Legal Articles

FCC Proposes to Transform the RMD into a Rigorous Compliance Gatekeeper

Rather than functioning principally as a repository for STIR/SHAKEN certifications and robocall-mitigation plans, the FCC proposes to make the RMD a more active screening, verification, and enforcement tool

On September 9th, the FCC published a Further Notice of Proposed Rulemaking (“FNPRM”) on the Robocall Mitigation Database (“RMD”). Initially circulated on July 1st, the FNPRM signals a substantial shift in how the Commission views the RMD.

Rather than functioning principally as a repository for STIR/SHAKEN certifications and robocall-mitigation plans, the FCC proposes to make the RMD a more active screening, verification, and enforcement tool—one that may determine whether a provider can continue to exchange voice traffic in the U.S. network. The proceeding is not yet a final rule, but it would materially expand the compliance burden and market-access consequences associated with RMD participation.

Why the FCC is Concerned

The RMD was established in 2021 to support implementation of the TRACED Act and the FCC’s caller-ID-authentication rules. It requires voice service providers to certify their STIR/SHAKEN implementation status, describe their robocall-mitigation program, identify responsible personnel, and provide related information intended to help providers and regulators prevent illegal robocall traffic from entering or moving through U.S. networks.

The FCC’s concern is that the current system relies too heavily on provider self-certification. Although the RMD contains important information, the Commission believes filings can be incomplete, inaccurate, stale, internally inconsistent, or insufficiently specific to permit meaningful vetting. A filing’s presence in the Database can currently carry major commercial significance because intermediate and terminating providers generally may not accept traffic directly from a provider whose RMD certification is absent or has been removed. Yet the Commission is concerned that mere submission of a filing has not always ensured that the provider is legitimate, understands its obligations, has an effective mitigation program, or is capable of responding to traceback and enforcement requests.

The FNPRM also reflects the FCC’s concern that problematic actors may exploit corporate complexity, reselling arrangements, indirect numbering access, third-party platforms, or other features of the modern voice ecosystem to avoid scrutiny. The Commission accordingly asks whether RMD obligations should be applied more clearly and broadly to entities that furnish or enable voice communications using North American Numbering Plan (“NANP”) resources—even if they do not own network facilities, do not directly hold numbering resources, use upstream providers for transmission or authentication, or characterize themselves as technology platforms, information-service providers, or call-center operators.

In short, the FCC appears concerned that the RMD can be used as a low-friction entry point into the voice ecosystem without enough up-front validation, continuing oversight, or reliable consequences for inaccurate representations and illegal-call activity.

Proposed RMD Reforms

The FNPRM contains a broad set of reforms designed to address specific problems with the RMD identified by the Commission.  If these solutions are adopted, they will make RMD filings more informative, more verifiable, and more consequential.

Uncertainty over which entities must file: Clarify and potentially expand the categories of entities treated as voice service providers subject to RMD and illegal-call obligations, focusing on whether an entity furnishes or enables voice communications using NANP resources rather than on labels, facilities ownership, or direct customer relationships.

Corporate structures may obscure responsibility: Require separate filings where individual parents, affiliates, or subsidiaries independently qualify as voice service providers, rather than allowing a single filing to stand in for an entire corporate family.

Filings may be incomplete or unreliable:  Require expanded certifications and disclosures, including information about principals, related entities, network roles, regulatory history, numbering arrangements, third-party vendors, and STIR/SHAKEN practices.

Claimed STIR/SHAKEN exemptions may lack support: Require a provider claiming partial or no implementation to identify the specific exemption relied upon and explain the provider-specific facts supporting that claim.

New filings may enter the RMD without enough vetting:  Allow FCC staff to place submissions in pending status, withhold publication, reject filings, or conduct more extensive review where a submission appears deficient, evasive, unauthorized, or associated with a previously removed provider.

Inconsistencies across FCC and industry records may go undetected: Consider automated validation and cross-checks against CORES, Form 499, STIR/SHAKEN authorization records, numbering information, and other reliable sources.

Removal and enforcement tools may be too limited or slow: Codify broader grounds for suspension, removal, audits, and reinstatement restrictions, including inaccurate filings, failure to update or recertify, illegal-call transmission, inadequate mitigation, traceback failures, lack of candor, and failure to cooperate with investigations.

Removed or high-risk providers may reenter under new identities:  Consider stronger anti-reentry measures, additional ownership and principal disclosures, and enhanced scrutiny of filings connected to previously removed entities or individuals.

These proposals would turn the RMD submission into a significantly broader compliance representation. A provider could be required to certify not only the existence of a mitigation plan and its STIR/SHAKEN status, but also compliance with applicable FCC rules concerning illegal calls, caller-ID authentication, call blocking, traceback cooperation, and related regulatory obligations.

More Detailed Ownership and Contact Disclosures

The FCC proposes considerably more granular company and personnel disclosures. Potential requirements include identifying a human principal and providing that person’s title, phone number, email address, physical address, country of residence, and citizenship; identifying other principals and corporate affiliates; and identifying the business addresses and RMD identifiers of related entities. The Commission also seeks comment on requiring a U.S. registered agent and may consider government-issued identification for principals.

The policy objective is apparent: make it harder for an entity to file anonymously, obscure who controls it, or return to the marketplace after an RMD removal under a new company name or affiliated entity.

More Support for Exemption Claims

The Commission is particularly focused on providers reporting only partial STIR/SHAKEN implementation or relying on an exemption. Under the proposal, a provider would need to identify the rule authorizing the exemption and give facts specific to its network and operations. The FCC emphasizes that small size, indirect number access, use of an upstream provider, or lack of an SPC token does not automatically establish a valid basis for an exemption.

The FNPRM also considers a limited temporary pathway for a new provider that is actively pursuing an SPC token. Such an applicant could be required to provide its Operating Company Number and explain the steps it has taken to obtain token authorization, with possible suspension or removal if it does not secure the token and timely update its RMD filing.

Pre-publication Screening and Validation

Perhaps the most operationally consequential proposal is to permit FCC staff to place a new or modified filing into a pending status, withhold its publication, or reject it pending further review. Under that approach, a provider could submit an RMD filing but not immediately obtain the practical benefits associated with an active, publicly appearing filing.

The FCC is considering screening for incomplete or inconsistent information, unauthorized use of another party’s identity, connections to removed providers, and other indications that a filing warrants scrutiny. It also seeks comment on supporting documentation, additional vetting, and even a standby letter of credit or similar financial-assurance requirement.

For legitimate new entrants, resellers, hosted-voice providers, CPaaS businesses, and other non-facilities-based providers, this could create longer onboarding timelines, increased documentation demands, and potentially significant barriers to commencing or expanding service. Because downstream providers commonly rely on RMD status in deciding whether to accept traffic, an unpublished, pending, suspended, or removed filing can have immediate commercial consequences.

Faster Suspension and Removal Mechanisms

The FNPRM would also formalize a much broader list of grounds for RMD removal or related enforcement. Proposed grounds include:

-       Incomplete, deficient, inaccurate, or internally inconsistent RMD submissions.

-       Material inconsistencies between RMD information and information submitted to the FCC or other designated entities.

-       False statements or lack of candor.

-       Failure to timely update a filing or complete annual recertification

-       Failure to respond fully to traceback requests.

-       Transmission of illegal calls.

-       Inadequate robocall-mitigation measures or failure to follow the provider’s own stated mitigation plan.

-       Failure to cooperate with an FCC investigation.

-       Unauthorized use of another entity’s identity or identifying information.

-       STIR/SHAKEN implementation, authentication, or attestation violations.

-       National-security or law-enforcement concerns.

-       Repeated violations after reinstatement.

The Commission proposes an expedited process that, in many circumstances, could give a provider only five days to cure or respond before removal. It also seeks comment on an even faster, one-step removal process for particularly egregious conduct, as well as temporary suspensions during review.

These proposals materially increase the importance of accuracy and consistency. A provider whose mitigation plan says one thing, whose RMD certification says another, and whose actual practices differ from both could face a heightened risk of an enforcement inquiry or removal proceeding.

Practical Implications

The proposed reforms have implications far beyond traditional incumbent, wireless, and interconnected VoIP providers. The Commission’s discussion could encompass entities operating as VoIP resellers, MVNOs, PBX providers, cloud-communications and CPaaS platforms, dialing-platform providers, call centers, number-service providers, over-the-top communications providers, and value-added voice-service providers when their activities furnish or enable voice communications using NANP resources.

Companies in the voice ecosystem should therefore assume that the FCC may increasingly examine substance rather than nomenclature. A business may not avoid RMD-related scrutiny solely because it does not own facilities, relies on an upstream carrier, lacks a direct retail relationship with the ultimate caller or recipient, or describes itself primarily as a software provider.

The FNPRM also reinforces that reliance on a vendor does not transfer accountability. Providers would remain responsible for their filings and compliance representations even where consultants, counsel, STIR/SHAKEN vendors, analytics providers, traceback contractors, or other third parties help prepare submissions or operate compliance functions.

The central business message is that an RMD filing may no longer be treated as a static administrative submission. The FCC is positioning it as a market-access credential that can affect a provider’s ability to establish carrier relationships, originate or exchange traffic, obtain or retain caller-ID-authentication credentials, and maintain access to numbering and related communications infrastructure.

What Happens Next

The FNPRM was published in the Federal Register on September 9, 2026. Initial comments are due October 9, 2026, and reply comments are due November 9, 2026. Interested parties should file in WC Docket Nos. 24-213 and 17-97 and CG Docket No. 17-59. Comments will be especially useful if they provide concrete evidence on:

-       The practical boundaries of the proposed “voice service provider” definition.

-       The burdens on legitimate small providers, resellers, hosted-voice providers, and new entrants.

-       The reliability and due-process safeguards needed before a filing is withheld, suspended, rejected, or removed.

-       The costs and implementation time required for expanded disclosures, recordkeeping, vendor oversight, and data validation.

-       Appropriate cure periods, reinstatement procedures, confidentiality protections, and appeal mechanisms.

-       Whether a financial-assurance or standby-letter-of-credit requirement would deter illegal callers without creating an unnecessary barrier to legitimate competition.

-       How the FCC can distinguish bad actors from providers experiencing technical, administrative, or third-party data discrepancies.

After the initial and reply-comment cycle closes, the FCC will evaluate the record and could issue a further notice, public notice, order, or report and order adopting some or all of the proposals.

The scope and timing of a final rulemaking cannot be predicted with certainty. Given the Commission’s sustained focus on illegal robocalls, caller-ID authentication, upstream-provider diligence, and RMD enforcement, however, the likely direction is toward more detailed filings, more verification, more aggressive enforcement, and greater consequences for companies whose RMD records do not accurately reflect their real-world operations.