CallataGuides

STIR/SHAKEN Explained for Business Callers

What STIR/SHAKEN caller ID authentication is, what A, B and C attestation mean, the FCC deadlines, and what a business should ask its phone provider.

STIR/SHAKEN is the caller ID authentication system US phone carriers use to show that a call really comes from the number on the screen. The provider that originates a call signs it with an attestation level, A, B or C, and the receiving provider checks the signature before deciding how to present the call.

For a business, STIR/SHAKEN is mostly invisible, but it affects whether your calls get answered. Calls carrying full "A" attestation give carriers more reason to trust your caller ID, though authentication alone does not prevent spam labels.

What the acronyms mean

According to the FCC, STIR/SHAKEN is a framework of technical standards for authenticating and verifying caller ID on calls carried over Internet Protocol (IP) networks:

  • STIR: Secure Telephone Identity Revisited, the underlying standards
  • SHAKEN: Signature-based Handling of Asserted information using toKENs, the framework for implementing them in carrier networks

The FCC says the system helps subscribers trust that callers are who they say they are and "erodes the ability of callers to illegally spoof a caller ID."

How it works on a call

  1. You place a call from your business number.
  2. Your provider, the originating provider, checks what it knows about you and the number, assigns an attestation level, and adds a digital signature to the call.
  3. The call travels across networks. Each IP hop can carry the signature forward.
  4. The receiving provider verifies the signature using the originating provider's certificate.
  5. The receiving provider uses the result, along with its own analytics, to decide how to present the call: normal, verified, labeled, or blocked.

If the call passes through a non-IP (older TDM) segment, the signature can be lost. The FCC requires providers with non-IP networks to upgrade to IP or work on a non-IP authentication solution.

Attestation levels

According to Bandwidth's explanation of the framework:

Level Name What the originating provider is saying
A Full attestation We know this customer, and they are authorized to use this calling number
B Partial attestation We know this customer, but we cannot confirm they are authorized to use this number
C Gateway attestation We are passing along this call from another source and cannot vouch for it

Business calls should ideally get A attestation. That generally requires the number to be one your provider assigned to you, or one it has otherwise verified you are allowed to use.

Why business calls sometimes get B

Common causes:

  • Displaying a number from a different provider, such as your old main line, on calls placed through a new system
  • Call center software that sets the caller ID to a client's number
  • Numbers ported in that the provider has not yet associated with your account

If you need to display a number your provider did not assign, ask whether it can verify your right to that number so calls can receive full attestation.

The FCC timeline

Date What happened
December 2019 TRACED Act enacted, directing the FCC to require caller ID authentication
2020 FCC adopted rules requiring STIR/SHAKEN in IP networks
June 30, 2021 Deadline for voice service providers to implement in IP networks
June 30, 2023 Extended deadline for providers with 100,000 or fewer voice subscriber lines, per Davis Wright Tremaine's summary of the FCC order
September 18, 2025 Effective date of the FCC's third-party authentication rule

The FCC says that today most providers, including voice service providers and gateway providers, must implement STIR/SHAKEN, and all providers must file in the Robocall Mitigation Database describing their efforts to fight illegal robocalls.

The 2025 third-party authentication rule

Some providers relied on outside vendors to sign their calls. Under the FCC's rule published in the Federal Register on August 19, 2025, providers with a STIR/SHAKEN obligation must obtain their own Service Provider Code (SPC) token and ensure calls are signed using their own certificate, even if a third party performs the technical signing. The provider must also make all attestation-level decisions itself, and any provider certifying STIR/SHAKEN implementation in the Robocall Mitigation Database must be registered with the STIR/SHAKEN Policy Administrator. The rule took effect September 18, 2025. For businesses, it means the provider responsible for your calls is accountable for the signature, and an SPC token can be revoked if a provider fails to comply.

What STIR/SHAKEN does not do

  • It does not judge the call's content. A fully attested call can still be an unwanted sales call.
  • It does not guarantee your calls are answered or unlabeled. Carriers combine authentication with analytics on calling patterns and complaints. See why business calls show Spam Likely.
  • It does not display your name. Your caller ID name comes from separate databases. See CNAM caller ID name.
  • It does not cover every call path. Calls through non-IP segments or some international routes may arrive unsigned.

Spoofing and the law

STIR/SHAKEN makes spoofing harder; the law makes some spoofing illegal. According to the FCC, under the Truth in Caller ID Act, FCC rules prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value, with penalties of up to $10,000 for each violation.

The FCC also notes that not all spoofing is illegal. Its examples include a doctor calling a patient from a personal mobile phone while displaying the office number, and a business displaying its toll-free call-back number. Displaying your own business's main number on staff calls is in that legitimate category. Displaying a number you do not control is legally risky and likely to lower your attestation level.

Checklist: what to ask your phone provider

  • Do you sign our outbound calls with STIR/SHAKEN?
  • What attestation level do our calls receive, and on which numbers?
  • Will ported-in numbers receive full attestation after the port?
  • Do you have your own SPC token and certificate?
  • Are you listed in the FCC's Robocall Mitigation Database?
  • How do we display a number you did not assign, if we need to?
  • Do you help register our numbers with call analytics providers?

For businesses that make many calls

Teams that call customers frequently, such as service businesses confirming appointments or sales teams following up on inquiries, should:

  1. Call from numbers their provider assigned and can attest.
  2. Use a consistent set of numbers rather than rotating many.
  3. Call people who expect the call.
  4. Keep short, unanswered calls to a minimum.
  5. Register numbers with the analytics providers' free caller registry.
  6. Set an accurate caller ID name.

Caller ID on Callata

Callata assigns your business local numbers, and calls from your team, whether placed from the browser or routed through Callata, show your business number as caller ID. Callata's terms prohibit spoofing caller ID. Each number is registered with a caller ID name based on your business name. The plan is $99 a month for up to five users, with up to three local numbers included. Sign up.

Frequently asked questions

What is STIR/SHAKEN in simple terms?

It is a caller ID authentication framework. The provider that originates a call digitally signs it to vouch for the caller's right to use the number shown, and the receiving provider verifies the signature. The FCC requires voice providers to use it in the IP portions of their networks.

What do attestation levels A, B and C mean?

A (full) means the provider knows the customer and that the customer is authorized to use the calling number. B (partial) means the provider knows the customer but cannot confirm the right to the number. C (gateway) means the provider is passing along a call it received from elsewhere and cannot vouch for the source.

Will STIR/SHAKEN stop my calls showing as spam?

Not on its own. Authentication confirms caller ID is not spoofed, and carriers use it in labeling decisions, but labels also depend on calling patterns and complaints.

Do businesses have to do anything for STIR/SHAKEN?

The legal obligation falls on voice providers, not on businesses that make calls. Businesses should use numbers their provider assigns or can verify, avoid displaying numbers they do not control, and ask their provider what attestation their calls receive.