FCC proposes expanding Robocall Mitigation Database to OTT and cloud providers
The FCC has issued a Further Notice of Proposed Rulemaking to expand the Robocall Mitigation Database, proposing to include OTT providers, cloud platforms, and call centers. The initiative mandates stricter STIR/SHAKEN compliance, enhanced background screening for filers, and an expedited 24-hour response requirement for call traceback requests.
Key Takeaways
- Redefines 'voice service provider' to include PBXs, dialing platforms, and value-added-service providers regardless of end-user interaction
- Estributes a 24-hour mandatory deadline for responding to Industry Traceback Group investigative requests
- Requires separate RMD filings for parent companies, affiliates, and subsidiaries to prevent 'bad actors' from hiding operational links
- Proposes a 'One-Step Removal Process' for quick delisting of providers engaged in egregious conduct without a prior cure period
- Forces filers to implement Robocall Mitigation Plans containing 'affirmative, effective measures' for all illegal calls, not just robocalls
Why It Matters
This move signals a shift from passive registration to active gatekeeping, directly impacting SaaS and OTT companies that utilize PSTN-accessible voice via providers like Twilio or Sinch. By expanding the 'voice service provider' definition, the FCC effectively deputizes these platforms to monitor upstream traffic and verify customer identities. For the streaming and cloud ecosystem, non-compliance now carries the immediate risk of downstream providers being legally prohibited from accepting their traffic. Investors and strategists should monitor the administrative burden of separate corporate filings, which targets obfuscated corporate structures frequently used by high-volume dialers to evade prior enforcement actions.
Additional Context
The FCC’s July 2026 proposal is part of a broader regulatory stack intended to target illegal traffic at every point in the call path. This initiative follows the April 2026 adoption of enhanced 'Know-Your-Customer' (KYC) rules, which specifically focused on vetting the end-user customers who originate calls. Per Mintz (July 2026), these rules now include a proposed minimum fine of $2,500 per call for deficient onboarding. Parallel to this, the FCC’s 'Know-Your-Upstream-Provider' (KYUP) rulemaking, adopted in May 2026, requires providers to verify the RMD status and robocall mitigation plans of the entities they receive traffic from before transmitting it downstream. Simultaneously, the FCC has implemented a mandatory annual recertification cycle for the Robocall Mitigation Database. According to JSI (July 2026), federal filings must now be updated every March 1 to ensure that STIR/SHAKEN implementation certifications and contact details remain current. Providers also face a strict 10-business-day window to report any material changes to their corporate structure or routing practices. This tightening of reporting requirements is paired with increased enforcement, such as the FCC’s recent show-cause orders against entities including Mexico IP, which cited failure to respond to traceback requests as a primary basis for potential removal from the database. The industry response to this regulatory push has been divided. Financial industry groups, including the American Bankers Association, have largely supported stricter vetting to combat fraud losses, whereas consumer advocacy coalitions have warned that uniform identity-verification mandates could disproportionately burden smaller providers. As of July 2026, the FCC is also exploring financial assurance mechanisms, such as letter-of-credit requirements, to prevent fraudulent actors from simply refiling under new names after being debarred from the RMD.
Read full article at wiley.law
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source