Home/Compliance Insights/Voice Authentication
Voice Authentication

What Is STIR/SHAKEN?

Attestation, SPC tokens, and certificates — what the framework does, and why implementation quality shows up in your carrier relationships.

EquiTel Compliance Solutions· ·7 min read ·Reviewed and kept current

STIR/SHAKEN is the caller ID authentication framework used across the North American voice network. STIR (Secure Telephone Identity Revisited) is the set of standards; SHAKEN is the deployment profile that applies them to SIP networks. Together they allow an originating provider to cryptographically sign a call so downstream providers can verify that the calling number was legitimately used.

The moving parts

A participating provider obtains a Service Provider Code (SPC) token from the STI Policy Administrator, which establishes eligibility. Using that token it obtains a signing certificate. Calls it originates are then signed with an attestation level, and downstream providers verify the signature and may use the result in analytics, labelling, or blocking decisions.

The three attestation levels

LevelMeaningWhat it asserts
A — FullKnown customer, known numberYou know the customer and confirmed their right to use the number
B — PartialKnown customer, unverified numberYou know the customer but cannot confirm number ownership
C — GatewayNeither establishedYou are passing traffic whose origin you cannot vouch for
Attestation is a factual assertion, not a setting

Signing A-level traffic you cannot actually vouch for is not a configuration preference. It is a statement about what your company knows — and it will not survive a traceback. This is why attestation problems are almost always customer onboarding problems.

Why implementation quality becomes visible

STIR/SHAKEN is unusual among compliance obligations in that the quality of your implementation is observable to your commercial counterparties. Carriers and analytics providers see your signing behaviour across large volumes of traffic. Weak onboarding controls, over-attestation, or inconsistent practice show up as a reputation signal long before they show up as a regulatory matter — and reputation signals affect whether your traffic completes.

Where providers commonly find themselves exposed

  • Treating it as a one-time project. Certificates expire, tokens require renewal, and company records change.
  • Stale upstream records. Eligibility depends on other records — OCN, RMD filing, 499 filer ID — and when those drift, renewal fails for reasons that are not obvious from the error.
  • Over-attestation. The most common cause of reputation damage we are asked to repair.
  • No documentation. When a carrier asks how attestation is determined, "our vendor handles it" is not an answer that resolves the conversation.

STIR/SHAKEN and robocall mitigation are separate obligations

Caller ID authentication is one requirement; maintaining and certifying a robocall mitigation program in the Robocall Mitigation Database is another. Providers regularly satisfy one and assume it covers the other. It does not — and the RMD entry is the more externally visible of the two.

EquiTel handles registration, remediation, and reputation recovery as STIR/SHAKEN practice work.

Frequently Asked Questions

What is STIR/SHAKEN?

STIR/SHAKEN is the caller ID authentication framework allowing originating voice providers to cryptographically sign calls so downstream providers can verify the calling number was legitimately used.

What are the STIR/SHAKEN attestation levels?

A (full) means the provider knows the customer and confirmed their right to use the number. B (partial) means the customer is known but number ownership is not confirmed. C (gateway) means neither is established.

What is an SPC token?

The Service Provider Code token is issued by the STI Policy Administrator and establishes a provider’s eligibility to obtain signing certificates.

Is STIR/SHAKEN the same as robocall mitigation?

No. Caller ID authentication and maintaining a certified robocall mitigation program in the Robocall Mitigation Database are separate obligations.

Sister company — STIRSHAKEN.AI

Who gets you certified.

STIR/SHAKEN certification — STI-PA eligibility, SPC token, certificates and renewal records — is handled end to end by STIRSHAKEN.AI. Continuous monitoring afterwards is STIR SHIELD, a STIRSHAKEN.AI product.

EquiTel does the recovery. STIRSHAKEN.AI certifies, files and monitors. Engaging either does not commit you to the other.

Voice Authentication Practice

This guide is part of the Voice Authentication cluster. The practice page covers how EquiTel handles these matters directly.

View the Practice

Filed by STIRSHAKEN.AI

Who gets you certified. Filing execution and STIR/SHAKEN certification are handled by our sister company STIRSHAKEN.AI — AI-powered, backed by humans. Continuous monitoring is STIR SHIELD.

STIRSHAKEN.AI

Facing This Now?

EquiTel provides confidential telecom compliance recovery, remediation, and regulatory advisory for established providers.

Request a Consultation

Facing a Telecom Compliance Issue?Talk to EquiTel.

EquiTel Compliance Solutions provides telecom compliance recovery, remediation, and regulatory advisory for established telecommunications providers. Every inquiry is confidential.