Home › Yeastar › Complete Guide to Achieving STIR/SHAKEN Compliance with Yeastar PBX
Yeastar AI Briefed

Complete Guide to Achieving STIR/SHAKEN Compliance with Yeastar PBX

Achieve STIR/SHAKEN compliance with Yeastar PBX using built-in certificate signing, verification, and automated workflows for secure, trusted call authentication.

In brief: STIR/SHAKEN is the authentication framework combating caller ID spoofing in modern VoIP networks. SA resellers selling SIP trunking should understand how RICA compliance interacts with international number verification.

This guide explains how to achieve STIR/SHAKEN compliance with Yeastar PBX, including who needs certificates, how to obtain them, and how Yeastar’s built-in signing and verification make compliance dramatically easier for service providers of all sizes.


TL;DR / Key Takeaways

  • Any voice service provider originating SIP calls must implement STIR/SHAKEN and sign outbound calls.
  • Yeastar P-Series Cloud PBX includes a built-in STIR/SHAKEN engine – no external signing systems needed.
  • Providers need STI certificates; resellers rely on upstream carriers and register in the FCC RMD.
  • Certification requires FCC registration, OCN approval, STI-PA onboarding, and RMD registration.
  • Yeastar YCM handles automated call signing, verification, and call record tracking for compliance.

Introduction: Why STIR/SHAKEN Compliance Matters More Than Ever

STIR/SHAKEN became mandatory for U.S. service providers following the FCC’s aggressive post-2021 enforcement against spoofing and illegal robocalling. Fraudulent call activity has surged globally, directly impacting user trust, carrier reputation, and regulatory compliance.

But while the rules are clear – if you originate SIP calls, you must sign them – many ITSPs, PBX hosts, and smaller providers still struggle with:

  • Where to get certificates
  • How to register with the correct authorities
  • How to build a signing and verification system
  • How to remain compliant without massive infrastructure costs

Yeastar solves this with a fully integrated STIR/SHAKEN framework built directly into the P-Series Cloud PBX. No external signing servers, no custom integrations, no added infrastructure – just upload your authorized STI certificates and the system automates everything.

This guide walks you step-by-step through:

  • Who needs an STI certificate
  • How to obtain certificates
  • How Yeastar PBX implements STIR/SHAKEN end-to-end
  • How to ensure your business or carrier operation stays compliant

Who Needs the STIR/SHAKEN Certificate (STI Certificate)

According to the FCC, any provider originating SIP calls must sign those calls using a valid STI certificate.

Providers who must obtain their own STI certificates:

  • Tier-1 carriers
  • CLECs
  • ITSPs controlling their own PSTN number resources
  • Providers operating their own softswitch and originating outbound calls

Providers who do NOT need their own certificates:

  • Resellers using upstream carrier trunks exclusively
  • Providers relying 100% on hosted or wholesale signing

However, these resellers must still register in the FCC Robocall Mitigation Database (RMD), disclose their upstream signing partner, and implement mitigation procedures.

Yeastar Cloud PBX requirement:

To activate Yeastar’s built-in STIR/SHAKEN signing:

  • Use your own STI certificate or
  • Use a certificate provided/authorized by your upstream carrier

The PBX handles all signing and verification automatically once the certificate is uploaded.


4 Steps to Obtain the STIR/SHAKEN Certificates

If your company originates calls using your own trunk resources, you must obtain your own certificate. While the process appears complex, there are only four core steps:


Step 1: Verify Eligibility as a Voice Service Provider

The FCC requires all voice service providers to validate their identity and authority before requesting certificates.

Requirements:

FCC Registration (Form 499-A)

  • Register with the FCC and obtain a 499 Filer ID
  • Registration is free

Operating Company Number (OCN)

Issued by NECA, requiring:

  1. Interconnection agreement
  2. Customer invoice copy
  3. Articles of Association
  4. Basic administrative info
  • Cost: $475 (€600 for expedited service)

Verified Number Resources

You must control or have allocated NANP numbers for voice service provisioning.

Without a valid OCN and FCC Filer ID, STI-PA authorization will not be granted.


Step 2: Register with Iconectiv, the STI-PA

Iconectiv is the FCC-designated Secure Telephony Identity Policy Administrator (STI-PA).

Submit:

  • Company details
  • Address and contacts
  • FCC 499 Filer ID
  • OCN

Once approved, you receive an SPC Token (valid for one year). This token authorizes you to request STIR/SHAKEN certificates from approved CAs.


Step 3: Obtain Your STIR/SHAKEN Certificate

Use your SPC Token to request a certificate from an approved Certification Authority (CA).

Submit:

  • SPC Token
  • CSR (Certificate Signing Request)
  • Company information

The CA will then issue your STI Certificate, used for signing outbound calls and verifying inbound calls.

Note: Most CAs charge annual certificate issuance fees.


Step 4: Register in the FCC Robocall Mitigation Database (RMD)

Mandatory for all voice service providers – even those using upstream signing.

Submit:

  • FCC Filer ID
  • Company info
  • STIR/SHAKEN implementation type
  • Robocall mitigation description

Once approved, your business appears in the public RMD.

If your upstream carrier signs calls:

Register as:

  • Hosted
  • Partial Implementation

This satisfies FCC requirements for non-infrastructure providers.


Certificate Application Checklist

Step What You Need to Do Links
Verify Eligibility Register with FCC (Form 499-A), apply for OCN, verify NANP number resources FCC Registration, NECA OCN
Register with STI-PA Register with Iconectiv and get SPC Token Iconectiv
Obtain Certificate Request STI Certificate from CA Approved CA List
Register in RMD Declare STIR/SHAKEN status, mitigation policies FCC RMD Portal

In-House STIR/SHAKEN Solution on the Yeastar Cloud PBX

With Yeastar P-Series Cloud PBX, STIR/SHAKEN signing and verification are handled natively — no external servers, APIs, or custom infrastructure.

Once your certificate is uploaded to Yeastar Central Management (YCM), the system:

  • Signs every outbound call
  • Verifies every inbound call
  • Logs all signing/verification outcomes

How it works:

Outbound Call Signing

  • Yeastar PBX uses your STI Certificate to generate a signed SIP Identity Header
  • This confirms caller authenticity
  • Ensures downstream carriers can verify your traffic
  • Strengthens trust in your outbound call reputation

Inbound Call Verification

When calls arrive:

  1. PBX checks the SIP header for the calling party’s signature
  2. Retrieves the public key reference
  3. Validates signature using the certificate
  4. Marks the call as Trusted or Unverified

This prevents spoofed calls or robocalls from hitting your end users.

CDR Logging & Compliance Reporting

All results are recorded in the PBX Call Detail Records:

  • Signed calls
  • Verified calls
  • Failed verifications
  • Suspicion results

These logs support audits, regulatory reporting, and fraud mitigation.

Image

Why Yeastar’s Built-In STIR/SHAKEN Matters for Providers

Many providers struggle with STIR/SHAKEN because:

  • Signing systems are expensive
  • Integration requires custom SIP manipulation
  • Misconfiguration leads to call failures
  • Certification management is complex

Yeastar removes all of that.

Benefits:

  • Zero additional infrastructure
  • Faster deployment
  • Lower cost than third-party signing tools
  • Full compliance baked directly into PBX workflows
  • Automatic handling of both inbound and outbound calls

This allows ITSPs and service providers to remain compliant while focusing on business growth — not backend engineering.


Final Thoughts

STIR/SHAKEN is now essential for any provider originating SIP calls into the U.S. network. Although certification processes can feel overwhelming, the steps are manageable – and Yeastar’s Cloud PBX makes the final implementation effortless.

With a built-in signing engine, automated verification, and centralized certificate management, Yeastar drastically simplifies compliance while reducing operational costs. Providers can finally meet regulatory requirements without deploying costly external systems or custom software.

For resellers and integrators in South Africa and abroad, STIR/SHAKEN compliance represents both a responsibility and a competitive differentiator – and Yeastar P-Series Cloud PBX provides one of the most efficient pathways to achieving it.

This article was inspired by the original post here: https://www.yeastar.com/blog/built-in-stir-shaken-with-yeastar/

Belinda November
Belinda November
Intelligence Team · South Africa

Belinda November is a contributing editor at Telecoms-Channel, covering vendor developments, product launches, and channel partner news for South Africa's telecoms reseller community. She researches and writes about unified communications, cloud telephony, contact centre technology, and networking solutions — translating complex vendor announcements into actionable intelligence for SA resellers and ICT distributors. Belinda contributes to Telecoms-Channel's vendor intelligence coverage, including company profiles, product reviews, and market trend analysis focused on the South African telecoms channel.