By: Ali Mumtaz, Chief Technology Officer, 46 Labs
As robocalls and spoofed numbers continue to challenge trust in phone communications, the telecom industry is working toward a more secure future. At the heart of this transformation is the STIR/SHAKEN framework, a set of standards designed to verify caller identity on IP-based voice networks, and Branded Caller ID (BCID), an emerging standard for displaying verified caller information. Together, they are laying the groundwork for a future in which businesses can engage customers with greater transparency, trust, and control.
However, these technologies are not without their challenges. STIR/SHAKEN still faces limitations in legacy network environments, and BCID adoption depends on having a fully IP-based voice ecosystem. Recognizing both the potential and the challenges of these frameworks is essential for advancing how organizations communicate in a digital-first world.
What is STIR/SHAKEN–and Why it Matters
STIR/SHAKEN stands for two technical standards: Secure Telephone Identity Revisited (STIR) and Signature-based Handling of Asserted information using toKENs (SHAKEN). At its core, STIR/SHAKEN is a system designed to authenticate caller ID information for calls traveling over Internet Protocol (IP)-based networks, such as Voice over IP (VoIP). Think of it as a digital signature system for phone calls: service providers sign each outbound call to prove the caller is who they say they are, and receiving carriers verify those signatures before the call reaches your device.
The system was mandated by the FCC in 2021 for major voice service providers as part of a broader effort to fight spoofed robocalls. While it does not eliminate illegal calls completely, STIR/SHAKEN helps to significantly reduce the effectiveness of spoofing, making it easier to trace and block fraudulent calls. It also gives consumers more reliable caller ID information, helping them make informed decisions about answering calls.
Calls are signed with one of three levels of attestation, which reflect how much the originating provider knows about the caller:
- A-level (Full): The service provider knows the customer and can vouch for their right to use the calling number.
- B-level (Partial): The provider knows the customer but cannot verify the number itself.
- C-level (Gateway): The provider merely passes the call along without knowing the origin.
These levels affect how calls are treated downstream, such as whether they show up as “Verified Caller” with a checkmark or warning label. While attestation is a technical mechanism, it carries important policy implications, especially around “Know Your Customer” (KYC) obligations that can help prevent abuse.
A-level attestation is generally considered the preferred standard. It signals that the provider has vetted the caller and confirmed they’re authorized to use the number, making it more likely to be trustworthy. Intra-carrier calls, for example, should typically be A-attested, reinforcing accountability within a provider’s own network.
In practice, STIR/SHAKEN helps network operators verify their own traffic, trace suspicious calls more easily, and give consumers better insight into who’s calling and why. It’s a foundational shift for voice trust and the basis for innovations like Branded Caller ID.
Current Limitations of STIR/SHAKEN
While STIR/SHAKEN represents a significant leap forward in caller ID authentication, it only works on IP-based voice networks. Many legacy systems still use time-division multiplexing (TDM) or SS7 infrastructure, which creates “gaps” where signed caller identity information may be stripped away. This weakens the integrity of the call as it moves across networks, making it more challenging to verify its origin.
These gaps prevent the receiving carrier from validating the original attestation level, and in some cases, result in the loss of trust indicators like the “Verified Caller” label. For consumers and businesses, that means legitimate calls may not display helpful verification cues, while bad actors may still find ways to bypass protections.
This fragmentation presents a challenge for both call authentication and branded calling. STIR/SHAKEN cannot deliver its full value unless the entire call path is IP-based. Until the industry completes the transition to all-IP routing, these vulnerabilities will continue to affect spoofing protections and limit the effectiveness of tools like Branded Caller ID (BCID).
Current Value of STIR/SHAKEN
Despite its limitations, STIR/SHAKEN represents a critical step forward in the fight against robocalls and fraud. It’s not just a technical upgrade—it’s a foundational shift in how voice calls are validated and trusted in a digital world.
For example, STIR/SHAKEN prevents certain types of call spoofing, such as intra-carrier call scenarios mentioned earlier. It also plays a vital role in call tracebacks—the process of identifying the origin of illegal or fraudulent calls—by providing verifiable information about the call’s origin. This digital “paper trail” allows for more efficient, automated, and reliable tracking of suspicious calls through complex networks, supporting both industry and law enforcement efforts.
Perhaps equally important, STIR/SHAKEN underpins Rich Call Data (RCD)-based branded calling, also known as Branded Caller ID (BCID). This new form of branded calling displays detailed caller information—company name, logo, and reason for the call—directly on the recipient’s device, offering a richer and more trustworthy experience.
So, What Comes Next?
The future of STIR/SHAKEN will be shaped by policy execution and a clear understanding of its role. It’s essential to recognize its limitations: the framework is not designed to vet organizations or evaluate their credibility. It focuses solely on verifying call authenticity at the network and telephone number level.
Because of this, STIR/SHAKEN does not authenticate business legitimacy, the content of the call, or organizational behavior. It cannot be relied upon to verify who a caller truly is in a business sense—only that the call is coming from a valid number associated with a known provider.
This gap is where BCID plays a critical role. BCID adds a trust layer by requiring businesses to register their brand data and be vetted by authorized partners using strict Know Your Customer (KYC) practices. That vetted data—logo, name, call purpose—is then cryptographically attached to calls alongside STIR/SHAKEN signatures via RCD certificates.
To realize the full potential of BCID, however, calls must travel end-to-end over all-IP networks. Any legacy TDM/SS7 systems in the call path can strip out the STIR token, which prevents branded information from displaying. Until those gaps are closed, branded caller identity will face limitations.
Still, BCID offers clear advantages over proprietary branded calling models. As an open ecosystem, it provides greater flexibility and better economics for enterprises, and a marked improvement over legacy systems like Calling Name Delivery (CNAM).
CNAM is limited to static, text-only lookups from third-party databases. Caller names are often outdated, inconsistent, or truncated, and businesses have no control over how their name appears. CNAM also lacks support for branding elements like logos or clear call reasons, leading to missed opportunities and reduced trust.
In contrast, BCID empowers enterprises to define their caller identity precisely. Imagine your customers seeing a high-resolution logo, a clear and professional name, and a brief call purpose message the moment their phone rings. This level of control increases the likelihood of higher answer rates, greater trust, and a more consistent brand experience.
As the industry moves toward fully IP-based networks, STIR/SHAKEN and BCID together provide the foundation for a safer, smarter voice channel—one where calls are not only authenticated but also clearly attributable. While gaps remain, particularly in legacy infrastructure, the direction is clear: a voice ecosystem where transparency, accountability, and user trust are becoming the standard.



