Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • CISA Offers K-12 Cybersecurity Help as Schools Prepare for New Year
    • Bipartisan Senate Bill Targets Chinese Exploitation of U.S. Tech
    • NIST Eyes AI to Solve Cyber Vulnerability Database Backlog
    • Parties Question Scope of FCC Know-Your-Upstream-Provider Proposal
    • Two Cyber Trust Mark Administrators Win Conditional FCC Approval
    • UAS Vendor’s FCC Authorizations Revoked Over Security Concerns
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Parties Question Scope of FCC Know-Your-Upstream-Provider Proposal, (Aug 12, 2026)

    Organizations Mentioned:ACA International | American Bankers Association | American Financial Services Association | Bank Policy Institute | Consumer Bankers Association | Electronic Transactions Association | Incompas | Mortgage Bankers Association | T-Mobile US | TransUnion Corp. | USTelecom

    By Jeff Williams

    While attracting widespread support for its overarching goal, the FCC’s further notice of proposed rulemaking designed to enhance the STIR/SHAKEN caller ID authentication framework for combatting illegal robocalls by boosting know-your-upstrea ...

    By Jeff Williams

    While attracting widespread support for its overarching goal, the FCC’s further notice of proposed rulemaking designed to enhance the STIR/SHAKEN caller ID authentication framework for combatting illegal robocalls by boosting know-your-upstream-provider (KYUP) requirements has also prompted calls from numerous parties for improvements.

    The FNPRM the FCC unanimously adopted in May in WC docket 17-97 and CG docket 17-59 proposed improving KYUP oversight, raising standards for STIR/SHAKEN attestations, and closing implementation loopholes (CPR, May 21).

    CTIA said the FCC should “maintain its current approach which allows for appropriate flexibility” and “avoid adopting a rigid one-size-fits-all KYUP approach to information collection, due diligence, verification, monitoring, and recordkeeping, which would fail to allow for the varied approaches to KYUP necessary to appropriately vet a diverse range of VSPs,” or voice service providers.

    Implementing “rigid rules would risk providing a roadmap for bad actors to exploit” and “impose additional operational costs and burdens in the form of onerous paperwork and record retention requirements without benefit, given that KYUP is a common industry practice already.”

    Incompas and the Cloud Communications Alliance said in a joint filing that “any new obligations must be proportionate to the risk they address and must not convert the existing, flexible regulatory framework into a rigid set of prescriptive mandates untethered from the size, role, and risk profile of the provider subject to them.”

    In addition, it said, the FCC should “preserve the existing industry-governance structures,” including the Secure Telephone Identity Governance Authority (STI-GA) and the Industry Traceback Group (ITG) “in the roles those structures were designed to play, rather than seeking changes that will add unanticipated enforcement responsibilities to these organizations’ scope of work” and provide "meaningful, predictable safe harbor protection for providers that make good-faith compliance efforts.”

    WISPA urged the Commission to “recognize that the market consists of different types of upstream providers and not place untenable and/or impossible requirements on smaller voice providers that would lead them to have to leave the market.”

    USTelecom said the FNPRM “proposes prescriptive, static KYUP requirements detached from marketplace realities, which would impose unnecessary burdens on providers while also removing the flexibility needed to tackle the ever-changing threat landscape.”

    The group also said that, among other things, the “enforcement of any KYUP regime should target truly culpable providers and the Commission should avoid a strict liability approach, which would only undercut constructive provider engagement.”

    USTelecom was also among those proposing safe harbor provisions.

    NCTA said the FCC “should base any expanded vetting framework on good faith collaboration with industry to ensure that the adopted changes will be practical and effective and should also include safe harbors for providers that apply the identified baseline practices.”

    The Commission also should reject any proposals in the FNPRM that “depart from industry standards, impose unworkable obligations, and expose providers to disproportionate forfeitures,” NCTA said.

    ACA Connects stressed the need for the FCC to establish “clear and enforceable” KYUP rules while realizing that “overly prescriptive ‘one-size-fits-all’ rules can saddle providers with operational burdens that do not materially advance the Commission’s robocall mitigation objectives.”

    The Voice on the Net Coalition (VON) urged the Commission to “use its existing enforcement authority to target the small cohort of bad actors responsible for the vast majority of unlawful traffic, rather than imposing sweeping mandates on the entire ecosystem.”

    The American Bankers Association, ACA International, the American Financial Services Association, America’s Credit Unions, the Bank Policy Institute, the Consumer Bankers Association, the Defense Credit Union Council, the Electronic Transactions Association, the Financial Technology Association, the Mortgage Bankers Association, the National Council of Higher Education Resources, the Payments Leadership Council, and the Student Loan Servicing Alliance said they “strongly” supported the proposal to “specify the criteria that originating (or initiating) providers must satisfy before providing an attestation level to a call” and “require voice service providers to take specific, affirmative steps to know the providers from which they accept call traffic.”

    The Alliance for Telecommunications Industry Solutions (ATIS) on behalf of the Cross Border Call Authentication Governance Authority (CBCA-GA) asked the FCC to “require service providers to accept foreign originated call attestations only from providers that have been approved” by the (STI-GA).

    The STI-GA said it supported the FCC’s “continued focus on strengthening the STIR/SHAKEN ecosystem and reducing illegal robocalls” but argued that the FNPRM “overstates the roles of the STI-GA and of Certification Authorities and does not accurately reflect the effectiveness of the STI ecosystem.”

    The Industry Traceback Group pointed to work it was doing to formalize and publish KYUP best practices “in the near term” and detailed improvements it was making regarding coordination and information sharing.

    T-Mobile US, Inc., said that implementing “broad new KYUP and STIR/SHAKEN obligations on all voice service providers may not be the most effective way to address problems concentrated among particular providers or call paths.”

    Somos, Inc., said the FCC needed to “[c]odify and strengthen” the STIR/SHAKEN attestation framework and should specify how each criteria is satisfied.

    Pinger, Inc., offered recommendations that included having the FCC “[r]evise the attestation criteria and the associated definitions so that the provider that directly serves the end user, holds the customer knowledge, and makes the attestation-level decision the proposed rules themselves assign to it can qualify for A-level attestation.”

    Sorenson Communications LLC said the Commission “should adopt a framework that requires originating providers to authenticate TRS [telecommunications relay service] calls using the attestation determinations made by the certified Internet-based TRS provider with the direct customer relationship.”

    Any framework the FCC implements “should enable certified TRS providers to securely communicate their attestation determinations through a trusted credential without imposing duplicative verification or unnecessary regulatory burdens on the customer,” Sorenson said.

    The Joint IP Network-to-Network Task Force urged the FCC “not to require service providers to incorporate requirements that are unrelated to identifying the end user or upstream service provider into the attestations requirements of, or are otherwise inconsistent with, ATIS-1000074, Signature-based Handling of Asserted information using toKENs (SHAKEN).”

    Numeracle, Inc., said the FCC should, among other recommendations, adopt five categories of “baseline” KYUP measures covering information collection, compliance review, information verification, monitoring, and responsive action as “mandatory rules, not best practices," and “[r]ecognize accredited, independent third-party verification services as a core component of KYUP compliance, supported by a conditional safe harbor.”

    Teknyx LLC argued that “prescriptive, document-heavy identity mandates impose substantial costs without a demonstrated reduction in illegal calling.”

    ZipDX LLC recommended that the “largest terminating providers must offer to their subscribers a tool that diverts calls according to the reputation of the signer of each call.”

    Bandwidth, Inc., and Bandwidth.com CLEC LLC said the Commission should not impose new KYUP “diligence or compliance burdens on the competitive carriers least responsible for the problem the Commission is trying to solve.”

    Hamilton Relay, Inc., said the FCC “should ensure that relay users are not shut out of the framework enabling those protections, nor inadvertently disadvantaged by new rules” and that the Commission “should adopt reasonable guidelines that provide clarity to voice service providers and relay providers.”

    TextNow, Inc., argued that a “provider that originates under the definitions as written should be confirmed as an originating provider, not reclassified out of a framework it has fully implemented.”

    TransUnion stated that “successful anti-robocall solutions must preserve the flexibility of terminating providers” and that while the company appreciates the FNPRM’s “focus on preventing bad actors from accessing the network, no upstream compliance framework can eliminate the need for effective downstream protections.”

    Mezmo Corp., d/b/a InnoCaption, told the Commission that it “must ensure that its STIR/SHAKEN framework (i) properly accounts for the role that TRS providers play in the communications ecosystem and (ii) does not disadvantage or otherwise burden individuals with disabilities who rely on TRS to communicate.”

    ZP Better Together LLC said the FCC “should mandate that TRS provider calls be given an A-level attestation by their underlying providers—and amend its rules as necessary for TRS providers to share the information required for such providers to certify as such.”

    Contact Center Compliance expressed support for proposals covering “SPC-token safe harbor, optional consent-based use of third-party KYUP services, the proposed effective date, and enhanced, consent-based Governance Authority vetting.”

    News: FederalLegislation DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use