Important Registrations and VoIP Compliance Requirements for U.S. Telecom & VoIP Service Providers
Starting a telecom or VoIP business in the United States is much easier technically than it was a decade ago. A company can purchase numbers, connect to an upstream carrier, deploy a hosted PBX, and start serving customers relatively quickly. The regulatory side is different. If your company provides interconnected VoIP, SIP trunking, hosted voice, […]
Starting a telecom or VoIP business in the United States is much easier technically than it was a decade ago. A company can purchase numbers, connect to an upstream carrier, deploy a hosted PBX, and start serving customers relatively quickly.
The regulatory side is different.
If your company provides interconnected VoIP, SIP trunking, hosted voice, wholesale voice, PBX services, or other telecommunications services, you may have obligations involving the FCC, USAC, Robocall Mitigation Database, STIR/SHAKEN, 911, customer privacy, CALEA, and state regulators.
One common misconception is that using an upstream carrier automatically transfers all compliance responsibility to that carrier. That is not always true.
Your obligations depend on what service you provide, who your customers are, whether you originate or terminate calls, your control over network infrastructure, and how your company is classified under FCC rules.
Here are the major registrations and compliance areas every U.S. telecom or VoIP provider should review.
1. FCC CORES Registration and FRN
For many telecom businesses, the regulatory journey begins with an FCC Registration Number (FRN).
An FRN is a unique 10-digit number assigned to an individual or business that registers with the Federal Communications Commission through the Commission Registration System (CORES).
Think of the FRN as your company’s identity within the FCC ecosystem.
It may be required before completing several other regulatory filings.
For example, the FCC’s current Robocall Mitigation Database guidance states that a provider submitting an RMD filing must have its own FRN.
It is important to keep your company information consistent across your regulatory registrations. Your:
- Legal company name
- EIN or Tax ID
- Business address
- Responsible officials
- Contact details
should be reviewed carefully before moving on to later registrations.
Incorrect company names or mismatched information can create unnecessary delays when dealing with the FCC, USAC, STI-PA, carriers, and other industry organizations.
2. FCC Form 499 and USAC Filer ID
One of the most important compliance areas for telecommunications and interconnected VoIP providers is FCC Form 499 registration and revenue reporting.
The Form 499 system is administered through the Universal Service Administrative Company, better known as USAC.
The FCC’s Form 499 database covers interstate telecommunications carriers, interconnected VoIP providers, and certain other providers of interstate telecommunications.
FCC Form 499-A
FCC Form 499-A is the annual Telecommunications Reporting Worksheet.
It is used to report the company’s actual telecommunications revenue from the previous calendar year.
USAC currently states that:
- Form 499-A is required for all filers.
- It reports actual prior-year revenue.
- The normal annual due date is April 1.
For calendar year 2026, for example, the Form 499-A reporting 2025 revenue was due April 1, 2026.
FCC Form 499-Q
Form 499-Q is different.
It is a quarterly worksheet used primarily by non-de-minimis filers to forecast future telecommunications revenue for Universal Service Fund purposes.
The normal quarterly filing schedule is:
- February 1
- May 1
- August 1
- November 1
When a deadline falls on a weekend or federal holiday, the actual due date may move to the next business day.
Providers should therefore check the current USAC filing calendar instead of relying only on a recurring date in an internal spreadsheet.
Check current FCC Form 499 filing requirements with USAC
What about de minimis providers?
Being de minimis for Universal Service Fund contributions does not necessarily mean there is no Form 499 filing obligation.
For example, USAC’s current guidance states that Form 499-A is required for all filers, while Form 499-Q applies to non-de-minimis filers.
This distinction is important because some new VoIP companies incorrectly assume that having little or no revenue means they can simply ignore Form 499.
3. FCC Robocall Mitigation Database Registration
The Robocall Mitigation Database (RMD) has become one of the most important compliance systems for companies carrying U.S. voice traffic.
According to the FCC’s January 2026 guidance, all voice service providers and intermediate providers, including gateway providers, are required to file in the Robocall Mitigation Database.
The RMD filing includes information regarding the provider’s implementation of STIR/SHAKEN and/or robocall mitigation practices.
This is not simply a company-directory registration.
Providers should understand the statements they make in the database and ensure those statements match their actual operations.
A provider’s robocall mitigation procedures may address areas such as:
- Customer identification and KYC
- Prevention of illegal traffic
- Traffic monitoring
- Customer vetting
- Suspicious calling patterns
- Traceback cooperation
- Investigation procedures
- Suspension or termination of abusive customers
The FCC continues to treat the RMD as an important part of its anti-robocall framework. In July 2026, the Commission also advanced additional proposals aimed at strengthening the reliability and integrity of the database.
For providers building their regulatory setup from scratch, Robocall Mitigation should therefore be treated as an operational compliance program—not simply another filing.
4. Your Robocall Mitigation Program Must Match Your Operations
Preparing an RMD filing is one thing.
Actually operating according to that filing is another.
A telecom company should have internal procedures that answer basic questions such as:
Who is allowed to become a customer?
Before activating service, the provider should know who the customer is and understand the nature of the customer’s expected traffic.
What happens when unusual traffic appears?
Sudden increases in short-duration calls, unusually high outbound volumes, consumer complaints, invalid caller ID use, or other suspicious patterns may need investigation.
Who handles traceback requests?
There should be a designated process for receiving, investigating, and responding to traceback requests.
What happens when a customer is clearly abusing the network?
Customer agreements and internal processes should give the company the ability to restrict, suspend, or terminate illegal or abusive traffic.
A Robocall Mitigation Plan that exists only as a PDF is not enough. Your actual business practices should support what your company has certified to the FCC.
5. STIR/SHAKEN Compliance
STIR/SHAKEN is the caller ID authentication framework used throughout the modern U.S. voice network.
In simple terms, it helps receiving networks determine whether the provider originating a call has authenticated the caller ID information associated with that call.
STIR/SHAKEN commonly uses three attestation levels.
A — Full Attestation
The originating provider knows the customer and has a high level of confidence that the customer is authorized to use the telephone number presented with the call.
B — Partial Attestation
The provider knows the customer but cannot fully establish the customer’s authorization to use the telephone number.
C — Gateway Attestation
The provider is responsible for bringing the call onto the IP network but does not have the relationship or information needed to provide A or B attestation.
The FCC describes these levels as full, partial, and gateway attestation.
The correct attestation cannot simply be selected because a customer wants better call completion. It should reflect the provider’s actual knowledge and relationship with the originating party and calling number.
Providers that want a deeper explanation of the process can also review our Bizz Core Solutions STIR/SHAKEN compliance services, covering FCC/USAC registration, Robocall Mitigation, OCN, STI-PA, SPC Token, and STI certificate support.
Explore Bizz Core Solutions STIR/SHAKEN Compliance Services
6. The September 2025 STIR/SHAKEN Rule Change
This is particularly important for providers operating in 2026.
New FCC requirements concerning third-party STIR/SHAKEN authentication became effective on September 18, 2025.
Under the rules, a provider with a STIR/SHAKEN implementation obligation may still use a third party to perform the technological act of digitally signing calls.
However, the provider with the implementation obligation must:
- Make its own attestation-level decisions; and
- Ensure the calls are signed using the provider’s own STIR/SHAKEN certificate, rather than the certificate of the third party.
The rules also explicitly require providers with a STIR/SHAKEN implementation obligation to obtain an SPC Token and use it to obtain their digital certificate from an approved Certificate Authority.
This is an important distinction.
A VoIP company may outsource the technology used to sign a call, but where these requirements apply, it cannot simply borrow another provider’s identity or certificate and treat the result as its own STIR/SHAKEN implementation.
7. OCN — Operating Company Number
Companies entering the U.S. telecom and STIR/SHAKEN ecosystem may also encounter the Operating Company Number (OCN).
An OCN is an industry identifier associated with a telecommunications provider.
It is different from:
- An EIN
- An FCC FRN
- A Form 499 Filer ID
- An SPC Token
- An STI certificate
These identifiers have different functions, even though several may eventually be associated with the same company.
For providers pursuing their own STIR/SHAKEN certificate, OCN eligibility is particularly relevant to the STI-PA vetting process.
Because the process involves multiple organizations, companies should make sure their legal name and regulatory information remain consistent from one application to the next.
8. STI-PA Registration and SPC Token
Once a provider is eligible to participate in the STIR/SHAKEN trust ecosystem, it can proceed with the Secure Telephone Identity Policy Administrator (STI-PA) process.
The STI-PA performs the vetting necessary before an eligible provider can obtain a Service Provider Code Token, or SPC Token.
The SPC Token is an important credential within the STIR/SHAKEN framework.
It is not itself the final certificate used to authenticate calls.
Instead, an eligible provider uses the SPC Token as part of its certificate enrollment with an approved STI Certificate Authority.
The STI-GA currently maintains formal policies covering:
- SPC Token access
- STI certificates
- SPC Token revocation
- SPC Token reinstatement
- Funding
- Certificate Authority suspension and revocation
Review the official STI-GA policy documents
9. STI Certificate Authority and Digital Certificate
After obtaining the appropriate SPC Token, the provider can work with an approved STI Certificate Authority (STI-CA) to obtain its STIR/SHAKEN digital certificate.
That certificate is part of the cryptographic trust framework used when calls are authenticated.
The basic relationship can be understood as:
STI-PA → SPC Token → STI Certificate Authority → Digital Certificate → STIR/SHAKEN Call Authentication
Providers using a third-party STIR/SHAKEN platform, SBC, softswitch, SIP infrastructure, or other hosted signing solution should understand exactly whose certificate is being used.
Since September 18, 2025, providers subject to the applicable STIR/SHAKEN implementation obligation must ensure that calls are signed with their own certificate even where a third party performs the technical signing function.
10. 911 and E911 Compliance
If you provide interconnected VoIP service, emergency calling should be considered before customer activation.
FCC rules require covered interconnected VoIP providers to provide E911 service, including routing 911 calls and providing appropriate callback and registered-location information where required.
Providers should have procedures for areas such as:
- Collecting the initial service location
- Updating registered locations
- Routing emergency calls
- Providing callback information
- Customer notices
- Remote and nomadic users
- Power and broadband outages
- Appropriate emergency-service testing
This is particularly important for hosted PBX businesses because a customer can move an IP phone from one physical location to another while keeping the same telephone number.
A customer’s billing address should not automatically be assumed to be the correct emergency-service location.
11. CPNI and Customer Privacy
Voice providers process sensitive customer information every day.
This can include information relating to:
- Numbers called
- Call duration
- Calling patterns
- Services purchased
- Customer account activity
Certain information falls under Customer Proprietary Network Information (CPNI) protections.
The FCC states that telecommunications carriers and interconnected VoIP providers are required to maintain systems designed to protect subscriber CPNI.
Companies subject to the FCC’s CPNI rules must also submit an annual CPNI certification.
The FCC currently states that the certification must be filed on or before March 1 each year.
View the FCC CPNI certification system
This is an area that smaller VoIP businesses frequently underestimate.
A standard website privacy policy is not the same thing as an internal CPNI compliance program.
12. CALEA and the System Security and Integrity Plan
Certain telecommunications and interconnected VoIP providers also need to review their obligations under the Communications Assistance for Law Enforcement Act (CALEA).
CALEA addresses providers’ responsibilities relating to properly authorized lawful surveillance.
The FCC expanded CALEA coverage to facilities-based broadband Internet access providers and interconnected VoIP providers.
Providers subject to CALEA are required to file a System Security and Integrity Plan (SSI Plan) before commencing service, and a complete updated SSI Plan must be re-filed within 90 days following applicable changes to previously filed information.
Using an upstream carrier does not automatically mean every possible regulatory responsibility disappears.
A reseller or VoIP provider should review its actual role before deciding that CALEA requirements are entirely someone else’s responsibility.
13. State PUC Registrations
Federal registration is only one part of telecom compliance.
Depending on the company’s activities and states of operation, requirements may also exist through state:
- Public Utility Commissions
- Public Service Commissions
- Departments of Revenue
- 911 authorities
- State telecommunications regulators
The requirements are not identical across all 50 states.
A state may treat:
- Interconnected VoIP providers
- Resellers
- Facilities-based carriers
- Competitive local exchange carriers
- Toll providers
- Wholesale carriers
differently.
This is why automatically filing in every state is not necessarily the right approach.
First determine what your company actually provides and where it provides it. Then determine which registrations, taxes, reports, and certificates apply in those jurisdictions.
14. Telecom Taxes, USF, TRS and Other Assessments
Telecom revenue is not always treated like ordinary business revenue.
Depending on the provider’s services and jurisdiction, regulatory obligations may involve areas such as:
- Universal Service Fund contributions
- Telecommunications Relay Service assessments
- NANPA/LNPA-related assessments
- State telecommunications taxes
- Sales or communications taxes
- State and local 911 surcharges
- Regulatory assessments
The correct treatment can depend on whether revenue is interstate, intrastate, international, end-user, wholesale, bundled, or otherwise classified.
For this reason, proper monthly telecom revenue reconciliation is extremely important.
Waiting until April to reconstruct an entire year of telecom revenue can create unnecessary Form 499 problems.
15. Compliance Does Not End After Registration
A company can obtain:
FRN → 499 Filer ID → RMD Registration → OCN → SPC Token → STI Certificate
and still become non-compliant later.
These registrations create ongoing responsibilities.
A telecom compliance calendar may need to include:
Annually
- FCC Form 499-A
- CPNI certification
- Applicable state reports
- Regulatory renewals
- Revenue reconciliation
- Compliance-policy reviews
Quarterly, where applicable
- FCC Form 499-Q
- Revenue review and classification
- Contribution reconciliation
Ongoing
- Robocall Mitigation Program
- Customer KYC
- Traceback response
- Traffic monitoring
- STIR/SHAKEN certificate management
- RMD updates
- 911 location management
- CALEA procedures
- State compliance
- Regulatory correspondence
Registration is therefore the starting point, not the finish line.
A Practical Compliance Roadmap for a New VoIP Provider
Although every company is different, a typical compliance journey may look something like this:
Step 1 — Establish the Business
Create the legal entity, obtain the EIN, establish the business address, and determine exactly what telecommunications service will be sold.
Step 2 — Obtain the FCC FRN
Register the company through FCC CORES and establish its FCC identity.
Step 3 — Complete FCC/USAC Registration
Review Form 499 requirements, obtain the appropriate Filer ID, and establish a revenue-reporting process.
Step 4 — Address Robocall Mitigation
Develop the company’s actual mitigation procedures and complete the appropriate Robocall Mitigation Database filing.
Step 5 — Obtain Required Telecom Identifiers
Determine whether an OCN or another relevant industry identifier is required.
Step 6 — Complete STIR/SHAKEN Onboarding
Where the company has a STIR/SHAKEN implementation obligation, complete the applicable STI-PA, SPC Token, and STI Certificate Authority process.
Step 7 — Build Operational Compliance
Implement appropriate:
- KYC
- Traceback procedures
- Traffic monitoring
- 911/E911 processes
- CPNI controls
- CALEA procedures
- Customer agreements
Step 8 — Review State Requirements
Determine which state PUC registrations, telecom taxes, 911 requirements, and recurring filings apply based on where and how the company operates.
Step 9 — Maintain a Compliance Calendar
Track deadlines instead of dealing with them after receiving a regulator or USAC notice.
One Upstream Carrier Does Not Equal Complete Compliance
This is probably the most important point for new VoIP businesses to understand.
Many companies begin as resellers.
They purchase SIP termination, origination, DIDs, E911, CNAM, or other services from larger carriers and then sell a hosted voice service to their own customers.
That business model can be perfectly legitimate.
But having a wholesale agreement with an upstream carrier does not automatically mean:
“The carrier handles everything, so we have no regulatory obligations.”
Your responsibilities depend on the service you are actually providing.
Before launching, you should be able to answer:
- Who is the customer’s actual voice service provider?
- Who has the customer relationship?
- Who bills the customer?
- Who originates the traffic?
- Who selects the caller ID?
- Who decides the STIR/SHAKEN attestation?
- Whose certificate signs the call?
- Who provides 911?
- Who responds to traceback requests?
- Who maintains KYC records?
- Who reports the revenue?
- Which party appears in the Robocall Mitigation Database?
If those questions are unclear, the company’s compliance structure is probably unclear as well.
Final Thoughts
The technical barrier to launching a VoIP service has become very low.
The regulatory barrier has not.
A modern provider may need to coordinate requirements across the FCC, USAC, Robocall Mitigation Database, STI-GA/STI-PA ecosystem, 911 systems, state regulators, tax authorities, upstream carriers, and its own network infrastructure.
That sounds complicated, but the process becomes much easier once the company’s business model is properly classified.
The goal should never be to obtain every telecom registration simply because it exists.
The goal is to determine which requirements actually apply to your company, complete them correctly, and maintain them as your business grows.
Need Help With U.S. Telecom & VoIP Compliance?
Bizz Core Solutions helps VoIP providers, telecom resellers, hosted PBX companies, MSPs, and startups navigate the administrative and regulatory side of building a U.S. voice business.
Our support includes:
- FCC CORES / FRN
- FCC Form 499 and Filer ID
- Robocall Mitigation Program
- Robocall Mitigation Database
- OCN application support
- STI-PA onboarding
- SPC Token process
- STIR/SHAKEN certificate coordination
- Ongoing Form 499 compliance
- Telecom compliance guidance
Whether you are starting a new VoIP operation or trying to bring an existing business into compliance, the first step is understanding what applies to your specific business model.
Explore Bizz Core Solutions Telecom & STIR/SHAKEN Compliance Services
Disclaimer: This article is provided for general informational purposes and does not constitute legal, tax, or regulatory advice. Telecom requirements depend on a provider’s services, network architecture, regulatory classification, customers, and jurisdictions of operation.