HadloTechnologies
All posts
FCCComplianceRMD

The RMD recertification window is a deadline, not a reminder

Hadlo Technologies · Invalid Date · 3 min read

Some compliance obligations are forgiving. The Robocall Mitigation Database recertification is not one of them. Every US voice service provider — including intermediate and gateway providers — is required to recertify its RMD filing each year, within a defined annual window. Miss it, and the consequences are not a warning letter. Providers that fail to recertify can be removed from the database entirely, and being out of the RMD functionally means you cannot originate or carry US voice traffic. It is one of the few compliance failures that can take a carrier off the air.

What the RMD actually is

The Robocall Mitigation Database is the FCC registry in which every US voice provider certifies its STIR/SHAKEN implementation status and describes the robocall mitigation program it operates. It is the mechanism by which the industry, and downstream carriers specifically, can check that a provider has made the required commitments. Terminating carriers are expected not to accept traffic from providers who are not properly listed — which is what turns an administrative delisting into a commercial emergency. The moment you drop off the RMD, your traffic can start getting rejected upstream, whether or not you realise why.

Why a calendar entry is not enough

A deadline this consequential should never depend on one person happening to remember it. Yet in many organisations that is exactly where it lives: in the head of whoever filed last year, protected by nothing more than their continued attention. If that person is on holiday during the window, changes roles, or simply gets busy, the filing slips, and the first sign of trouble may be traffic starting to fail.

The correct treatment is to make recertification a tracked workflow rather than a memory. That means three things: a named owner who is accountable for the filing, a hard deadline recorded somewhere the whole team can see, and a stored evidence trail of exactly what was filed and when. If the usual filer is unavailable, the next person can pick it up from the record instead of reconstructing it from scratch.

Accuracy matters as much as timeliness

It is not enough to file on time; the filing has to be accurate. An RMD certification that misrepresents a provider’s STIR/SHAKEN status or robocall mitigation program is its own exposure, separate from missing the deadline. The mitigation plan you describe should be the mitigation plan you actually operate — the Do-Not-Originate list you genuinely use, the traffic monitoring you actually perform, the traceback cooperation you actually provide. The filing is a statement, and it should be a true one.

Treating compliance as infrastructure

The broader point is that recertification is one instance of a pattern. The FCC has moved steadily toward treating robocall and fraud compliance as an ongoing verification-and-documentation obligation rather than a one-time certification. That trend cuts directly against any process that lives in one person’s inbox. The providers who handle it well are the ones who build compliance into their operations — a calendar of obligations with owners and deadlines, evidence stored as it is produced, and alerts that fire before a window closes rather than after.

  • Assign a named owner for the RMD recertification, not a shared responsibility.
  • Record the window as a hard, visible deadline with an alert well before it opens.
  • Keep a stored copy of exactly what was filed each year, with dates.
  • Make sure the mitigation plan you file describes the program you actually run.

At Hadlo, RMD recertification is a tracked filing with an owner, a deadline, and an evidence trail — not a date someone hopes to remember. Compliance is not an add-on here; it is in the network. If you want a wholesale partner who treats it that way, talk to us.