U.S. Telecom Regulations

Call Center Compliance Resources

The FTC's Telemarketing Sales Rule (TSR)

The FCC's Telephone Consumer Protection Act (TCPA)

FCC Rules Implementing the TCPA

FTC guide for complying with the TSR

FTC News

Email Compliance Resources

The Federal CAN-SPAM Act of 2003

A Short CAN-SPAM Summary

FTC CAN-SPAM Compliance Guide

State Anti-Spam Statutes

Marketing and Advertising Law Resources

Advertising FAQs - A Guide for Small Businesses

FTC guide regarding claims to Environmental Friendliness

FTC's "Deception" Policy Statement

FTC's "Unfairness" Policy Statement

Guide to the FTC's Mail and Telephone Order Merchandise Rule

Children's Online Privacy Protection Rule

FTC's "Comparative Advertising" Policy Statement

FTC's 900-Number Rule

Truth In Lending Act (TILA)

Dot Com Disclosures - Information about Advertising Online

FTC Guide for Use of Testimonials and Endorsements

FTC Statement on Food Advertising

FTC Regulations Concerning Use of the Word "Free"

Big Print. Little Print. What's the Deal?

Business Guide for Selling Internationally over the Internet

The Consumer Leasing Act

Rules against Deceptive Pricing

The regulatory stack: five frameworks every business communicator operates under

US telecom regulation isn't one rulebook — it's a stack of them. The FCC sets the federal floor, the CTIA and carriers layer industry rules on top, The Campaign Registry governs who may send business SMS, and states like Florida, Oklahoma, and Washington add their own mini-TCPA statutes. Any business that calls or texts customers in the United States is operating inside all of these frameworks at once, whether it knows it or not.

TCPA — Telephone Consumer Protection Act

The federal law behind almost every texting lawsuit you've read about. It requires prior express written consent for marketing calls and texts made with automated technology, honoring of opt-out requests, and calling-time restrictions. Statutory damages run $500 to $1,500 per violation — per message — which is why TCPA class actions routinely settle in the millions.

10DLC — the A2P registration framework

Since 2021, businesses sending SMS over standard 10-digit numbers must register their brand and campaigns with The Campaign Registry. Unregistered traffic is filtered or blocked outright by AT&T, T-Mobile, and Verizon. Registration involves brand vetting, campaign use-case review, and per-campaign monthly fees.

STIR/SHAKEN — caller ID authentication

A cryptographic framework mandated by the FCC that lets carriers verify a call's origin and attest that the caller is authorized to use the number. It is the backbone of the fight against spoofed robocalls and the foundation for Branded Caller ID.

CTIA Messaging Principles

The industry handbook that defines what carriers consider compliant messaging: consent standards, prohibited content categories (SHAFT — sex, hate, alcohol, firearms, tobacco), opt-out language, and traffic patterns that trigger filtering.

Every clause of the principles, from the three consent tiers to snowshoeing and the October 2025 security addendum, is walked through in our plain-English guide to the CTIA Messaging Principles and Best Practices.

Do Not Call Registry and state mini-TCPAs

The federal DNC list applies to telemarketing calls, and a growing list of states enforce their own stricter versions with separate consent rules and private rights of action.

Who enforces what

The FCC writes and enforces federal communications rules and levies forfeitures. The FTC polices deceptive marketing practices and runs the DNC registry. State attorneys general enforce state statutes. And in practice, the fastest enforcement of all comes from the carriers themselves — they don't sue you, they just stop delivering your messages.

How Signalmash keeps you compliant

Compliance is built into the platform, not bolted on: 10DLC brand and campaign registration handled end-to-end with a 94% first-time approval rate, STIR/SHAKEN attestation on outbound calls, automated opt-out handling, and a compliance team that tracks FCC dockets so rule changes reach you before fines do. For providers who want the whole burden lifted, Compliance as a Service manages it continuously. Questions about your specific traffic? Talk to a compliance expert.

What changed in 2025 and 2026, and what is scheduled next

The frameworks above are stable; the rules inside them move every few months. These are the changes that affect US business calling and texting programmes, in date order, with the practical consequence of each. Checked against the FCC orders and statutes on 4 September 2026.

24 January 2025: the one-to-one consent rule is struck down

The Eleventh Circuit vacated the FCC's rule that would have required lead-generation consent to name one seller at a time (Insurance Marketing Coalition v. FCC), and the FCC later repealed it. Consequence: the standard for marketing calls and texts placed with an automated system remains prior express written consent that clearly identifies the seller, and state laws, not the vacated rule, now set the tighter limits on shared consent forms.

11 April 2025: consent revocation by any reasonable means

The FCC's revocation rules took effect. A consumer can withdraw consent by any reasonable method, including replies such as STOP, QUIT, END, REVOKE, OPT OUT, CANCEL or UNSUBSCRIBE and plain-language equivalents, and the sender must honour the request within a reasonable time not exceeding ten business days. One confirmation text is permitted, provided it asks for nothing else. Consequence: keyword lists must be broader than STOP, opt-outs must flow to every system that sends, and the ten-day clock should be logged.

1 September 2025: Texas SB 140 extends telemarketing registration to text messages

Texas amended Business and Commerce Code Chapters 301 to 306 so that a telephone solicitation includes a text, graphic or image message. Sellers that market by text to Texas residents must register annually with the Texas Secretary of State, post $10,000 security and pay a $200 filing fee per business location, unless an exemption applies (publicly traded companies, supervised financial institutions, insurers, FCC-regulated companies, non-profits, sellers contacting existing customers, and businesses earning most revenue at physical locations, among others). Enforcement runs through the Deceptive Trade Practices Act, with a private right of action of up to $1,500 per violation, treble damages for wilful violations, Attorney General penalties of $5,000 per violation and a Class A misdemeanour for failing to register. Consequence: check the exemptions before your next Texas campaign, and treat Texas alongside Florida and Oklahoma as a state with its own rulebook.

18 September 2025: STIR/SHAKEN signing must use your own certificate

The FCC's third-party authentication rules took effect. A provider with a STIR/SHAKEN obligation may let a vendor perform the technical signing, but the call must be signed with the obligated provider's own certificate and SPC token, the provider keeps control of attestation decisions, and the arrangement must be documented. Consequence for SIP trunking customers: ask your carrier who signs your calls and at what attestation level, because the answer now determines how your traffic is scored.

5 February 2026 and 1 March 2026: Robocall Mitigation Database penalties and recertification

Base forfeitures for the Robocall Mitigation Database took effect on 5 February 2026: $10,000 for false or inaccurate filings and $1,000 for failing to update a filing within ten business days, alongside the annual recertification that opened on 1 February and closed on 1 March 2026. Consequence: providers, including resellers and enterprises that operate as voice service providers, need a named owner for the filing and a calendar entry for every February.

31 January 2027: the "revoke-all" provision is on hold until then

One part of the 2025 revocation rules, which treats an opt-out received in response to one type of informational message as revoking consent for all future robocalls and robotexts from that caller on unrelated matters, has been waived twice and is now scheduled to take effect on 31 January 2027. Consequence: design the opt-out plumbing now so that a single STOP can suppress every programme for that number, because that is where the rule is heading.

What this means for a messaging programme in practice

  • Keep one consent record per number that captures the source, wording, timestamp and channel, because consent is now litigated on evidence rather than assertion.
  • Treat any reasonable opt-out phrase as revocation, propagate it to every sending system within ten business days, and be ready for it to apply across programmes.
  • Review state registration duties (Texas, Florida, Oklahoma and the growing list of mini-TCPA states) before each campaign, not after the first complaint.
  • Confirm with your carrier who signs your outbound calls and who files your Robocall Mitigation Database certification; the 10DLC readiness checker and compliance page cover the messaging side.

Signalmash reviews these rules with every customer during onboarding and keeps 10DLC, toll-free and RCS registrations current as they change; the dated notes on this page are updated each quarter.

Frequently asked questions

Do I need consent to text my customers?

Yes. Marketing texts require prior express written consent under the TCPA — a checkbox at signup, a keyword opt-in, or a signed form. Transactional messages such as order updates and appointment reminders have a lower bar, but documented consent is still the safest standard.

What happens if I skip 10DLC registration?

US carriers filter or block unregistered A2P traffic on 10-digit numbers. Messages fail silently — no bounce, no error — and repeat offenses can get numbers blocklisted entirely.

Is it legal to cold-call businesses in the US?

B2B calls sit outside most TCPA consent rules, but DNC rules, state statutes, and calling-time restrictions can still apply. See our full guide to cold calling legality in the US.

What is SHAFT and why do carriers care?

Sex, hate, alcohol, firearms, and tobacco — content categories carriers restrict or prohibit over A2P messaging regardless of legality, because carrier rules are stricter than federal law.

How do state mini-TCPAs differ from the federal TCPA?

States like Florida (FTSA) and Oklahoma add their own consent requirements, calling-hour limits, and private rights of action — often with lower thresholds for what counts as an autodialer.

Lost in the acronyms? The telecom and messaging glossary defines TCPA, STIR/SHAKEN, attestation, robocall mitigation, DNC, 10DLC, CTIA and fifty other terms in plain English, each linked to the relevant guide.

Who is responsible for compliance — my business or my provider?

Legally, the sender. Practically, a good CPaaS shares the load: registration, opt-out automation, and traffic monitoring. Signalmash does the heavy lifting, but consent collection always lives with your business.