BlogsIndustry InsightsUS Regulatory Compliance for Wholesale Voice T…

US Regulatory Compliance for Wholesale Voice Termination: STIR/SHAKEN, FCC Rules & E911

US wholesale voice providers face regulatory obligations that international-only carriers don't: STIR/SHAKEN attestation, FCC registration, and E911 compliance. Here's what to verify before signing.

Get Started
SOFTTOPINDUSTRY INSIGHTS
SOFTTOP BLOG
US Regulatory Compliance for Wholesale Voice Termination: STIR/SHAKEN, FCC Rules & E911
US Regulatory Compliance for Wholesale Voice Termination: STIR/SHAKEN, FCC Rules & E911
SK
Author - Shoeb Khan
Published: June 8, 2026

1Introduction

US-bound voice traffic carries rules that international-only routes never face. Say a carrier only sends calls to Europe or Asia. It answers to a different rulebook than one carrying traffic to US phone numbers.

If you are choosing a wholesale voice provider for US traffic, the rules often matter more than the rate card. Some providers cannot show proper FCC registration, STIR/SHAKEN attestation, and 911 compliance. That is not just a paper risk. Your calls can get labeled as spam. Downstream carriers can block your traffic. And your business can inherit liability it never signed up for.

This guide covers the US rules for wholesale voice termination. It explains what the STIR/SHAKEN attestation levels mean. It covers what the FCC's Robocall Mitigation Database asks for. It shows how E911 duties under Kari's Law and RAY BAUM'S Act apply to voice providers. And it lists the documents to request before you send a provider any traffic.

TL;DR

US wholesale voice traffic carries three duties that international-only routing does not. They are STIR/SHAKEN caller ID attestation, FCC Robocall Mitigation Database registration, and E911 location rules under Kari's Law and RAY BAUM'S Act. Before you send traffic, ask any US-facing provider for three things in writing. Their FCC registration. Their current attestation level. And their Robocall Mitigation Database filing.

2STIR/SHAKEN Attestation Levels: What A, B, and C Actually Mean

Why Caller ID Authentication Became a Regulatory Requirement

STIR/SHAKEN is the caller ID check the FCC requires US voice service providers to run. It was built to stop the illegal caller ID spoofing behind the robocall wave. Here is how it works. The provider that starts a call signs it with an attestation level. That signature travels with the call, so the carrier at the other end can verify it. Frameworks like this sit on top of core signaling standards such as SIP (RFC 3261), which sets out how call setup data moves across IP voice networks.

STIR/SHAKEN attestation framework for US wholesale voice traffic

Full Attestation (A), Partial Attestation (B), and Gateway Attestation (C)

Full Attestation (A) is the strongest. The originating provider has checked who the caller is, confirmed the caller may use that number, and can vouch for the whole call.

Partial Attestation (B) is weaker. The provider has checked the customer placing the call but cannot confirm that customer owns the number being used. This is common when a call comes from a customer the carrier has verified, but not on number ownership.

Gateway Attestation (C) is weakest. It applies when a call arrives from outside the provider's own network — an international gateway, for example. The provider cannot verify the origin at all. It can only say that it accepted the call and passed it on.

Attestation level has practical consequences for traffic ending on US numbers. Calls carrying low attestation, or none at all, are more and more likely to be blocked or tagged "Spam Likely" by the mobile carriers that deliver them. That happens even when the call is legitimate business traffic.

3How Attestation Level Affects Call Deliverability and Answer Rates

Attestation level is not just a compliance checkbox. It shapes whether your calls get answered at all. Mobile carriers treat it as one of the strongest signals in their spam filters. So a drop from Full to Partial or Gateway can measurably cut your answer rate, even when nothing else about the call has changed.

  • Full Attestation (A): most terminating carriers treat this traffic as trusted. It rarely triggers a spam-likely label on its own.
  • Partial Attestation (B): this traffic draws more scrutiny. High call volumes and unusual calling patterns raise the risk further.
  • Gateway Attestation (C): common on calls arriving from international legs. It faces the highest risk of being flagged, because the terminating carrier can see least about where the call really started.
  • Attestation can drop mid-relationship if your provider's own upstream checks change. Confirm the level periodically, not just at onboarding.

Attestation is only one input into deliverability. It pays to weigh a provider's overall route quality alongside it. ASR, PDD, and CLI data cover the rest of what decides whether your US-bound calls actually connect.

4FCC Registration and the Robocall Mitigation Database

Registration Requirements Under the TRACED Act

The TRACED Act told the FCC to build the machinery behind STIR/SHAKEN enforcement. One result is that voice service providers must file with the FCC's Robocall Mitigation Database (RMD). The filing states whether the provider has rolled out STIR/SHAKEN across its network. If it has not, the filing must set out what it does instead to curb robocalls.

The database has teeth. Providers in the middle and at the end of the call path are expected to reject traffic from anyone not listed in the RMD. So a wholesale voice provider without a current, accurate filing risks having its traffic blocked further down the path. That risk passes straight to any business routing calls through it.

Why This Differs From International Wholesale Voice

Carriers that only handle non-US destinations face no FCC registration and no Robocall Mitigation Database at all. Those are US-specific duties, layered on top of the general carrier relationships covered in our overview of Wholesale VoIP Carriers. A provider that carries both US and international traffic must meet the US rules on the US-bound part specifically. So ask which parts of the network are FCC-registered, and which are purely international transit.

5E911 Compliance: Kari's Law and RAY BAUM'S Act Obligations

Kari's Law: Direct 911 Dialing and Notification

Kari's Law asks two things of multi-line telephone systems. Users must be able to dial 911 directly, with no prefix first. And the system must alert a named person or on-site location whenever someone places a 911 call. The duty sits mainly with the equipment and how it is configured. Even so, any voice provider supporting MLTS deployments for US customers must make sure its platform does not interfere with direct 911 dialing.

E911, Kari's Law, and RAY BAUM'S Act compliance requirements for US voice providers

RAY BAUM'S Act: Dispatchable Location

RAY BAUM'S Act goes further. It requires a dispatchable location to travel with every 911 call. That means an address precise enough for first responders to find the caller, not just a general service address. The rule covers fixed, nomadic, and interconnected VoIP services. If your business has several offices, remote employees, or softphone users who call from changing places, your voice platform needs a reliable way to attach and update that location.

These duties apply to the US market only. Most international wholesale voice deals have no equal, because emergency calling and the rules behind it are built country by country.

6How to Verify E911 Location Accuracy for Remote and Multi-Site Teams

Dispatchable location is not a one-time setup step. It has to stay accurate as employees move between offices, work remotely, or use softphones from changing places. This matters most for distributed teams. A stale or default address on file can send first responders to the wrong building entirely.

  • Ask how often location data can be updated for nomadic or softphone users, and whether updates apply in real time or after a delay.
  • Test a 911 call from a secondary office or a remote desk. Check that it reports that address, not the company's main registered one.
  • Ask whether the platform can tell a general service address apart from a true dispatchable location, down to the floor or room where that is required.
  • Check that the on-site alert required by Kari's Law reaches the right designated person at each site, not one company-wide contact.

For the federal source behind these duties, the FCC's official Kari's Law and RAY BAUM'S Act guidance sets out the exact dispatchable location and notification rules a provider's platform has to support.

7Compliance Documentation to Demand From a US-Facing Provider

Spoken assurances are not enough. If an upstream provider falls short, your own business carries part of the regulatory exposure. So before you route US-bound wholesale voice traffic through any carrier, request the following in writing:

Compliance documentation checklist for US wholesale voice providers
  • Current FCC registration status, plus the operating company number (OCN) or equivalent identifier used in their FCC filings.
  • Proof of their Robocall Mitigation Database filing. This should include the attestation practices they declared and the date they last filed.
  • The STIR/SHAKEN attestation level they usually apply to traffic like yours. Ask what would make it drop from A to B or C.
  • A description of how they handle E911 and dispatchable location for any interconnected VoIP or MLTS traffic they carry.
  • Written confirmation of how they answer and act on traceback requests from the FCC or industry traceback consortiums. Cooperating with traceback work is a core expectation of the framework.

Watch how a provider answers. One that produces these documents promptly and in detail is showing that compliance is built into how it operates. One that points instead to marketing claims about being "fully compliant" is treating it as an afterthought.

8Ongoing Compliance Monitoring After You Sign

Collecting documentation at onboarding is only the starting point. FCC registration status, attestation practices, and Robocall Mitigation Database filings can all change after a contract is signed. A provider slipping out of compliance will not necessarily announce it.

  • Re-verify RMD filing status periodically. Do not assume a provider's first filing stays current indefinitely.
  • Watch for unexplained shifts in attestation level or answer rates on US-bound traffic. Both can signal a change in upstream compliance practices.
  • Ask providers to notify you if their attestation practices or FCC registration status change. Put that expectation in writing when you sign.
  • Revisit the same due-diligence questions on a regular cadence. Compliance posture is not a one-time evaluation.

The red flags worth watching for before signing are worth re-checking afterward. See our vendor due-diligence checklist for the warning signs that a provider's compliance and operational practices are slipping.

9Conclusion

US regulatory compliance is a different exercise from comparing rates, routing quality, or platform features. It is a separate set of legal and operational duties, and they apply for one reason: the traffic touches the US telephone network. STIR/SHAKEN attestation, FCC Robocall Mitigation Database registration, and the E911 rules under Kari's Law and RAY BAUM'S Act each carry consequences if a provider falls short. Those consequences can land on your business as much as on the provider's.

Treat compliance documentation the way you treat a rate deck. Ask for it in writing. Ask for specifics rather than general assurances. And revisit it periodically, because registration status and attestation practices change. A provider carrying both US and international traffic should be able to explain clearly which duties apply to which portion of your traffic, and back that up with documentation rather than a sales pitch.

10Frequently Asked Questions

What is STIR/SHAKEN attestation and why does it have levels?

STIR/SHAKEN is a caller ID authentication framework. It lets the provider that starts a call sign it cryptographically, showing how sure it is of the caller's identity. There are three levels: Full (A), Partial (B), and Gateway (C). They exist because providers can see different amounts about who is really placing a call, especially when traffic arrives from another carrier.

What is the FCC Robocall Mitigation Database and who has to file with it?

The Robocall Mitigation Database is a registry the FCC maintains. Voice service providers file details there about their STIR/SHAKEN implementation and how they curb robocalls. Providers that are not listed risk having their traffic rejected further along the call path. That makes RMD registration a practical requirement for anyone carrying US-bound traffic.

Do international wholesale voice providers need to comply with US STIR/SHAKEN and FCC rules?

Only for the portion of their traffic that touches the US telephone network. A provider that routes calls solely between non-US destinations faces no FCC registration and no STIR/SHAKEN. But the moment a call is bound for a US number, those requirements apply to whichever provider handles that leg.

What do Kari's Law and RAY BAUM'S Act require of a voice provider?

Kari's Law says multi-line telephone systems must support direct 911 dialing with no prefix, and must trigger an on-site notification when someone calls 911. RAY BAUM'S Act says a dispatchable location — precise enough for first responders — must travel with 911 calls, including those from VoIP and nomadic services. Both are US-specific duties tied to the domestic 911 system.

What documentation should I request from a wholesale voice provider before routing US traffic through them?

Ask for four things at minimum: their FCC registration status, their current Robocall Mitigation Database filing, the STIR/SHAKEN attestation level they usually apply, and how they handle E911 dispatchable location for any VoIP traffic they support. If a provider cannot produce that in writing, treat it as a compliance risk whatever the advertised rates.

Keep Reading

You might also like

All posts
Wholesale VoIP Minute Billing: Per-Minute vs. Bundled Plans
Industry Insights

Wholesale VoIP Minute Billing: Per-Minute vs. Bundled Plans

Two providers quoting the same headline rate can bill wildly different amounts for the same call. Learn how billing increments, prepaid vs. postpaid bundles, and committed-minute overage terms decide your true cost per minute.

May 21, 2026Read
VoIP Termination Vendor Due Diligence: How to Spot Red Flags Before You Sign
Industry Insights

VoIP Termination Vendor Due Diligence: How to Spot Red Flags Before You Sign

Signing with the wrong VoIP termination vendor rarely looks like a mistake on day one — it looks like a great rate sheet. Here's the due-diligence checklist for spotting shell resellers, inflated interconnect claims, and bait-and-switch pricing before you commit any volume.

June 8, 2026Read
Wholesale VoIP Rates Compared: Per-Minute vs. Tiered vs. Volume Pricing
Industry Insights

Wholesale VoIP Rates Compared: Per-Minute vs. Tiered vs. Volume Pricing

Wholesale VoIP rate sheets rarely mean what they appear to mean. This guide breaks down how per-minute, tiered, and committed-volume pricing actually work, where FAS fees and billing increments hide, and how to compare rate sheets apples-to-apples.

June 8, 2026Read

Ready to put these insights to work?

Start a free 14-day trial — no credit card needed. Every feature unlocked from day one.