Originally published at ictcontact.com
The FCC's Know-Your-Upstream-Provider proposal stops taking comments today, 10 August 2026. If it becomes a rule, three things change for outbound teams: attestation levels get written into the regulations instead of living in an industry document, "improper attestation" becomes a defined offence with a defined remedy, and every provider in the chain has to vet the one feeding it traffic.
None of that binds you tomorrow. Rulemakings take months. But the record closing today is the record the eventual order gets built from, and the direction of travel is already clear enough to plan against.
What the FCC actually proposed
The item is a Further Notice of Proposed Rulemaking, adopted as FCC 26-32 and running in WC Docket No. 17-97 alongside CG Docket No. 17-59. It landed in the Federal Register on 9 July 2026. Comments are due today. Reply comments run until 8 September 2026.
Four groups of proposals matter if you run campaigns:
Baseline KYUP obligations. Providers would have to collect specific information about whoever hands them traffic, review it, verify it, monitor it over time, and take action when something is wrong. Today "know your upstream provider" is more of an expectation than a checklist. The proposal turns it into one.
A stronger Governance Authority. The body that issues STIR/SHAKEN certificates would get wider vetting, enforcement and reporting duties, so a provider that abuses a certificate can lose it rather than simply being asked to behave.
Codified attestation levels. A, B and C would be defined in the rules. So would improper attestation. The FCC also asks what mechanisms should count as valid for verifying that a number really belongs to the customer using it.
Fewer gaps. Provider definitions get refined, existing exemptions get revisited, providers serving end users would have to assign an attestation, and calls would have to carry their authentication information all the way through instead of losing it at a handoff.
Why the attestation piece is the one to read
Most contact center teams treat attestation as somebody else's job. Your carrier signs the call, you see A on a spot check, everyone moves on. That works right now because the definitions live in ATIS documentation and enforcement is uneven.
Codifying the levels changes the incentives on the carrier side. Once "improper attestation" is a defined thing with consequences attached, a carrier that has been signing A on numbers it never really verified has a reason to stop. The likely outcome is not that your calls get blocked. It is that your carrier starts asking you for proof it never asked for before, and downgrades you to B while it waits.
B is not fatal. It also is not free. Analytics engines weigh attestation alongside complaint rates and call patterns, and a downgrade you did not plan for shows up as a drop in answer rate a week later, with no obvious cause in your own reporting.
Five things worth checking this month
You do not need a compliance project for this. You need answers to questions you can ask by email.
What attestation does each of your numbers get, and from which provider? Teams with more than one carrier often find the answer differs by route and nobody had noticed.
How does your carrier establish that a number is yours? A letter of authorisation, a porting record and a verbal confirmation are not equally defensible, and the FCC is asking exactly this question.
Who is upstream of your carrier? If your traffic passes through a wholesale layer before it reaches a tier-1, the KYUP duties land on that layer, and its answer becomes your problem.
Do you keep your own records of number ownership? When a carrier tightens its process, the customers who can produce documentation the same day keep their A. The rest wait.
Can you see attestation in your own reporting? If the only way to check is to call a mobile and look at the screen, you will find out about a downgrade late.
Where the software side comes in
Two habits make a carrier tightening its process survivable rather than disruptive.
The first is clean number-to-campaign mapping. If your contact center software can tell you which numbers ran which campaigns over the last quarter, you can answer a carrier questionnaire in an afternoon. If that lives in a spreadsheet somebody maintains by hand, you cannot.
The second is watching answer rate per caller ID rather than per campaign. Attestation problems are number-level. A campaign-level average hides a single downgraded number until the quarter looks bad. Per-number reporting in your CDR and live statistics turns that into something you spot in days.
Neither of these is a compliance feature. They are ordinary operational hygiene that happens to be what regulators are moving toward.
What we would not do
Do not buy anything on the strength of an FNPRM. The comment cycle has not closed on reply comments yet, the order will differ from the proposal, and vendors selling KYUP compliance today are selling a guess.
Do not assume this only touches US traffic either. The FCC explicitly asks about foreign-originated calls, and the pattern it is describing, pushing verification back along the chain, is the same one branded calling programmes in other markets have already adopted.
Frequently asked questions
Does anything change for my calls today?
No. This is a proposal. The comment deadline closing today affects who gets to shape the rule, not what your carrier does this week.
Can we still file a comment?
Comments are due on or before 10 August 2026 in WC Docket No. 17-97. Reply comments stay open until 8 September 2026, so there is a second window if you miss the first.
What is the difference between A, B and C attestation?
A means the provider knows the customer and knows they have the right to use that number. B means it knows the customer but not the number. C means it is passing the call along without either. The proposal would write those definitions into the rules rather than leaving them to industry documentation.
Will B attestation get our calls blocked?
Not on its own. Analytics engines weigh attestation together with complaint rates, call duration patterns and volume. B narrows your margin rather than ending the call.
We use a wholesale provider. Does KYUP apply to us?
The obligations as proposed sit with providers rather than with calling parties. The practical effect reaches you anyway, because the provider carrying your traffic has to be able to answer for it.
How do we prove a number belongs to us?
Keep porting records, letters of authorisation and provisioning confirmations somewhere you can retrieve them by number. That is the evidence a carrier will ask for, and the FCC is currently taking comment on which forms of it should count.
The short version
The FCC is moving verification away from a single signature at the edge and spreading it across the whole call path. For contact centers the practical consequence is not a new compliance burden, it is a carrier that starts asking harder questions. Teams that can answer with records rather than assurances will keep their attestation. Teams that cannot will spend a quarter finding out why answer rates slipped.
If you want to talk through how your numbers and campaigns are mapped, open a ticket and we will take a look.
Top comments (0)