Quick answer: if your business sells voice service to end users under its own brand, your upstream platform's Robocall Mitigation Database filing does not cover you. You are a voice service provider in your own right under FCC rules, and you owe your own RMD certification, your own robocall mitigation plan, and a documented know-your-customer process describing exactly how you vet the customers you let originate traffic.
This guide is educational and not legal advice. Confirm your specific obligations with counsel and the current FCC public notices before filing.
Robocall mitigation for VoIP resellers used to feel like someone else's problem, something the upstream carrier handled quietly in the background. That stopped being true in 2023, when the FCC extended Robocall Mitigation Database filing obligations to every voice service provider in the call chain, resellers included. As of Q3 2026, a reseller serving end users carries its own federal compliance duties: an RMD filing, a documented know-your-customer process, and an obligation to answer tracebacks within 24 hours. Miss any one of them, and the FCC's rules let downstream providers refuse your traffic outright.
TL;DR
- A reseller serving end users is a voice service provider and has its own RMD filing obligation.
- An upstream platform's RMD filing does not cover the reseller. Each provider files separately.
- The robocall mitigation plan must document the reseller's know-your-customer process in specifics, not generalities.
- The FCC now requires annual recertification, a filing fee, two-factor authentication, and a 10-business-day update rule.
- Every provider must respond to traceback requests within 24 hours, and the FCC has removed providers from the RMD for ignoring that clock.
What Is Robocall Mitigation and KYC for VoIP Resellers and the RMD?
Robocall mitigation is the set of steps a voice provider takes to keep illegal robocall traffic off its network, whether that traffic originates with its own customers or simply passes through on its way somewhere else. The Robocall Mitigation Database, or RMD, is the FCC's public registry where every provider files a certification of its STIR/SHAKEN status alongside a written robocall mitigation plan describing those steps.
The RMD is not paperwork for its own sake. Downstream providers check it before they will accept a call, and the FCC treats a missing or inaccurate filing as an enforcement matter rather than an oversight. A complete filing has three parts: a STIR/SHAKEN certification, a robocall mitigation plan, and identifying information about the provider and its principals. For the fuller history of how the RMD reached its current form, see Viirtue's STIR/SHAKEN and Robocall Mitigation Database filing requirements guide.
Do VoIP Resellers Have to File in the RMD?
Yes, and this is the point that trips up more resellers than any other rule on the books. A VoIP reseller that sells voice service to end users meets the FCC's definition of a voice service provider under section 64.6305, and that definition carves out no exception for a company reselling someone else's network. The obligation to file your own RMD certification and mitigation plan sits with you, not with the platform whose infrastructure you resell.
Does my upstream provider's filing cover me? No. Every provider in the call path files for itself. Your upstream platform's RMD entry describes its own network and its own practices. It says nothing about your customers, your onboarding process, or how you respond when one of your accounts gets flagged in a traceback, because the FCC's rules assume you are the party closest to that information. Treating the platform's filing as a substitute for your own is the single most common compliance gap among white label VoIP resellers, and it is also the gap the FCC has been most explicit about closing. The Commission has said plainly that resellers serving end users are often in the best position to identify the customers responsible for illegal traffic, which is exactly why the filing duty follows the reseller and not just the network owner.
What KYC Means Under FCC Rules
Know-your-customer, or KYC, is the part of your robocall mitigation plan where you describe how you vet the customers who originate calls on your network. It sits alongside a related duty called know-your-upstream-provider, which covers how you vet the providers and customers who hand you traffic in the other direction. Both requirements come from the same FCC rulemaking, and both expect specifics, not a general statement of good intentions.
What does a KYC process actually need to include? At minimum, your plan should describe how you verify a customer's identity at onboarding, how you monitor calling patterns for signs of illegal traffic, how you respond when a customer is flagged in a traceback, and what your contract lets you do about it, up to and including suspension. If you use a third-party call analytics or blocking vendor, name it. Viirtue's breakdown of where Know Your Customer and Know Your Upstream Provider rules are heading next is worth reading alongside this section, since both requirements are still being sharpened by active rulemakings.
Market and Regulatory Context
The rules that put resellers in this position trace back to the TRACED Act of 2019, which directed the FCC to require STIR/SHAKEN authentication and laid the groundwork for the RMD. The real expansion came with the FCC's Sixth Caller ID Authentication Report and Order in 2023, which extended filing obligations to every provider regardless of STIR/SHAKEN status and set the deadline that made the RMD universal: February 26, 2024. Three months later, on May 28, 2024, the rule that gives the RMD its teeth took effect. Intermediate and voice service providers are prohibited from accepting traffic directly from any provider not listed in the database, and that single rule is what turns a missing filing into lost connectivity.
STIR/SHAKEN: What Resellers Must Certify
STIR/SHAKEN, short for Secure Telephone Identity Revisited and Signature-based Handling of Asserted information using toKENs, is the caller ID authentication framework that cryptographically signs calls so downstream networks can verify a calling number was not spoofed. In the RMD, a provider certifies whether it has fully, partially, or not implemented STIR/SHAKEN on the IP portions of its network.
For a reseller, the practical question is who performs the signing. A reseller operating on a carrier-grade voice network typically has its traffic authenticated through that network's STIR/SHAKEN infrastructure, but the reseller still certifies its own status and still files its own plan. Certifying accurately matters, since the certification is a sworn statement. The FCC set a base forfeiture of $10,000 for each submission of false or inaccurate information to the RMD, plus $1,000 for each failure to update a filing within 10 business days.
What Changed for 2025 and 2026
The FCC tightened RMD obligations through 2025 and into 2026, and resellers need to track the recurring duties, not just the original filing. These changes come from the Commission's order improving the effectiveness of the Robocall Mitigation Database, adopted December 30, 2024, with new forfeitures and deadlines taking effect February 5, 2026.
| Requirement | What It Means for Resellers | Effective |
|---|---|---|
| Annual recertification | Re-certify the accuracy of your RMD filing every year, by March 1 | Took effect Feb 5, 2026 |
| Application processing fee | Initial RMD filings now carry a fee | FCC 24-135 |
| Two-factor authentication | RMD portal access now requires 2FA | FCC 24-135 |
| 10-business-day updates | Update RMD and CORES information within 10 business days of any company change | FCC 24-135 |
The takeaway is that the RMD is now a living obligation. A reseller that filed once in 2024 and never touched it again is very likely out of compliance today, since the rules now require annual recertification and prompt updates whenever company information changes.
What Happens If You Do Not Comply
Noncompliance with RMD and robocall mitigation rules has a direct operational consequence: removal from the database and refusal of your traffic. This is not theoretical. In December 2024, the FCC's Enforcement Bureau directed 2,411 filers to cure deficiencies in their RMD filings, and through 2025 the Bureau made good on that warning, removing 185 non-compliant providers in August and a further 1,203 later that same month, nearly 1,400 providers cut off in a single four-week stretch. Once a provider is removed, every intermediate and voice service provider must stop accepting calls directly from it.
For a reseller, removal is an existential event, because traffic refusal means customers cannot complete calls. Beyond delisting, the FCC can impose monetary penalties for failing to file or for filing false information, and under 47 CFR 64.6305 every provider's mitigation plan must include a commitment to answer traceback requests within 24 hours. The FCC has already used that clock as grounds for enforcement, naming providers in 2025 who had promised a 24-hour response and then failed to deliver it. For the broader set of obligations that apply to every provider type, not just resellers, see Viirtue's robocall mitigation requirements overview. The compliance cost here is small. The cost of losing connectivity is the entire business.
The Reseller Robocall Compliance Checklist
Treat this sequence as recurring, not a one-time project.
- Register in CORES, obtain a business FCC Registration Number, and file your own RMD certification and robocall mitigation plan as a voice service provider.
- Document your know-your-customer process: identity verification at onboarding, monitoring for suspicious patterns, and suspension provisions for illegal traffic.
- Document your know-your-upstream-provider procedures and your call analytics or blocking systems, naming any third-party vendor.
- Certify your STIR/SHAKEN status accurately for the IP portions of your network.
- Build a traceback response process that can answer the Industry Traceback Group within 24 hours, as 47 CFR 64.6305 requires.
- Re-certify annually by the FCC's deadline and update your filing within 10 business days of any company change.
How a Platform Helps (and What It Cannot Do for You)
A carrier-grade platform reduces the technical burden of robocall compliance, but it cannot file your RMD certification for you. The right platform handles the heavy infrastructure: STIR/SHAKEN signing on the IP portions of the network, call analytics that flag suspicious patterns, and the traceback tooling you need to answer the Industry Traceback Group quickly.
Viirtue partners build on a carrier-grade voice network that performs STIR/SHAKEN authentication and supports the analytics and traceback workflows compliance depends on, while ViiBE keeps the telecom tax and regulatory side automated. What remains the reseller's responsibility is the part the FCC assigns to the voice service provider directly: filing in the RMD, documenting KYC, and answering tracebacks. This division of labor is also why the Managed Intelligence Provider model depends on owning a real platform rather than stitching tools together: compliance ownership does not disappear just because you outsource the infrastructure.
A carrier-grade platform can sign your calls and flag suspicious patterns, but it cannot file your RMD certification for you. Compliance ownership stays with the reseller because the FCC built the rule that way on purpose. Resellers who treat RMD filing, KYC documentation, and traceback response as recurring line items, not a one-time task, are the ones who never have to explain a delisting to their customers.
Key Takeaways
- A VoIP reseller serving end users is a voice service provider and must file its own RMD certification and robocall mitigation plan.
- An upstream platform's RMD filing does not cover the reseller. Each provider files for itself.
- The robocall mitigation plan must document the reseller's know-your-customer and know-your-upstream-provider processes in specifics.
- The FCC now requires annual recertification, a filing fee, two-factor authentication, and 10-business-day updates.
- Every provider must answer traceback requests within 24 hours, and the FCC has already enforced against providers who missed that window.
- A carrier-grade platform handles STIR/SHAKEN and analytics, but the RMD filing, KYC, and traceback response stay with the reseller.
Robocall Mitigation for VoIP Resellers: What to Do Next
Robocall mitigation for VoIP resellers is now a standing duty, not a problem the upstream carrier absorbs quietly. A reseller serving end users files its own RMD certification, documents its KYC process in specifics, re-certifies annually, and answers tracebacks within 24 hours. The providers who treat this as routine keep their traffic flowing. The ones who assume someone else has it covered are one delisting away from going dark.
If you want a platform that handles the authentication and analytics while a partner team helps you stay current on the rules, see Viirtue's white label partner program, or watch the full KYC and robocall compliance webinar for a walkthrough of what regulators expect from reseller filings.
FAQ: Robocall Mitigation and KYC for VoIP Resellers
Do VoIP resellers have to file in the Robocall Mitigation Database?
Yes. A reseller that sells voice service to end users is a voice service provider under FCC rules and must file its own certification and robocall mitigation plan in the RMD. The upstream platform’s filing does not satisfy the reseller’s obligation.
What is KYC for a VoIP provider?
KYC, or know-your-customer, is the FCC requirement that a voice service provider describe in its robocall mitigation plan how it verifies and monitors the customers originating calls on its network. It includes onboarding identity checks, monitoring for illegal traffic, and the ability to suspend offending customers.
What is the Robocall Mitigation Database recertification deadline?
The FCC now requires annual recertification of RMD submissions. The Wireline Competition Bureau sets the date by public notice; the 2026 annual recertification deadline was March 1, 2026. Always confirm the current date against the latest FCC public notice.
What happens if a provider is not listed in the RMD?
Intermediate and voice service providers are prohibited from accepting traffic directly from any provider not listed in the RMD. In practice that means a delisted or unlisted provider’s calls get refused downstream, which can take its service offline.
Does Viirtue handle robocall compliance for its partners?
Viirtue’s carrier-grade voice network performs STIR/SHAKEN authentication and supports the analytics and traceback workflows compliance relies on. The RMD filing, the documented KYC process, and traceback responses remain the reseller’s responsibility as the voice service provider, which is what the FCC rules require.