their compliance posture should contact us promptly. 

 

ROBOCALL MITIGATION RESPONSE TEAM

Jonathan Marashlian

jsm@commlawgroup.com

Rob Jackson

rhj@commlawgroup.com

Diana James

daj@commlawgroup.com

Ron Quirk

req@commlawgroup.com