Reference

The Robocall Mitigation Database (RMD)

The RMD is the FCC database where every voice, intermediate, and gateway provider certifies its robocall mitigation. It's provider-side — but a provider falling out of it gets your traffic blocked. Annual recertification is due Mar 1, 2026.

reference Last verified mid-2026 3 min read

The Robocall Mitigation Database (RMD) is the FCC’s registry where every voice provider certifies how it fights illegal robocalls. Providers that fully implement STIR/SHAKEN attest to that; providers that can’t must file a robocall mitigation plan describing their controls. Either way, being in the RMD — and staying in it — is a precondition for having your traffic accepted across the network.

This is a provider-side obligation. You, the brand, don’t file. But it belongs in your voice-trust playbook because your provider’s RMD standing directly determines whether your calls get delivered at all.

What the RMD is and who must file

STIR/SHAKEN is FCC-mandated on IP networks. To enforce it, the FCC requires that all voice, intermediate, and gateway providers be filed in the RMD — including MVNOs. The certification covers their authentication status and mitigation practices, and downstream providers are prohibited from accepting traffic from any provider not listed in the database.

Provider typeObligation
Voice providers (originating)File certification + mitigation status
Intermediate providersFile certification
Gateway providers (foreign-originated traffic)File certification; must authenticate
MVNOsMust file / recertify

Annual recertification

The RMD now requires annual recertification — not a one-and-done filing. Every voice, intermediate, and gateway provider (including MVNOs) must reconfirm its information each year.

Deadline · 2026-03-01
RMD annual recertification deadline — The recertification window opened February 1, 2026; filings are due by March 1, 2026. Miss it and the provider risks removal from the RMD — which forces downstream providers to block all of its traffic. Confirm your provider has recertified.

The recertification requirement was formalized through the FCC’s CORES registration-system rule (Federal Register, Jan 6, 2026). Related: new third-party caller-ID authentication obligations took effect Sept 18, 2025, broadening who must authenticate — see STIR/SHAKEN and attestation.

What non-compliance costs

The consequences of a bad or missing filing are severe and they cascade downstream:

  • Removal from the RMD → downstream providers must block 100% of the removed filer’s traffic. This is the part that reaches you: if your provider is removed, your calls stop.
  • Forfeitures of roughly $10,000 base per false or inaccurate submission.
Your provider's failure blocks your calls
You can have perfect A-level attestation and a clean reputation across all three analytics engines, and it all goes to zero if your originating provider drops out of the RMD. Treat your provider’s RMD standing as a vendor-risk item: confirm it’s filed, confirm it has recertified for the current year, and ask the question before you commit volume.

The August 2025 enforcement

The FCC’s 2025 cleanup made the stakes concrete. In August 2025, the FCC revoked RMD certification for 185 providers and then 1,200+ more — roughly 1,400 total — the most aggressive RMD enforcement to date. In parallel, 51 state attorneys general launched “Operation Robocall Roundup,” warning 37 voice providers.

This sits alongside the broader traceback regime run by the ITG (Industry Traceback Group) — the USTelecom-led, FCC-designated Traceback Consortium under the TRACED Act — whose live-call identifications jumped from 607 (2023) to 1,408 (2024). The direction of travel is unambiguous: more enforcement, faster removals, lower tolerance for providers that don’t keep their filings clean.

Why it matters to a brand

You don’t file in the RMD, but you depend on it completely. The practical actions for a brand:

  1. Vet your provider’s RMD standing before signing — is it filed and currently certified?
  2. Confirm annual recertification each year, around the March 1 deadline.
  3. Factor RMD risk into provider choice — a provider that gets removed takes your delivery down with it.

It’s the quiet foundation under everything else in the voice-trust stack: A-level attestation, clean analytics reputation, and branded calling all assume your traffic is being accepted in the first place, and the RMD is what makes that true.

Next: back to the calling overview or run the outbound calling trust checklist.

Sources