VoiceFiling
FAQ

RMD and CPNI filing questions, answered with the rule

Short answers to what small voice providers ask about the Robocall Mitigation Database, the March 1 recertification, STIR/SHAKEN certification options and the annual CPNI certification — each with the rule or FCC document it comes from.

Last updated: September 2026

The Robocall Mitigation Database

Who has to file in the Robocall Mitigation Database?

All voice service providers and intermediate providers, including gateway providers (FCC Public Notice DA 26-72, FAQ 1). The FCC says this includes voice over Internet protocol (VoIP) resellers and mobile virtual network operators (MVNOs), and its Enforcement Bureau repeated it for MVNOs on February 20, 2026 (DA 26-174).

An affiliate or subsidiary that independently provides voice service files its own filing, under its own FRN.

What happens if we are not listed in the Database?

Voice service providers and intermediate providers may accept calls directly from a domestic voice service provider only if that provider’s filing appears in the Robocall Mitigation Database and has not been removed by an enforcement action (47 CFR § 64.6305(g)). In practice, other U.S. providers must refuse the traffic you send them directly.

When is the annual RMD recertification due?

On or before March 1 every year (47 CFR § 64.6305(h)). The rule took effect February 5, 2026, and the first deadline was March 1, 2026. The next one is Monday, March 1, 2027.

The FCC’s filing instructions (July 2026) say the recertification window opens each year on February 1, and a filing can be recertified only once per window.

What are the penalties for an inaccurate or outdated RMD filing?

Since February 5, 2026: a $10,000 base forfeiture for each violation for submitting false or inaccurate information to the Database, and a $1,000 base forfeiture for failing to update it within 10 business days of a change. Both are continuing violations until cured (47 CFR § 1.80(b)(11)).

The FCC also said failure to recertify will result in referral to the Enforcement Bureau, which may lead to a forfeiture or removal from the Database (91 FR 348).

How quickly must we update our filing after a change?

Within 10 business days of any change to the information in your filing (47 CFR § 64.6305(d)(5)), including changes in ownership or control from a merger or acquisition (DA 26-72, FAQ 14). Name, address and contact changes also go into CORES within 10 business days (47 CFR § 1.8002(b)(2)).

Is there an FCC fee to file in the RMD?

Not yet. The FCC adopted a $100 application fee for initial filings and annual recertifications, but its January 22, 2026 Public Notice (DA 26-72) says the requirement is not yet effective, and as of September 2026 the fee schedule in 47 CFR § 1.1105 does not include it. The FCC says no fee applies to routine updates.

Our wholesale provider signs our calls. Can we certify complete STIR/SHAKEN implementation?

Not on that basis. A provider that certifies complete or partial implementation must be registered with the STIR/SHAKEN Policy Administrator, hold its own SPC token and certificate, and have the calls it must authenticate signed with that certificate — directly, or through a third party that signs with the provider’s certificate while the provider makes the attestation-level decisions (47 CFR § 64.6301(b); DA 26-72, FAQ 9–11). Complete implementation (Option 1) is only for an all-IP network.

A provider that lacks control over the network infrastructure needed to implement STIR/SHAKEN may certify to partial or no implementation, as long as it explains in detail how that applies to it (as the FCC restated in its July 2026 proposal, FCC 26-32).

What must a robocall mitigation plan contain?

The specific reasonable steps you take to avoid originating, carrying or processing illegal robocalls: how you know your customers, new and renewing; your procedures to know your upstream providers; the call analytics you use, with vendor names; the contract terms you rely on against illegal calling; and your commitment to answer traceback requests within 24 hours and cooperate with the FCC, law enforcement and the industry traceback consortium (47 CFR § 64.6305(d)(2); DA 24-73).

The FCC’s standard is whether the program includes detailed practices that can reasonably be expected to significantly reduce illegal robocalls. A plan that only explains how STIR/SHAKEN works is one of its examples of a facially deficient filing (DA 24-73).

Do we have to use call analytics?

No. But your plan should say whether you use them, describe any system you use, and name any third-party analytics vendor — or the underlying provider whose analytics you rely on (47 CFR § 64.6305(d)(2)(ii); DA 26-72, FAQ 12).

How fast must we answer a traceback request?

Fully, within 24 hours (47 CFR § 64.1200(n)(1)). A request received outside business hours (8 a.m. to 5:30 p.m. local time, Monday to Friday, excluding federal legal holidays) counts as received at 8 a.m. on the next business day, and the clock does not run over weekends or federal legal holidays.

On September 30, 2025 the Enforcement Bureau removed 12 providers from the Database for failing to respond to tracebacks (DA 26-174).

The annual CPNI certification

Who must file the annual CPNI certification, and when?

Telecommunications carriers and interconnected VoIP providers, with no exemption for small companies, and a separate certification for each affiliate with its own Form 499 Filer ID. It is filed with the Enforcement Bureau on or before March 1 each year, in EB Docket No. 06-36, for the previous calendar year (47 CFR § 64.2009(e); DA 26-139).

The next one is due Monday, March 1, 2027, covering calendar year 2026.

What must the CPNI certification include?

A compliance certificate signed by an officer; the officer’s statement of personal knowledge that the company’s operating procedures are adequate to ensure compliance; an accompanying statement explaining how those procedures ensure compliance; an explanation of any actions taken against data brokers; and a summary of all customer complaints received in the past year about unauthorized release of CPNI (47 CFR § 64.2009(e)).

If there were no actions or complaints, the filing must say so affirmatively — the FCC lists those missing statements among the deficiencies it keeps finding (DA 26-139).

Working with us

Do you file for us?

No. We prepare; you submit. Your RMD filing is made under your company’s FRN, through a CORES login with multi-factor authentication, and an officer signs the declaration under penalty of perjury (47 CFR § 1.16). Your CPNI certificate is signed by your officer and filed in ECFS or through the FCC’s CPNI web form. We never ask for your FCC login.

Are you a law firm?

No. We don’t give legal advice and we don’t represent anyone before the FCC. We prepare written filings from the facts you give us, cite the rule text behind every section, and tell you plainly when something needs a lawyer — an Enforcement Bureau letter, a Notice of Apparent Liability or a removal order, for example.

What don’t you do?

We don’t submit filings for you, give legal advice or represent you. We don’t implement STIR/SHAKEN (SPC tokens, certificates, signing or network work), prepare Form 499 filings or calculate universal service contributions, file confidentiality requests (we do prepare the redacted and unredacted plans), or answer tracebacks on your behalf.

Who do you turn away?

Businesses built on high-volume unsolicited calling campaigns, and providers that are currently the subject of an FCC enforcement action or robocall-related investigation, or whose earlier filing was removed by the FCC. They need counsel, not a filing service.

How much does it cost, and how do we pay?

New Provider RMD Filing: $490, one-time. Annual Compliance Pack: $790 per year (RMD recertification, plan update, CPNI certificate and statement, compliance calendar, one mid-year change update). Change Update: $150 per change.

You receive a written quote, then pay in advance by secure card link. If we miss the delivery date in your quote, we refund 100% of the fee.

Who are you?

A small, distributed team that prepares FCC robocall and CPNI filings for small voice providers, and nothing else. Everything happens in writing: you get a reply within one U.S. business day, and you never need to get on a call.

What is likely to change next?

These are proposals, not rules: in September 2026 the FCC published proposals (FCC 26-49) to clarify who must file in the RMD, strengthen screening of new filers, speed up removals and prevent re-entry, with comments due October 9 and replies November 9, 2026. Related proposals would set baseline know-your-upstream-provider duties (FCC 26-32) and more rigorous know-your-customer steps, with per-call penalties for violations (FCC 26-27).

If any is adopted, plans will need updating; for Annual Compliance Pack clients, one rule-change update per pack year is included, and any further one is billed as a Change Update ($150).

Is our information kept confidential?

Your questionnaire answers and documents are used only to prepare your filings. Keep in mind that the robocall mitigation plan itself is published in the RMD unless you request confidential treatment of specific parts, and over-redacted plans are not appropriate (DA 26-72, FAQ 7).

Get a written quote

Tell us what you need to file. We reply within one U.S. business day.

A fixed price and a delivery date, in writing. No call, no sales meeting. Send it tonight, read it in the morning.