What 'Know Your Upstream Provider' Really Means for Gateway Carriers
TL;DR: Gateway providers carry the FCC's heaviest compliance load. Beyond the standard 24-hour traceback response, they must authenticate foreign traffic with STIR/SHAKEN, block calls on notice, and prove they vet every upstream provider under a five-part rule called Know Your Upstream Provider, or KYUP.
We've covered the four roles in the call path, and what happens if you don't cooperate. Now it's time to go deep on the one role that consistently carries the heaviest regulatory weight.
If your business brings foreign originated traffic onto the US network, this article matters more than any other in the series. The obligations here go well beyond the baseline traceback response every carrier already owes.
A real ITG notice we reviewed made this point plainly. It named originating, transit, and gateway providers together as bearing the same core obligation, citing both the traceback rule and the RMD certification rule side by side.
Let's break down what that actually means for a gateway operation.
Why Gateway Providers Carry the Heaviest Obligation
Gateway providers sit at a specific point in the call path: the moment foreign originated traffic first touches the US telephone network. Every other role we've covered deals mainly with traffic that's already domestic. Gateway providers are the actual border crossing.
That position carries consequences. Foreign originated illegal robocall traffic remains one of the largest sources of fraud reaching US consumers, and scammers operating overseas often sit outside direct FCC jurisdiction. The gateway provider becomes the last US entity with real accountability before that traffic reaches a phone.
A Real Gateway Enforcement Case
The FCC's own enforcement record makes this concrete. In a cease and desist letter, the Enforcement Bureau identified a gateway provider, One Eye LLC, as the point of entry for substantial volumes of unlawful robocalls tied to multiple fraud schemes.
The letter required One Eye to investigate and mitigate the traffic within 48 hours, then report within 14 days on the steps taken to prevent new or renewing customers from repeating the pattern.
That same structure, investigate fast, report fast, fix the underlying vetting gap, shows up across nearly every gateway enforcement action the FCC has issued.
The FCC's Regulatory Proving Ground
This isn't a new idea for the FCC. Several of the industry's toughest rules, including the 24 hour traceback response window, started as gateway-only requirements before expanding to every voice service provider in 2023.
Gateway providers have consistently been the testing ground for obligations that later go universal. Their experience offers a useful signal for where regulation is headed next.
That pattern matters strategically, not just historically. A carrier that treats today's gateway-only requirement as a preview of tomorrow's industry-wide rule is better positioned. Waiting for the requirement to apply broadly before investing in it can leave carriers playing catch-up.
The Five KYUP (Know Your Upstream Provider) Categories at a Glance
The know your upstream provider rule, or KYUP, requires gateway providers to take reasonable and effective steps ensuring their immediate upstream foreign provider isn't using the gateway to carry illegal traffic.
The FCC has broken that requirement into five distinct categories. Each is treated as a separate operational task, rather than one vague policy. It allows for separating a defensible program from one that only looks good on paper.
Why is the FCC Proposing to Go Further?
The FCC has since proposed tightening all five categories. The proposed rules add specific due diligence steps, such as confirming a Service Provider Code token, verifying active phone numbers and email addresses, and having verbal contact with a real company principal.
A parallel proposal would require gateway providers to retain KYUP records for a minimum of four years, long enough to cover most statutes of limitations. None of this is final yet, but the direction is unmistakable: expect more documentation, not less.
How does KYUP Connect to STIR/SHAKEN Attestation?
KYUP and STIR/SHAKEN sound like separate obligations, but they're increasingly linked in practice. The FCC's attestation framework grades how confident a provider is in a call's origin. Each level maps back to a specific KYC or KYUP obligation.
An A-level attestation requires the originating provider to know its customer. The provider must also verify the customer's right to use the calling number, typically through number-assignment records.
B-level keeps the know-your-customer requirement but drops the number-verification step. C-level, the one gateway providers most often issue, covers transit and gateway traffic where no direct customer relationship exists at all.
That last tier is exactly why KYUP exists as a separate rule from STIR/SHAKEN. A gateway provider cannot attest at a level that implies direct customer knowledge it does not have. Instead, the FCC added a separate vetting obligation focused on the upstream relationship.
What a Compliant Mitigation Plan Must Say?
None of the five KYUP categories matter without proof, and proof means a specific, detailed robocall mitigation plan filed alongside your RMD certification. A compliant plan generally needs to cover four elements:
- The reasonable steps you take to avoid carrying illegal traffic,
- Your customer onboarding controls where applicable,
- A description of the analytics systems you use,
- Your specific upstream-provider vetting procedures.
Generic language doesn't survive scrutiny here. A plan that says "we monitor upstream traffic for suspicious patterns" doesn't meet the bar.
A plan that names the specific analytics tool, explains what it flags, and describes what happens operationally when it flags something, does. If you use a third party vendor, the FCC expects that vendor named, not referenced as "industry standard analytics."
Building a Filing That Holds Up
Carriers under scrutiny in 2025 enforcement actions consistently lost on the same point: their filed mitigation plans were too generic to demonstrate real compliance. Treat your plan as a living document tied to your actual operational controls, not a one-time filing exercise you write once and forget.
A useful internal test: could someone outside your compliance team read your mitigation plan and actually replicate your vetting process from it?
If the plan is vague enough that two different employees would vet a new upstream provider differently, it's too vague for the FCC too.
Specificity protects you twice, once during a routine audit, and again if a traceback pattern ever forces a closer look at your filing.
STIR/SHAKEN Authentication and Blocking Obligations
Beyond KYUP, gateway providers carry two further specific duties. First, apply STIR/SHAKEN authentication to any unauthenticated foreign originated SIP call carrying a US NANP number. Second, block calls once properly notified they're a conduit for illegal traffic, an obligation that isn't optional once triggered.
Both duties close specific gaps bad actors have historically exploited. Authentication makes a spoofed foreign number harder to pass off as a legitimate US caller.
The blocking requirement removes "we didn't realize" as a valid excuse the moment the FCC has issued actual written notice, backed by evidence, that a specific traffic pattern is illegal.
What Happens If You Ignore the Notice?
When the FCC's Enforcement Bureau sends a written notice of illegal traffic, the clock starts. You have at least fourteen days to investigate the traffic and take corrective action. The structure is straightforward: investigate, explain, and comply within the window.
Ignore the notice, however, and the situation escalates quickly.
USTelecom's traceback process starts with escalation emails to a provider that fails to respond. Continued non-cooperation can then result in the provider being marked as non-cooperative in the ITG's database. From there, the ITG can refer that status directly to the FCC or FTC.
Building ahead of the curve here has real competitive value. Compliant carriers become the safer counterparty of choice as scrutiny on the wider industry increases.
Federal enforcement can take the escalation a step further. The FCC can direct downstream providers to stop accepting traffic from the gateway altogether. Such a move effectively cuts that provider off from the US telephone network.
And this isn't a hypothetical endpoint. The FCC has used this mechanism against non-cooperative providers before.
There is also a clear incentive to act within the fourteen-day window. A gateway provider that follows Section 64.1200(n)(5) in good faith is protected from liability under the Communications Act for the traffic it blocks.
The escalation path has already played out in real enforcement actions. In separate actions in 2020, the FCC directed participating carriers to stop accepting traffic from specific non-cooperating providers after the ITG's escalation process failed to produce a response.
That makes the takeaway straightforward: an unanswered notice does not simply sit in an inbox. It can trigger a documented escalation. From a traceback, to non-cooperative status, to federal intervention, and ultimately to downstream carriers being told to stop accepting the provider's traffic.
Why This Role Keeps Getting More Scrutiny
Gateway obligations have expanded steadily rather than settling, and there is a structural reason for that. Gateways sit at a critical point between foreign-originating traffic and the US telephone network. Regulators have a practical place to intervene before illegal traffic reaches consumers.
As a result, the gateway's role is evolving from simply carrying traffic to actively demonstrating that the traffic it carries is legitimate. The regulatory focus has progressively moved toward knowing who is sending traffic, verifying the customer's authority to use calling numbers, responding to traceback requests, identifying suspicious patterns, and blocking traffic when required.
That shift also changes what “we didn't know” means in practice. Once a gateway receives a traceback request or other regulatory notice, the expectation is increasingly that it can investigate, identify the relevant upstream relationship, take appropriate action, and document what it did.
For operators, the takeaway is straightforward: regulatory compliance is becoming an operational capability, not just a legal requirement. Gateways entering this market should plan for obligations that demand better visibility, faster response, and stronger controls over time.
What's Next in This Series
Gateway compliance doesn't stop at foreign-originating traffic. The same discipline around traceback, investigation, documentation, and escalation becomes just as important when the trail leads somewhere much closer to home: your own customer.
That changes the question from “Which upstream provider sent this traffic?” to “What should we do when our own customer is responsible?”
The next article in this series examines that scenario in detail. We'll look at what happens when a traceback identifies your customer, how a gateway should investigate and document the relationship, what evidence matters, and when continued service becomes a compliance risk.
The principle remains the same: when scrutiny arrives, the ability to demonstrate what you knew, what you investigated, and what you did next matters.

















