CallCert

Next deadline 1 March 2027

Prepare your filing set.

The questions below cover every element the rules list for a robocall mitigation plan, every field the Robocall Mitigation Database form asks for, and the CPNI annual certificate if you want it. Answer in your own words about your own operation — a description of how STIR/SHAKEN works in general is what gets a filing called deficient.

Before you start, have these to hand

The questions take about 15 to 20 minutes. $149 one time, for one provider and one filing year. Recertification is due every 1 March.

1. Your company

Exactly as it appears in CORES. If the database name and your CORES name differ, the filing can be rejected.

The ten-digit FCC Registration Number on your CORES account.

The year you are filing in, not the year being certified.

Type of filing
2. Your role in the call chain
Select every role your company plays

Most filers play one role. Pick more than one only if your company really does the work of each.

3. Caller-ID authentication status
How far along is STIR/SHAKEN on your network?

If another provider signs your traffic, or you sign on behalf of someone else, describe the arrangement and who holds the certificate.

4. What you do to stop illegal calls

Describe what your company actually does: what you check before a customer can send traffic, what you monitor afterwards, what thresholds or alerts you use, and what happens when a customer trips one. A description of how STIR/SHAKEN works in general is the specific thing the FCC calls facially deficient.

Cover both new and renewing customers: what you collect and verify before service starts, and what would make you refuse or terminate one. This is the element most often missing from the filings the FCC ordered to be cured.

Describe what you check about the providers who send you traffic, and what you do when one sends traffic you would not accept. If you accept traffic from no one, say that.

Describe in general terms what your customer and carrier contracts say about illegal calling, and whether those terms are in every contract or only some. If your contracts say nothing about it, say that — it is an answer.

Describe what the system examines and what happens when it flags a call. If you use none, say so — silence on this point is itself a deficiency the FCC has cited.

The 24-hour commitment itself is written for you. Naming who answers a traceback and how they meet the deadline makes the plan concrete.

5. The form fields the database asks for

Name at least one individual — an owner, director, officer, or manager. The database asks for people, not holding companies.

Any affiliated company that also originates, carries, or terminates voice traffic.

Any other FCC Registration Numbers this company holds.

Your OCN, if you have one.

Any d/b/a name you operate under.

Any name this company has filed under before.

6. Your robocall contact

The person the FCC, law enforcement, and the traceback consortium reach about robocall issues. This contact is published in the database.

Only if the database should show one.

The address the FCC should use for robocall mitigation contact, including country.

7. The CPNI certificate

A separate annual certificate about how you protect customer information. It is filed in EB Docket No. 06-36 and is signed by an officer of the company. Include it here and the answers below go into the certificate; leave it out and this section is skipped.

8. Where we send it

Where the filing set is sent. It can be different from the robocall contact above.

$149 one time

One filing set for one provider and one filing year. We prepare the documents from your answers. Nothing is filed on your behalf: your officer reviews the documents, signs them, and submits them.