What the two names mean
- STIR — Secure Telephone Identity Revisited. The IETF protocol work: cryptographically signing calling-party information so it can be verified downstream.
- SHAKEN — Signature-based Handling of Asserted information using toKENs. The ATIS framework for deploying STIR across carrier networks in practice.
The mechanism is straightforward in outline. The originating provider signs the call with a certificate, asserting something about how well it knows the caller. The terminating provider verifies that signature and can act on the result — display a verified indicator, label the call, or apply analytics.
Attestation levels: the part that affects you
The signature carries an attestation level, and it is the single most consequential detail for any organization making outbound calls.
| Level | Name | The provider is asserting |
|---|---|---|
| A | Full attestation | It knows the customer and confirms they are authorized to use the calling number. |
| B | Partial attestation | It knows the customer, but cannot confirm the right to use that specific number. |
| C | Gateway attestation | It only knows where the call entered its network. Essentially: "this arrived from somewhere." |
This is worth auditing specifically. Organizations frequently discover that outbound campaigns are underperforming not because of list quality or timing, but because half their calling numbers attract B attestation.
Who has to implement it
Most providers — voice service providers, gateway providers, and intermediate providers that receive unauthenticated calls directly from originating providers — are required to use STIR/SHAKEN to authenticate caller ID information.
Most enterprises are not themselves voice service providers, and reach these obligations through their carrier. But the boundary is less obvious than it looks. Organizations that resell voice, operate as an intermediate in a call path, or originate on behalf of third parties can fall within scope. If there is any doubt about your classification, it is worth confirming rather than assuming.
The Robocall Mitigation Database
The FCC launched the Robocall Mitigation Database in April 2021. Providers file certifications describing the status of their STIR/SHAKEN implementation and their robocall mitigation efforts.
The critical point: all providers in the call chain must file and maintain an RMD certification and plan, regardless of their STIR/SHAKEN implementation status. Having fully deployed STIR/SHAKEN does not exempt you from filing, and not having deployed it does not exempt you either.
Key dates
| Date | Requirement |
|---|---|
| Apr 2021 | Robocall Mitigation Database launched |
| 30 Jun 2021 | Service providers required to complete RMD registration |
| 28 Sep 2021 | Carriers directed to block calls — including internationally originated traffic — from providers not registered in the RMD |
| 18 Sep 2025 | New third-party authentication rules took effect |
| 1 Mar 2026 | Annual RMD recertification deadline |
The September 2021 date is the one with teeth. Other providers may decline to accept call traffic directly from a voice service provider that is not listed in the database. Failing to file also exposes a provider to FCC fines.
Note the annual recertification. This is not a one-time filing — an entry that lapses can lead to traffic being refused, and the failure mode is abrupt rather than gradual.
What an enterprise should actually do
- Inventory every number you present as calling party, and identify which carrier owns each. Multi-carrier and CCaaS arrangements are where mismatches hide.
- Confirm the attestation level your calls receive, per number range, with your outbound provider. Ask directly; do not assume A.
- Fix the records that cause B attestation. This is usually paperwork — establishing with the originating provider that you are authorized to use the numbers — rather than an engineering change.
- Establish whether you are a provider under the rules. If you resell, originate on behalf of others, or sit in a call path as an intermediate, get that determined properly.
- If you file in the RMD, calendar the annual recertification and give it a named owner. Lapses are avoidable and expensive.
- Monitor how your calls are labeled. Answer rates by number range will tell you something is wrong before anyone reports it.
What STIR/SHAKEN does not do
It authenticates the calling number. It does not establish that the caller is honest, that the call is wanted, or that the content is legitimate. A fraudster calling from a number they genuinely own receives full attestation.
It is an identity mechanism, not a fraud filter — which is why robocall mitigation plans are a separate requirement alongside it, and why analytics engines still apply their own judgement on top.
Related reading
- SS7 & call signaling — the trust model this replaces.
- SIP trunking & SBCs — where identity headers are set and normalized.
Sources
- FCC — Combating spoofed robocalls with caller ID authentication
- FCC — Robocall Mitigation Database
- FCC — TRACED Act implementation
- Bandwidth — STIR/SHAKEN and Robocall Mitigation Database filing deadlines
- Viirtue — STIR/SHAKEN compliance requirements (2026) for MSPs and voice resellers
- Davis Wright Tremaine — FCC requires all voice providers to implement STIR/SHAKEN or adopt robocall mitigation plans
Current as of July 2026. Not legal advice. Whether your organization is a "provider" under the FCC's rules is a legal determination — take advice rather than inferring it from a summary.
Underperforming outbound campaigns are often an attestation problem, not a list problem.
Book a call