Guide · Compliance & Trust

STIR/SHAKEN explained for contact center buyers.

STIR/SHAKEN is a caller-ID authentication framework that lets carriers attach a cryptographic attestation to outbound calls, signaling to the receiving carrier how confident the originating network is that the caller ID is legitimate — and it directly affects whether your calls get labeled "Spam Likely" or answered at all. This article is general information, not legal advice. Confirm current requirements with qualified counsel before making a compliance decision.

What STIR/SHAKEN actually does

STIR (Secure Telephony Identity Revisited) defines how a call’s caller ID gets a digital signature; SHAKEN (Signature-based Handling of Asserted information using toKENs) defines how carriers apply and pass that signature through the call path. In combination, they let a terminating carrier verify that the caller ID on an incoming call was authenticated by the originating carrier, rather than trusting the number unverified — the core defense against caller-ID spoofing.

The three attestation levels

Calls are attested at one of three levels. Full attestation (A) means the originating carrier authenticated both the caller and their right to use that specific number. Partial attestation (B) means the carrier authenticated the caller but not their right to that specific number. Gateway attestation (C) means the call entered the carrier’s network from an untrusted source with no verification of the caller’s identity at all. Lower attestation levels are the calls most likely to get flagged or blocked by carrier and handset-level spam filtering.

Why this matters for answer rates, not just compliance

Attestation level is not primarily a legal requirement on the calling organization directly — it is largely a carrier and infrastructure responsibility — but it has a direct commercial consequence: calls with weak or missing attestation are more likely to be labeled as spam risk by carriers and consumer call-screening apps, which suppresses answer rates regardless of how compliant the underlying campaign is. A contact center can run a fully TCPA/DNC-compliant campaign and still see poor answer rates if its calls are consistently attested at a low level.

What to ask a contact-center vendor about STIR/SHAKEN

Ask whether the platform’s outbound calling path is aware of carrier attestation policy and can route or flag calls accordingly, and whether the vendor works with underlying carrier infrastructure that supports proper caller-ID registration and attestation. A vendor that cannot discuss attestation level at all is a signal that carrier trust has not been engineered into the calling path.

Where Voz360’s carrier-policy layer fits in

Voz360’s Compliance Engine includes STIR/SHAKEN-aware carrier policy as part of its outbound gate sequence, alongside DNC, TCPA consent, and allowed-hours checks, so carrier trust posture is considered as part of the same compliance-gating layer rather than treated as a purely separate telephony concern. Specific carrier registration, attestation configuration, and number-reputation management are confirmed with the technical team during discovery, since they depend on carrier relationships and number provisioning.

The practical test

Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?

Questions, answered

What enterprise buying teams want to know.

Self-contained answers, so the questions a security or procurement reviewer asks first don't require reading the whole page.

Is STIR/SHAKEN a legal requirement for the calling organization?

STIR/SHAKEN implementation obligations are generally placed on carriers under applicable telecommunications regulation, not directly on the businesses placing calls. However, a business’s answer rates and caller reputation are directly affected by the attestation level its calls receive, which depends on the calling infrastructure and carrier relationships involved. This is general information, not legal advice.

What is the difference between full, partial, and gateway attestation?

Full attestation (A) means the originating carrier verified both the caller and their right to the specific number used; partial attestation (B) verifies the caller but not the specific number; gateway attestation (C) means the call entered from an unverified source with no identity confirmation.

Why would a compliant campaign still have low answer rates?

Low attestation levels can cause carriers or consumer call-screening apps to flag calls as spam risk independent of whether the campaign itself follows TCPA and DNC rules — attestation and legal compliance are related but separate factors in whether a call gets answered.

What should a buyer ask about STIR/SHAKEN during a contact-center evaluation?

Ask whether the platform’s outbound calling path is carrier-policy and attestation aware, and how the vendor’s carrier relationships support proper caller-ID registration — a vendor unable to speak to attestation level has likely not engineered for carrier trust.

Talk to Voz360

Make the next decision with more signal.

Bring the guide, the questions, and the real deployment constraints to a Voz360 session.