Print Article
SHARE

Companies that previously may have viewed themselves as outside the FCC’s Robocall Mitigation rules — including “information service” providers, communications platforms, call centers, SaaS providers, AI platforms, and other businesses incorporating PSTN-accessible voice functionality through NANP telephone numbers supplied by providers such as Twilio, Bandwidth, Sinch, Telnyx, and others — may soon lose that safe haven.

New proposal would broaden RMD accountability, expand the universe of entities expected to file, increase filing detail, scrutinize third-party filings, and create new risks of suspension, removal, downstream blocking, and enforcement exposure.

On July 1, 2026, the Federal Communications Commission released a draft Further Notice of Proposed Rulemaking proposing substantial changes to the Robocall Mitigation Database (“RMD”) framework. The proposal is part of the FCC’s continuing effort to strengthen its illegal robocall prevention regime by making the RMD a more reliable, accurate, and enforceable compliance tool.

The draft item is scheduled for consideration at the FCC’s July open meeting and, if adopted, comments will be due 30 days after Federal Register publication, with reply comments due 60 days after publication. The Commission emphasizes that the document remains subject to change until adopted, but the direction of travel is clear: the FCC wants the RMD to become less of a passive registry and more of an active gatekeeping, enforcement, and provider-vetting system.

For voice service providers, VoIP providers, resellers, MVNOs, platform providers, call centers, dialing platforms, cloud communications providers, wholesale carriers, numbering partners, and companies that rely on third-party telecom arrangements, this is not a narrow robocall compliance update. It’s a broader compliance architecture proposal that could materially affect market access, downstream interconnection, customer onboarding, STIR/SHAKEN implementation, traceback response, and the continued ability to transmit traffic over the U.S. voice network.

The Commission’s central premise is straightforward: all providers in the voice ecosystem should be identifiable, accountable, reachable, and removable if they submit inaccurate filings, fail to meet mitigation obligations, or are connected to illegal traffic. That theme runs throughout the proposal.

At a practical level, the stakes are significant. Under the existing rules, downstream providers may accept traffic only from providers whose RMD filings appear in the Database and haven’t been removed by FCC enforcement action. The draft FNPRM would build on that framework by proposing tighter filing obligations, more detailed disclosures, stronger certification requirements, enhanced screening, and improved removal tools for bad actors and non-compliant providers.

1. The FCC is signaling a broad view of who must file in the RMD

One of the most important parts of the FNPRM is the Commission’s discussion of which entities qualify as “voice service providers” for purposes of the RMD and related illegal-call rules.

The FCC expresses concern that some entities involved in voice communications may still not view themselves as “voice service providers,” even where they furnish, enable, initiate, originate, carry, process, or otherwise support voice communications using NANP resources. The Commission states that the relevant analysis does not turn on traditional telecom labels, service classification, technology, facilities ownership, or whether the company holds a particular FCC authorization.

In other words, “we’re not a carrier,” “we’re just a platform,” “we’re only a reseller,” “we’re an information service,” “we don’t own the network,” or “our upstream provider handles that” may not be enough.

The draft specifically identifies a wide range of services and entities that may fall within the voice ecosystem, including traditional wireline, wireless, and VoIP providers, but also PBXs, dialing platforms, cloud service providers, over-the-top providers, call centers, value-added service providers, and telephone number service providers, to the extent they furnish or enable voice communications using NANP resources.

That’s a meaningful development. It means companies that historically viewed the RMD as a “carrier problem” may need to reassess whether their products, customer relationships, numbering arrangements, call flows, and commercial roles create an independent RMD filing obligation.

2. Non-facilities-based providers, VoIP resellers, and MVNOs remain squarely in the FCC’s sights

The draft FNPRM reinforces that RMD obligations are not limited to facilities-based carriers. The FCC expressly discusses non-facilities-based providers, including interconnected VoIP resellers and MVNOs, as part of the broader provider universe subject to the Commission’s illegal-call rules.

This is especially important for companies that sit between a wholesale provider and an end user. Many resellers, managed service providers, communications platforms, UCaaS providers, CPaaS providers, and mobile resellers may assume that their upstream carrier’s compliance posture is enough. The FCC is continuing to push in the opposite direction. If the reseller or platform provider is providing voice service, serving end users, enabling use of NANP numbers, making attestation-level decisions, controlling customer relationships, or otherwise participating in the call path, the Commission may expect an independent compliance showing.

The proposed rules would also require providers to more accurately identify their roles in the call chain. Providers may need to disclose whether they are facilities-based, non-facilities-based, originating, terminating, gateway, intermediate, retail-facing, wholesale-facing, or some combination of those roles. The FCC recognizes that provider status may vary on a call-by-call basis, which means providers may not be able to rely on a single simplistic label.

3. Related entities may need separate RMD filings

The FCC proposes to codify the requirement that parents, affiliates, and subsidiaries that independently meet the definition of a voice service provider must each file separately in the RMD.

This is a critical point for corporate families, multi-brand service providers, affiliated resellers, roll-up platforms, holding company structures, and providers that operate through multiple subsidiaries or DBAs. The Commission is plainly concerned that related-party structures can obscure responsibility, hide relationships with prohibited entities, or allow bad actors to re-enter the voice ecosystem under a different name.

The proposal seeks comment on whether specific identifiers should be used to evaluate filing obligations, including OCNs, FRNs, Form 499 Filer IDs, and SPC token authorizations. The FCC also notes a discrepancy between the number of RMD filings claiming full or partial STIR/SHAKEN implementation and the much smaller number of providers appearing on the Governance Authority’s authorized provider list. That gap appears to be raising questions about whether providers are sharing SPC tokens, misunderstanding STIR/SHAKEN implementation status, or making incomplete or inaccurate RMD certifications.

4. Third-party RMD filings are likely to receive increased scrutiny

Many providers rely on consultants, counsel, compliance vendors, or other third parties to prepare and submit RMD filings. The FCC is now looking directly at that practice.

The draft FNPRM asks whether third parties should be permitted to complete RMD filings; whether only an officer should be allowed to sign the filing under penalty of perjury; whether third-party preparers should be identified in the RMD submission; whether the third party’s FRN should be disclosed; and whether bad actor third parties should be barred from preparing filings.

This is a major issue. RMD filings are not clerical registrations. They contain certifications, mitigation representations, traceback commitments, business identity information, ownership disclosures, provider role information, STIR/SHAKEN implementation claims, and robocall mitigation plans. A filing prepared by a third party who does not understand the provider’s actual network, traffic, customers, contracts, numbering arrangements, or upstream/downstream relationships can create serious exposure.

The provider remains responsible for the filing. Outsourcing the drafting does not outsource the obligation.

5. The FCC proposes stronger certifications and broader bases for removal

The draft FNPRM proposes several new or revised certification obligations.

First, providers serving end users directly may be required to certify compliance with any new STIR/SHAKEN attestation obligations adopted in the related Know Your Upstream Provider proceeding. This is particularly relevant for non-facilities-based providers that may not perform the technical act of signing calls but may nevertheless play a role in determining attestation levels or providing customer-specific information necessary for proper signing.

Second, providers may need to certify they have not submitted false, misleading, or inaccurate information to the FCC, FCC-designated agents, the Industry Traceback Group, NANPA, or the STIR/SHAKEN Governance Authority. This “lack of candor” certification would give the FCC a more direct basis to act against providers that submit inaccurate information not only to the Commission, but also to key entities in the robocall mitigation ecosystem.

Third, providers may need to certify compliance with all applicable FCC rules pertaining to robocalls and illegal calls, including rules in Parts 52 and 64. This would create a broader compliance certification, not merely a statement about the contents of the RMD filing.

Fourth, the FCC proposes to simplify and strengthen traceback-related obligations. Providers would certify that they will respond within 24 hours to traceback requests from the FCC, law enforcement, and the industry traceback consortium, and that they will cooperate in investigating and stopping illegal calls transmitted over their network or services. The FCC also seeks comment on whether providers should be required to participate in the Industry Traceback Group’s automated traceback response process as a condition of being listed in the RMD.

The takeaway is simple: the FCC is considering turning the RMD filing into a more robust compliance certification vehicle. Inaccurate or stale filings may become easier enforcement targets.

6. STIR/SHAKEN exemption claims would need to be more precise and better supported

The draft FNPRM identifies a problem many industry participants have seen in practice: some providers claim STIR/SHAKEN exemptions without clearly identifying a valid exemption or explaining why the exemption actually applies.

The FCC notes that being a small provider or lacking direct numbering resources is not, by itself, a valid basis for claiming a STIR/SHAKEN implementation exemption. The Commission also notes that merely stating that the provider lacks an SPC token or that downstream providers perform STIR/SHAKEN authentication does not necessarily qualify as a valid exemption.

The FCC proposes to require providers claiming an exemption to cite the specific rule supporting the exemption and explain in detail why the exemption applies based on facts specific to the provider’s network and services. Providers would also need to describe steps taken to confirm that they cannot implement STIR/SHAKEN, where applicable.

This is a key compliance issue. Many RMD filings were prepared quickly, updated unevenly, or based on assumptions that may no longer be valid. Providers that claim partial or no STIR/SHAKEN implementation should revisit their filings now, before the FCC’s enforcement posture tightens further.

7. A new temporary SPC token exemption may help new providers, but it may also create new deadlines

The FCC proposes a temporary exemption for providers that are in the process of obtaining an SPC token. The Commission recognizes a practical problem: providers may need to be listed in the RMD to satisfy Governance Authority requirements for SPC token access, but may not yet be able to certify full STIR/SHAKEN implementation because they do not yet have the token.

The proposed temporary exemption would require providers to describe the steps they have taken to obtain an SPC token and provide their OCN. The FCC also seeks comment on how long the temporary exemption should last and whether filings should be suspended or removed if the provider does not update its filing after obtaining token access or after a specified period.

For new providers, this could be useful. But it also creates a likely compliance clock. Providers claiming a temporary exemption should be prepared to document their token pursuit, track timelines carefully, and update the RMD promptly.

8. Business identity, ownership, principal, and registered agent information may become much more detailed

The draft FNPRM proposes to codify and expand requirements to disclose principals, affiliates, subsidiaries, and parent companies. The FCC is particularly focused on human principals and asks whether providers should have to disclose title, phone number, email address, physical address, country of residence, and citizenship for those individuals.

The FCC also asks whether providers should have to provide government-issued identification, photos with IDs, prior business names, DBAs, and additional information about parents, affiliates, and subsidiaries.

Separately, the FCC proposes requiring providers to identify a U.S. registered agent with a U.S. mailing address, telephone number, and email address. The Commission frames this as especially important for enforcement against foreign entities and providers that may be using nominal U.S. offices or shared addresses to appear domestic.

For legitimate providers, these proposals may feel burdensome. But the FCC’s concern is obvious: bad actors can hide behind shell entities, virtual offices, incomplete ownership disclosures, and serial refilings under new names. The Commission wants more data points to connect the dots.

9. Numbering resources and upstream/downstream relationships may become part of RMD transparency

The FCC seeks comment on whether providers should have to submit information about access to and use of numbering resources in the RMD. This could include whether numbers are obtained directly or indirectly, which providers supply numbers, what blocks or ranges are used, whether numbers are made available wholesale to resellers, and whether number-related relationships involve affiliated entities.

This would be a meaningful expansion of RMD functionality. It would also connect the RMD more directly with the FCC’s broader numbering, KYC, KYUP, traceback, and robocall mitigation initiatives.

Providers that obtain numbers through wholesale arrangements, RespOrg relationships, reseller channels, affiliated numbering entities, or third-party platforms should pay close attention. The FCC is increasingly focused on the relationship between number access and illegal traffic.

10. Providers should treat this as an opportunity to audit before the rules change

The FNPRM is not yet final, and the details may change. But providers should not wait until final rules are adopted to assess exposure. The proposal reflects the FCC’s current enforcement and policy priorities, and many of the risks discussed in the draft already exist under current rules.

Providers should consider reviewing:

  • Their current RMD filing for accuracy, completeness, and consistency.
  • Their STIR/SHAKEN implementation status and any claimed exemption.
  • Their robocall mitigation plan and whether it describes actual operational practices.
  • Their traceback response process, including ability to respond within 24 hours.
  • Their KYC and KYUP processes.
  • Their upstream and downstream provider relationships.
  • Their numbering arrangements and use of NANP resources.
  • Their corporate structure, affiliates, subsidiaries, DBAs, FRNs, Form 499 Filer IDs, OCNs, and SPC token status.
  • Their reliance on third-party consultants, vendors, or counsel for RMD submissions.
  • Their customer-facing and reseller-facing contracts, especially where customers, resellers, MSPs, call centers, or platforms may be using voice services in ways that affect robocall risk.

This is also a good time for providers to evaluate whether they should file comments. Small and mid-sized providers, legitimate VoIP resellers, MVNOs, MSP-channel providers, CPaaS platforms, call centers, wholesale providers, and numbering partners may all have useful real-world information to provide the FCC, particularly on cost, implementation timelines, third-party filing practices, automated traceback participation, and how to distinguish responsible providers from bad actors without creating unnecessary barriers to entry.

Call Out: The RMD is becoming a front-line enforcement tool

The Commission’s proposal confirms what has been increasingly clear for some time: the RMD is no longer just a filing database. It is becoming a central enforcement, vetting, interconnection, and market-access mechanism.

An inaccurate RMD filing can create regulatory risk. A deficient mitigation plan can create enforcement risk. A stale certification can create blocking risk. A weak traceback process can create escalation risk. And a provider that gets removed from the RMD may find itself functionally cut off from the U.S. voice network.

CALL TO ACTION!

CommLaw Group’s Robocall Mitigation Response Team is available to assist providers with evaluating the FNPRM, preparing comments, reviewing and updating RMD filings, assessing STIR/SHAKEN implementation or exemption claims, strengthening robocall mitigation plans, developing KYC/KYUP procedures, and responding to FCC, ITG, traceback, downstream carrier, or enforcement-related inquiries.

Providers that are uncertain whether their current RMD filing accurately reflects their business, network, customers, numbering arrangements, or robocall mitigation practices should not wait for the FCC to ask questions.

Please contact CommLaw Group’s Robocall Mitigation Response Team to schedule a privileged review of your RMD compliance posture and determine whether proactive corrective action or participation in the FCC proceeding is advisable.

ROBOCALL MITIGATION RESPONSE TEAM

 

Jonathan Marashlian

jsm@commlawgroup.com

Rob Jackson

rhj@commlawgroup.com

Diana James

daj@commlawgroup.com

Ron Quirk

req@commlawgroup.com