The FCC’s proposal to rebuild the Robocall Mitigation Database was published in the Federal Register on 9 September 2026. Comments are due 9 October, replies 9 November. The line that matters for anyone running outbound: the Commission wants the rules to reach an entity by what it does with voice traffic, and it names dialing platforms and call centers as examples.
That is a change in kind, not degree. For five years the database has been a place where carriers file a description of how they fight illegal robocalls. The proposal turns it into a vetting file that decides whether you get to hand traffic to anyone.
What the proposal actually says
The Further Notice was adopted 22 July and released 23 July 2026, under WC Docket Nos. 24-213 and 17-97 and CG Docket No. 17-59. None of it is law yet. Read what follows as the direction of travel rather than a checklist you owe anybody in October.
The scope language is the part worth reading twice. The FCC proposes clarifying that the rules apply across the voice ecosystem regardless of how an entity describes its service, and it lists VoIP resellers, MVNOs, PBX providers, dialing platforms and call centers. If you have spent years confident that the database was your carrier’s problem, that sentence is aimed at you.

I want to be careful not to overstate this, because plenty of compliance blogs will. The proposal asks questions. It does not yet impose a filing duty on every call center in the country, and a lot of comment filings between now and November will argue about exactly where that line lands. But the Commission has been widening this net steadily since the gateway provider rules, and I would not bet on it narrowing.
Four certifications, and one with a clock on it
Filers would certify four things: that they have not submitted false, misleading or inaccurate information to the FCC, that they comply with the robocall, caller ID authentication and numbering rules, that they meet STIR/SHAKEN attestation requirements, and that they respond to traceback requests within 24 hours.
That last one is the operational item. Twenty four hours is not long if traceback requests land in a shared inbox that somebody checks when they get a minute. The Industry Traceback Group typically wants to know which customer originated a specific call at a specific second, and if your platform cannot answer that from a CDR in a few minutes, the clock is already against you.
Run a drill. Pick a call from last Tuesday out of your own logs and see how long it takes someone who is not you to produce the originating tenant, the source IP, the caller ID presented, and the consent record. Most teams find the answer is somewhere between twenty minutes and never.
The disclosures are about people, not technology
The proposed filing would carry principals’ contact details and citizenship, every affiliate and subsidiary, a US registered agent, prior regulatory actions, and identification of third party vendors. Any STIR/SHAKEN exemption you claim would have to name the specific rule that allows it and explain why it applies using facts about your own network.
Read that list again and notice what the FCC is building. It is a map of who is behind an entity, so that a provider removed under one name cannot reappear the following month under another. The database stops being a description of your mitigation and becomes a description of you.
For an honest operator this is mostly paperwork. For anyone who has ever quietly stood up a second company to carry traffic the first one could not, it is the end of that trick.
How a stale filing becomes blocked traffic
The enforcement side is where the proposal has teeth. Staff would be able to hold a filing in pending status, withhold publication, or reject it outright, particularly where it looks connected to a previously removed provider. Grounds for suspension or removal get codified: a deficient filing, inconsistencies with what the Commission can see elsewhere, failure to update on time, carrying illegal calls, mitigation that does not work in practice, and caller ID authentication violations. Serious cases get an expedited process with five days to cure or respond before removal.

Removal from the database is not a fine. It means downstream providers are required to stop accepting your traffic. You do not get to appeal your way back into service while your campaigns keep dialing. That asymmetry is the whole point, and it is why the existing obligations are worth more attention than they usually get: recertify by 1 March every year, and update the entry within ten business days of a change to your address, ownership, registered agent or officers.
The ten day rule catches more people than the annual one. Nobody forgets 1 March twice. Plenty of companies change a registered agent in June and update the database the following spring.
What this asks of your call center software
Strip out the filing mechanics and four capabilities decide whether you can live with rules like these. They are worth auditing whatever happens to this proposal.
Per-tenant attribution that survives a year. When a traceback arrives you need to name the customer, not the platform. On a multi-tenant deployment that means CDRs that carry the tenant identity, the campaign, and the caller ID presented, retained long enough to answer a request about a call from eight months ago.
Consent you can produce, not just claim. The certification about complying with the robocall rules is only as good as the record behind it. If consent lives in a CRM nobody exports and the dialer only holds a phone number, you have an assertion rather than evidence.
Controls that actually stop a campaign. Your mitigation description has to match what the platform enforces. Do not write that you throttle suspicious traffic if the only throttle is a person watching a dashboard. Pacing, abandonment and calling window controls that are configured at the tenant level are the difference between a description and a control.
Somebody who owns the traceback queue. This is a staffing answer, not a software one, but the software decides how painful it is. A named person, a monitored address, and a documented lookup that takes minutes.
Self-hosted platforms have a real advantage on the first two, and I say that as someone with an obvious interest. When the CDRs and the consent records sit in your own database you can answer a traceback without opening a vendor ticket. When they sit in a hosted platform you are waiting on somebody else’s support queue while a 24 hour clock runs. We made a similar argument about upstream provider vetting last year, and this proposal is the same pressure arriving one layer closer to you.
What I would do before March
Not much of this requires a decision from the FCC first.
Check whether your company or any affiliate has an entry in the database, and read what it says. A surprising number of entries were written by someone who left, describe a stack that has since been replaced, and have not been touched since the original filing. If the description does not match what your platform does today, that is an inconsistency under the proposed grounds for removal, and it is also just bad practice.
Then write down your affiliates. Every entity that touches the traffic, every reseller relationship, every white label tenant operating under their own brand. The proposal wants that list and most operators cannot produce it in an afternoon.
Last, if the scope language worries you, file a comment. The window is open until 9 October and the record is genuinely thin on what these rules cost a twenty seat call center as opposed to a carrier. Regulators write the rule they have evidence for. Nobody is going to make that argument on your behalf.
FAQ
Does my call center have to file in the Robocall Mitigation Database today?
Today the filing obligation sits with voice service providers and intermediate and gateway providers. If you buy origination from a carrier and do not hold numbering resources yourself, you are most likely not a filer. The proposal asks whether that line should move, and names call centers and dialing platforms while asking.
What happens if a provider is removed from the database?
Downstream providers are required to stop accepting its traffic. In practice that is an outage rather than a penalty, which is why filings and updates deserve more attention than their tedium suggests.
When are the comment deadlines?
Comments are due 9 October 2026 and reply comments 9 November 2026, in WC Docket Nos. 24-213 and 17-97 and CG Docket No. 17-59. The Further Notice was adopted 22 July and published in the Federal Register on 9 September 2026.
Is the 24 hour traceback response a new rule?
Responding to traceback has been expected for years. What the proposal adds is a certification, signed by you, that you do it within 24 hours. Certifying something you cannot demonstrate is a worse position than not certifying it.
Does STIR/SHAKEN exemption paperwork change?
Under the proposal, claiming an exemption would mean naming the rule that authorises it and explaining why it applies with facts about your own network. A generic exemption claim would not survive screening.
How does ICTBroadcast help with any of this?
It is not a compliance product and I would not sell it as one. What it gives you is the underlying evidence: per-tenant CDRs on your own server, recordings, calling window and pacing controls set per tenant, and a REST API to pull all of it out when someone asks. Our TCPA and STIR/SHAKEN checklist covers the rest of the routine. The filing is still yours to write.
If you are sizing up whether your current stack could answer a traceback inside a day, that is a good test to run this week rather than next March. Take ICTBroadcast for a look and try the lookup on your own data.
