US Codex
C.F.R.
Browse by date
Notes

47 C.F.R. §§ 64.6301–64.6305

5 sections in range

§64.6301. Caller ID authentication.

47 C.F.R. § 64.6301

(a)
STIR/SHAKEN implementation by voice service providers. Except as provided in §§ 64.6304 and 64.6306, not later than June 30, 2021, a voice service provider shall fully implement the STIR/SHAKEN authentication framework in its internet Protocol networks. To fulfill this obligation, a voice service provider shall:
(1)
Obtain an SPC token from the Secure Telephone Identity Policy Administrator and use that token to obtain a Secure Telephone Identity certificate from a Secure Telephone Identity Certificate Authority;
(2)
Using the certificate obtained pursuant to paragraph (a)(1) of this section—
(i)
Authenticate and verify caller identification information for all SIP calls that exclusively transit its own network;
(ii)
Authenticate caller identification information for all SIP calls it originates and that it will exchange with another voice service provider or intermediate provider and, to the extent technically feasible, transmit that call with authenticated caller identification information to the next voice service provider or intermediate provider in the call path; and
(3)
Verify caller identification information for all SIP calls it receives from another voice service provider or intermediate provider which it will terminate and for which the caller identification information has been authenticated.
(b)
A voice service provider may fulfill its obligations to authenticate caller identification information under paragraph (a)(2) of this section by entering into an agreement with a third-party authentication service, provided that the voice service provider.
(1)
Requires the third party to sign all calls using the certificate obtained by the voice service provider in accordance with paragraph (a)(1);
(2)
Makes all attestation-level decisions regarding the caller identification information of each SIP call it originates;
(3)
Memorializes the agreement between it and the third party for the authentication service in writing, which:
(i)
Specifies the specific tasks that the third-party authenticator will perform on the voice service provider's behalf, and
(ii)
Confirms that the voice service provider shall make all attestation-level decisions for calls signed pursuant to the agreement, and that all calls shall be signed using the voice service provider's Secure Telephone Identity certificate;
(4)
Maintains any agreement entered into pursuant to paragraph (b) of this section for as long as any third-party authentication arrangement exists; and
(5)
Retains a copy of any agreement entered into pursuant to paragraph (b) of this section for a period of two (2) years from the end or termination of the agreement.
Notes, amendments, and revision history

Amendments

[85 FR 22043, Apr. 21, 2020, as amended at 85 FR 73394, Nov. 17, 2020; 90 FR 40255, Aug. 19, 2025]

Source

Source: 85 FR 22043, Apr. 21, 2020, unless otherwise noted.

Authority

Authority: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228, 251(a), 251(e), 254(k), 255, 262, 276, 403(b)(2)(B), (c), 616, 620, 716, 1401-1473, unless otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091; Pub. L. 117-338, 136 Stat. 6156.

Source

Source: 28 FR 13239, Dec. 5, 1963, unless otherwise noted.

Amendments

[85 FR 22043, Apr. 21, 2020, as amended at 85 FR 73394, Nov. 17, 2020; 90 FR 40255, Aug. 19, 2025]

§64.6302. Caller ID authentication by intermediate providers.

47 C.F.R. § 64.6302

Not later than June 30, 2021, each intermediate provider shall fully implement the STIR/SHAKEN authentication framework in its internet Protocol networks. To fulfill this obligation, an intermediate provider shall:
(a)
Obtain an SPC token from the Secure Telephone Identity Policy Administrator and use that token to obtain a Secure Telephone Identity certificate from a Secure Telephone Identity Certificate Authority;
(b)
Pass unaltered to the subsequent intermediate provider or voice service provider in the call path any authenticated caller identification information it receives with a SIP call, subject to the following exceptions under which it may remove the authenticated caller identification information:
(1)
Where necessary for technical reasons to complete the call; or
(2)
Where the intermediate provider reasonably believes the caller identification authentication information presents an imminent threat to its network security; and
(c)
Authenticate caller identification information for all calls it receives for which the caller identification information has not been authenticated and which it will exchange with another provider as a SIP call using the Secure Telephone Identity certificate it received from the Secure Telephone Identity Certificate Authority pursuant to paragraph (a) of this section, except that the intermediate provider is excused from such duty to authenticate if it:
(1)
Cooperatively participates with the industry traceback consortium; and
(2)
Responds fully and in a timely manner to all traceback requests it receives from the Commission, law enforcement, and the industry traceback consortium regarding calls for which it acts as an intermediate provider.
(d)
Notwithstanding paragraph (c) of this section, a gateway provider must authenticate caller identification information using the Secure Telephone Identity certificate it received pursuant to paragraph (a) of this section for all calls it receives that use North American Numbering Plan resources that pertain to the United States in the caller ID field and for which the caller identification information has not been authenticated and which it will exchange with another provider as a SIP call, unless that gateway provider is subject to an applicable extension in § 64.6304.
(e)
Notwithstanding paragraph (c) of this section, a non-gateway intermediate provider must authenticate caller identification information using the Secure Telephone Identity certificate it received pursuant to paragraph (a) of this section for all calls it receives directly from an originating provider and for which the caller identification information has not been authenticated and which it will exchange with another provider as a SIP call, unless that non-gateway intermediate provider is subject to an applicable extension in § 64.6304.
(f)
An intermediate provider may fulfill its obligations to authenticate caller ID information under paragraphs (d) and (e) of this section by entering into an agreement with a third-party authentication service, provided that the intermediate provider:
(1)
Requires the third party to sign all calls using the certificate obtained by the intermediate provider in accordance with paragraph (a) of this section;
(2)
Makes all attestation-level decisions regarding the caller identification information of each SIP call it originates;
(3)
Memorializes the agreement between it and the third party for the authentication service in writing, which:
(i)
Specifies the specific tasks that the third-party authenticator will perform on the intermediate provider's behalf, and
(ii)
Confirms that the intermediate provider shall make all attestation-level decisions for calls signed pursuant to the agreement, and that all calls shall be signed using the voice service provider's Secure Telephone Identity certificate;
(4)
Maintains any agreement entered into pursuant to paragraph (f) of this section for as long as any third-party authentication arrangement exists; and
(5)
Retains a copy of any agreement entered into pursuant to paragraph (f) of this section for a period of two (2) years from the end or termination of the agreement.
Notes, amendments, and revision history

Amendments

[85 FR 73395, Nov. 17, 2020, as amended at 87 FR 42946, July 18, 2022; 88 FR 40118, June 21, 2023; 90 FR 40255, Aug. 19, 2025]

Source

Source: 85 FR 22043, Apr. 21, 2020, unless otherwise noted.

Authority

Authority: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228, 251(a), 251(e), 254(k), 255, 262, 276, 403(b)(2)(B), (c), 616, 620, 716, 1401-1473, unless otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091; Pub. L. 117-338, 136 Stat. 6156.

Source

Source: 28 FR 13239, Dec. 5, 1963, unless otherwise noted.

Amendments

[85 FR 73395, Nov. 17, 2020, as amended at 87 FR 42946, July 18, 2022; 88 FR 40118, June 21, 2023; 90 FR 40255, Aug. 19, 2025]

§64.6303. Caller ID authentication in non-IP networks.

47 C.F.R. § 64.6303

(a)
Except as provided in §§ 64.6304 and 64.6306, not later than June 30, 2021, a voice service provider shall either:
(1)
Upgrade its entire network to allow for the initiation, maintenance, and termination of SIP calls and fully implement the STIR/SHAKEN framework as required in § 64.6301 throughout its network; or
(2)
Maintain and be ready to provide the Commission on request with documented proof that it is participating, either on its own or through a representative, including third party representatives, as a member of a working group, industry standards group, or consortium that is working to develop a non-internet Protocol caller identification authentication solution, or actively testing such a solution.
(b)
Except as provided in § 64.6304, not later than June 30, 2023, a gateway provider shall either:
(1)
Upgrade its entire network to allow for the processing and carrying of SIP calls and fully implement the STIR/SHAKEN framework as required in § 64.6302(d) throughout its network; or
(2)
Maintain and be ready to provide the Commission on request with documented proof that it is participating, either on its own or through a representative, including third party representatives, as a member of a working group, industry standards group, or consortium that is working to develop a non-internet Protocol caller identification authentication solution, or actively testing such a solution.
(c)
Except as provided in § 64.6304, not later than December 31, 2023, a non-gateway intermediate provider receiving a call directly from an originating provider shall either:
(1)
Upgrade its entire network to allow for the processing and carrying of SIP calls and fully implement the STIR/SHAKEN framework as required in § 64.6302(e) throughout its network; or
(2)
Maintain and be ready to provide the Commission on request with documented proof that it is participating, either on its own or through a representative, including third party representatives, as a member of a working group, industry standards group, or consortium that is working to develop a non-internet Protocol caller identification authentication solution, or actively testing such a solution.
Notes, amendments, and revision history

Amendments

[87 FR 42946, July 18, 2022, as amended at 87 FR 75944, Dec. 12, 2022; 88 FR 40118, June 21, 2023; 90 FR 40256, Sept. 18, 2025]

Source

Source: 85 FR 22043, Apr. 21, 2020, unless otherwise noted.

Authority

Authority: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228, 251(a), 251(e), 254(k), 255, 262, 276, 403(b)(2)(B), (c), 616, 620, 716, 1401-1473, unless otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091; Pub. L. 117-338, 136 Stat. 6156.

Source

Source: 28 FR 13239, Dec. 5, 1963, unless otherwise noted.

Amendments

[87 FR 42946, July 18, 2022, as amended at 87 FR 75944, Dec. 12, 2022; 88 FR 40118, June 21, 2023; 90 FR 40256, Sept. 18, 2025]

§64.6304. Extension of implementation deadline.

47 C.F.R. § 64.6304

(a)
Small voice service providers.
(1)
Small voice service providers are exempt from the requirements of § 64.6301 through June 30, 2023, except that:
(i)
A non-facilities-based small voice service provider is exempt from the requirements of § 64.6301 only until June 30, 2022;
(ii)
A small voice service provider notified by the Enforcement Bureau pursuant to § 0.111(a)(27) of this chapter that fails to respond in a timely manner, fails to respond with the information requested by the Enforcement Bureau, including credible evidence that the robocall traffic identified in the notification is not illegal, fails to demonstrate that it taken steps to effectively mitigate the traffic, or if the Enforcement Bureau determines the provider violates § 64.1200(n)(2), will no longer be exempt from the requirements of § 64.6301 beginning 90 days following the date of the Enforcement Bureau's determination, unless the extension would otherwise terminate earlier pursuant to paragraph (a)(1) introductory text or (a)(1)(i), in which case the earlier deadline applies; and
(iii)
Small voice service providers that originate calls via satellite using North American Numbering Plan numbers are deemed subject to a continuing extension of § 64.6301.
(2)
For purposes of this paragraph (a), “small voice service provider” means a provider that has 100,000 or fewer voice service subscriber lines (counting the total of all business and residential fixed subscriber lines and mobile phones and aggregated over all of the provider's affiliates).
(b)
Voice service providers, gateway providers, and non-gateway intermediate providers that cannot obtain an SPC token. Voice service providers that are incapable of obtaining an SPC token due to Governance Authority policy are exempt from the requirements of § 64.6301 until they are capable of obtaining an SPC token. Gateway providers that are incapable of obtaining an SPC token due to Governance Authority policy are exempt from the requirements of § 64.6302(d) regarding call authentication. Non-gateway intermediate providers that are incapable of obtaining an SPC token due to Governance Authority policy are exempt from the requirements of § 64.6302(e) regarding call authentication.
(c)
Services scheduled for section 214 discontinuance. Services which are subject to a pending application for permanent discontinuance of service filed as of June 30, 2021, pursuant to the processes established in 47 CFR 63.60 through 63.100, as applicable, are exempt from the requirements of § 64.6301 through June 30, 2022.
(d)
Non-IP networks. Those portions of a voice service provider, gateway provider, or non-gateway intermediate provider's network that rely on technology that cannot initiate, maintain, carry, process, and terminate SIP calls are deemed subject to a continuing extension. A voice service provider subject to the foregoing extension shall comply with the requirements of § 64.6303(a) as to the portion of its network subject to the extension, a gateway provider subject to the foregoing extension shall comply with the requirements of § 64.6303(b) as to the portion of its network subject to the extension, and a non-gateway intermediate provider receiving calls directly from an originating provider subject to the foregoing extension shall comply with the requirements of § 64.6303(c) as to the portion of its network subject to the extension.
(e)
Provider-specific extensions. The Wireline Competition Bureau may extend the deadline for compliance with § 64.6301 for voice service providers that file individual petitions for extensions by November 20, 2020. The Bureau shall seek comment on any such petitions and issue an order determining whether to grant the voice service provider an extension no later than March 30, 2021.
(f)
Annual reevaluation of granted extensions. The Wireline Competition Bureau shall, in conjunction with an assessment of burdens and barriers to implementation of caller identification authentication technology, annually review the scope of all previously granted extensions and, after issuing a Public Notice seeking comment, may extend or decline to extend each such extension, and may decrease the scope of entities subject to a further extension.
Notes, amendments, and revision history

Amendments

[85 FR 73395, Nov. 17, 2020, as amended at 87 FR 3693, Jan. 25, 2022; 87 FR 42946, July 18, 2022; 88 FR 40118, June 21, 2023; 90 FR 40256, Aug. 19, 2025]

Source

Source: 85 FR 22043, Apr. 21, 2020, unless otherwise noted.

Authority

Authority: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228, 251(a), 251(e), 254(k), 255, 262, 276, 403(b)(2)(B), (c), 616, 620, 716, 1401-1473, unless otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091; Pub. L. 117-338, 136 Stat. 6156.

Source

Source: 28 FR 13239, Dec. 5, 1963, unless otherwise noted.

Amendments

[85 FR 73395, Nov. 17, 2020, as amended at 87 FR 3693, Jan. 25, 2022; 87 FR 42946, July 18, 2022; 88 FR 40118, June 21, 2023; 90 FR 40256, Aug. 19, 2025]

§64.6305. Robocall mitigation and certification.

47 C.F.R. § 64.6305

(a)
Robocall mitigation program requirements for voice service providers.
(1)
Each voice service provider shall implement an appropriate robocall mitigation program.
(2)
Any robocall mitigation program implemented pursuant to paragraph (a)(1) of this section shall include reasonable steps to avoid originating illegal robocall traffic and shall include a commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to originate calls.
(b)
Robocall mitigation program requirements for gateway providers.
(1)
Each gateway provider shall implement an appropriate robocall mitigation program with respect to calls that use North American Numbering Plan resources that pertain to the United States in the caller ID field.
(2)
Any robocall mitigation program implemented pursuant to paragraph (b)(1) of this section shall include reasonable steps to avoid carrying or processing illegal robocall traffic and shall include a commitment to respond fully and within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to carry or process calls.
(c)
Robocall mitigation program requirements for non-gateway intermediate providers.
(1)
Each non-gateway intermediate provider shall implement an appropriate robocall mitigation program.
(2)
Any robocall mitigation program implemented pursuant to paragraph (c)(1) of this section shall include reasonable steps to avoid carrying or processing illegal robocall traffic and shall include a commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to carry or process calls.
(d)
Certification by voice service providers in the Robocall Mitigation Database.
(1)
A voice service provider shall certify that all of the calls that it originates on its network are subject to a robocall mitigation program consistent with paragraph (a) of this section, that any prior certification has not been removed by Commission action and it has not been prohibited from filing in the Robocall Mitigation Database by the Commission, and to one of the following:
(i)
It has fully implemented the STIR/SHAKEN authentication framework across its entire network and all calls it originates are compliant with § 64.6301;
(ii)
It has implemented the STIR/SHAKEN authentication framework on a portion of its network and all calls it originates on that portion of its network are compliant with § 64.6301(a) and (b); or
(iii)
It has not implemented the STIR/SHAKEN authentication framework on any portion of its network.
(2)
A voice service provider shall include the following information in its certification in English or with a certified English translation:
(i)
Identification of the type of extension or extensions the voice service provider received under § 64.6304, if the voice service provider is not a foreign voice service provider, and the basis for the extension or extensions, or an explanation of why it is unable to implement STIR/SHAKEN due to a lack of control over the network infrastructure necessary to implement STIR/SHAKEN;
(ii)
The specific reasonable steps the voice service provider has taken to avoid originating illegal robocall traffic as part of its robocall mitigation program, including a description of how it complies with its obligation to know its customers pursuant to § 64.1200(n)(4), any procedures in place to know its upstream providers, and the analytics system(s) it uses to identify and block illegal traffic, including whether it uses any third-party analytics vendor(s) and the name(s) of such vendor(s);
(iii)
A statement of the voice service provider's commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to originate calls; and
(iv)
State whether, at any time in the prior two years, the filing entity (and/or any entity for which the filing entity shares common ownership, management, directors, or control) has been the subject of a formal Commission, law enforcement, or regulatory agency action or investigation with accompanying findings of actual or suspected wrongdoing due to the filing entity transmitting, encouraging, assisting, or otherwise facilitating illegal robocalls or spoofing, or a deficient Robocall Mitigation Database certification or mitigation program description; and, if so, provide a description of any such action or investigation, including all law enforcement or regulatory agencies involved, the date that any action or investigation was commenced, the current status of the action or investigation, a summary of the findings of wrongdoing made in connection with the action or investigation, and whether any final determinations have been issued.
(3)
All certifications made pursuant to paragraphs (d)(1) and (2) of this section shall—
(i)
Be filed in the appropriate portal on the Commission's website; and
(ii)
Be signed by an officer in conformity with 47 CFR 1.16.
(4)
A voice service provider filing a certification shall submit the following information in the appropriate portal on the Commission's website:
(i)
The voice service provider's business name(s) and primary address;
(ii)
Other business names in use by the voice service provider;
(iii)
All business names previously used by the voice service provider;
(iv)
Whether the voice service provider is a foreign voice service provider;
(v)
The name, title, department, business address, telephone number, and email address of one person within the company responsible for addressing robocall mitigation-related issues;
(vi)
Whether the voice service provider is—
(A)
A voice service provider with a STIR/SHAKEN implementation obligation directly serving end users;
(B)
A voice service provider with a STIR/SHAKEN implementation obligation acting as a wholesale provider originating calls on behalf of another provider or providers; or
(C)
A voice service provider without a STIR/SHAKEN implementation obligation; and
(vii)
The voice service provider's OCN, if it has one.
(5)
A voice service provider shall update its filings within 10 business days of any change to the information it must provide pursuant to paragraphs (d)(1) through (4) of this section.
(i)
A voice service provider or intermediate provider that has been aggrieved by a Governance Authority decision to revoke that voice service provider's or intermediate provider's SPC token need not update its filing on the basis of that revocation until the sixty (60) day period to request Commission review, following completion of the Governance Authority's formal review process, pursuant to § 64.6308(b)(1) expires or, if the aggrieved voice service provider or intermediate provider files an appeal, until ten business days after the Wireline Competition Bureau releases a final decision pursuant to § 64.6308(d)(1).
(ii)
If a voice service provider or intermediate provider elects not to file a formal appeal of the Governance Authority decision to revoke that voice service provider's or intermediate provider's SPC token, the provider need not update its filing on the basis of that revocation until the thirty (30) day period to file a formal appeal with the Governance Authority Board expires.
(e)
Certification by gateway providers in the Robocall Mitigation Database.
(1)
A gateway provider shall certify that all of the calls that it carries or processes on its network are subject to a robocall mitigation program consistent with paragraph (b)(1) of this section, that any prior certification has not been removed by Commission action and it has not been prohibited from filing in the Robocall Mitigation Database by the Commission, and to one of the following:
(i)
It has fully implemented the STIR/SHAKEN authentication framework across its entire network and all calls it carries or processes are compliant with § 64.6302;
(ii)
It has implemented the STIR/SHAKEN authentication framework on a portion of its network and calls it carries or processes on that portion of its network are compliant with § 64.6302; or
(iii)
It has not implemented the STIR/SHAKEN authentication framework on any portion of its network for carrying or processing calls.
(2)
A gateway provider shall include the following information in its certification made pursuant to paragraph (e)(1) of this section, in English or with a certified English translation:
(i)
Identification of the type of extension or extensions the gateway provider received under § 64.6304 and the basis for the extension or extensions, or an explanation of why it is unable to implement STIR/SHAKEN due to a lack of control over the network infrastructure necessary to implement STIR/SHAKEN;
(ii)
The specific reasonable steps the gateway provider has taken to avoid carrying or processing illegal robocall traffic as part of its robocall mitigation program, including a description of how it complies with its obligation to know its upstream providers pursuant to § 64.1200(n)(5), the analytics system(s) it uses to identify and block illegal traffic, and whether it uses any third-party analytics vendor(s) and the name(s) of such vendor(s);
(iii)
A statement of the gateway provider's commitment to respond fully and within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to carry or process calls; and
(iv)
State whether, at any time in the prior two years, the filing entity (and/or any entity for which the filing entity shares common ownership, management, directors, or control) has been the subject of a formal Commission, law enforcement, or regulatory agency action or investigation with accompanying findings of actual or suspected wrongdoing due to the filing entity transmitting, encouraging, assisting, or otherwise facilitating illegal robocalls or spoofing, or a deficient Robocall Mitigation Database certification or mitigation program description; and, if so, provide a description of any such action or investigation, including all law enforcement or regulatory agencies involved, the date that any action or investigation was commenced, the current status of the action or investigation, a summary of the findings of wrongdoing made in connection with the action or investigation, and whether any final determinations have been issued.
(3)
All certifications made pursuant to paragraphs (e)(1) and (2) of this section shall—
(i)
Be filed in the appropriate portal on the Commission's website; and
(ii)
Be signed by an officer in conformity with 47 CFR 1.16.
(4)
A gateway provider filing a certification shall submit the following information in the appropriate portal on the Commission's website:
(i)
The gateway provider's business name(s) and primary address;
(ii)
Other business names in use by the gateway provider;
(iii)
All business names previously used by the gateway provider;
(iv)
Whether the gateway provider or any affiliate is also foreign voice service provider;
(v)
The name, title, department, business address, telephone number, and email address of one person within the company responsible for addressing robocall mitigation-related issues;
(vi)
Whether the gateway provider is—
(A)
A gateway provider with a STIR/SHAKEN implementation obligation; or
(B)
A gateway provider without a STIR/SHAKEN implementation obligation; and
(vii)
The gateway provider's OCN, if it has one.
(5)
A gateway provider shall update its filings within 10 business days to the information it must provide pursuant to paragraphs (e)(1) through (4) of this section, subject to the conditions set forth in paragraphs (d)(5)(i) and (ii) of this section.
(f)
Certification by non-gateway intermediate providers in the Robocall Mitigation Database.
(1)
A non-gateway intermediate provider shall certify that all of the calls that it carries or processes on its network are subject to a robocall mitigation program consistent with paragraph (c) of this section, that any prior certification has not been removed by Commission action and it has not been prohibited from filing in the Robocall Mitigation Database by the Commission, and to one of the following:
(i)
It has fully implemented the STIR/SHAKEN authentication framework across its entire network and all calls it carries or processes are compliant with § 64.6302;
(ii)
It has implemented the STIR/SHAKEN authentication framework on a portion of its network and calls it carries or processes on that portion of its network are compliant with § 64.6302; or
(iii)
It has not implemented the STIR/SHAKEN authentication framework on any portion of its network for carrying or processing calls.
(2)
A non-gateway intermediate provider shall include the following information in its certification made pursuant to paragraph (f)(1) of this section in English or with a certified English translation:
(i)
Identification of the type of extension or extensions the non-gateway intermediate provider received under § 64.6304, if the non-gateway intermediate provider is not a foreign provider, and the basis for the extension or extensions, or an explanation of why it is unable to implement STIR/SHAKEN due to a lack of control over the network infrastructure necessary to implement STIR/SHAKEN;
(ii)
The specific reasonable steps the non-gateway intermediate provider has taken to avoid carrying or processing illegal robocall traffic as part of its robocall mitigation program, including a description of any procedures in place to know its upstream providers and the analytics system(s) it uses to identify and block illegal traffic, including whether it uses any third-party analytics vendor(s) and the name of such vendor(s);
(iii)
A statement of the non-gateway intermediate provider's commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium, and to cooperate with such entities in investigating and stopping any illegal robocallers that use its service to carry or process calls; and
(iv)
State whether, at any time in the prior two years, the filing entity (and/or any entity for which the filing entity shares common ownership, management, directors, or control) has been the subject of a formal Commission, law enforcement, or regulatory agency action or investigation with accompanying findings of actual or suspected wrongdoing due to the filing entity transmitting, encouraging, assisting, or otherwise facilitating illegal robocalls or spoofing, or a deficient Robocall Mitigation Database certification or mitigation program description; and, if so, provide a description of any such action or investigation, including all law enforcement or regulatory agencies involved, the date that any action or investigation was commenced, the current status of the action or investigation, a summary of the findings of wrongdoing made in connection with the action or investigation, and whether any final determinations have been issued.
(3)
All certifications made pursuant to paragraphs (f)(1) and (2) of this section shall—
(i)
Be filed in the appropriate portal on the Commission's website; and
(ii)
Be signed by an officer in conformity with 47 CFR 1.16.
(4)
A non-gateway intermediate provider filing a certification shall submit the following information in the appropriate portal on the Commission's website:
(i)
The non-gateway intermediate provider's business name(s) and primary address;
(ii)
Other business names in use by the non-gateway intermediate provider;
(iii)
All business names previously used by the non-gateway intermediate provider;
(iv)
Whether the non-gateway intermediate provider or any affiliate is also foreign voice service provider;
(v)
The name, title, department, business address, telephone number, and email address of one person within the company responsible for addressing robocall mitigation-related issues;
(vi)
Whether the non-gateway intermediate provider is—
(A)
A non-gateway intermediate provider with a STIR/SHAKEN implementation obligation; or
(B)
A non-gateway intermediate provider without a STIR/SHAKEN implementation obligation; and
(vii)
The non-gateway intermediate service provider's OCN, if it has one.
(5)
A non-gateway intermediate provider shall update its filings within 10 business days of any change to the information it must provide pursuant to this paragraph (f) subject to the conditions set forth in paragraphs (d)(5)(i) and (ii) of this section.
(g)
Intermediate provider and voice service provider obligations—
(1)
Accepting traffic from domestic voice service providers. Intermediate providers and voice service providers shall accept calls directly from a domestic voice service provider only if that voice service provider's filing appears in the Robocall Mitigation Database in accordance with paragraph (d) of this section and that filing has not been de-listed pursuant to an enforcement action.
(2)
Accepting traffic from foreign providers. Beginning April 11, 2023, intermediate providers and voice service providers shall accept calls directly from a foreign voice service provider or foreign intermediate provider that uses North American Numbering Plan resources that pertain to the United States in the caller ID field to send voice traffic to residential or business subscribers in the United States, only if that foreign provider's filing appears in the Robocall Mitigation Database in accordance with paragraph (d) of this section and that filing has not been de-listed pursuant to an enforcement action.
(3)
Accepting traffic from gateway providers. Beginning April 11, 2023, intermediate providers and voice service providers shall accept calls directly from a gateway provider only if that gateway provider's filing appears in the Robocall Mitigation Database in accordance with paragraph (e) of this section, showing that the gateway provider has affirmatively submitted the filing, and that filing has not been de-listed pursuant to an enforcement action.
(4)
Accepting traffic from non-gateway intermediate providers. Intermediate providers and voice service providers shall accept calls directly from a non-gateway intermediate provider only if that non-gateway intermediate provider's filing appears in the Robocall Mitigation Database in accordance with paragraph (f) of this section, showing that the non-gateway intermediate provider affirmatively submitted the filing, and that filing has not been de-listed pursuant to an enforcement action.
(5)
Public safety safeguards. Notwithstanding paragraphs (g)(1) through (4) of this section:
(i)
A provider may not block a voice call under any circumstances if the call is an emergency call placed to 911; and
(ii)
A provider must make all reasonable efforts to ensure that it does not block any calls from public safety answering points and government emergency numbers.
(h)
Annual Recertification Requirement. In accordance with this section and 47 CFR 1.16, all providers shall certify annually, on or before March 1, that any information submitted to the Robocall Mitigation Database is true and correct.
Notes, amendments, and revision history

Amendments

[87 FR 42946, July 18, 2022, as amended at 88 FR 40119, June 21, 2023; 88 FR 43459, July 10, 2023; 90 FR 40256, Aug. 19, 2025; 91 FR 357, Jan. 6, 2026]

Source

Source: 85 FR 22043, Apr. 21, 2020, unless otherwise noted.

Authority

Authority: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228, 251(a), 251(e), 254(k), 255, 262, 276, 403(b)(2)(B), (c), 616, 620, 716, 1401-1473, unless otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091; Pub. L. 117-338, 136 Stat. 6156.

Source

Source: 28 FR 13239, Dec. 5, 1963, unless otherwise noted.

Amendments

[87 FR 42946, July 18, 2022, as amended at 88 FR 40119, June 21, 2023; 88 FR 43459, July 10, 2023; 90 FR 40256, Aug. 19, 2025; 91 FR 357, Jan. 6, 2026]