Reference

CTIA: The Carrier-Enforced Messaging Rulebook

CTIA is the wireless carriers' trade association. Its Messaging Principles & Best Practices are technically non-binding — but the carriers enforce them as conditions of carriage, so in practice they govern whether your texts get delivered.

reference Last verified mid-2026 3 min read

CTIA — the Cellular Telecommunications Industry Association — is the wireless trade association: the industry group representing AT&T, T-Mobile, Verizon, and the rest of the US mobile ecosystem. It is not a government regulator and it cannot fine you. But because its members are the carriers that own the last mile, CTIA’s documents function as the operational rulebook for US business texting and branded calling. Almost every messaging-compliance rule on this site — opt-in standards, STOP/HELP handling, the privacy-policy clause, the SHAFT content list — descends from a CTIA best-practices document.

The key distinction: non-binding, carrier-enforced

CTIA can't fine you. The carriers can block you.
CTIA’s guidance is technically non-binding — it is a trade association, not a regulator, and has no statutory authority. But the carriers it represents adopt these documents as conditions of carriage: violate the Messaging Principles and your campaign gets rejected at vetting, or your traffic gets filtered downstream. The legal force is zero; the deliverability force is total. Treat CTIA rules as mandatory in practice even though they aren’t law. (Binding law comes from the FCC and the TCPA — see /regulations/fcc/.)

Messaging Principles & Best Practices (May 2023)

The flagship document is CTIA’s Messaging Principles and Best Practices, latest revision May 2023. It is the de facto standard the carriers enforce through 10DLC campaign vetting and content filtering. It defines, among other things:

  • Consent standards — what a compliant opt-in looks like, including the prior-express-written-consent expectation for marketing and the required Call-to-Action disclosures.
  • STOP / HELP handling — mandatory opt-out and help keyword behavior.
  • The privacy-policy clause — the carrier-mandated “we do not share or sell SMS opt-in data” language that is a top rejection cause when missing.
  • Prohibited content — the SHAFT categories (Sex, Hate, Alcohol, Firearms, Tobacco) plus carrier-blocked verticals.

These translate directly into the operator-facing pages: see texting compliance for how to satisfy each one in practice, and campaign rejection reasons for what happens when you don’t.

Messaging Security Best Practices (Oct 2025)

In October 2025, CTIA published a separate Messaging Security Best Practices document — a newer companion focused on the security side of the messaging ecosystem (anti-spoofing, anti-phishing, and fraud-mitigation guidance) rather than the consent-and-content rules of the 2023 Principles. It’s the most recent addition to the CTIA rulebook and worth watching as carriers begin folding it into enforcement.

Branded Calling ID (BCID)

On the voice side, CTIA governs BCID (Branded Calling ID) — the industry-standard ecosystem for delivering a verified business name, logo, and call reason to the handset. BCID is operated by BCID, LLC, a CTIA subsidiary, and carries that branding as RCD (Rich Call Data) inside the STIR/SHAKEN PASSporT. CTIA also publishes Branded Calling Best Practices (the logo and display standards — e.g. color PNG, minimum 400×400 px).

Enterprises don’t enroll with CTIA directly — they go through an Originating Service Provider or an Authorized Partner. The full enrollment path, pricing model, and how BCID supersedes legacy CNAM are covered on branded calling (BCID / RCD).

How CTIA fits with the rest of the stack

  • CTIA sets the operational rules carriers enforce on delivery (texting) and branding (calling).
  • The FCC sets the binding law (TCPA, STIR/SHAKEN, RMD) — see /regulations/fcc/.
  • TCR runs the 10DLC registry the carriers read; the carriers apply both CTIA and FCC rules at the network edge.

When a compliance requirement isn’t in the TCPA but still gets your campaign rejected, it almost always traces back to a CTIA best practice.

Next

Sources