robocall-tcpa · Federal Communications Commission · Published 2025-08-19 · Effective 2025-09-18 · 90 FR 40241
Document
Document number
2025-15809
Federal Register citation
90 FR 40241
CFR reference
47 CFR 64
Type
Rule
Action
Final rule.
Category
robocall-tcpa
Publication date
2025-08-19
Effective date
2025-09-18
FCC docket
WC Docket No. 17-97
Abstract
In this document, the Federal Communications Commission (Commission) adopts rules that strengthen the Commission's caller ID authentication requirements by establishing clear practices for providers that rely on third parties to fulfill their STIR/SHAKEN implementation obligations. The rules authorize providers with a STIR/ SHAKEN implementation obligation to engage third parties to perform the technological act of digitally "signing" calls consistent with the requirements of the STIR/SHAKEN technical standards so long as: the provider with the implementation obligation makes the "attestation- level" decisions for authenticating caller ID information; and all calls are signed using the certificate of the provider with the implementation obligation--not the certificate of a third party. The rules also explicitly require all providers with a STIR/SHAKEN implementation obligation to obtain a Service Provider Code (SPC) token from the STIR/SHAKEN Policy Administrator and present that token to a STIR/SHAKEN Certificate Authority to obtain a digital certificate. Additionally, the rules include recordkeeping requirements for third- party authentication arrangements to enable the Commission to monitor compliance with and enforce Commission rules.