Written by: Matt Beucler, CEO, Plura AI | Last updated: August 27, 2026
Key Takeaways for Gateway and International Voice Providers
- Gateway and international voice providers already must register in the RMD, authenticate calls with STIR/SHAKEN, file a Robocall Mitigation Plan, and cooperate with traceback under 47 CFR 64.6305.1
- S.2666 (FREA) would add a surety bond requirement before RMD certification, expand traceback authority, grant consortium immunity, and create a joint FCC-FTC-DOJ task force.2
- Non-compliance with current rules can lead to RMD removal and mandatory downstream traffic blocking by intermediate and terminating carriers.2
- Providers should audit RMD status, confirm STIR/SHAKEN implementation, review upstream relationships, and prepare for potential bond exposure within a focused 90-day window.2
- Plura AI helps carriers and enterprises support compliance with STIR/SHAKEN authentication, real-time DNC scrubbing, and RMD-aligned infrastructure, and you can talk to the team directly.
Current 47 CFR 64.6305 Requirements for Gateway and International Providers
Gateway and international voice providers already operate under a defined set of FCC obligations. The table below maps those obligations and timelines. Consult qualified counsel for interpretation of how these rules apply to a specific network configuration.
| Obligation | Rule Citation | Gateway/International Provider Action | Timeline |
|---|---|---|---|
| RMD Registration and Annual Certification | 47 CFR 64.6305; USAC RMD filing requirements | Every voice service provider originating or carrying calls, including international carriers handling U.S.-bound traffic, must register in the RMD with no small-provider exemption regardless of size or call volume. Gateway providers register under the “Gateway” implementation type. | Ongoing, with annual recertification required to maintain active status |
| STIR/SHAKEN Authentication | 47 CFR 64.6305; FCC Eighth Report and Order | Providers certifying to partial or full STIR/SHAKEN implementation must register with the STIR/SHAKEN Policy Administrator, obtain their own SPC token, and authenticate all calls using a certificate from a Certificate Authority. Pure resellers without network control must select “No STIR/SHAKEN Implementation” and cite their exemption under 47 CFR 64.6305(d)(2)(i). | Third-party authentication rules effective September 18, 2025 |
| Robocall Mitigation Plan (RMP) | 47 CFR 64.6305; RMD filing guide | Gateway providers must submit a Robocall Mitigation Plan detailing specific reasonable steps taken to avoid carrying illegal robocall traffic if not fully STIR/SHAKEN compliant. | Filed at registration and updated with each annual certification |
| Traceback Cooperation | 47 CFR 64.6305; FCC enforcement record | Gateway providers must maintain a robocall mitigation program and cooperate with traceback requests, and failure to demonstrate an adequate program can result in removal from the RMD, after which intermediate and terminating providers are required to cease accepting the non-compliant carrier’s traffic. | Ongoing, with traceback consortium applications reviewed annually under current rules |
| Know-Your-Upstream-Provider (KYUP) | FCC FNPRM FCC 26-32, WC Docket No. 17-97 | Providers must take reasonable and effective steps to prevent upstream providers from transmitting large volumes of illegal calls, and the FCC proposes replacing this with a requirement to take “affirmative, effective measures” to prevent any illegal calls. | Current obligation ongoing, with proposed strengthening under FNPRM |
Proposed FREA Additions in S.2666
S.2666 would layer new financial and enforcement tools on top of existing obligations, but these additions do not yet have the force of law. The FCC has not established final exemption criteria, bond conditions, or implementation timelines. Consult qualified counsel before making compliance decisions based on this proposed legislation.
| Addition | Bill Text Citation | New Obligation | Effective Upon Enactment |
|---|---|---|---|
| RMD Surety Bond Requirement | S.2666, Senate-reported text; CBO Cost Estimate, May 26, 2026 | Certain voice service providers would be required to post a bond before filing RMD certifications. The FCC would establish specific conditions, exemptions, and terms. Providers failing to satisfy bond conditions could forfeit it, with forfeited payments deposited in the Treasury general fund. | Upon FCC rulemaking following enactment, and Senate text makes the bond mandatory, unlike the House version (H.R. 6152) where it is contingent on FCC rulemaking |
| Expanded Traceback Authority and Consortium Immunity | S.2666 bill summary; CBO Cost Estimate | The traceback consortium application process would be modified, and the registered consortium would receive immunity for receiving, sharing, or publishing covered traceback information. The FCC or consortium could publish a list of providers based on refusal to participate in traceback or substantial unlawful robocall activity. | Upon enactment |
| FCC-FTC-DOJ Robocall Task Force | S.2666, CBO Cost Estimate, May 26, 2026 | The FCC, in coordination with the FTC and DOJ, would establish a task force on unlawful robocalls that reports to Congress on the most effective ways to address them. | Upon enactment, and CBO estimates implementation costs for the FCC, FTC, and DOJ would be insignificant over the 2026-2031 period |
| International STIR/SHAKEN and Foreign-Origin Identification | FCC FNPRM on Advanced Methods to Target and Eliminate Robocalls, December 2025 | The FCC proposes requiring voice service providers to implement measures ensuring consumers know which calls originate outside the United States and to prohibit spoofing of U.S. telephone numbers for calls originating from outside the United States. This parallel rulemaking track would interact with any enacted FREA provisions. | Proposed, not yet final rule |
Carriers evaluating their exposure to proposed bond requirements can review Plura’s compliance-ready infrastructure and pricing.
Because both current obligations and proposed S.2666 provisions carry operational and financial consequences, gateway providers benefit from a structured near-term plan. The next section outlines a 90-day approach that addresses existing requirements while preparing for possible FREA enactment.
90-Day Compliance Readiness Plan for Gateway Providers
This 90-day plan helps providers address current rules and prepare for potential S.2666 obligations. The checklist describes regulatory actions and does not constitute legal advice. Consult qualified counsel before acting on any item.
- Days 1-15: Audit RMD Filing Status. Confirm active registration in the FCC Robocall Mitigation Database maintained by USAC. Verify that the implementation type selected, such as Full, Partial, Gateway, or Hosted, accurately reflects current network configuration. International carriers handling U.S.-bound traffic have no small-provider exemption regardless of size or call volume.
- Days 1-15: Verify STIR/SHAKEN Certification Path. Confirm whether the provider has obtained its own SPC (Service Provider Code) token and certificate from a STIR/SHAKEN Certificate Authority. Third-party authentication arrangements are prohibited unless the provider independently determines attestation levels and uses its own certificate, and violations constitute breaches of caller ID authentication rules.
- Days 15-30: Review Robocall Mitigation Plan. Confirm the RMP on file with the RMD describes specific, current steps taken to avoid carrying illegal robocall traffic. Generic or outdated plans have appeared in FCC enforcement actions.
- Days 15-30: Map Upstream Provider Relationships. Document all upstream voice service providers. The FCC proposes requiring providers to refuse or discontinue service to an upstream provider when the upstream provider lacks an objectively reasonable basis of legitimacy, evidence shows transmission of illegal calls, required regulatory filings or authentication credentials are missing, or the upstream provider has faced significant regulatory enforcement actions.
- Days 30-60: Assess Bond Exposure Under S.2666. Identify whether the provider might fall within the category of providers subject to the proposed bond requirement. The FCC would establish exemption criteria for providers where the bond is not needed to deter unlawful robocall activity. Monitor FCC rulemaking for exemption definitions.
- Days 30-60: Evaluate Traceback Cooperation Posture. Review internal procedures for responding to traceback requests from the registered consortium. S.2666 would authorize the FCC or consortium to publish a list of providers based on refusal to participate in traceback efforts.
- Days 60-90: Monitor FCC FNPRM Comment Deadlines. The FCC sought comments on FCC 26-32 (WC Docket No. 17-97). File or retain counsel to file comments on proposed KYUP and STIR/SHAKEN changes that would affect gateway operations.
- Days 60-90: Prepare for Expanded RMD Disclosure Requirements. The July 2026 FCC draft FNPRM proposes requiring providers to disclose whether they are facilities-based, non-facilities-based, originating, terminating, gateway, intermediate, retail-facing, or wholesale-facing, with status potentially varying on a call-by-call basis. Audit network architecture documentation to support these disclosures.
Positioning for Bona Fide Provider Bond Exemptions
S.2666 directs the FCC to establish exemption criteria for providers where a bond is not needed to deter unlawful robocall activity. Because the FCC has not yet established the exemptions, conditions, and terms of the bond required under S.2666, the criteria for qualifying as a bona fide provider are not yet fully defined in the legislative materials.
The bill text directs the FCC to issue rules requiring certain providers to post a bond before filing an RMD certification, with the FCC required to establish exemption criteria for providers where the bond is not needed to deter unlawful robocall activity. Based on the legislative record, providers seeking to position for exemption consideration should document factors that demonstrate a low risk of unlawful robocall activity:
- Active, accurate RMD registration with a current Robocall Mitigation Plan on file, which establishes baseline regulatory alignment
- Full or partial STIR/SHAKEN implementation using the provider’s own SPC token and Certificate Authority certificate, which demonstrates technical capability to authenticate calls
- Documented history of traceback cooperation with the registered consortium, which shows willingness to assist enforcement efforts
- Absence of significant FCC enforcement actions or removal orders, which supports a clean compliance record
- Contractual KYUP requirements with upstream providers, including provisions for discontinuing service upon evidence of illegal call transmission, which extends compliance expectations upstream
S.2666 empowers the FCC to require certain providers to post a bond before certifying them to the Robocall Mitigation Database, with exemptions for established, compliant providers. Providers should consult qualified counsel to assess their specific exemption eligibility once the FCC issues implementing rules.
Understanding exemption criteria matters because the alternative, non-compliance, carries severe operational consequences that extend beyond any proposed bond requirement.
Downstream Blocking and Financial Risk for Non-Compliant Gateways
Under current rules, the consequences of RMD non-compliance are operationally severe. Failure by a gateway provider to demonstrate an adequate robocall mitigation program in its RMD certification can result in removal from the Robocall Mitigation Database, after which intermediate and terminating voice service providers are required to cease accepting the non-compliant carrier’s traffic, effectively shutting down the carrier operationally.
S.2666 would add a financial penalty layer on top of existing blocking risk. Providers that fail to satisfy the conditions for the bond established by the FCC could forfeit it, with forfeited payments deposited in the Treasury general fund.
The proposed KYUP FNPRM would also raise the per-violation cost of non-compliance. The FCC proposes base forfeitures for KYUP violations, improper attestations or unauthenticated calls, and failing to implement STIR/SHAKEN.
2026 Status of S.2666 and Related FCC Rulemakings
S.2666 was ordered reported by the Senate Committee on Commerce, Science, and Transportation on October 21, 2025. As of August 2026, the bill has not been enacted into law.
Two parallel FCC rulemaking tracks are active alongside the legislative debate and will shape the environment that any enacted bill would enter:
- FCC 26-17, “Combatting Illegal Robocalls Through FCC Numbering Policies” (WC Docket No. 26-49), adopted March 26, 2026, proposes expanding robocall certifications to all service providers receiving numbering resources directly from NANPA (North American Numbering Plan Administration) and to resellers of telephone numbers.
- FCC 26-32 (WC Docket No. 17-97), adopted May 20, 2026, proposes strengthening the robocall mitigation framework through enhanced KYUP requirements, expanded STIR/SHAKEN Governance Authority oversight, raised caller ID attestation standards, and measures to close STIR/SHAKEN implementation gaps.
On July 1, 2026, the FCC released a draft Further Notice of Proposed Rulemaking proposing substantial changes to the Robocall Mitigation Database framework to make it a more reliable, accurate, and enforceable compliance tool. Neither the legislative nor the rulemaking tracks had reached final rule or enactment status as of the publication date of this article.
Enforcement Gaps S.2666 Seeks to Address
S.2666’s legislative record highlights specific enforcement gaps that sponsors aim to close, and these gaps frame how providers should think about risk.
- No financial stake in RMD certification. Under current rules, providers certify to the RMD without posting any financial instrument. H.R. 6152 would require voice providers to post a bond before being able to conduct business, potentially pushing them and their insurers to more rigorously prevent scam traffic.
- Annual traceback consortium review cycle. S.2666 would revise the FCC’s process for seeking applications from the designated traceback consortium, reducing administrative burden while extending consortium stability.
- Consortium liability exposure. S.2666 would grant the registered traceback consortium immunity from prosecution for publishing information on suspected fraudulent, abusive, or unlawful robocalls, thereby limiting private entities’ rights of action to seek redress or recover damages for the sharing or publishing of such information.
- Foreign-originated call identification. The FCC proposes requiring voice service providers to implement measures to ensure that consumers know which calls originate from outside of the United States and to prohibit spoofing of United States telephone numbers for calls that originate from outside of the United States.
Carriers and enterprises evaluating their compliance infrastructure can explore Plura’s FCC-licensed infrastructure and compliance features.
Frequently Asked Questions
How do current 47 CFR 64.6305 obligations compare to S.2666 proposals?
Under 47 CFR 64.6305, gateway and international voice providers currently face four categories of mandatory obligations. These include registration and annual certification in the FCC Robocall Mitigation Database, STIR/SHAKEN authentication using the provider’s own SPC token and Certificate Authority certificate, submission of a Robocall Mitigation Plan detailing specific steps to avoid carrying illegal robocall traffic, and cooperation with traceback requests from the registered consortium. These obligations are in force now, and non-compliance can result in removal from the RMD and mandatory traffic blocking by downstream carriers.
S.2666 would add a financial instrument requirement, where certain providers would need to post a bond before filing RMD certifications. The bill would also modify the traceback consortium application cycle, grant the consortium immunity for publishing traceback information, and direct the FCC to establish a joint task force with the FTC and DOJ. The FCC has not yet established the specific conditions, exemptions, or bond amounts that would apply to individual providers under S.2666.
Which providers might be subject to the proposed RMD bond under S.2666?
S.2666 directs the FCC to issue rules requiring “certain” voice service providers to post a bond before certifying to the RMD. The bill text also directs the FCC to establish exemption criteria for providers where the bond is not needed to deter unlawful robocall activity. Because the FCC has not yet issued implementing rules, the precise provider categories subject to the bond and the criteria for exemption are not yet defined. The Senate version of the bill makes the bond mandatory upon FCC rulemaking, unlike the House version (H.R. 6152) where the bond requirement is contingent on FCC rulemaking. Providers should monitor FCC rulemaking proceedings and consult qualified counsel to assess their specific exposure once implementing rules are proposed.
What are the consequences when a gateway provider is removed from the Robocall Mitigation Database?
Removal from the RMD has immediate operational consequences under current FCC rules. Once a provider is removed, intermediate and terminating voice service providers are required to cease accepting that carrier’s traffic. The FCC Enforcement Bureau has issued enforcement orders directing carriers to show cause within 14 days why they should not be removed, based on alleged failure to implement an effective robocall mitigation program. S.2666 would add a bond forfeiture mechanism on top of existing blocking consequences, and providers that fail to satisfy the FCC-established bond conditions could forfeit the bond, with forfeited payments deposited in the Treasury general fund. The proposed KYUP FNPRM, or Further Notice of Proposed Rulemaking, would further add per-call base forfeitures for KYUP violations, improper attestations or unauthenticated calls, and failing to implement STIR/SHAKEN.
How does the July 2026 FCC FNPRM on the RMD interact with S.2666?
The July 2026 FCC draft FNPRM on the Robocall Mitigation Database is a separate administrative proceeding from S.2666 but remains directly relevant because any enacted bill would interact with RMD certifications and filing obligations. The draft FNPRM proposes that entities such as information service providers, communications platforms, call centers, SaaS providers, and AI platforms using NANP telephone numbers may lose their prior safe harbor and become subject to RMD filing obligations. It also proposes requiring providers to disclose their network role on a call-by-call basis, requiring parents, affiliates, and subsidiaries to each file separately, and requiring providers claiming a STIR/SHAKEN exemption to cite the specific rule supporting the exemption and explain in detail why it applies based on facts specific to the provider’s network. The FCC accepted comments on FCC 26-32. If S.2666 is enacted, its bond and traceback provisions would layer on top of whatever RMD framework the FCC finalizes through this separate rulemaking track.
Conclusion: Operating Across Current Rules and Emerging FREA Proposals
Gateway and international voice providers face two distinct compliance tracks in 2026. The first is the existing mandatory framework under 47 CFR 64.6305, which includes RMD registration, annual certification, STIR/SHAKEN authentication using the provider’s own SPC token, a documented Robocall Mitigation Plan, and traceback cooperation. Non-compliance with these current rules results in RMD removal and mandatory downstream traffic blocking. The second track is conditional, because S.2666, ordered reported by the Senate Commerce Committee in October 2025 but not yet enacted, would add a bond requirement before RMD certification, expanded traceback consortium authority and immunity, and a joint FCC-FTC-DOJ task force. Parallel FCC rulemaking proceedings, including FCC 26-32 and the July 2026 draft FNPRM, are advancing on a separate administrative track and would interact with any enacted FREA provisions.
Plura operates as an FCC-licensed audio bridging carrier with STIR/SHAKEN authentication on every outbound call and RMD-aligned infrastructure. Carriers and compliance teams evaluating their infrastructure against both current rules and proposed expansions can review Plura’s compliance-ready plans.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 This article contains forward-looking statements regarding industry trends, technology adoption, and future capabilities. These statements reflect current expectations and are subject to change. Plura AI undertakes no obligation to update forward-looking statements except as required.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.