appliedbits
DISPATCH  ·  Regulatory Watch PUBLISHED
PUBLISHED 2026-08-15

Week ending August 14, 2026

Comments on the KYUP FNPRM closed Monday, and two dozen of them hit WC 17-97 and CG 17-59 over 48 hours. The FNPRM (FCC 26-32, released May 21) proposed three things: a prescriptive know-your-upstream-provider checklist binding every voice service provider in the call chain, a rule obligating providers to prevent all illegal calls, and codification of the ATIS attestation levels into the Commission’s rules. The record now has an answer to each.

The trade associations want a safe harbor, not a checklist

CTIA, USTelecom, NCTA, ACA Connects, WISPA and the Voice on the Net Coalition all filed on August 10, and they converged on the same structure: keep the KYUP rule flexible, build baseline practices through industry, and give providers that adopt them a safe harbor from enforcement.

USTelecom put it most directly — the FNPRM “proposes prescriptive, static KYUP requirements detached from marketplace realities.” Its alternative is to move the judgment somewhere else entirely. An improved Robocall Mitigation Database, USTelecom argued, “would provide the Commission’s definitive judgment regarding whether a provider should be allowed in the ecosystem, eliminating the need for duplicative KYUP rules.” That points at the RMD FNPRM (FCC 26-49, released July 23) as the place where upstream vetting should actually be settled, with the ITG best-practices process supplying the operational content in the meantime.

CTIA ran the same argument with a sharper edge on the second proposal. A one-size-fits-all rule “could provide a roadmap for bad actors,” and a strict-liability standard for illegal calls “would punish legitimate providers.” NCTA warned about proposals that “depart from industry standards, impose unworkable obligations, and expose providers to disproportionate forfeitures.” WISPA argued from the small-carrier end — requirements calibrated to the largest providers would force smaller ones out of the voice market.

Numeracle filed the counterargument and titled it plainly: flexibility has failed, baseline KYUP rules are overdue. Keith Buell’s comments make the mechanism explicit. The existing rule asks for “reasonable and effective steps” and leaves the content to each provider’s judgment, and “the providers whose diligence matters most — the ones profitably interconnected with the sources of illegal traffic — have treated flexibility as permission to do nothing.” Numeracle wants rules rather than best practices, elimination of the “high volume” limitation, defined minimums replacing “regularly” and “timely,” and a narrowed explanation escape hatch in the information-collection requirement. It also asks the Commission not to let compliance costs become “a new termination-side toll.”

Telnyx attacked the operational assumptions instead of the policy. The compliance-review and monitoring obligations “assume the existence of industry data sources that do not currently exist.” The responsive-action framework “improperly treats unadjudicated allegations as grounds for mandatory service termination.” And the five-business-day notice requirement cuts against what a provider already needs to do when it finds unlawful traffic, which is act immediately.

The certificate layer says it cannot judge traffic it never sees

The STI-GA filed 43 pages, and most of them are about what a governance authority is positioned to know. It was established “as a voluntary, industry-led governance body for the STIR/SHAKEN trust framework, not as a general-purpose investigative or enforcement agency.” It asks to keep “administering only objective rules for SPC token eligibility, token revocation, and Certification Authority compliance,” and to leave “broader robocall enforcement, including enforcement of the Commission’s rules, to the Commission and law enforcement.”

The FNPRM cited staff concern that some CAs issue a disproportionate number of certificates used on improperly attested calls. The STI-GA’s answer: “The FNPRM incorrectly associates a provider engaging in illegal robocalling with a failure of a Certification Authority or a violation of the Certificate Policy. This association does not exist.” A CA assigns certificates and reports revocations. It “is not involved in the call flow and therefore has no means of knowing how its provider clients are using the certificates assigned to them,” which is why the Certificate Policy “does not attempt to require an STI-CA to monitor its provider-clients’ behavior.”

The same argument answers the FNPRM’s proposal to deny tokens or CA status where there is a reasonable basis to believe an entity is “unlikely to comply.” The GA “cannot and should not speculate about whether an entity is likely to be a rule-breaker,” and it names the failure mode: “The risk of competitive harm is too great if all a competitor must do to affect another’s operations is to allege that the other company is somehow unlikely to comply with a rule.” Absent objective criteria, the GA says it would be drawing inferences from anecdotal evidence or from statements by the applicant’s competitors.

The legal-authority argument is in there, and it is scoped to these proposals. Section 251(e) “concerns numbering administration”; section 227(e) reaches parties that spoof or cause misleading caller ID to be transmitted, and the GA “is not in the call flow at all”; ancillary authority does not reach a body that “has no legal existence — it is an industry group formed under the auspices of ATIS.” But the GA pairs that with “viable, better alternatives available to address the governance concerns raised in the FNPRM that do not require the Commission to have such authority,” and its own recommendation is to defer the governance proposals until the KYUP and RMD rules are adopted and their effectiveness can be evaluated. On timing, any implementation needs more than six months.

VON made the procedural version. The STI-GA “is not intended to act as an enforcement authority, gatekeeper or fact finder,” and it was not created by Congress. If the Commission wants a body that follows its rules and acts at its behest, VON argued, “the Commission must establish a third party body and adopt rules governing that body through formal rulemaking, similar to what it has done with the ITG, the Local Number Portability Administrator, and the Universal Service Administrative Company.”

INCOMPAS and the Cloud Communications Alliance aimed at a different target: the KYUP duties on voice service providers. Requiring providers to check that competitors comply with the Commission’s service rules — not just the robocall rules — and then make “objectively reasonable” determinations to cut them off is “an unprecedented delegation of federal enforcement authority to the private sector,” with the Commission playing “no role in a provider’s decision to stop providing service to the upstream provider.” Their phrase for it is “the role of judge, jury and executioner.” Their remedy is to move KYUP obligations to the RMD or to a new independent entity.

The Cross Border Call Authentication Governance Authority filed separately and described itself as “a non-jurisdictional governance authority with a structure similar to the STI-GA,” built on ATIS-1000087 with an oversight committee whose founding members are Google, Microsoft, RingCentral and Bandwidth. Thomas Goode signed the STI-GA, ATIS and CBCA filings.

Codify the attestation levels — or don’t touch them

The ATIS Joint IP-NNI Task Force, which wrote the SHAKEN standards, urged the Commission “not to require service providers to incorporate requirements that are unrelated to identifying the end user or upstream service provider into the attestations requirements of, or are otherwise inconsistent with, ATIS-1000074.” CTIA argued that codifying the levels would hinder ATIS’s ability to revise them, and added that A-level attestations “do not guarantee caller legitimacy or reputation and were never intended to do so.” VON took the opposite side and supported codification, on the theory that clear standards keep the majority of providers signing calls.

Somos argued for codification and then for going past it. The filing starts from the Commission’s own definition of attestation as a provider’s assertion about what it knows, and draws the consequence: “Even a properly applied A-level attestation is a vouching, not proof.” Codifying the A/B/C levels, specifying how each criterion is satisfied, defining improper attestation and prohibiting pay-for-attestation all make the opinion more reliable — but the trustworthiness stays capped because the assertion remains an opinion. Somos’s proposed move is “from opinion to authentication: telephone-number-based credentials that cryptographically establish a specific entity’s right to use a specific number and carry that proof to the point where the attestation decision is made.” The organizing rule it asks the Commission to adopt is that no call should enter the network unless it has been authenticated and the party placing it is authorized to do so — two conditions, not one. The filing treats delegate certificates as first-party authentication rather than third-party, issued by STI-GA-authorized certificate authorities, available to enterprise customers, and it argues that contracts, letters of authorization and customer certifications should not establish right-to-use on their own. VESPER gets named as the path forward under a mechanism-neutral rule.

Delegate certificates showed up in filings that share nothing else. WISPA called them “a practical, immediately implementable solution that would preserve competition without compromising authentication.” ACA Connects named them as one mechanism for communicating an initiating provider’s attestation decision to the originating provider, alongside the initiating provider getting its own SPC token. Sorenson’s TRS filing runs 17 mentions of them.

ZipDX led with a proposal no other filer made: the largest terminating providers “must offer to their subscribers a tool that diverts calls according to the reputation of the signer of each call.” It also proposed hard routing rules — a provider may use a route that cannot propagate a signature only when no SHAKEN-capable route exists, and an intermediate provider may pass a call onward only if it already carries a signature.

TextNow proposed a single principle for the definitional questions: how a provider’s calls are treated, whether it may hold signing credentials, whether it may be cut off, and what penalties it faces “should each turn on what the provider does, not on the category it occupies.” Pinger made the same case from facts — it holds its own SPC token and STI certificates, and “every attestation decision for Pinger traffic is made by Pinger, the provider that knows the customer, and executed with Pinger’s credentials.”

Four relay providers answered paragraph 123

The FNPRM asked, at paragraphs 123 and 124, how the STIR/SHAKEN requirements apply to TRS providers. Sorenson/CaptionCall, Hamilton Relay, InnoCaption and ZP Better Together all answered, and they agree on the diagnosis.

Hamilton Relay drew the line by service type. For IP CTS, the current framework “generally reaches the right result, so long as the user’s voice service provider assigns the attestation the call has earned.” For PSTN-based relay it does not: “the conferenced nature of these calls means they cannot satisfy the criteria for A-level attestation.” InnoCaption explained why the obvious fix fails — TRS providers “cannot obtain Service Provider Code (‘SPC’) tokens, as they do not meet the STIR/SHAKEN Governance Authority’s requirements to obtain a token,” and many lack control over the underlying network. All four ask the Commission not to fold TRS providers into the revised definition of “voice service provider” at paragraph 124.

ZP Better Together quoted the Notice back at the Commission: downstream filtering of unsigned VRS calls “disproportionately harm[s] individuals with disabilities.” Its ask is a mandate that TRS calls receive A-level attestation from their underlying providers, and no new certification obligations on TRS providers, which it grounds in §225(b)(1)’s requirement that relay be provided in the most efficient manner.

Sorenson and CaptionCall, through John Nakahata, filed the structural version and cross-listed it into eight dockets. VRS and IP CTS providers “perform the functions of an initiating provider.” A-level attestation “consists of three components that can be performed by different providers” — which means the Commission can require originating providers to recognize a trusted certificate carrying the TRS provider’s attestation of end-user verification, rather than forcing the relay provider into a role it cannot occupy. The alternative Sorenson offers is expanding SPC token eligibility to internet-based TRS providers, with an interim mandate of A-level attestation for authenticated relay calls. It also argues the existing VRS and IP CTS user-registration and identity-verification regimes already satisfy KYC and KYUP.

The Bureau filed the IP transition workshop into the authentication docket

On Wednesday the Wireline Competition Bureau filed the letter and full transcript of the two-day IP Transition Workshop held at FCC headquarters July 15 and 16. It is filed in WC 26-96, 25-311, 25-304, 25-208, 17-97 and 10-90. The Bureau put the call authentication docket in the transition cluster.

Bandwidth made the connection explicit in its KYUP comments, devoting a section to the proposition that completing the orderly transition to all-IP will enable end-to-end STIR/SHAKEN, which it calls the best available tool against fraudulent calling. Bandwidth also asked the Commission to “more explicitly coordinate its KYC, KYUP, RMD, and numbering rulemakings.” VON came at the same interdependence from the other end, asking the Commission not to block calls routed over the legacy network until the shift to internet-based calling is complete.

The retirement side of the transition produced a filing in WC 25-209. A resident of southern Fauquier County, Virginia objected to Verizon’s copper retirement effective on or after October 23, citing the FCC’s own National Broadband Map, which designates the address unserved with zero fixed broadband providers, and indoor LTE that degrades to unusable. The ask is deferral “until a reliable, functionally equivalent wired alternative is physically active.”

Honorable mentions

The Public Safety and Homeland Security Bureau conditionally approved Cybersecurity Label Administrators and opened a new CLA filing window under the U.S. Cyber Trust Mark program (DA 26-834, PS Docket 23-239, August 11).

The Commission issued a consumer alert on August 10 about scammers impersonating FCC commissioners and employees.

A joint filing from the American Bankers Association, ACA International and the American Financial Services Association brought numbers to the legitimate-caller side of the KYUP record: the FTC’s estimate of $196 billion in 2024 fraud and scam losses, and a 2026 finding that 6% of U.S. adults — about 15.1 million people — were scammed out of money in 2025.

The Global Clarity Foundation met with CGB staff on August 12 to present measurable communication-clarity standards for the call center onshoring proceeding, CG Docket 26-52.

Looking ahead

KYUP replies are due September 8, and the shape of the reply round is already visible: whether the safe-harbor construct can absorb Numeracle’s evidence that flexibility failed, and whether anyone engages the STI-GA’s position argument — that a certification authority outside the call flow has no way to know how its certificates get used. Watch the RMD proceeding (FCC 26-49) — USTelecom, INCOMPAS and Bandwidth all tried to route KYUP obligations into it, and the Commission has not said whether it will take the handoff. Watch WC 26-96 for the reply round on high-cost reform now that the IP transition workshop transcript is on the record across the whole cluster. And watch whether the TRS filings draw a response from the Consumer and Governmental Affairs Bureau’s Disability Rights Office.