ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

How to register for stir shaken?

Back to InsightsHow to register for stir shaken?

How to register for stir shaken?

Key Facts

Why Unregistered Calls Get Blocked — and What STIR/SHAKEN Registration Actually Is

Outbound calls to past customers are increasingly getting flagged as spam, silenced by carriers, or simply ignored—undermining reactivation efforts before they even begin. This happens because unregistered numbers lack the caller ID authentication that modern phone networks now require to distinguish legitimate outreach from robocalls.

STIR/SHAKEN functions as a digital passport check at the border of the phone network, verifying that a caller has the right to use a specific phone number. Without this authentication, carriers treat the call as unverified and potentially fraudulent, especially when the provider isn’t listed in the FCC’s Robocall Mitigation Database. As a result, downstream networks refuse to exchange traffic with providers missing from the database, effectively blocking calls at the source.

Adoption of STIR/SHAKEN remains uneven, creating a growing trust gap for unregistered traffic. In August 2026, only 54.8% of calls were signed at termination, with Tier-1 carriers signing and verifying 85% of voice traffic compared to just 17.5% for smaller carriers. This disparity means calls from providers using smaller or unregistered carriers are far more likely to be flagged, delayed, or blocked—even when the outreach is legitimate and consent-based.

For businesses relying on voice reactivation, this technical barrier directly impacts reach and response rates. Ensuring your calls are signed with proper attestation isn’t just about compliance—it’s about making sure your message gets heard. CallMyCustomers helps service businesses navigate these requirements by managing outreach under approved scripts and consent-based processes, so every call aligns with both regulatory standards and customer expectations.

The Three Prerequisites: What You Need Before You Can Register

Before beginning the STIR/SHAKEN registration process, providers must meet three essential prerequisites. First, they need an Operating Company Number (OCN), which serves as a unique identifier within the telecommunications industry. Second, they must be certified in the FCC's Robocall Mitigation Database, demonstrating their commitment to preventing illegal robocalls. Third, providers must have a current annual FCC Form 499-A on file, which reports telecommunications revenue and determines Universal Service Fund contributions. These three elements form the foundational pathway required to obtain a provider's own certificate from a STIR/SHAKEN Certificate Authority, a necessity underscored by the FCC's Eighth Report and Order adopted in November 2024 regulatory analysis.

The September 18, 2025 deadline is particularly critical for voice service providers relying on third parties to implement STIR/SHAKEN caller ID authentication. After this date, such providers will no longer be permitted to use third-party certificates for signing calls and must instead secure their own certification through the established prerequisites. This regulatory shift aims to strengthen accountability in the call authentication ecosystem, ensuring that entities responsible for call signing maintain direct oversight of their attestation practices. Industry data shows that while STIR/SHAKEN coverage reached 54.8% of signed calls at termination in August 2026, significant gaps remain—particularly among smaller carriers, where only 17.5% of call traffic was signed in 2025 industry report.

For first-time filers of FCC Form 499-A, an important consideration involves potential retroactive obligations. Providers who submit Form 499-A for the first time to meet STIR/SHAKEN compliance deadlines may be required to file for prior years of service, which could trigger Universal Service Fund contribution liabilities for those periods. This underscores the importance of proactive compliance planning, especially for businesses in sectors like home services, healthcare, and professional services that rely on outbound calling for customer engagement. CallMyCustomers, which manages reactivation campaigns for U.S. service businesses, integrates these compliance requirements into its operational framework to ensure all outreach adheres to current telecommunications regulations. Understanding these prerequisites is not merely procedural—it is a strategic necessity for maintaining network access and avoiding service disruption.

The Registration Process: Getting Your Own Certificate from a Certificate Authority

The registration process for STIR/SHAKEN begins once three key prerequisites are satisfied: obtaining an Operating Company Number (OCN), achieving certification in the FCC's Robocall Mitigation Database, and maintaining a current annual FCC Form 499-A on file. Only after these steps can a voice service provider apply for their own Service Provider Code (SPC) token from a STIR/SHAKEN Certificate Authority (STI-GA), which is essential for signing outbound calls with cryptographic identity tokens. This requirement applies universally, even when businesses delegate the technical signing function to a third-party hosted service.

Industry research confirms that providers must obtain their own certificate rather than relying on a third party's, reinforcing that while technology can be outsourced, responsibility for attestation-level decisions cannot be. As noted in regulatory analyses, expert commentary emphasizes that maintaining control over whether calls receive A, B, or C-level attestation remains the legal obligation of the originating provider, regardless of who performs the signing. This principle aligns with CallMyCustomers' approach to compliance, where clients retain final approval over all messaging while the service handles execution.

The process typically involves submitting an application to a STI-GA-accredited Certificate Authority, including proof of OCN assignment, Robocall Mitigation Database listing, and valid FCC Form 499-A filing. Upon approval, the provider receives their unique SPC token, enabling them to sign calls under their own identity. Recent data shows that as of August 2026, STIR/SHAKEN coverage reached 54.8% of signed calls at termination, underscoring ongoing adoption but also highlighting gaps in full implementation across smaller carriers.

  • Confirm OCN assignment through your telecommunications regulatory authority
  • Achieve and maintain listing in the FCC's Robocall Mitigation Database
  • Ensure your annual FCC Form 499-A is current and accurately filed
  • Apply to a STI-GA-accredited Certificate Authority for your SPC token
  • Integrate the token into your call signing infrastructure or hosted service

Looking ahead, proposed FCC rules signal stricter vetting of SPC token applications, potentially introducing enhanced KYC/KYUP (Know-Your-Customer/Know-Your-Upstream-Provider) requirements and more rigorous validation of applicant legitimacy. These developments reflect a broader trend toward treating STIR/SHAKEN not just as a technical checkbox but as a foundational element of trust in the voice ecosystem—one where accountability for call integrity remains firmly with the provider, even in outsourced models.

After Registration: Attestation Levels and Staying Compliant as Rules Evolve

Getting your certificate is only half the job. What happens after registration — how you sign calls and how you prove you're following the rules — determines whether your numbers stay trusted on the other end of the line.

Every signed call carries an attestation level, and picking the wrong one creates real risk. According to August 2026 SHAKEN statistics, A-level attestation accounts for 33.8% of signed calls, B-level for 5.7%, and C-level for 8.0%. A-level means you've verified the caller's identity and their right to use the number; B confirms the call origin but not full subscriber verification; C means you can only attest that the call originated on your network.

Over-attestation is the industry's quiet failure. A TNS robocall report found that up to 20% of signed traffic in some networks exhibits improper attestation, and as much as 13% of traffic using invalid numbers was signed with A-level attestation in 2025. Signing calls at a level your verification can't support undermines the authentication data downstream carriers rely on.

The regulatory bar is rising. The FCC's proposed expansion of the Robocall Mitigation Database would shift providers from demonstrating "reasonable steps" to implementing "affirmative, effective measures" for robocall mitigation. Removal from the database effectively cuts off a provider's ability to exchange traffic with U.S. networks.

Legal analysts also flag expanded KYUP obligations — Know-Your-Upstream-Provider — and stricter vetting for Service Provider Code tokens. To stay ahead:

  • Re-audit your attestation decisions quarterly against actual subscriber verification records.
  • Document KYUP diligence on every upstream traffic partner before accepting handoffs.
  • Track FCC rulemakings — proposed orders can change compliance obligations with limited notice.
  • Keep your Robocall Mitigation Database certification current, since it gates U.S. traffic exchange.

Here's the honest caveat: STIR/SHAKEN verifies the number, not the intent. As one analysis puts it, it's "essentially a passport check at the border" — it tells the network the caller has the right to use that number, but says nothing about whether they had permission to dial it (First Orion). Scammers even rent clean, verified numbers to bypass filters.

That's why permission-based outreach still matters. At CallMyCustomers, every reactivation campaign runs only against lists of real customers, with opt-outs honored immediately and every message approved by the business owner before it goes out. A properly attested call to a customer who actually wants to hear from you is the combination that gets answered — authentication handles the technical trust, and consent handles the human kind.

What This Means for Your Customer Outreach: Compliant Calls That Actually Get Answered

Compliant calls that actually get answered start with trust, and STIR/SHAKEN registration is how you build that trust at the network level. When your caller ID is verified through proper authentication, past customers are far more likely to pick up—especially when they already know your business. This isn’t just about avoiding spam flags; it’s about ensuring your reactivation campaigns reach real people who’ve chosen you before, with every call and text fully compliant and owner-approved.

For service businesses relying on repeat work, this means win-back campaigns can reconnect with inactive customers in as little as two to four weeks, often seeing replies from the very first wave of outreach. Because CallMyCustomers handles all calling and texting regulations—TCPA, A2P 10DLC, and HIPAA/BAA for clinics—every script, offer, and message is reviewed and signed off by you before anything goes out. Opt-outs are honored immediately, and replies route straight into your existing booking process, so no opportunity slips through the cracks.

The impact of proper call authentication is measurable: STIR/SHAKEN coverage reached 54.8% of signed calls at termination in August 2026, showing steady growth in network-wide trust. Yet disparities remain—only 17.5% of traffic between smaller carriers was signed in 2025, compared to 85% for Tier-1 networks. This gap highlights why verified caller ID matters more than ever for local businesses trying to stand out in a crowded inbox and call log. When your number is properly signed, it signals legitimacy before the phone even rings.

STIR/SHAKEN compliance requires providers to obtain their own certificate from a STIR/SHAKEN Certificate Authority, which hinges on three prerequisites: an Operating Company Number (OCN), certification in the FCC's Robocall Mitigation Database, and a current annual FCC Form 499-A on file. For businesses using third-party voice services, the September 18, 2025 deadline is critical—after this date, providers must have their own certificate to ensure calls are signed and trusted end-to-end.

  • Verify your FCC Form 499-A is current and on file
  • Secure your Operating Company Number (OCN)
  • Ensure certification in the FCC's Robocall Mitigation Database
  • Obtain your own STIR/SHAKEN certificate from a STI-GA
  • Maintain control over attestation levels when using hosted services

By aligning your outreach with these standards, you’re not just checking a compliance box—you’re creating the conditions for real conversations with customers who already value your service. Every approved script, every honored opt-out, every reply routed to your calendar turns past familiarity into present revenue. And because the campaign runs on your terms, with your approval at every step, it feels less like outreach and more like a natural continuation of the relationship.

Frequently Asked Questions

What do I need before I can register for STIR/SHAKEN?
You need three prerequisites in place: an Operating Company Number (OCN), certification in the FCC's Robocall Mitigation Database, and a current annual FCC Form 499-A on file. Only after all three are satisfied can you apply for your own Service Provider Code (SPC) token from a STI-GA-accredited Certificate Authority, per the FCC's Eighth Report and Order.
Can I just use my third-party provider's certificate instead of getting my own?
No — after the September 18, 2025 deadline, voice service providers relying on third parties to sign calls must obtain their own certificate from a STIR/SHAKEN Certificate Authority. You can outsource the technical signing, but regulatory analysis confirms responsibility for attestation-level decisions stays with you as the originating provider.
Why are my legitimate outbound calls getting blocked or flagged as spam?
Unregistered calls lack the caller ID authentication carriers now use to distinguish legitimate calls from robocalls, so they're treated as unverified and potentially fraudulent. Adoption is also uneven: TNS data shows 85% of Tier-1 carrier traffic was signed in 2025 versus just 17.5% for smaller carriers, so calls routed through smaller providers are far more likely to be flagged or blocked.
Is filing FCC Form 499-A for the first time a big deal?
It can be, yes. First-time filers submitting Form 499-A to meet STIR/SHAKEN deadlines may be required to file for prior years of service, which can trigger retroactive Universal Service Fund contribution liabilities for those periods, according to Wiley's regulatory analysis. That's why proactive compliance planning matters before you file.
Does STIR/SHAKEN registration guarantee my calls won't be marked as spam?
Not by itself. STIR/SHAKEN verifies the caller has the right to use a number — it's "essentially a passport check at the border" — but says nothing about whether they had permission to dial, and scammers even rent clean, verified numbers to bypass filters, per First Orion. Authentication handles the technical trust; consent-based outreach (like CallMyCustomers' owner-approved, opt-out-honoring campaigns) handles the human kind.
What should I watch out for after I'm registered?
Over-attestation is the industry's quiet failure — TNS research found up to 20% of signed traffic in some networks exhibits improper attestation, and as much as 13% of traffic using invalid numbers was signed with A-level attestation in 2025. Re-audit your attestation decisions quarterly, document KYUP diligence on upstream partners, and keep your Robocall Mitigation Database certification current, since removal effectively cuts off your ability to exchange U.S. traffic.

Registered, Signed, and Actually Answered: Your Next Step

STIR/SHAKEN registration comes down to three prerequisites—an Operating Company Number, Robocall Mitigation Database certification, and a current FCC Form 499-A—followed by your own certificate from a STI-GA-accredited Certificate Authority. After that, the work continues: choosing attestation levels your verification can actually support, since up to 20% of signed traffic in some networks shows improper attestation, per the TNS robocall report. But remember: authentication verifies the number, not the intent. A properly signed call still needs a customer who wants to hear from you. That's where permission-based outreach earns its keep—calls to real past customers, with honored opt-outs and owner-approved scripts, are the ones that get picked up. If you'd rather focus on reactivating customers than navigating FCC filings, CallMyCustomers handles the compliance side of calls and texts while you approve every message. Start with a free list review to see what your past customers could produce before you spend a dollar.

Stay in the Loop