> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# FCC Robocall Mitigation Database (RMD) certification

> Prepare, file, and keep current your FCC RMD certification from the compliance console — required for every US voice originator under 47 CFR § 64.6305.

# FCC Robocall Mitigation Database (RMD) certification

If your organization originates US outbound calls, the FCC's Robocall
Mitigation Database (RMD) requires you to file a robocall-mitigation
certification and keep it current. Terminating carriers must refuse traffic
from providers whose certification is missing or deficient — so an absent
filing can stop downstream carriers from accepting your calls at all.

The console at **Settings → Compliance → RMD** (`/settings/compliance/rmd`)
is where you prepare the filing, track its lifecycle, and watch the
recertification clock. Every control here is **tenant-owned**: you draft the
certification, you file it with the FCC, and you keep it current. Orbit
records the state for your audit trail — this page does not transmit to the
FCC or wire a carrier on your behalf. Restricted to **owner** and **admin**
roles.

<Warning>
  This page is not legal advice. Confirm your filing obligations and program
  wording with counsel.
</Warning>

## 1. Who needs a filing — and where it shows up downstream

47 CFR § 64.6305 requires every voice service provider to hold a current RMD
certification before traffic terminates in the US. Scope is **US outbound
voice only** — messaging, email, and non-US voice are out of RMD scope. If
you do not place US calls at all, this obligation does not apply to you.

Two places your RMD record surfaces downstream:

* **Intercarrier reviews.** When you onboard a carrier or vendor, they verify
  your RMD record as part of STIR/SHAKEN attestation
  (see [STIR/SHAKEN attestation](/channels/voice/stir-shaken)). A missing or
  stale record rejects the review before it starts.
* **Traceback response.** When a flagged call routes back to you, an absent
  or deficient filing sharpens the ITG's position — see
  [ITG traceback workflow](/guides/compliance-traceback-itg) for the
  full response workflow.

Pair this with your other gate surfaces: an RMD certification is a passing
prerequisite in the
[send-gates preflight checklist](/guides/send-gates-preflight-checklist) and
the [campaign list-hygiene projection](/guides/campaign-list-hygiene-projection),
and a hard stop in the
[compliance emergency stop](/guides/compliance-emergency-stop).

## 2. Open the console

Go to **Settings → Compliance → RMD**. The page has two cards: your
registration (or an invitation to start one), and below it the **Call-time
origination enforcement** setting. That second setting is opt-in and off
by default — do not switch it to **Enforce** while you are still drafting,
or Orbit blocks every outbound call on this organization.

## 3. Prepare the certification

The FCC filing needs five pieces of company information. Assemble them
before you open the form so you are not drafting by guess:

| Field                             | What it carries                                                                                                                                                |
| --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Company name and business address | The legal entity that files.                                                                                                                                   |
| OCN                               | Operating Company Number — the carrier identifier the FCC uses to index your record. Optional in the form, but it anchors the filing at the FCC.               |
| STIR/SHAKEN implementation        | Complete, partial, or none. This decides whether a mitigation plan is mandatory.                                                                               |
| Robocall-mitigation plan          | Required unless STIR/SHAKEN is **complete** network-wide. Describe how you prevent illegal robocall origination — vetting, CDR monitoring, traceback response. |
| Compliance contact                | Name, email, and optionally phone — the person carriers and the FCC reach on this filing.                                                                      |

Match the entity details to your
[Organization KYC profile](/guides/organization-kyc-onboarding) before you
submit. The most common validation loop with carriers is a name or address
mismatch between the filed entity and the KYC record — identical spelling,
not just "close enough".

## 4. File it — the lifecycle

The certification moves through a five-state lifecycle. Orbit renders the
live status as a badge on the registration card, and only the actions legal
from the current state show as buttons.

| State                  | Meaning                                                        | Next legal move                                                 |
| ---------------------- | -------------------------------------------------------------- | --------------------------------------------------------------- |
| `Draft`                | Saved locally, not yet filed.                                  | **Submit filing**                                               |
| `Submitted`            | You filed with the FCC and recorded the filing reference here. | **Mark active** once the FCC publishes it                       |
| `Active`               | Published and accepted. This starts the recertification clock. | **Flag remediation** if a carrier or the FCC flags a deficiency |
| `Remediation required` | A deficiency was flagged and must be corrected.                | **Resolve & re-certify** once corrected                         |
| `Withdrawn`            | Superseded or intentionally pulled.                            | Re-open to a draft and re-file                                  |

Before you submit, the form enforces completeness: the mitigation plan is
mandatory unless STIR/SHAKEN is complete, contact fields are required, and
the entity identity is present. A rejection after filing is typically a
deficiency the FCC or a carrier flagged — record it with **Flag
remediation**, correct the draft body (withdrawn and draft registrations
stay editable), and resolve.

The console also carries the **recertification verdict** on every read:

| Verdict                   | Meaning                                            |
| ------------------------- | -------------------------------------------------- |
| `Current`                 | Within the recert interval.                        |
| `Review due soon`         | Approaching the review date.                       |
| `Recertification overdue` | Past the review date — carriers can gap you here.  |
| `Not certified`           | Never marked active, or filed but never confirmed. |

The default interval is 365 days; the form accepts a custom interval up to
3,650 days. A material change to your business details must be reflected in
the RMD within the 10-business-day window the console displays on the
registration card.

## 5. Keep it current

Three classes of change trigger a refiling — always within the 10-business-
day update window:

* **Business details.** Entity name, address, or OCN changed.
* **Mitigation program.** The robocall-mitigation plan you filed is revised
  (new vetting step, new monitoring tool, changed traceback SLA).
* **STIR/SHAKEN status.** Your implementation level changed — partial
  upgrading to complete drops the mandatory plan, for example.

The console surfaces staleness two ways: the recertification verdict badge
flips to `Review due soon` and then `Recertification overdue`, and the
update window readout on the card reminds you how long you have to reflect
a material change. Treat `Review due soon` the way you treat an expiring
cert — book the review before it flips overdue.

## 6. The certification id and how it interacts with traceback

After you file with the FCC, store the confirmation or filing id in the
**Filing reference** field (you get the prompt on Submit, and again on
Mark active). That reference is what carriers ask for when they verify
your record, and what you cite back when a traceback reviewer asks which
filing covers the implicated traffic. For the traceback workflow itself,
see [ITG traceback workflow](/guides/compliance-traceback-itg).

## 7. One posture surface in a broader profile

RMD is one surface of your full compliance posture — the assembly that also
carries your KYC record, your DPA/BAA papers, your sender registrations, and
your policy scanners. Assemble that profile as one unit in
[Compliance profiles](/guides/compliance-profiles-assemble) instead of
managing each surface alone.

## Worked example: a healthcare org opening US calling

A clinic already handling EU voice signs a US customer and needs to
originate US calls. Sequence:

1. Counsel confirms the organization files as the voice originator.
2. The admin opens **Settings → Compliance → RMD** and starts a
   registration — fills the legal entity exactly as it appears in
   Organization KYC, declares STIR/SHAKEN **partial** (deployment in
   progress), and writes the mitigation plan describing patient-vetting and
   traceback-response SLAs.
3. Because declaration is partial, the plan is mandatory — the form keeps
   it required.
4. They file with the FCC, come back, click **Submit filing**, and paste
   the FCC confirmation id as the filing reference.
5. Once the FCC publishes the record, they click **Mark active**. The
   recertification clock starts; the badge shows `Current`.
6. Six months later the mitigation program changes — new vetting step. They
   edit the draft plan inside the 10-business-day window, re-file at the
   FCC, and the record stays current.

## Troubleshooting

| Symptom                                       | Likely cause                                                              | Fix                                                                                                        |
| --------------------------------------------- | ------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| FCC or a carrier rejected the filing          | Incomplete plan, or entity details that do not match KYC                  | Record **Flag remediation**, correct the draft, **Resolve & re-certify**                                   |
| Record flipped `Recertification overdue`      | Review interval passed without a refresh                                  | Re-certify now; the interval restarts when you mark active                                                 |
| Carrier says the legal contact does not match | Entity name/address filed ≠ the KYC record                                | Align the entity fields exactly with [Organization KYC](/guides/organization-kyc-onboarding), then re-file |
| You cannot edit the draft                     | Registration is in `submitted`, `active`, or `remediation_required` state | Withdraw to re-open the draft, edit, and re-file                                                           |

***

## Deep dives

* [ITG traceback workflow](/guides/compliance-traceback-itg) — the
  downstream surface your RMD record is cited back on.
* [STIR/SHAKEN attestation](/channels/voice/stir-shaken) — the signing your
  mitigation program complements.
* [Organization KYC](/guides/organization-kyc-onboarding) — the entity
  identity your filing must match.
* [Compliance profiles](/guides/compliance-profiles-assemble) — the assembly
  RMD sits inside.
* [RMD registration API reference](/compliance/rmd-registration) — the
  endpoint surface behind this console.
