Protecting Consumers from SIM Swap and Port-Out Fraud, Report and Order and FNPRM (FCC 23-95, WC Docket 21-341) (Part 2 of 3)

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Hacks

2

2023-11-15

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

(describing its routine use of “a one-time PIN delivered via SMS message or

an outbound voice call to a postpaid customer’s device for enhanced customer validation,” and its “Number Transfer
PIN process to validate postpaid port-out transactions”); CCA Comments at 3-4 (describing U.S. Cellular’s
assigning of a PIN code to each customer that is used for customer authentication); Better Identity Coalition
Comments at 4 (noting that “two major mobile network operators already support FIDO authentication for their
customers”); NCTA Comments at 4-5 (describing authentication measures some wireless providers already use,
including account PINs); T-Mobile Comments at 4 (“T-Mobile offers various customer authentication options,
which may vary based on customer, account, and device characteristics. T-Mobile customers set up an individual 6-
to-15 digit PIN that can be used to verify the customer’s identity when calling customer service. . . . T-Mobile
customers must provide their PIN when requesting a port-out associated with that account. Most customers that
choose to create a T-Mobile ID for use on My.T-Mobile.com or with the My T-Mobile app have the option of
setting up multi-factor authentication (‘MFA’) using methods including security questions, SMS, or device-based
biometrics such as Face ID or fingerprint recognition on devices that support such features. T-Mobile uses MFA,
consistent with the FCC’s rules, for validating customer identity and verifying the legitimacy of account changes.”);
Verizon Comments at 8-9 (describing current authentication measures, including a transaction-specific “Number
Transfer PIN” and notifying customers of port requests via text message and email).
226 See Wireless Number Portability Order, 18 FCC Rcd at 20979, para. 26; North American Numbering Council

Wireless Number Portability Subcommittee Report on Wireless Number Portability Technical, Operational, and
Implementation Requirements Phase II, CC Docket No. 95-116 at 13 (filed Sept. 26, 2000).
227 For example, this would include delivering a notification in the language of the customer’s choosing, if the

wireless provider permits communications preferences in other languages and the customer has previously indicated
such choice.

                                                          37
                                    Federal Communications Commission                                     FCC 23-95

the Commission’s rules implementing that Act.228 We require that wireless providers notify their
customers “immediately” of a porting request to not only ensure that porting requests are processed
efficiently, but also help alert customers quickly to potential fraud to allow them to mitigate damages and
inconvenience resulting from fraudulent or inadvertent port-outs.229 The notification requirement will
provide a uniform safety measure for all port-out requests across the mobile wireless industry, which we
anticipate will reduce the instances of port-out fraud.230
         59.      As with SIM change notifications, we decline to prescribe particular methods for
providing port-out notifications or particular content and wording for these notifications, but do require
that the notification methods be reasonably designed to reach the customer associated with the account
and that the content and wording use clear and concise language that provides sufficient information to
effectively inform a customer that a port-out request involving the customer’s number was made.231 We
recognize that wireless providers are in the best position to determine which notification methods and
what content and wording will be most effective at notifying customers of port-out requests and potential
fraud under the particular circumstances, including the real-world security needs of the transaction, and
the technical capabilities, accessibility needs, or broadband access of individual customers. As such, we
encourage wireless providers to leverage existing notification methods that are reasonably designed to
reach the customer associated with the account,232 and to adopt new notification methods as they are
developed to stay responsive to evolving fraud schemes.
         60.     On balance, we find that benefits accrued from early warning to customers of potential
fraudulent account activity outweigh any potential burdens imposed on wireless providers by this
notification requirement. First, we find that customer notification of port-out requests is unlikely to
prevent or unreasonably delay customer porting requests, as we require “immediate” notification and do
not require a delay or customer verification or acknowledgement of that notification before continuing the
porting-out process. Second, because wireless providers are already familiar with notifying customers
regarding changes to their accounts,233 and in many cases likely already notify customers of port-out

228 Appx. A (47 CFR § 52.37(c)); see also Safe Connections Order, FCC 23-96, at para. 97 (“To the extent that a

survivor initiates a port-out request with a new service provider for a line that is the subject of an in-process line
separation request, we prohibit the current service provider from notifying the account holder of the request to port-
out that number until after the line separation request has been completed.”); id. at Appx. A (new 47 CFR §
64.6402(i) (a covered provider shall not notify a primary account holder of a request by a survivor to port-out a
number that is the subject of a line separation request)).
229 See Princeton Comments at 7 (noting that “notice is essential, so that a customer can take prompt action to

protect their telecommunications account, their other accounts, and their devices”); Prove Comments at 6
(supporting timely notice for high risk events such as port-out requests so customers can “be afforded the
opportunity to prevent account takeovers before they are completed”).
230 For the same reasons we raised in the SIM change context, we decline to impose a blanket yes/no verification

requirement for authentication attempts. See supra para. 40; SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at
14139, para. 51.
231 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14141-42, paras. 57 (seeking comment on port-out

notification requirements).
232 Such measures may include, but are not limited to, live or automated telephone calls, text messages, emails, or

push notification through wireless provider software applications. Verizon Comments at 6 (“Providers also should
have discretion to use a push notification together with supplemental verification methods to stop a high risk
transaction.”).
233 See AT&T Comments at 6 (explaining that for transactions meeting a certain threshold of AT&T’s “risk model,”

it will send one-way SMS notifications of a SIM change request, and for transactions meeting a higher risk
threshold, it will require customers confirm the SIM change request via an SMS notification); T-Mobile Comments
at 4 (noting that as part of its efforts to “help customers secure their accounts, T-Mobile notifies customers of
account changes and requests”); Verizon Comments at 6 (“Verizon already employs (or is on track to employ) many
of the methods identified in the NPRM, such as notifying customers of high-risk SIM change authentication
                                                                                                          (continued….)
                                                          38
                                     Federal Communications Commission                                      FCC 23-95

requests,234 we anticipate that wireless providers will face low burdens in implementing today’s customer
notification requirement for port-out requests. We also expect that these existing notification systems can
be leveraged to help minimize any potential costs associated with notifying customers of port-out
requests. Third, we disagree with AT&T’s assertion that customer notification of port-out requests will
result in notice fatigue, undermining its efficacy.235 Nothing in the record supports the notion that
customers request port-outs at such a rate that, upon the adoption of this rule, wireless providers will be
forced to inundate their customers with the required notifications.236 As such, we conclude that the
significant benefits of alerting customers to potential fraudulent account activity outweighs any
speculative negative impacts on wireless providers or customers.
                  3.        Account Locks for Port-Outs
         61.     For the same reasons explained above with respect to SIM change requests,237 we require
wireless providers to offer their customers, at no cost, the ability to lock or freeze their accounts to stop
port-outs.238 We anticipate that this requirement will provide customers with more consistent and
meaningful protection against fraudulent port-outs. The record reflects that account locks can be
powerful tools against fraudulent port-outs, particularly for customers that are at high-risk of being a
target of the practice.239 As in the SIM swap context,240 we conclude that it should be offered to
customers of both pre-paid and post-paid services,241 and that this requirement is feasible for both
categories of customers despite assertions to the contrary.242

(Continued from previous page)
attempts, failed or otherwise, and of other account changes.”); CTIA Comments at 18 (explaining that “there are
many instances where notifications to consumers are appropriate and providers can and do make reasonable efforts
to provide them”); 47 CFR § 64.2010(f); 2007 CPNI Order, 22 FCC Rcd at 6942, para. 24.
234 See, e.g., CCA Comments at 3-4 (describing the current procedures that T-Mobile, U.S. Cellular, and GCI use to

notify customers of a change to their account or port-out request, and that other members are “similarly adopting
heightened security measures”); see also Wireless Number Portability Order, 18 FCC Rcd at 10975-76, paras. 14-
16.
235 AT&T Comments at 15 (noting that mandating notice when it is not necessary would lead to frequent

notifications that would leave customers “numb or immune to them or tire of [them] and consciously choose to
ignore them, thus undermining all value they might otherwise have when the threat of fraud is real”); see also CTIA
Comments at 18 (asserting that notifications can be appropriate in “many instances” but that notifications “must be
weighed against other goals, and in general, avoid unnecessary friction in the user experience or other unintended
consequences, such as notice fatigue”).
236 For the same reasons, we decline CTIA’s request that customer notification of port-out requests be “limited to

situations where the carrier determines that there is an increased risk of fraud” on the basis that the notification
requirements “threaten to cause customer confusion, concern, and fatigue,” and could increase costs for carriers
because such notifications increase customer calls. CTIA Nov. 8, 2023 Ex Parte Letter at 8.
237 See supra section III.A.4.

238 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14141-42, para. 57.

239 See, e.g., South Carolina Department of Consumer Affairs Comments at 2 (“Carriers should also offer customers

the option to lock port requests, similar to an account freeze, in order to prohibit unauthorized requests.”); DC Stone
Comments (Express) at 1 (arguing that account locks are “an effective tool for concerned or savvy consumers to
prevent unauthorized account activity and especially fraud, just as with credit reporting agencies”); NCLC/EPIC
Comments at 11 (explaining that “the ability to freeze one’s own account is an excellent way for an individual
consumer to guard against fraud”).
240 See supra section III.A.4.

241 See, e.g., DC Stone Comments (Express) at 1 (arguing that account locks must be available for any customer

account, including pre-paid accounts); cf. Verizon Comments at 4 (“A service provider will have limited information
about the prepaid customer, and in many cases, about the customer’s device. Even so, Verizon only allows
                                                                                                     (continued….)
                                                           39
                                    Federal Communications Commission                                   FCC 23-95

         62.     Like the other rules we adopt today, we give wireless providers flexibility on how to
comply with the measure.243 In particular, the record does not evince a need for us to prescribe a method
or methods for customers to unlock or unfreeze their accounts or impose a waiting period before an
unlocked account can be transferred, and as such, we decline to do so at this time. Although we do not
prescribe the exact form of the account lock mechanism wireless providers must adopt, the process to
activate and deactivate an account lock must not be unduly burdensome for customers such that it
effectively inhibits them from implementing their choice.244 We stress that when activated, wireless
providers must not fulfill port-out requests until the customer deactivates the lock,245 except to the extent
otherwise required by the Safe Connections Act or the Commission’s rules implementing that statute.246
         63.     Consistent with this flexible approach, and as we did with the SIM change rules, we
permit wireless providers to proactively initiate a port-out lock on a customers’ account when they
believe a customer may be at high risk of fraud, so long as providers promptly provide clear notifications
to those customers that a lock has been activated with instructions on how the customers can deactivate
account locks if they choose and promptly deactivates the account lock upon receipt of the customer’s
legitimate request to do so.247 We also caution wireless providers that any proactive initiation of a port-
out lock must be limited in duration and extend only so long as the high risk of fraud is evident to the
(Continued from previous page)
authentication using reliable, available methods, and has begun integrating systems used for postpaid customers to
further align and improve our methods to prevent . . . fraudulent activity.”).
242 See, e.g., CTIA Comments at 14-15 (asserting that account locks “may negatively impact pre-paid customers

whose devices are lost or stolen, as the pre-paid market offers consumers the option to purchase service with less
identifiable information than post-paid, and thus information that may be necessary to deactivate a freeze may not
have been provided when an account is initialized. Thus this may limit a consumer’s ability to remove a freeze and
validate an account where the consumer does not have a working device”); AT&T Comments at 17 (noting that “an
account lock would likely create more of a burden than a benefit for prepaid customers and their carriers” given the
discrepancy in information provided, but supporting an optional account freeze). Because the account lock is an
optional security measure for customers, carriers can, if necessary, require customers to provide information to use
for authentication purposes to activate and deactivate the account lock.
243 See AT&T Comments at 2-3, 12 (arguing, generally, that the Commission should not “[prescribe] specific

methods wireless carriers must employ to combat fraudulent SIM swaps and port-outs”); CTIA Reply at 26-27
(“While the Commission’s rules should allow for port freeze options, the rules should also be flexibly designed to
recognize that freezes are not always appropriate.”). We decline CTIA’s request that the Commission find that
mandatory port-out PINs satisfy this requirement. CTIA Nov. 8, 2023 Ex Parte Letter at 5-6. We discuss the
benefits and drawbacks of port-out PINs as a method of customer authentication, above. See supra Section III.B.1.
We disagree that a mandatory port-out PIN has the same effect as an optional account lock; while the two
protections serve complementary functions, one is focused on customer authentication for a specific one-time
request, and the other functions as a customer directed general account security feature.
244 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14141-42, para. 57 (seeking comment on port-out lock

requirements).
245 Id.

246 See 47 U.S.C. § 345(b)(2)(D) (prohibiting carriers from making valid line separation requests from survivors of

domestic violence contingent on any requirement or limitation, including restrictions on number portability); Safe
Connections Order, FCC 23-96, at para. 76 and Appx. A (new 47 CFR § 64.6402(l)) (requiring a covered provider
to effectuate a legitimate line separation request, and any associated number port and SIM change requests,
regardless of whether an account lock is activated on the account); id. at Appx. A (new 47 CFR § 64.6402(k))
(requiring that as soon as feasible after receiving a legitimate line separation request from a survivor, a covered
provider shall lock the account affected by the line separation request to prevent all SIM changes, number ports, and
line cancellations other than those requested as part of the line separation request pursuant to 47 U.S.C. § 345 and
the Commission’s rules until the request is processed or denied); id. at Appx. A (new 47 CFR § 64.6404(a)).
247 See supra para. 43; SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14141, para. 57 (seeking comment on

port-out lock requirements).

                                                         40
                                     Federal Communications Commission                                     FCC 23-95

provider. In establishing this limitation, we intend to prohibit wireless provider abuse of port-out locks to
avoid, among other outcomes, preventing the customer from terminating service with the provider or
moving to another competing provider.
        64.      As with account locks for SIM changes,248 given that several wireless providers already
voluntarily offer account locks to all their customers,249 and coupled with the flexible approach we adopt,
we are unpersuaded by AT&T’s claim that implementing account lock offerings will be unduly costly and
time-consuming for wireless providers.250 To the extent there are costs associated with the requirement,
we find that they are outweighed by the benefits.
                   4.         Wireless Port Validation Fields
         65.     After review of the record, we decline to codify the wireless port validation fields.251 We
also decline to require wireless providers to implement a customer-initiated passcode field for all
wireless-to-wireless number porting requests.252 Currently, the mobile wireless industry uses four data
fields of customer-provided information to validate a wireless-to-wireless porting request: telephone
number, account number, five-digit ZIP code, and passcode (if applicable).253 In the SIM Swap and Port-
Out Fraud Notice, we sought comment on whether we should “codify the types of information carriers
must use to validate simple wireless-to-wireless port requests.”254 While some commenters did not
oppose codification of some of the customer-provided wireless data fields, they preferred that the
Commission continue to give wireless providers the flexibility to adjust to business and customer
needs.255 We are persuaded by the record that separate codification of the customer-provided data fields

248 See supra para. 42.

249 See, e.g., CCA Comments at 3-4 (describing T-Mobile’s free service called “Account Takeover Protection”

which “blocks unauthorized users from porting numbers and allows only the billing responsible party to turn the
feature off”); CTIA Comments at 3-4 (noting that “examples of the variety of tactics used to combat SIM swapping
and port-out fraud include . . . the ability to lock or freeze wireless accounts”); CTIA Reply at 26-27 (“The record
demonstrates that absent a requirement, many providers already offer account freeze options to their customers.”);
T-Mobile Comments at 4 & 11 (“Qualifying customers may wish to enable safeguards such as setting up account
takeover protection—a free feature that prohibits unauthorized users from porting the customer’s phone line to
another wireless carrier.”); NCTA Comments at 4-5 (“Wireless providers already engage in many [measures to
prevent SIM swap and port-out fraud] today, including . . . providing the ability to lock or freeze wireless
accounts.”); see also Verizon, Additional Support Information, https://www.verizon.com/support/port-out-
faqs/#setup-freeze (last visited Oct. 18, 2022) (offering a “Number Lock” service that is a customer-managed
porting freeze option accessible by dialing 611 or through the MyVerizon app); T-Mobile, Account Takeover
Protection by T-Mobile, https://www.t-mobile.com/support/plans-features/account-takeover-protection (last visited
Oct. 18, 2023) (providing information on its Account Takeover Protection feature, which “adds additional security
to your account by blocking unauthorized users from transferring your lines to another wireless carrier”).
250 AT&T Comments at 17; see also CTIA Nov. 8, 2023 Ex Parte Letter at 5 (asserting that implementing this

requirement “is likely to be costly for providers, who will have to offer account lock options to all customers, across
all covered systems”).
251 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14142, para. 58.

252 Id. at 14142, para. 60.

253 See 2007 LNP Four Fields Declaratory Ruling, 22 FCC Rcd at 19557, para. 48.

254 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14142, para. 58.

255 Compare Verizon Comments at 10 (supporting codification of “aspects” of the four data fields, noting that “ZIP

code is of limited use for verification given its wide availability” and its use to complete porting requests “has
resulted in unnecessary confusion”) with CCA Comments at 6-7 (noting that data fields should not be mandatory as
flexibility allows carriers to respond to “security needs and capabilities”); AT&T Comments at 15 & n.15
(“Proposed rule § 52.37(a) – (c), addressing data fields to validate a port-out request, should retain the flexibility to
allow carriers to continue using temporary transaction-specific PINs assigned by the carrier in lieu of account-level
passcodes assigned by customers, as the temporary PIN offers superior protection”); CTIA Comments at 19 (stating
                                                                                                          (continued….)
                                                           41
                                    Federal Communications Commission                                    FCC 23-95

for validation of wireless-to-wireless ports is not necessary at this time, as we have been provided no
evidence that wireless providers are not complying with the validation obligations imposed in the Four
Fields Declaratory Ruling.256 As such, we decline to separately codify the customer-provided wireless-
to-wireless port validation fields at this time.
         C.       Additional Consumer Protection Measures
         66.     In the SIM Swap and Port-Out Fraud Notice, we sought comment on whether we should
adopt additional measures to address the problems associated with SIM swap and port-out fraud.257 As
discussed below, we require that wireless providers inform customers of any account protection
mechanisms the provider offers, ensure that customer service representatives are trained to recognize bad
actors’ attempts at these fraudulent schemes, and deliver timely resolution of SIM swap and port-out
fraud when it does occur. We decline, however, to establish a working group to further study and develop
solutions to address the harms of SIM swap and port-out fraud. We also decline to adopt other proposals
in the record regarding wireless provider liability and dispute resolution related to SIM swap and port-out
fraud.
         67.     Customer Notice of Account Protection Measures. Many of the account protection
measures wireless providers offer and that we require wireless providers to adopt today are designed to
empower customers to take steps to protect themselves from SIM swap and port-out fraud if they choose,
but this empowerment will be stifled if customers are not effectively made aware of the measures that are
available. Accordingly, we require wireless providers to provide notice, using clear and concise
language, of any account protection measures the provider offers, including the measures we adopt in this
Report and Order, and make this notice easily accessible via provider websites and applications.258 We
decline to specify the exact format or content of the required notice, as we agree with CCA that wireless
providers are well-positioned to determine exactly how best to communicate information about account
protection measures to their customers.259 The record also demonstrates that some wireless providers
have already developed content to educate customers about some account protection measures.260
        68.     We decline to require wireless providers to deliver an annual notice to customers
regarding the availability of the account protection mechanisms they offer.261 The record does not exhibit

(Continued from previous page)
that the Commission should “not require the use of a passcode or foreclose the option for providers to use a porting-
specific, one-time passcodes”); T-Mobile Comments at 10-11 (encouraging the Commission to not require one-time
PINs for validating porting requests, as “secure methods of authentication and carrier practices may evolve over
time”).
256 2007 LNP Four Fields Declaratory Ruling, 22 FCC Rcd at 19553-58, paras. 42-49.

257 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14144-46, paras. 68-73.

258 See id. at 14135, para. 39 (seeking comment on a notice requirement and expressing our belief that such notices

should be brief, use easy-to-understand language, and be delivered in a manner that is least burdensome to
customers). To provide greater clarity on what we require, the language we adopt slightly deviates from what we
sought comment on in the SIM Swap and Port-Out Fraud Notice.
259 See CCA Comments at 4 (arguing the Commission should allow “carriers to continue to communicate with their

customers in the manner that they have found to be most effective”).
260 AT&T Comments at 7 (“AT&T’s website provides information about SIM swap scams and misuse of the porting

process and offers guidance about how customers can protect themselves against such fraud.”); T-Mobile Comments
at 5-6 (“T-Mobile publishes Safety Tips to educate subscribers on how to protect themselves online and directs
customers to additional resources on identity theft and online safety from the FTC, CTIA, and others. T-Mobile’s
online resources also inform the customer of what to do if they believe someone has made unauthorized charges to
their account.”) (footnote omitted); CTIA Comments at 4 (stating that “[it] provides resources for consumers on
steps that they can take to protect their wireless accounts”).
261 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14135, para. 39.

                                                         42
                                    Federal Communications Commission                                     FCC 23-95

support for this requirement and we have no basis for concluding that it would be meaningfully more
beneficial for customers than our requirement that wireless providers make notice about the availability of
account protection measures easily accessible through provider websites and applications. We therefore
decline to adopt an annual notice requirement.
         69.     Employee Training. We require wireless providers to develop and implement training for
employees on how to identify, investigate, prevent, and remediate SIM swap and port-out fraud.262 We
find that adopting this employee training requirement will serve as a “first line of defense” against these
damaging and evolving practices by preparing employees to defend against such fraud and preventing
them from inadvertently or intentionally assisting bad actors in fraudulent schemes.263
        70.       We agree with Verizon that “customer care and employee training programs are critical
for preventing and identifying unauthorized and high-risk SIM changes for postpaid customers,”264 and
we find that all customers will benefit from employee training. The record reflects the industry’s
recognition of the importance of employee training; the country’s three largest wireless providers—
Verizon, T-Mobile, and AT&T—have already implemented some training measures for customer service
representatives to identify, prevent, and remediate fraud.265 The record also shows, however, that some
wireless providers’ current practices for customer service representative training may be lacking, as there
are reported instances of wireless provider employees failing to identify, prevent, or quickly remediate
SIM swap and port-out fraud.266 We have previously determined that customer service training
262 See id. at 14134-35 & 14144-45, paras. 38 & 69 (seeking comment on training requirements).

263 See, e.g., NCLC/EPIC Comments at ii, 8-9 (asserting that the Commission should ensure that “providers prohibit

their employees from . . . prompting leading questions or other mechanisms to enable fraudulent swaps”); id. at 6
(explaining that employees who assist victims “should be trained to provide responsive assistance in a timely
manner”); Robert Ross Comments at 7-8 (arguing that any employee that a provider authorizes to perform a SIM
swap should, amongst other precautions, “go through a higher level of training and repeat training in a program that
is custom developed for high-risk transactions”); OPUS Research Comments at 1 (explaining that “the measures to
secure SIM Swap and Port-Out employed by wireless service providers are . . . reliant on well-trained staff at retail
stores and customer contact centers” and observing that “fraudsters employ ‘human engineering’ techniques to enlist
support from sales or customer support personnel through multiple calls into a contact center or visits that too often
result in successful identity theft in the form of SIM swaps or porting out of a number”); ATL Comments at 1
(asserting that “implementing additional training for all customer service representatives initiating the port outs
would provide consistency in security protocols”).
264 Verizon Comments at 2.

265 See Verizon Comments at 3 (“Verizon also trains all customer care employees to identify and prevent

unauthorized SIM change attempts through the use of multiple authentication protocols. . . . Customer care
employees identifying potentially fraudulent SIM changes refer those reports to dedicated investigative teams.”); T-
Mobile Comments at 5 (“T-Mobile trains its employees on how to recognize fraud and account takeover attempts
and how to respond if fraud occurs. Customer service representatives complete ongoing interactive training
curricula on fraud and response. Moreover, T-Mobile provides resources on combatting fraud to employees. These
resources are provided and maintained so that employees are knowledgeable about steps and guidelines for
recognizing attack attempts and can properly respond to customer reports of fraud.”); CTIA Comments at 3-4
(“While each provider’s practices are different and many are not publicly visible so as to shield provider tactics from
criminals, examples of the variety of tactics used to combat SIM swapping and port-out fraud include: . . . [t]raining
employees to identify signs of a fraudulent SIM swap request and uses.”); CTIA Reply at 7-8 (“AT&T reports that
its customer service agents complete mandatory training, including on fraud prevention, authentication, social
engineering, protection of CPNI, and account verification.”).
266 See, e.g., Erik Faraldo Comments (Express) at 1 (reporting that he attempted to enable a port validation feature

offered by his provider to prevent port-out fraud but eventually abandoned the effort due to difficulty reaching
customer support, lack of knowledge about the feature by customer support representatives, and long wait times);
Robert Ross Comments at 1 (detailing that it only took hackers minutes to complete a fraudulent SIM swap and that
remediating the fraud took many months); Lee et al. at 7 (discussing how customer service representatives for some
carriers processed SIM swaps without proper authentication under existing mechanisms).

                                                          43
                                     Federal Communications Commission                                      FCC 23-95

requirements play an important role in safeguarding the proper use of CPNI and have required
telecommunications carriers to train their personnel on when they are and are not authorized to use
CPNI.267 We similarly conclude that the employee training requirement we adopt today is necessary to
ensure customer service representatives are prepared to identify, prevent, and remediate fraudulent SIM
change and port-out activity.
         71.      In applying this requirement, we give wireless providers flexibility on designing their
training programs.268 But we do require that all employees who may communicate with customers
regarding SIM changes and number ports must be trained on how to recognize potentially fraudulent
requests, how to recognize when a customer may be the victim of fraud, and how to direct potential
victims and individuals making potentially fraudulent requests to employees specifically trained to handle
such incidents.269 Given that (1) some wireless providers already train employees on how to address
fraud,270 (2) our new training requirement builds upon our existing CPNI training rule,271 and (3) we are
providing wireless providers with flexibility on how to design their training programs, we do not
anticipate that imposing this training requirement will be overly costly for wireless providers.
         72.     Requirements to Remedy SIM Swap and Port-Out Fraud. We are concerned that in some
cases, “consumers who have been the victims of SIM swaps or port-out fraud have had difficulties
obtaining assistance from the carriers” when they report it.272 Accordingly, we require wireless providers
to maintain a clearly disclosed, transparent, and easy-to-use process for customers to report SIM swap and
port-out fraud, promptly investigate and take reasonable steps within their control to remediate such
fraud, and, upon request, promptly provide customers with documentation of SIM swap and port-out
fraud involving their accounts.273 These measures must be provided to victims of SIM swap and port out
fraud at no cost. We anticipate that, in combination, these requirements will serve to minimize the harms
that victims experience as a result of SIM swap and port-out fraud.
        73.     Our requirement that wireless providers maintain a clearly disclosed, transparent, and
easy-to-use process for customers to report SIM swap and port-out fraud rests on our concern that
customers currently struggle to report SIM swap and port-out fraud to their wireless providers.274 When
customers are unable to find information about how to report such fraud or use existing customer service
avenues to do so, it not only frustrates these customers, it prevents initiation of steps to investigate and

267 See 47 CFR § 2009(b); CPNI Reconsideration Order, 14 FCC Rcd at 14476-77, para. 130.

268 See, e.g., CCA Comments at 4 (“Should the Commission determine that additional rules are necessary to prevent

SIM swap and port out fraud, it should ensure that such rules are sufficiently flexible to account for evolving
technologies.”); CTIA Reply at 27 (“[T]here is no one-size-fits-all solution to [protecting customer accounts] and
that the measures necessary to protect different customers and different types of services vary greatly.”).
269 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14134-35, 14144-45, paras. 38, 69 (seeking comment

on training requirements); Verizon Comments at 3 (explaining that customer care employees identifying potentially
fraudulent SIM changes refer those reports to dedicated investigative teams, and observing that there is a toll-free
number for customers to contact or obtain assistance from Verizon in the event of an unauthorized SIM change).
270 See supra n.265.

271 47 CFR § 64.2009(b) (“Telecommunications carriers must train their personnel as to when they are and are not

authorized to use CPNI, and carriers must have an express disciplinary process in place.”); see also CPNI Order, 13
FCC Rcd at 8198, para. 198.
272 NCLC/EPIC Comments at 5.

273 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14145, para. 69.

274 Princeton Comments at 11-12 (“We recommend that the Commission require carriers to have a clearly disclosed

process for customers to quickly and easily report account compromise.”); NCLC/EPIC Comments at ii (asserting
that the Commission should “[r]equire carriers to offer a redress program that . . . is fully accessible and transparent
to all customers”); see also SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14144-45, para. 69.

                                                           44
                                    Federal Communications Commission                                    FCC 23-95

remediate the fraud, which increases the risk that fraudsters will be able to use a victim’s SIM or phone
number to accomplish further fraud. We anticipate that clear methods for reporting SIM swap and port-
out fraud that are transparent to customers will “ensure that customers have easy access to information
they need to report SIM swap, port-out, or other fraud.”275 We decline to specify the exact means wireless
providers must put in place for customers to report SIM swap and port-out fraud, but we stress that the
process must be a clearly disclosed, transparent, and easy-to-use process for customers to notify
providers.
         74.     We require wireless providers to establish procedures to promptly investigate and take
reasonable steps within their control to remediate SIM swap and port-out fraud because the record
demonstrates that even when victims of SIM swap and port-out fraud are successful in reporting such
fraud to their providers, they have difficulty obtaining assistance from their providers to remediate the
fraud.276 This is consequential because “[i]dentity theft, including SIM swap fraud, can cause intense
anxiety for victims and must be addressed in a timely manner to prevent financial losses and exposure of
personal information.”277 Thus, we conclude that “it should be easy for a customer to get access to
appropriate carrier resources that can help mitigate the significant harms caused by SIM swap or port-out
fraud.”278 Although we do not specify the procedures that wireless providers must adopt,279 we agree with
commenters that investigations must be instigated and resolved expeditiously.280
        75.      To ensure victims of SIM swap and port-out fraud have additional means to resolve other
consequences that result from SIM swap and port-out fraud, we require wireless providers to give
customers documentation regarding such fraud on their accounts, upon request.281 In the SIM Swap and
Port-Out Fraud Notice, we recognized that “customers sometimes need documentation of the fraud
incident to provide to law enforcement, financial institutions, or others to resolve financial fraud or other
harms of the incident” and acknowledged that “[a] SIM swap or port-out fraud victim may have difficulty
obtaining such documentation from the carrier because the carrier may not have processes in place to
produce such documentation.”282 Requiring wireless providers to give fraud victims supporting
documentation will enable those victims to seek remedies from other institutions for additional fraud that
bad actors achieve using a victim’s SIM or phone number. We do not specify the form that such

275 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14145, para. 69.

276 See Princeton Comments at 11-12 (“There are countless anecdotes of SIM swap and port-out victims who

struggle to regain control of their telephone number.”); NCLC/EPIC Comments at 5 (“[M]any consumers who have
been the victims of SIM swaps or port-out fraud have had difficulties obtaining assistance from the carriers.”); Erik
Faraldo Comments (Express) (describing one customer’s challenges with seeking remediation of SIM swap fraud).
277 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14145, para. 69.

278 Id. See also Kyle Ratcliff Comments (Express) (urging that the Commission “mandate carriers adopt an easy-to-
use and standardized remediation process for those customers who are affected by this type of identity theft. Given
the fact that so much of our day to day lives are currently managed by our smartphones, the last thing a consumer
should have to do if they have been victimized is negotiate an increasingly Byzantine system of bureaucracy in order
to get their rightful account ownership restored.”).
279 See Princeton Comments at 11-12 (“We do not take a position on what the nature of that investigation should be

or how quickly the carrier should complete it, since the details will vary by account compromise.”).
280 See Princeton Comments at 11-12 (“If a carrier receives a credible report of compromise, it should expeditiously

investigate without unreasonable delay and, if the report is accurate, restore access to the customer’s account.”);
NCLC/EPIC Comments at 6 (asserting the reports of SIM swap and port-our fraud “should trigger . . . [i]mmediate
assistance to the customer both to stop further losses [and an] internal investigation by the customer’s provider to
determine how the fraud was effectuated”).
281 See NCLC/EPIC Comments at ii (arguing that the Commission should “[r]equire carriers to offer a redress

program that . . . includes all information necessary for the customer to cooperate with law enforcement”).
282 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14144, para. 68.

                                                         45
                                     Federal Communications Commission                                      FCC 23-95

documentation must take or exactly what information it must contain, but it should be reasonably
designed to permit customers to demonstrate to other entities that they were victims of SIM swap or port-
out fraud and that bad actors may have used access to a victim’s telecommunications services to carry out
additional fraud.283 Additionally, because of the potential harms that can flow from SIM swap and port-
out fraud, we also require wireless providers to provide this documentation promptly.
         76.     We anticipate that the benefits of our requirements will outweigh any potential costs.
Although commenters did not address the costs of the additional measures we adopt here, we note that at
least one wireless provider has already adopted processes for customers to report SIM swap and port-out
fraud, to investigate and remediate such fraud, and to provide documentation of such fraud to customers
upon request.284 We also anticipate that allowing wireless providers flexibility in how to abide by these
new requirements will enable them to adopt cost-effective procedures that will also allow them to
successfully resolve SIM swap and port-out fraud incidents when they occur.
         77.     To maintain the flexibility we believe will be required for wireless providers to
adequately tailor and adapt their practices to address SIM swap and port-out fraud, we decline to impose
prescriptive measures raised in the SIM Swap and Port-Out Fraud Notice and the record. Specifically,
although we encourage wireless providers to establish a dedicated hotline for customers to report SIM
swap and port-out fraud285 and respond within 24 hours of a customer reporting suspected fraud,286 we
decline to require that wireless providers adopt these approaches. While the former requirement received
support from the National Consumer Law Center (NCLC) and the Electronic Privacy Information Center
(EPIC), we conclude that it may not benefit a wireless provider’s customers if it is inconsistent with a
provider’s established customer service methods. The latter may be infeasible for certain incidents and is
not necessary given our requirement that investigation and remediation be prompt. We also decline to
require that wireless providers give customers an alternative number on a temporary basis after SIM swap
or port-out fraud has occurred,287 as that may promote number resource exhaust in certain areas or for
certain wireless providers. However, we encourage wireless providers to offer customers a temporary
alternative number when the efforts to remediate SIM swap or port-out fraud may take a significant
amount of time or to assist customers who have critical needs to be accessible via phone at the time.288
We do not find it necessary at this time to require that wireless providers, upon being notified by a
customer of fraud, provide “detailed records of the fraud [to law enforcement]” or “offer to the customer
to notify financial institutions and creditors, the three national credit reporting agencies, and others of the
fraud, to help the customer recover control over their identity, if appropriate.”289 While we encourage

283 Such documentation must address the customer’s interest in protecting his or her account(s) or identity but may

be tailored not to include other proprietary, confidential, or law-enforcement-related information regarding the SIM
swap or port-out fraud or the account.
284 See T-Mobile Comments at 5 (“If a customer is a victim of SIM swap or port-out fraud, T-Mobile takes rapid,

responsive measures. Customers may report fraud or unauthorized activity by calling T-Mobile’s Customer Care
hotline, which is available 24/7. When fraud occurs, T-Mobile’s Fraud Operations specialists act quickly to ensure
all fraudulent changes are corrected and any wrongful T-Mobile account charges are refunded. T-Mobile also
assists with phone number recovery and provides victims with documentation of the fraud upon request.”).
285 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14145, para. 69; NCLC/EPIC Comments at 5 (“As

suggested, a dedicated and well-publicized hotline should be one component.”) (footnote omitted).
286 NCLC/EPIC Comments at ii (asserting that the Commission should “[r]equire carriers to offer a redress program

that . . . provides timely responses within 24 hours after a complaint is made”).
287 Id. at 6 (asserting that carriers should “provide a safe alternative mobile telephone” during the mitigation

process).
288 We also recognize that adequate remediation may require providing victims with permanent replacement

numbers or SIMs, and carriers should effectively assist customers with that transition should that be necessary.
289 NCLC/EPIC Comments at 6.

                                                           46
                                      Federal Communications Commission                                      FCC 23-95

wireless providers to take these steps upon the request of customers as part of their mitigation efforts, we
conclude that our new requirement that providers give customers documentation concerning fraudulent
SIM swaps and number ports will be sufficient to allow those customers to alert appropriate entities if
needed. We note, however, that we will monitor consumer complaints and may evaluate the remediation
programs implemented by wireless providers. If we find that such programs are not adequately resolving
SIM swap and port-out fraud in a timely manner, we may take steps to implement more specific
requirements in the future.
         78.      Working Group. While we recognize that the harmful effects of SIM swap and port-out
fraud may extend beyond the control of wireless providers and that the incentives to engage in such fraud
implicate the security practices of other industries,290 we decline at this time to direct or rely on standard-
setting bodies, industry organizations, or consumer groups to evaluate SIM swap and port-out fraud “to
augment our understanding and present possible solutions.”291 Instead, we find it most appropriate to
focus on solutions within the scope of the Commission’s authority that we anticipate will mitigate the
harmful consequences of this fraud.292 Additionally, to the extent that commenters advocated that we
direct this issue to a working group before taking action,293 we disagree with that approach and find that
doing so would only delay solutions that we expect will benefit customers now. Although we decline to
rely on a working group, we also do not foreclose wireless providers from forming or entering into cross-
sector, multi-stakeholder efforts, independent of Commission direction, to seek broader solutions to the
harms that may ultimately result from SIM swap and port-out fraud.294
         79.     Provider Liability and Dispute Resolution. We decline to adopt proposals in the record
that prescribe provider liability and dispute resolution requirements for disputes between wireless
providers and customers.
         80.      NCLC and EPIC argue that the Commission should “[r]equire carriers to offer a redress
program that . . . provides full coverage of losses to customers who have been the victims of a fraudulent
SIM swap or port-out fraud,” which they say would “[p]rovide strong financial incentives to providers to
stop SIM swapping and port-out fraud.”295 We agree with CTIA, however, that telecommunications
carriers are “but one link in the chain of consumer and business protection from account takeover

290 See, e.g., AT&T Comments at 2 (“SIM swap or port-out [fraud] is only a small part of the scheme to harm the

consumer, as these incidents implicate a range of stakeholders not controlled by carriers (e.g., financial institutions,
cryptocurrency companies, text message aggregators) that all play a role in the verification of customer identity.”);
T-Mobile Comments at 1-2 (“[C]ombatting SIM swap and port-out fraud is a team effort that requires action by an
entire ecosystem that includes carriers and subscribers as well as financial institutions, email providers, retail
websites, social media companies and others who rely on various customer authentication methods.”); CTIA Reply
at 11 (“[T]he record makes it abundantly clear that others beyond the wireless sector need to engage to address the
problem of fraudulent account takeovers.”).
291 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14146, para. 72.

292 AT&T Comments at 8 (acknowledging that “SIM swap and port-out scams implicate third parties outside the

Commission’s jurisdiction”).
293 See, e.g., id. at 3 (asserting that the Commission should “first leverage existing resources and expertise . . . before

deciding on a course of action”); Bandwidth Reply at 6 (“In order to fully explore and understand the full breadth of
the issues and their potential solutions, Bandwidth agrees with those opening comments that recommend that the
Commission support inclusive and consensus-driven industry efforts as its next step in this proceeding.”); cf. T-
Mobile Comments at 14-15 (suggesting that “the FCC could coordinate with other regulators, such as financial
services or healthcare regulators, on strategies” to address SIM swap and port-out fraud and that “[t]he Commission
also may want to coordinate with NIST on addressing authentication issues”).
294 See, e.g., CTIA Reply at 11 (“[T]he Commission should convene a cross-sector, multi-stakeholder working group

to study the broader questions in the NPRM that go beyond the rule changes proposed.”).
295 NCLC/EPIC Comments at ii.

                                                            47
                                    Federal Communications Commission                                    FCC 23-95

fraud,”296 and therefore that the responsibility for financial harms that a bad actor may be able to
perpetuate following such fraud is borne by several parties, including, significantly, the bad actor.
Imposing such liability on wireless providers would be inequitable and would reduce the incentives for e-
mail and social media providers, financial institutions, healthcare providers, retail websites, and other
entities that rely on cell phone-based identity authentication to improve their security practices,297 as well
as reduce the incentive for customers to act responsibly.298 We note, however, that compliance with our
rules is not a safe harbor for wireless providers; customers will still be able to pursue any existing
remedies available by law.299
         81.     Similarly, we decline to specify, as NCLC and EPIC request, that wireless providers are
“fully responsible for any abuse committed by its employees, whether the employees acted either
intentionally or negligently,”300 although we make clear that this statement does not absolve wireless
providers of any liability for employee actions that already exists. We anticipate that the requirements we
adopt today—including employee training regarding SIM swap and port-out fraud and restrictions on the
ability of employees to access CPNI prior to authentication—will ensure that wireless providers
implement adequate procedures to prevent employees from perpetuating SIM swap and port-out fraud.
         82.      Finally, we decline to adopt NCLC and EPIC’s proposal that “any arbitration clauses in
the providers’ agreements with consumers explicitly exclude resolutions” of SIM swap and port-out fraud
disputes at this time.301 They urge this because “[o]therwise, consumers who have not been made whole,
or who have difficulties obtaining relief for frauds that are perpetrated on them because of the provider’s
insufficiently strict authentication protocols, will have no meaningful way of enforcing the protections
mandated by the Commission.”302 The Commission has full authority to enforce the protections it has
mandated, and we anticipate that the rules we adopt today, coupled with this enforcement authority, will
incentivize wireless providers to adopt strong practices to protect customers from SIM swap and port-out
fraud. Nonetheless, we seek comment below on whether the Commission should require providers to
exclude disputes about SIM swapping or porting fraud from arbitration clauses.303 We encourage
customers and public interest organizations to submit complaints and evidence of wireless providers
failing to comply with these new rules in support of our enforcement efforts.
          D.      Implementation Timeframe
       83.      We require wireless providers to comply with the requirements we adopt today six
months after the effective date of the Report and Order or, for those requirements subject to review by the

296 CTIA Reply at 13-14.

297 See id. (“[H]olding providers solely or presumptively liable risks undermining the incentives other players

involved in SIM swap losses, such as banks and crypto wallets, have to prevent fraud. Such an approach also would
be inequitable.”).
298 For example, if customers knew that wireless providers must provide full coverage of losses resulting from SIM

swap and port-out fraud, they might not be fully incentivized to place locks on their account or take appropriate
action when they receive notice from their wireless providers about unauthorized SIM swap and port-out requests or
failed authentication attempts.
299 See, e.g., Al Weiss v. AT&T Inc., No. 6:23-cv-00120 (M.D. Fla., filed Jan. 23, 2023); Eman Bayani v. T-Mobile

USA, Inc., No. 2:23-cv-00271 (W.D. Wash. filed Feb. 27, 2023); Samuel Whatley, II v. T-Mobile USA, Inc., No.
2:23-cv-1339-RMG-MGB (D.S.C. filed Apr. 3, 2023); Feliks Roitman and Yekaterina Shkolnik v. T-Mobile USA,
Inc., No. 1:23-cv-06159 (E.D.N.Y., filed Aug. 16, 2023).
300 NCLC/EPIC Comments at 10.

301 Id. at 6.

302 Id.

303 See infra Further Notice.

                                                         48
                                    Federal Communications Commission                                     FCC 23-95

Office of Management and Budget (OMB), upon completion of that review, whichever is later. We
conclude that providing six months to achieve compliance with rules that are not subject to OMB review
accounts for the urgency of safeguarding customers from these fraudulent schemes, and will allow
wireless providers to coordinate any updates needed to their systems and processes to comply with the
Safe Connections Act and the rules we adopt to implement that statute.304 SIM swap and port-out fraud
can result in substantial harm to the customer, including loss of service on their devices. Fraudulent SIM
swaps and port-outs allow bad actors to perpetrate greater fraud by giving them the means to complete
text and voice authentications to access the victim’s other accounts, and as such, we find that an
aggressive implementation timeframe is appropriate to provide these important consumer protections
without substantial delay. We agree with some commenters that while many wireless providers can
immediately implement the revisions to our CPNI and number porting rules, other providers may require
this additional time.305 Some wireless providers already employ authentication306 and notification307
measures to process SIM change and port-out requests, offer account change locks,308 provide notice to

304 See generally Safe Connections Order.    But see Letter from Steven F. Morris, Vice President & Deputy General
Counsel, NCTA – The Internet & Television Association, to Marlene H. Dortch, Secretary, FCC, WC Docket No.
21-341 et al., at 2 (filed Nov. 7, 2023) (requesting an 18 month implementation timeframe, asserting that additional
time is needed because “there are numerous steps required for providers to implement [changes to their subscription
and account management procedures and systems], including, for example, IT grooming, design and development,
unified customer communications notification and development, development testing, quality assurance testing, user
acceptance testing, and training”); NTCA Nov. 8, 2023 Ex Parte Letter at 2 (expressing support for the 18-month
implementation timeframe requested by NCTA); CCA Nov. 9, 2023 Ex Parte Letter at 1-2; CTIA Nov. 8, 2023 Ex
Parte Letter at 2 (requesting an implementation timeframe of 24 months, or at a minimum 18 months, for the same
reasons, and given that “providers are simultaneously preparing to come into compliance with the Safe Connections
Act and its implementing regulations”).
305 See T-Mobile Comments at 13-14 (“While some of the changes proposed by the FCC can be implemented

immediately, others may require a longer implementation timeframe.”); NCTA Comments at 8 (“[I]t is important to
provide sufficient time for carriers to implement [new obligations] in a way that is robust, thorough, and clear so that
they do not cause customer confusion”).
306 See, e.g., AT&T Comments at 13 (“Carriers are already authenticating customers using one or more of the

methods identified in the Commission’s existing and/or proposed rules.”); id. at 6-7 (describing its routine use of “a
one-time PIN delivered via SMS message or an outbound voice call to a postpaid customer’s device for enhanced
customer validation,” and its “Number Transfer PIN process to validate postpaid port-out transactions”); CCA
Comments at 3-4 (describing U.S. Cellular’s assigning of a PIN code to each customer that is used for customer
authentication); Better Identity Coalition Comments at 4 (noting that “two major mobile network operators already
support FIDO authentication for their customers”); NCTA Comments at 4-5 (describing authentication measures
some wireless providers already use, including account PINs); T-Mobile Comments at 4 (“T-Mobile offers various
customer authentication options, which may vary based on customer, account, and device characteristics.”); Verizon
Comments at 8-9 (describing current authentication measures, including a transaction-specific “Number Transfer
PIN” and notifying customers of port requests via text message and email); CTIA Comments at 3-4 (noting that
some providers already employ multi-factor authentication when account changes are requested).
307 See, e.g., AT&T Comments at 6 (explaining that for transactions meeting a certain threshold of AT&T’s “risk

model,” it will send one-way SMS notifications of a SIM change request, and for transactions meeting a higher risk
threshold, it will require customers confirm the SIM change request via an SMS notification); T-Mobile Comments
at 4 (noting that “T-Mobile notifies customers of account changes and requests”); Verizon Comments at 6 (“Verizon
already . . . notif[ies] customers of high-risk SIM change authentication attempts, failed or otherwise, and of other
account changes.”); CCA Comments at 3-4 (describing the current procedures that T-Mobile, U.S. Cellular, and GCI
use to notify customers of a change to their account or port-out request, and that other members are “similarly
adopting heightened security measures”); CTIA Comments at 3-4 (explaining that some providers notify customers
when a SIM swap is initiated).
308 See, e.g., T-Mobile Comments at 4 (“[F]or most types of customers, T-Mobile can institute a ‘SIM change

block’. . .”); NCTA Comments at 4-5 (“Wireless providers already . . . provid[e] the ability to lock or freeze wireless
accounts.”); CTIA Reply at 26-27 (“[M]any providers already offer account freeze options to their customers.”);
                                                                                                        (continued….)
                                                          49
                                    Federal Communications Commission                                    FCC 23-95

customers about available fraud protection measures,309 and train employees on how to address SIM swap
and port-out fraud,310 and may simply need to refine those practices to align with our rules. Other
providers, particularly smaller providers, may need the additional time to upgrade their systems,
implement modifications to their policies and procedures, and conduct new customer service
representative training.311 We conclude that providing six months after the effective date of the Report
and Order to implement these revisions to our CPNI and number porting rules strikes the right balance
between time for wireless providers to implement these changes and accounting for the urgency of
safeguarding customers from these fraudulent schemes. We also find that this implementation timeframe
is consistent with other proceedings and regulatory frameworks adopted by the Commission where
consumer protection and numbering requirements were at issue.312 While we acknowledge industry’s
concerns that implementing these new rules will be a multistep process for many providers,313 providers
themselves acknowledge the necessity of implementing today’s revisions to our CPNI and LNP rules
concurrently with our rules implementing the Safe Connections Act, given how both frameworks address
many of the same actions (e.g., account locks, customer notifications, customer authentication).314 And as
we explain in the Safe Connections Order, “permitting a more extended compliance timeframe for
implementing the line separation provisions, as advocated for by industry commenters, would be
inconsistent with the urgency Congress demonstrated with the underlying statutory obligation as well as
with the critical wireless communications needs of survivors well-documented in the record.”315 For all of

(Continued from previous page)
CCA Comments at 3-4 (describing T-Mobile’s “Account Takeover Protection” service, which “blocks unauthorized
users from porting numbers and allows only the billing responsible party to turn the feature off”).
309 AT&T Comments at 7 (“AT&T’s website provides information about SIM swap scams and misuse of the porting

process and offers guidance about how customers can protect themselves against such fraud.”); T-Mobile Comments
at 5-6 (“T-Mobile publishes Safety Tips to educate subscribers on how to protect themselves online and directs
customers to additional resources on identity theft and online safety from the FTC, CTIA, and others. T-Mobile’s
online resources also inform the customer of what to do if they believe someone has made unauthorized charges to
their account.”) (footnote omitted); CTIA Comments at 4 (stating that “[it] provides resources for consumers on
steps that they can take to protect their wireless accounts”).
310 See, e.g., Verizon Comments at 3 (“Verizon also trains all customer care employees to identify and prevent
unauthorized SIM change attempts through the use of multiple authentication protocols. . . . Customer care
employees identifying potentially fraudulent SIM changes refer those reports to dedicated investigative teams.”); T-
Mobile Comments at 5 (“T-Mobile trains its employees on how to recognize fraud and account takeover attempts
and how to respond if fraud occurs.”); CTIA Comments at 3-4 (listing employee training as an example of the
tactics providers use to combat SIM swap and port-out fraud); CTIA Reply at 7-8 (“AT&T reports that its customer
service agents complete mandatory training, including on fraud prevention, authentication, social engineering,
protection of CPNI, and account verification.”).
311 See, e.g., NCTA Comments at 8 (“Many of the potential solutions might require modifications to internal

systems, as well as significant training of company personnel.”).
312 See, e.g., 2007 CPNI Order, 22 FCC Rcd at 6958, para. 61 (concluding that six months was sufficient for carriers

to implement the revised CPNI rules to address pretext (except for certain small carriers) “in light of the importance
of this issue to the public interest”); 2007 LNP Four Fields Declaratory Ruling, 22 FCC Rcd at 19552, 19557, paras.
40, 48 (concluding that 90 days was sufficient time for carriers to comply with LNP validation requirements and
requiring interconnected VoIP providers and their numbering partners to comply with LNP obligations 30 days after
Federal Register publication, subject to OMB review and approval).
313 See, e.g., CTIA Nov. 8, 2023 Ex Parte Letter at 2-3.

314 See, e.g., NCTA Nov. 7, 2023 Ex Parte Letter at 2-3 (“[M]any of the requirements that will be imposed in

connection with the Safe Connections item operate as exceptions to the verification and security requirements that
will be imposed in the SIM Swap and Port-Out Fraud item.”).
315 Safe Connections Order, FCC 23-96, at para. 103.

                                                           50
                                     Federal Communications Commission                                     FCC 23-95

these reasons, we require wireless providers to implement the rules we adopt today six months after the
effective date of this Report and Order, subject to review by OMB.
         E.       Legal Authority
         84.      The rules we adopt today build on the Commission’s existing rules to implement
Congress’s mandates to ensure that telecommunications carriers (which include, for purposes of our CPNI
rules, providers of interconnected VoIP service) protect the confidentiality of proprietary information of,
and relating to, customers and to provide number portability in accordance with requirements prescribed
by the Commission. As such, the rules we adopt are well-grounded in our authority in sections 222 and
251, as well as other provisions of the Act.
         85.     SIM Changes. Congress, through section 222 of the Act, requires telecommunications
carriers to protect the privacy and security of customers’ proprietary information that carriers obtain by
virtue of providing a telecommunications service.316 Under section 222(a), every telecommunications
carrier has a “duty to protect the confidentiality of proprietary information of, and relating to, . . .
customers.”317 Section 222(c)(1) provides that a telecommunications carrier may only use, disclose, or
permit access to customers’ individually identifiable CPNI that it has received or obtained by virtue of its
provision of a telecommunications service in limited circumstances: (1) as required by law; (2) with the
customer’s approval; or (3) in its provision of the telecommunications service from which such
information is derived or its provision of services necessary to, or used in, the provision of such
telecommunications service.318
         86.      The Commission has previously stated that to comply with these section 222
requirements, “telecommunications carriers [must] establish effective safeguards to protect against
unauthorized use or disclosure of CPNI.”319 The Commission also has established rules pursuant to its
section 222 authority to ensure such safeguards are in place. Among other things, the Commission’s rules
require carriers to take “reasonable measures to discover and protect against attempts to gain unauthorized
access to CPNI” and to “properly authenticate a customer prior to disclosing CPNI based on customer-
initiated telephone contact, online account access, or an in-store visit.”320 Like these safeguards, our
action today “strengthen[s] our privacy rules by adopting additional safeguards to protect customers’
CPNI against unauthorized access and disclosure.”321
       87.      Fraudulent SIM swaps result in unauthorized disclosure of and access to customers’
accounts, including individually identifiable CPNI.322 By successfully obtaining a fraudulent SIM swap, a

316 Congress extended this duty and others described herein to wireless providers. See 47 U.S.C. § 332(c)(1)(A) (“A
person engaged in the provision of a service that is a commercial mobile service shall, insofar as such person is so
engaged, be treated as a common carrier for purposes of this chapter.”).
317 47 U.S.C. § 222(a).

318 47 U.S.C. § 222(c)(1).

319 See 2007 CPNI Order, 22 FCC Rcd at 6932, para. 9 (citing the CPNI Order, 13 FCC Rcd at 8195, para. 193).

We note that the Commission’s CPNI rules apply not only to telecommunications carriers that are subject to Title II
of the Act, but also to interconnected VoIP providers. See id. at 6954-57, paras. 54-59 (relying on the Commission’s
Title I ancillary jurisdiction to apply CPNI rules to interconnected VoIP service providers); see also 47 CFR §
64.2003(o) (“For the purposes of this subpart, the term ‘telecommunications carrier’ or ‘carrier’ shall include an
entity that provides interconnected VoIP service, as that term is defined in section 9.3 of these rules.”).
320 47 CFR § 64.2010(a); see also 2007 CPNI Order, 22 FCC Rcd at 6959-60, paras. 63-66.

321 2007 CPNI Order, 22 FCC Rcd at 6928, para. 1.

322 The Act defines CPNI as “(A) information that relates to the quantity, technical configuration, type, destination,

location, and amount of use of a telecommunications service subscribed to by any customer of a telecommunications
carrier, and that is made available to the carrier by the customer solely by virtue of the carrier-customer relationship;
and (B) information contained in the bills pertaining to telephone exchange service or telephone toll service received
                                                                                                          (continued….)
                                                           51
                                     Federal Communications Commission                                     FCC 23-95

bad actor can access CPNI such as incoming call information (including the date and time of the call and
number from which the call is made), and gain access to a victim’s account, potentially giving the bad
actor access to other CPNI, like outgoing call history (including numbers called and the location,
frequency, duration, and timing of such calls)323 and the victim’s bills and the services purchased by the
victim. And as described above, fraudulent SIM swaps allow bad actors to perpetrate greater fraud by
giving them the means to complete text and voice authentications to access the victim’s other accounts.324
        88.      In light of the foregoing, we find that the rules we adopt today to address SIM swap fraud
advance the protections against unauthorized disclosure of, and access to, individually identifiable CPNI
and other sensitive personal information about customers, and therefore are squarely grounded in the
Commission’s authority under section 222. Our requirement that wireless providers use secure methods
of authenticating their customers that are reasonably designed to confirm a customer’s identity prior to
effectuating a SIM change request will help prevent unauthorized disclosure of and access to such
information. This requirement also sustains customer decisions regarding disclosure of their
information—if a wireless provider completes a SIM change requested by someone other than the actual
customer, then the wireless provider has not obtained the customer’s approval to disclose their CPNI in
accordance with section 222(c)(1).325
         89.     The other rules we adopt reinforce the protections afforded by this new rule. For
instance, the requirement that wireless providers develop, maintain, and implement procedures to respond
to failed authentication attempts will likewise serve to prevent unauthorized disclosure of and access to
CPNI. The rule requiring that wireless providers establish safeguards and processes so that employees
who receive inbound customer communications are unable to access CPNI until after the customer has
been properly authenticated will prevent inadvertent disclosure of CPNI to those making unauthorized
requests and inhibit the ability of employees to participate in fraudulent SIM swaps. Employee training
requirements will not only improve their ability to recognize and derail fraudulent SIM change requests,
such requirements will better prepare customer service representatives to address customer complaints
and remediate fraudulent SIM swaps when they do occur. Requiring wireless providers to maintain a
clear process for customers to report fraud, investigate and remediate fraud, and provide customers with
documentation of fraud involving their accounts will ensure that the harms of SIM swap and port-out
fraud are mitigated when it does occur. And the requirement that wireless providers keep records of data
regarding SIM change requests and the authentication measures they have in place will help ensure that
wireless providers have information they need to measure the effectiveness of their customer
authentication and account protection measures and make informed decisions about how they should be
updated over time.
        90.      Our rules also further the goals of section 222 by enabling customers to take action to
prevent and address fraudulent SIM changes, and therefore help wireless providers protect against
unauthorized disclosure and access to CPNI. The requirement that wireless providers immediately notify
customers regarding SIM change requests provides added protection by giving customers information
they can use to notify their providers that a fraudulent request has occurred at the time of the request or

(Continued from previous page)
by a customer of a carrier; except that such term does not include subscriber list information.” 47 U.S.C. §
222(h)(1).
323 See 2007 CPNI Order, 22 FCC Rcd at 6936, para. 13 & n.45 (defining this information as call detail information

and finding it to be CPNI).
324 See supra section II.

325 Section 222(f) of the Act also provides that for purposes of section 222(c)(1), without the “express prior

authorization” of the customer, a customer shall not be considered to have approved the use or disclosure of or
access to (1) call location information concerning the user of a commercial mobile service or (2) automatic crash
notification information of any person other than for use in the operation of an automatic crash notification system.”
47 U.S.C. § 222(f).

                                                          52
                                    Federal Communications Commission                                    FCC 23-95

shortly thereafter so that the provider can take timely steps to remediate the situation. Requiring wireless
providers to offer customers the option to lock their accounts so that their providers are prohibited from
processing SIM changes gives security-minded customers or those who are at high risk of fraud a tool to
prevent a fraudulent request from being processed in the first instance. Additionally, our new rule that
wireless providers make notice of account protection mechanisms easily accessible via their websites and
applications ensures that customers are aware of these tools. We also conclude that the requirements we
establish to promptly resolve SIM swap and port-out fraud extend from our section 222 authority because
they will help to mitigate the unauthorized disclosure of and access to CPNI.
         91.    Finally, the new customer authentication requirements, with which both facilities-based
providers and resellers must comply, apply to both pre-paid and postpaid services, which is consistent
with section 222(a)’s mandate that “[e]very telecommunications carrier . . . protect the confidentiality of
[customer] proprietary information” and section 222’s instruction that all “customers” of those carriers
benefit from such protections.326
         92.      While section 222 provides firm foundation for our rules to address SIM swap fraud, we
also find that section 251(e) of the Act provides additional authority for these rules.327 In section
251(e)(1), Congress expressly assigned to the Commission exclusive jurisdiction over that portion of the
North American Number Plan (NANP) that pertains to the United States and related telephone numbering
issues.328 The Commission retained its “authority to set policy with respect to all facets of numbering
administration in the United States.”329 Because our new SIM change rules prevent and address misuse of
NANP numbers assigned to wireless devices, we conclude that those rules are supported by our exclusive
numbering authority within section 251(e).
         93.     Number Porting. We rely on our authority derived from sections 1, 2, 4(i), 251(e), and
332 of the Act to implement the changes to our number porting rules to address port-out fraud. As the
Commission has consistently found since 1996, “[w]e possess independent authority under sections 1, 2,
4(i), and 332 of the Communications Act of 1934, as amended, to require CMRS providers to provide
number portability as we deem appropriate.”330 We rely on this well-established authority to adopt
number porting rules applicable to wireless providers that address port-out fraud.
         94.     We also find that the exclusive numbering authority that Congress granted this
Commission under section 251(e)(1) provides ample authority to extend the LNP requirements as set out
in this Report and Order. Specifically, in section 251(e)(1) of the Act, Congress expressly assigned to the
Commission exclusive jurisdiction over that portion of the NANP that pertains to the United States and
related telephone numbering issues.331 The Commission retained its “authority to set policy with respect

326 47 U.S.C. § 222(a) (emphasis added); 47 U.S.C. §§ 222(a), (c)(1), (h)(1) (all referring to “customers” of

telecommunications carriers without distinguishing between customers who subscribe to pre-paid and postpaid
service).
327 47 U.S.C. § 251(e).

328 47 U.S.C. § 251(e)(1).

329 Implementation of the Local Competition Provision of the Telecommunications Act of 1996 et al., CC Docket No.

96-98 et al., Second Report and Order and Memorandum Opinion and Order, 11 FCC Rcd 19392, 19512, para. 271
(1996) (Local Competition Second Report and Order) (explaining that by retaining exclusive jurisdiction over
numbering policy the Commission preserves its ability to act flexibly and expeditiously).
330 First Number Portability Order, 11 FCC Rcd at 8431, para. 153; see also First Number Portability Order on

Reconsideration, 12 FCC Rcd at 7315, para. 141; LNP Standard Fields Order, 25 FCC Rcd at 6955 n.10; Porting
Interval Order and FNPRM, 24 FCC Rcd at 6085 n.8; 2007 VoIP LNP Order, 22 FCC Rcd at 19534 n.11.
331 47 U.S.C. § 251(e)(1).

                                                          53
                                    Federal Communications Commission                                    FCC 23-95

to all facets of numbering administration in the United States.”332 We find that the revisions to our
number porting rules designed to protect the customers from port-out fraud fit comfortably within our
exclusive numbering authority because the requirements we establish to prevent and promptly resolve
port-out fraud are necessary to address improper use of numbering resources and ensure that customers
can recover their numbers when fraudulent ports have occurred.333
        95.      Other Sources of Authority. While the provisions discussed above provide sufficient
authority for the entirety of the rules we adopt in this Report and Order, we find additional support under
sections 201 and 303.334
         96.      Section 201(b) authorizes the Commission to prescribe rules to implement carriers’
statutory duty not to engage in conduct that is “unjust or unreasonable.”335 We conclude that practices
that allow for fraudulent SIM swaps and number ports are unjust and unreasonable because they are
contrary to the reasonable expectations of customers, are not reasonably avoidable by customers, and can
cause substantial customer harm. We also rely on our section 201(b) authority to find that the inability
for customers to effectively seek remedies from their wireless providers when fraudulent SIM swaps and
port outs have occurred is “unjust and unreasonable,” and therefore warrants these rules.336 We would
also find these practices unjust and unreasonable when a wireless provider says it will implement
reasonable measures to prevent fraudulent SIM swaps and number ports but fails to do so. Our findings
here are similar to and consistent with how the Federal Trade Commission (FTC) addresses inadequate
data security measures under section 5 of the FTC Act.337
         97.     We also rely on our broad authority under Title III, which allows us to protect the public
interest through spectrum licensing. Pursuant to section 303(b)’s directive that the Commission must,
consistent with the public interest, “[p]rescribe the nature of the service to be rendered by each class of
licensed stations and each station within any class,”338 these revisions to our CPNI and number porting

332 Local Competition Second Report and Order, 11 FCC Rcd at 19512, para. 271 (explaining that by retaining

exclusive jurisdiction over numbering policy the Commission preserves its ability to act flexibly and expeditiously).
333 See, e.g., 2007 VoIP LNP Order, 22 FCC Rcd at 19543, para. 22 (explaining that to the extent service providers

provide services that offer customers NANP telephone numbers, those service providers subject themselves to the
Commission’s plenary authority under section 251(e)(1) with respect to those numbers, and using that plenary
authority to extend local number portability requirements to interconnected VoIP providers and their numbering
partners).
334 Sections 201 and 303 of the Act generally give the Commission authority for prescribing rules, but we also rely

on these sources of authority as described herein. See 47 U.S.C. § 201(b) (“The Commission may prescribe such
rules and regulations as may be necessary in the public interest to carry out the provisions of this chapter.”); AT&T
Corp. v. Iowa Utils. Bd., 525 U.S. 366, 378 (1999) (holding that the last sentence in section 201(b) “means what it
says: The FCC has rulemaking authority to carry out the ‘provisions of this Act,’” including provisions added by
the Telecommunications Act of 1996); 2007 CPNI Order, 22 FCC Rcd at 6943, para. 27 n.94 (“Section 201(b)
authorizes the Commission to ‘prescribe such rules and regulations as may be necessary in the public interest to
carry out the provisions of this Act,’ including section 222.”); 47 U.S.C. § 303 (“Except as otherwise provided in
this chapter, the Commission from time to time, as public convenience, interest, or necessity requires, shall—(r)
Make such rules and regulations and prescribe such restrictions and conditions, not inconsistent with law, as may be
necessary to carry out the provisions of this chapter.”).
335 47 U.S.C. § 201(b).

336 Id.

337 Privacy and Security Enforcement, Federal Trade Commission, https://www.ftc.gov/news-

events/topics/protecting-consumer-privacy-security/privacy-security-enforcement (last visited Oct. 18, 2023) (“The
FTC has brought legal actions against organizations that . . . misled [consumers] by failing to maintain security for
sensitive consumer information.”).
338 47 U.S.C. § 303(b); Cellco P’ship v. FCC, 700 F.3d 534, 542-43 (D.C. Cir. 2012).

                                                         54
                                     Federal Communications Commission                                   FCC 23-95

requirements prescribe the conditions under which licensed wireless providers must provide their
services. They specifically require licensed wireless providers to provide their services in a way that
protects the interests of their customers, including reasonable measures to prevent fraudulent acts against
their customers.
IV.      FURTHER NOTICE OF PROPOSED RULEMAKING
         98.      Harmonizing the CPNI Safeguards Rules. In this Further Notice, we first seek comment
on whether to harmonize the existing requirements governing customer access to CPNI339 with the SIM
change authentication and protection measures we adopt today. This Further Notice expands on
questions the Commission asked in the SIM Swap and Port-Out Fraud Notice and several comments in
the record, but seeks more targeted feedback on a specific approach. In particular, in the SIM Swap and
Port-Out Fraud Notice, the Commission asked “whether any new or revised customer authentication
measures . . . would offer benefits for all purposes.”340 The Commission also asked whether there are
“benefits to providing expanded authentication requirements before providing access to CPNI to someone
claiming to be a carrier’s customer,” as well as “whether any heightened authentication measures required
(or prohibited) should apply for access to all CPNI, or only in cases where SIM change requests are being
made.”341 Additionally, the Commission proposed to add a prohibition on the use of recent payment and
call detail information to authenticate customers for online access to CPNI.342
         99.       Several commenters suggested that we harmonize our CPNI authentication rules with the
SIM change authentication rules we adopt.343 These commenters offered several rationales that
potentially support harmonization of these rules, including that: (1) the CPNI authentication requirements
are outdated and therefore vulnerable to fraud;344 (2) inconsistent rules are more burdensome on
carriers;345 (3) some carriers default to specified authentication measures and are disincentivized from

339 See 47 CFR § 64.2010.

340 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14136, para. 44.

341 Id. at 14137, para. 46.

342 See id. at 14132-33, para. 30.

343 See, e.g., CTIA Reply at 21-22 (advocating for “a harmonized approach to the Commission’s authentication

standards across a variety of settings with respect to CPNI access”) (emphasis in original); Princeton Comments at 8
(“The Commission should modernize and harmonize baseline authentication requirements for telephone access to
CPNI, online access to CPNI, SIM swaps, and number portability authentication methods.”); Verizon Comments at
7-8 (“The Commission should thus align the existing authentication rules to the NPRM’s flexible, non-prescriptive
approach by requiring providers to use security [sic] authentication methods for CPNI access without dictating the
provider’s method.”).
344 See, e.g., CTIA Comments at 18 (asserting that the CPNI rules “do not reflect the most up-to-date authentication

best practices”); Verizon Comments at 7 (asserting that “[m]any customer authentication and security tools have
surpassed the effectiveness of [the current CPNI rules for customer authentication]”); FIDO Alliance Comments at 4
(“In general, industry and government are moving away from knowledge-based approaches to authentication (i.e.
passwords).”); Robert Ross Comments at 7 (“[I]n-store authentication is highly susceptible to human error by store
personnel.”); AT&T Comments at 5 (“But no method of authentication is foolproof or effective in every instance.
Customers forget passwords and lose their IDs (often at the same time they lose their wireless device). By the same
token, passwords can be socially engineered, hacked or stolen, and driver’s licenses and other government-issued ID
cards can be faked.”); but see AT&T Comments at 5 (“Anti-fraud measures developed consistent with the
Commission’s existing authentication requirements protect consumers in most instances.”).
345 See, e.g., Princeton Comments at 8 (“The Commission’s proposed rules would establish five separate customer

authentication standards: (1) telephone access to CPNI, (2) online access to CPNI, (3) in-store access to CPNI, (4)
SIM swaps, and (5) number portability.”); Princeton Comments at 10 (“[A] unified approach will be easier to
implement: carriers need only adopt one compliant customer authentication system for all account access and
operations.”).

                                                         55
                                    Federal Communications Commission                                    FCC 23-95

adopting more secure measures;346 (4) a prescribed list provides a road map for bad actors;347 and (5) the
existing CPNI authentication requirements could undermine stronger authentication measures for SIM
changes and number ports.348 Harmonization also would be consistent with commenters’ assertions that
carriers need flexibility to implement more secure authentication measures.349 We seek comment on these
justifications.
         100.   We also seek comment on other potential justifications for harmonization. For instance,
we tentatively conclude that harmonized authentication and protection requirements will be easier for
wireless providers to implement and therefore will reduce costs and burdens on carriers, including small
carriers. We further tentatively conclude that multiple authentication standards and protection
requirements may be confusing for customers. Are these tentative conclusions correct?
        101.      We seek comment on any reasons why we should not harmonize our CPNI and SIM
change authentication rules. For example, would it be costly and burdensome for carriers, particularly
small carriers, to adjust the CPNI authentication and protection practices they have already implemented
to comply with the authentication requirements we adopted today? Are there other reasons harmonized
rules would increase the costs or burdens on carriers, including small carriers? Is there anything unique
about CPNI or SIM changes that warrants different authentication measures? For instance, even if the
existing measures for CPNI authentication may be outdated and less secure, are modifications to the rules
unwarranted because the risk of harm from unauthorized access to CPNI is lower than from SIM swap
fraud?
         102.     If we do choose to harmonize the rules addressing customer access to CPNI with our new
SIM change safeguards, we seek comment on the extent to which the rules should be harmonized. We
seek comment whether to remove the prescriptive authentication requirements in our current CPNI
rules350 and replace them with the single requirement that carriers use secure methods of authenticating
the identity of a customer prior to disclosing CPNI. We also seek comment on whether to use the same
definition of secure methods of authentication, which are those that are reasonably designed to confirm a
customer’s identity and excluding use of readily available biographical information, account information,
recent payment information, call detail information, or any combination of these factors.351 Additionally,

346 See, e.g., AT&T Comments at 14 (“Moreover, locking in a particular list of authentication methods would play

into bad actors’ hands by discouraging carriers from adopting new methods not expressly blessed by the
Commission’s rule, while inhibiting the ability of carriers and other stakeholders to innovate, as necessary and
appropriate, to address evolving threats.”).
347 See, e.g., AT&T Comments at 14-15 (asserting that “fixed authentication methods for SIM changes and port-outs

will provide a roadmap to bad actors”); CTIA Comments at 11 (“[R]igid and prescriptive requirements hurt security
more than they may help. . . . To this point, the NPRM asks whether ‘requiring specific methods of authentication
provides a ‘roadmap’ to bad actors.’ The answer is a resounding yes.”) (footnote omitted).
348 See, e.g., Princeton Comments at 10 (describing how “a unified approach to customer authentication avoids

subtle inconsistencies between levels of authentication that could undermine multi-factor authentication” used for
SIM swaps and number ports).
349 See, e.g., CCA Comments at 5 (“[T]he Commission should allow for flexibility for carriers to respond quickly

and nimbly to new threats and to encourage adopting innovative solutions to threats.”); Princeton Comments at 4
(“Authentication methods and security practices continue to evolve, and carriers should be welcome—and
encouraged—to adopt innovative safeguards.”); Somos Comments at 2 (“As with most fraud the telecom industry
suffers, the bad actors are constantly evolving. Solutions should evolve, as well.”); Verizon Comments at 7 (“To
keep ahead of bad actors, providers need flexibility to employ other more secure alternatives to passwords and
government-issued IDs.”); Better Identity Coalition at 4 (“Any regulatory approach that seeks to tie MNOs to using
specific authentication technologies is certain to fail to keep up as threat and security both evolve.”).
350 See 47 CFR § 64.2010(b)-(e).

351 See supra section III.A.1.

                                                         56
                                    Federal Communications Commission                                     FCC 23-95

we seek comment on whether the procedures we require carriers to adopt for responding to failed
authentication attempts in connection with SIM change requests should apply to all other CPNI
authentications as well.352 We also seek comment on whether the CPNI customer access rules should be
harmonized with any of the other SIM change protections we adopt today. Should the limits on access to
CPNI by employees who receive inbound customer communications prior to authentication of the
customer apply to all telecommunications carriers? Should the CPNI rules only be harmonized to include
some of these measures? If so, which measures should and should not be harmonized and why? Should
we harmonize the customer notification rules for all account changes? Additionally, are there any other
rules that would need to be modified for consistency if we harmonize the CPNI rules, such as the
Commission’s Telecommunications Relay Service (TRS) CPNI rules?353 Should the Commission apply
any harmonized rules to all customer proprietary information?
         103.    We tentatively conclude that we should rely on the same legal authority we used to
originally implement the CPNI authentication rules in order to harmonize any of the CPNI rules, and seek
comment on this tentative approach. In the 2007 CPNI Order, as with the rules we adopted today, we
relied primarily on section 222 to implement the CPNI authentication rules, and we tentatively conclude
this provision continues to provide us with sufficient authority to harmonize those rules with the SIM
change rules.354 We seek comment on this tentative conclusion. We also seek comment on whether there
are any legal implications for the harmonization approach we propose. For instance, in the 2016
Broadband Privacy Order, the Commission harmonized the CPNI rules for voice providers with those it
had adopted for broadband Internet access service providers,355 but those rules were nullified by Congress
pursuant to the Congressional Review Act,356 which prohibits the Commission from reissuing a
disapproved rule “in substantially the same form” and from issuing a new rule “that is substantially the
same as such a rule.”357 We tentatively conclude that the 2017 action by Congress has no effect on the
options we may consider here and seek comment on this tentative conclusion.
        104.     Harmonizing Government Efforts to Address SIM Swap and Port-Out Fraud. We seek
comment on what steps the Commission can take to harmonize government efforts to address SIM swap
and port-out fraud.358 As several commenters noted, SIM swap and port-out fraud implicates the
authentication practices of other industries.359 We recognize that there may be other efforts within the

352 See supra section III.A.2.

353 See, e.g., 47 CFR § 64.5110.

354 See 2007 CPNI Order, 22 FCC Rcd at 6930-31, paras. 4-6; supra section Error! Reference source not found..

355 See Protecting the Privacy of Customers of Broadband and Other Telecommunications Services, WC Docket No.

16-106, Report and Order, 31 FCC Rcd 13911, 13913, para. 3 (2016).
356 Joint Resolution, Pub. L. No. 155-22 (2017).

357 5 U.S.C. § 801(b)(2).

358 T-Mobile Comments at 14 (“[T]he FCC could coordinate with other regulators, such as financial services or

healthcare regulators, on strategies. Other regulators may consider new rules on authentication and steer companies
away from relying on methods that are not suitable given the nature and sensitivity of information or functions being
accessed.”).
359 See, e.g., Verizon Comments at 7 (“While a wireless provider’s practices could prove to be reasonable, effective

and thorough, the fraud prevention practices of the customer’s financial institution, or the customer’s email provider,
may not.”); AT&T Comments at 2 (“SIM swap or port-out [fraud] is only a small part of the scheme to harm the
consumer, as these incidents implicate a range of stakeholders not controlled by carriers (e.g., financial institutions,
cryptocurrency companies, text message aggregators) that all play a role in the verification of customer identity.”);
T-Mobile Comments at 1-2 (“[C]ombatting SIM swap and port-out fraud is a team effort that requires action by an
entire ecosystem that includes carriers and subscribers as well as financial institutions, email providers, retail
websites, social media companies and others who rely on various customer authentication methods.”); CTIA
Comments at 2 (“All actors across the mobile and Internet ecosystem—including financial and social media
                                                                                                          (continued….)
                                                          57
                                    Federal Communications Commission                                    FCC 23-95

government to tackle SIM swap and port-out fraud to address the broader implications of these harmful
practices. We seek information about those other efforts and the extent to which they seek to address the
practices of wireless providers. We also seek comment on how the Commission can work with other
government entities to harmonize our approaches to addressing SIM swap and port-out fraud.
         105.     Customer Notification of Failed Customer Authentication Attempts. We seek comment
on whether we should require wireless providers to immediately notify customers in the event of a failed
authentication attempt,360 except to the extent otherwise required by the Safe Connections Act of 2022 (47
U.S.C. § 345) or the Commission’s rules implementing that statute.361 We believe that such notifications
could empower customers to take action to prevent unauthorized access to their account when failed
authentication attempts are fraudulent. Should we require all telecommunications carriers to provide such
notifications to customers? In the event the Commission were to require such notifications, we tentatively
conclude that the notifications should be reasonably designed to reach the customer associated with the
account but otherwise would permit wireless providers to determine the method of providing these
notifications, taking into consideration the needs of survivors pursuant to the Safe Connections Act and
our implementing rules. We also tentatively conclude that such notifications should use “clear and
concise language” but do not propose to prescribe particular content or wording for the notifications.
         106.     Industry commenters assert that “a carrier does not typically know why a customer
authenticates until after the customer has successfully authenticated.”362 Based on these assertions, should
we permit carriers to employ “reasonable risk assessment techniques to determine when a failed
authentication attempt requires customer notification,”363 or require notification only in instances of
multiple failed attempts, or when there is reasonable suspicion of fraud?364 What are the benefits and
costs of doing so, for both providers and customers? If we were to require customer notification only
where there were multiple failed authentication attempts, what standard would we use to determine what
constitutes “multiple,” and how would providers track multiple authentication attempts across different
platforms (i.e., phone, application, and website)?

companies whose users’ accounts are often targeted—must work together to thwart the bad actors that perpetrate
these crimes.”); CCA Comments at 1 (“[M]obile customers’ phones have become the link between an individual’s
sensitive health records, banking and financial information, email, and social media accounts. SIM swap and port
out fraud are two methods that malicious actors increasingly are using not only to steal mobile accounts, but also to
engage in broader identity theft.”); Princeton Comments at 12 (“SIM swaps are an increasing attack vector for
online account compromises, especially in the financial services sector.”).
360 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14133, para. 33 (seeking comment on what processes

providers can implement to prevent bad actors from attempting multiple authentication methods, including
potentially notifying customers).
361 See Safe Connections Order, FCC 23-96, at para. 52 and Appx. A (new 47 CFR § 64.6402(b)) (requiring that

covered providers attempt to authenticate, using multiple authentication methods if necessary, that a survivor
requesting a line separation is a user of a specific line or lines) (emphasis added); id. at para. 100 and Appx. A
(revised 47 CFR § 64.2010(f)(2)) (clarifying that the rule requiring carriers to notify customers immediately
whenever a password, customer response to a back-up means of authentication for lost or forgotten passwords,
online account, or address of record is created or changed does not apply when such changes are made in connection
with a line separation request made pursuant to the Safe Connections Act); id. at para. 77 and Appx. A (new 47 CFR
§ 64.6402(i)) (prohibiting a covered provider from notifying a primary account holder of a survivor’s request for a
SIM change when made in connection with a line separation request pursuant to 47 U.S.C. § 345 and the
implementing rules); id. at para. 101 (making clear that compliance with the Safe Connections Act and rules
implementing it supersede and preempt any conflicting obligations under state law, Commission’s rules, or state
rules).
362 CTIA Nov. 8, 2023 Ex Parte Letter at 6-7; AT&T Nov. 8, 2023 Ex Parte Letter at 3.

363 AT&T Nov. 8, 2023 Ex Parte Letter at 3

364 See CCA Nov. 9, 2023 Ex Parte Letter at 2; CTIA Nov. 8, 2023 Ex Parte Letter at 7.

                                                         58
                                    Federal Communications Commission                                     FCC 23-95

        107.     Other Consumer Protection Measures. We reiterate the Commission’s request for
comment on whether there are any additional requirements the Commission should consider that would
help protect customers from SIM swap or port-out fraud or assist them with resolving problems resulting
from such incidents.365 For example, should we require wireless providers to explicitly exclude resolution
of SIM change and port-out fraud disputes from arbitration clauses in providers’ agreements with
customers or abrogate such clauses?366 Would this provide meaningful additional protections to
customers from SIM swap and port-out fraud? What would be the costs to wireless providers,
particularly small providers, from such a requirement?
         108.     Digital Equity and Inclusion. Finally, the Commission, as part of its continuing effort to
advance digital equity for all,367 including people of color, persons with disabilities, persons who live in
rural or Tribal areas, and others who are or have been historically underserved, marginalized, or adversely
affected by persistent poverty or inequality, invites comment on any equity-related considerations368 and
benefits (if any) that may be associated with the proposals and issues discussed herein. Specifically, we
seek comment on how our proposals may promote or inhibit advances in diversity, equity, inclusion, and
accessibility, as well as the scope of the Commission’s relevant legal authority.
V.       PROCEDURAL MATTERS
         109.   Paperwork Reduction Act Analysis. This Report and Order may contain new or modified
information collection requirements subject to the Paperwork Reduction Act of 1995 (PRA), Public Law
104-13. All such requirements will be submitted to OMB for review under Section 3507(d) of the PRA.
OMB, the general public, and other Federal agencies will be invited to comment on any new or modified
information collection requirements contained in this proceeding. In addition, we note that pursuant to
the Small Business Paperwork Relief Act of 2002, Public Law 107-198, see 44 U.S.C. § 3506(c)(4), we
previously sought specific comment on how the Commission might further reduce the information
collection burden for small business concerns with fewer than 25 employees.
        110.     In this Report and Order, we have assessed the effects of required customer notifications
and notices, and related recordkeeping requirements, to protect customers from SIM swap and port-out
fraud, and find that they do not place a significant burden on small businesses. Although no commenters
specifically addressed whether such requirements may place burdens on small wireless providers, we note
that CCA advised the Commission to “keep in mind the constraints with which many small carriers
operate against in adopting security measures,” asserting that any rules “should allow carriers to use
technologies that are reasonably available and have choice in the approach to take in authenticating their
customers.”369 As a general matter, the baseline, flexible rules we adopt reflect our recognition that, in

365 See SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14144, para. 68.

366 NCLC/EPIC Comments at 6.

367 Section 1 of the Communications Act of 1934 as amended provides that the FCC “regulat[es] interstate and

foreign commerce in communication by wire and radio so as to make [such service] available, so far as possible, to
all the people of the United States, without discrimination on the basis of race, color, religion, national origin, or
sex.” 47 U.S.C. § 151.
368 The term “equity” is used here consistent with Executive Order 13985 as the consistent and systematic fair, just,

and impartial treatment of all individuals, including individuals who belong to underserved communities that have
been denied such treatment, such as Black, Latino, and Indigenous and Native American persons, Asian Americans
and Pacific Islanders and other persons of color; members of religious minorities; lesbian, gay, bisexual,
transgender, and queer (LGBTQ+) persons; persons with disabilities; persons who live in rural areas; and persons
otherwise adversely affected by persistent poverty or inequality. See Exec. Order No. 13985, 86 Fed. Reg. 7009,
Executive Order on Advancing Racial Equity and Support for Underserved Communities Through the Federal
Government (January 20, 2021).
369 CCA Comments at 6.    See also RWA Comments at 12-13 (advocating for uniform authentication standards to
avoid anticompetitive effects and other costs or burdens on small wireless providers).

                                                          59
                                     Federal Communications Commission                           FCC 23-95

some cases, strict prescriptive requirements to prevent SIM swap and port-out fraud could be technically
and economically infeasible for wireless providers to implement, particularly for smaller providers.370
We emphasize that the record shows that many wireless providers already have in place some of the
policies and procedures we adopt today and that our rules may therefore only require them to adapt,
refine, or consistently apply those existing practices.371 Additionally, by setting baseline requirements
and giving wireless providers flexibility on how to meet them, we allow providers to adopt the most cost-
effective and least burdensome solutions to achieve the level of security needed to protect customers
against SIM swap and port-out fraud in a given circumstance.372 We have further minimized the potential
burdens of customer notifications by declining to prescribe particular content and wording and giving
wireless providers flexibility on how to deliver such notifications.373 Similarly, for customer notices, we
declined to require a specific format and content, and we declined to require such notices be delivered to
customers annually.374 Further, we mitigated potential burdens of the recordkeeping requirement by
declining to require that wireless providers include historic data in their recordkeeping, which we
acknowledged would be particularly burdensome for small providers, and declining to require that
providers report this data to the Commission regularly.375
         111.    The Further Notice of Proposed Rulemaking may contain new or modified information
collection(s) subject to the Paperwork Reduction Act of 1995.376 All such new or modified information
collection requirements will be submitted to OMB for review under section 3507(d) of the PRA. OMB,
the general public, and other federal agencies are invited to comment on any new or modified information
collection requirements contained in this proceeding. In addition, pursuant to the Small Business
Paperwork Relief Act of 2002,377 we seek specific comment on how we might “further reduce the
information collection burden for small business concerns with fewer than 25 employees.”378
         112.    Regulatory Flexibility Act. The Regulatory Flexibility Act of 1980, as amended (RFA)379
requires that an agency prepare a regulatory flexibility analysis for notice and comment rulemakings,
unless the agency certifies that “the rule will not, if promulgated, have a significant economic impact on a
substantial number of small entities.”380 Accordingly, the Commission has prepared a Final Regulatory
Flexibility Analysis (FRFA) concerning the potential impact of the rule and policy changes adopted in
this Report and Order on small entities. The FRFA is set forth in Appendix B.
         113.    We have also prepared an Initial Regulatory Flexibility Analysis (IRFA) concerning the
potential impact of rule and policy change proposals in the Further Notice on small entities. The IRFA is
set forth in Appendix C. Written public comments are requested on the IRFA. Comments must be filed
by the deadlines for comments on the Further Notice indicated on the first page of this document and
must have a separate and distinct heading designating them as responses to the IRFA.

370 See supra para. 23.

371 See supra paras. 20, 23, 37, 42, 57, 60, 64, 67, 70.

372 See supra para. 23.

373 See sections III.A.3& III.B.2.

374 See supra section III.C..

375 See supra section III.A.5.

376 Pub. L. No. 104-13.

377 Pub. L. No. 107-198.

378 44 U.S.C. § 3506(c)(4).

379 5 U.S.C. § 603.
                  The RFA, 5 U.S.C. § 601 et seq., has been amended by the Small Business Regulatory
Enforcement Fairness Act of 1996 (SBREFA), Pub. L. No. 104-121, Title II, 110 Stat. 857 (1996).
380 5 U.S.C. § 605(b).

                                                           60
                                 Federal Communications Commission                                FCC 23-95

         114.    Congressional Review Act. The Commission has determined, and the Administrator of
the Office of Information and Regulatory Affairs, Office of Management and Budget, concurs, that this
rule is “non-major” under the Congressional Review Act, 5 U.S.C. § 804(2). The Commission will send
a copy of this Report and Order to Congress and the Government Accountability Office pursuant to 5
U.S.C. § 801(a)(1)(A).
         115.    Ex Parte Presentations. The proceeding shall be treated as a “permit-but-disclose”
proceeding in accordance with the Commission’s ex parte rules. Persons making ex parte presentations
must file a copy of any written presentation or a memorandum summarizing any oral presentation within
two business days after the presentation (unless a different deadline applicable to the Sunshine period
applies). Persons making oral ex parte presentations are reminded that memoranda summarizing the
presentation must: (1) list all persons attending or otherwise participating in the meeting at which the ex
parte presentation was made, and (2) summarize all data presented and arguments made during the
presentation. If the presentation consisted in whole or in part of the presentation of data or arguments
already reflected in the presenter’s written comments, memoranda or other filings in the proceeding, the
presenter may provide citations to such data or arguments in his or her prior comments, memoranda, or
other filings (specifying the relevant page and/or paragraph numbers where such data or arguments can be
found) in lieu of summarizing them in the memorandum. Documents shown or given to Commission
staff during ex parte meetings are deemed to be written ex parte presentations and must be filed
consistent with rule 1.1206(b). In proceedings governed by rule 1.49(f) or for which the Commission has
made available a method of electronic filing, written ex parte presentations and memoranda summarizing
oral ex parte presentations, and all attachments thereto, must be filed through the electronic comment
filing system available for that proceeding, and must be filed in their native format (e.g., .doc, .xml, .ppt,
searchable .pdf). Participants in this proceeding should familiarize themselves with the Commission’s ex
parte rules.
        116.     Comment Period and Filing Procedures. Pursuant to sections 1.415 and 1.419 of the
Commission’s rules, 47 CFR §§ 1.415, 1.419, interested parties may file comments and reply comments
on or before the dates indicated on the first page of this document. Comments may be filed using the
Commission’s Electronic Comment Filing System (ECFS) or by paper. Commenters should refer to WC
Docket No. 21-341 when filing in response to this Further Notice.
    •   Electronic Filers: Comments may be filed electronically by accessing ECFS at
        https://www.fcc.gov/ecfs.
    •   Paper Filers: Parties who choose to file by paper must file an original and one copy of each
        filing. Paper filings can be sent by commercial overnight courier, or by first-class or overnight
        U.S. Postal Service mail.
    •   Effective March 19, 2020, and until further notice, the Commission no longer accepts any hand or
        messenger delivered filings.381
    •   Commercial overnight mail (other than U.S. Postal Service Express Mail and Priority Mail) must
        be sent to 9050 Junction Drive, Annapolis Junction, MD 20701.
    •   U.S. Postal Service first-class, Express, and Priority Mail must be addressed to 45 L Street NE,
        Washington, D.C. 20554.
       117.   Providing Accountability Through Transparency Act. The Providing Accountability
Through Transparency Act requires each agency, in providing notice of a rulemaking, to post online a

381 See FCC Announces Closure of FCC Headquarters Open Window and Change in Hand-Delivery Policy, DA 20-

304, Public Notice, 35 FCC Rcd 2788 (2020), https://www.fcc.gov/document/fcc-closes-headquarters-open-
window-and-changes-hand-delivery-policy.

                                                     61
                                  Federal Communications Commission                                FCC 23-95

brief plain-language summary of the proposed rule.382 Accordingly, the Commission will publish the
required summary of this Further Notice of Proposed Rulemaking on https://www.fcc.gov/proposed-
rulemakings.
         118.     People with Disabilities. To request materials in accessible formats for people with
disabilities (Braille, large print, electronic files, audio format), send an e-mail to [email protected] or call
the FCC’s Consumer and Governmental Affairs Bureau at (202) 418-0530 (voice).
        119.    Additional Information. For additional information on this proceeding, contact Melissa
Kirkel, Wireline Competition Bureau, Competition Policy Division, at 202-418-7958 or
[email protected].
VI.      ORDERING CLAUSES
         120.    Accordingly, IT IS ORDERED that, pursuant to the authority contained in sections 1, 2,
4, 201, 222, 251, 303, and 332 of the Communications Act of 1934, as amended, 47 U.S.C. §§ 151, 152,
154, 201, 222, 251, 303, and 332, this Report and Order in WC Docket No. 21-341 IS ADOPTED and
that Parts 52 and 64 of the Commission’s Rules, 47 CFR Parts 52, 64, are AMENDED as set forth in
Appendix A.
         121.    IT IS FURTHER ORDERED that this Report and Order SHALL BE EFFECTIVE 30
days after publication in the Federal Register, and that compliance with the rules adopted herein shall be
required six months after the effective date of the Report and Order, except that the amendments to
sections 52.37(c), 52.37(d), 52.37(e), 52.37(g), 64.2010(h)(2), 64.2010(h)(3), 64.2010(h)(4),
64.2010(h)(5), 64.2010(h)(6), and 64.2010(h)(8) of the Commission’s rules, 47 CFR §§ 52.37(c),
52.37(d), 52.37(e), 52.37(g), 64.2010(h)(2), 64.2010(h)(3), 64.2010(h)(4), 64.2010(h)(5), 64.2010(h)(6),
and 64.2010(h)(8), which may contain new or modified information collection requirements, will not
become effective until the later of i) six months after the effective date of this Report and Order; or ii)
after the Office of Management and Budget completes review of any information collection requirements
associated with this Report and Order that the Wireline Competition Bureau determines is required under
the Paperwork Reduction Act. The Commission directs the Wireline Competition Bureau to announce
the compliance date for sections 52.37(c), 52.37(d), 52.37(e), 52.37(g), 64.2010(h)(2), 64.2010(h)(3),
64.2010(h)(4), 64.2010(h)(5), 64.2010(h)(6), and 64.2010(h)(8) by subsequent Public Notice and to cause
47 CFR § 52.37 and § 64.2010 to be revised accordingly.
        122.    IT IS FURTHER ORDERED that pursuant to the authority contained in sections 1, 2, 4,
201, 222, 251, 303, and 332 of the Communications Act of 1934, as amended, 47 U.S.C. §§ 151, 152,
154, 201, 222, 251, 303, and 332, this Further Notice of Proposed Rulemaking in WC Docket No. 21-341
IS ADOPTED.
       123.      IT IS FURTHER ORDERED that the Commission’s Office of the Secretary, Reference
Information Center, SHALL SEND a copy of this Report and Order and Further Notice of Proposed
Rulemaking, including the Final Regulatory Flexibility Analysis and Initial Regulatory Flexibility
Analysis, to the Chief Counsel for Advocacy of the Small Business Administration.

382 5 U.S.C. § 553(b)(4).
                        The Providing Accountability Through Transparency Act, Pub. L. No. 118-9 (2023),
amended section 553(b) of the Administrative Procedure Act.

                                                      62
                              Federal Communications Commission                        FCC 23-95

        124.  IT IS FURTHER ORDERED that the Office of the Managing Director, Performance and
Program Management, SHALL SEND a copy of this Report and Order in a report to be sent to Congress
and the Government Accountability Office pursuant to the Congressional Review Act, see 5 U.S.C. §
801(a)(1)(A).

                                             FEDERAL COMMUNICATIONS COMMISSION

                                             Marlene H. Dortch
                                             Secretary

                                               63
                                 Federal Communications Commission                             FCC 23-95

                                              APPENDIX A
                                                Final Rules

The Federal Communications Commission amends Parts 52 and 64 of Title 47 of the Code of Federal
Regulations as follows:
PART 52 – NUMBERING
1.      The authority citation for part 52 continues to read as follows:
        AUTHORITY: 47 U.S.C. 151, 152, 153, 154, 155, 201-205, 207-209, 218, 225-227, 251-252, 271,
        303, 332, unless otherwise noted.
2.      Add § 52.37 to subpart C to read as follows:
§ 52.37 Number Portability Requirements for Wireless Providers
(a) Applicability. This section applies to all providers of commercial mobile radio service (CMRS), as
defined in 47 CFR § 20.3, including resellers of wireless service.
(b) Authentication of port-out requests. A CMRS provider shall use secure methods to authenticate a
customer that are reasonably designed to confirm the customer’s identity before effectuating a port-out
request, except to the extent otherwise required by 47 U.S.C. § 345 (Safe Connections Act of 2022) or
Part 64 Subpart II of this chapter. A CMRS provider shall regularly, but not less than annually, review
and, as necessary, update its customer authentication methods to ensure that its authentication methods
continue to be secure.
(c) Customer notification of port-out requests. Upon receiving a port-out request, and before effectuating
the request, a CMRS provider shall provide immediate notification to the customer that a port-out request
associated with the customer’s account was made, sent in accordance with customer preferences, if
indicated, and using means reasonably designed to reach the customer associated with the account and
clear and concise language that provides sufficient information to effectively inform a customer that a
port-out request involving the customer’s number was made, except if the port-out request was made in
connection with a legitimate line separation request pursuant to 47 U.S.C. § 345 and Part 64, Subpart II of
this chapter, regardless of whether the line separation is technically or operationally feasible.
(d) Account locks. A CMRS provider shall offer customers, at no cost, the option to lock their accounts to
prohibit the CMRS provider from processing requests to port the customer’s number. A CMRS provider
shall not fulfill a port-out request until the customer deactivates the lock on the account, except if the
port-out request was made in connection with a legitimate line separation request pursuant to 47 U.S.C. §
345 and Part 64, Subpart II of this chapter, regardless of whether the line separation is technically or
operationally feasible. The process to activate and deactivate an account lock must not be unduly
burdensome for customers such that it effectively inhibits customers from implementing their choice. A
CMRS provider may activate a port-out lock on a customer’s account when the CMRS provider has a
reasonable belief that the customer is at high risk of fraud, but must provide the customer with clear
notification that the account lock has been activated with instructions on how the customer can deactivate
the account lock, and promptly comply with the customer’s legitimate request to deactivate the account
lock.
(e) Notice of Account Protection Measures. A CMRS provider must provide customers with notice, using
clear and concise language, of any account protection measures the CMRS provider offers, including
those to prevent port-out fraud. A CMRS provider shall make this notice easily accessible through the
CMRS provider’s website and application.
(f) Employee Training. A CMRS provider shall develop and implement training for employees to
specifically address fraudulent port-out attempts, complaints, and remediation. Training shall include, at
a minimum, how to identify fraudulent requests, how to recognize when a customer may be the victim of

                                                     64
                                 Federal Communications Commission                              FCC 23-95

fraud, and how to direct potential victims and individuals making potentially fraudulent requests to
employees specifically trained to handle such incidents.
(g) Procedures to resolve fraudulent ports. A CMRS provider shall, at no cost to customers:
        (1) maintain a clearly disclosed, transparent, and easy-to-use process for customers to report
fraudulent number ports;
       (2) promptly investigate and take reasonable steps within its control to remediate fraudulent
number ports; and
        (3) promptly provide customers, upon request, with documentation of fraudulent number ports
involving their accounts.
(h) This section may contain information-collection and/or recordkeeping requirements. Compliance with
this section will not be required until this paragraph is removed or contains a compliance date, which will
not occur until the later of: i) [INSERT DATE SIX MONTHS AFTER THE EFFECTIVE DATE OF
THIS REPORT AND ORDER]; or ii) after the Office of Management and Budget completes review of
any information collection requirements in this section that the Wireline Competition Bureau determines
is required under the Paperwork Reduction Act or the Wireline Competition Bureau determines that such
review is not required. The Commission directs the Wireline Competition Bureau to announce a
compliance date for this section by subsequent Public Notice and to cause this section to be revised
accordingly.
PART 64 – MISCELLANEOUS RULES RELATING TO COMMON CARRIERS
3.      The authority citation for part 64 continues to read as follows:
        AUTHORITY: 47 U.S.C. 151, 152, 154, 201, 202, 217, 218, 220, 222, 225, 226, 227, 227b, 228,
        251(a), 251(e), 254(k), 262, 276, 303, 332, 403(b)(2)(B), (c), 616, 620, 1004, 1401-1473, unless
        otherwise noted; Pub. L. 115-141, Div. P, sec. 503, 132 Stat. 348, 1091.
4.      Amend § 64.2010 by adding paragraph (h) to read as follows:
§ 64.2010 Safeguards on the disclosure of customer proprietary network information.
*****
(h) Subscriber Identity Module (SIM) changes. A provider of commercial mobile radio service (CMRS),
as defined in 47 CFR § 20.3, including resellers of wireless service, shall only effectuate SIM change
requests in accordance with this section. For purposes of this section, SIM means a physical or virtual
card associated with a device that stores unique information that can be identified to a specific mobile
network.
          (1) Customer authentication. A CMRS provider shall use secure methods to authenticate a
customer that are reasonably designed to confirm the customer’s identity before executing a SIM change
request, except to the extent otherwise required by 47 U.S.C. § 345 (Safe Connections Act of 2022) or
Part 64, Subpart II of this chapter. Authentication methods shall not rely on readily available biographical
information, account information, recent payment information, or call detail information unless otherwise
permitted under 47 U.S.C. § 345 or Part 64, Subpart II of this chapter. A CMRS provider shall regularly,
but not less than annually, review and, as necessary, update its customer authentication methods to ensure
that its authentication methods continue to be secure. A CMRS provider shall establish safeguards and
processes so that employees who receive inbound customer communications are unable to access CPNI in
the course of that customer interaction until after the customer has been properly authenticated.
        (2) Response to failed authentication attempts. A CMRS provider shall develop, maintain, and
implement procedures for addressing failed authentication attempts in connection with a SIM change
request that are reasonably designed to prevent unauthorized access to a customer’s account, which,
among other things, take into consideration the needs of survivors pursuant to 47 U.S.C. § 345 and Part
64, Subpart II of this chapter.
                                                     65
                                  Federal Communications Commission                               FCC 23-95

         (3) Customer notification of SIM change requests. Upon receiving a SIM change request, and
before effectuating the request, a CMRS provider shall provide immediate notification to the customer
that a SIM change request associated with the customer’s account was made, sent in accordance with
customer preferences, if indicated, and using means reasonably designed to reach the customer associated
with the account and clear and concise language that provides sufficient information to effectively inform
a customer that a SIM change request involving the customer’s SIM was made, except if the SIM change
request was made in connection with a legitimate line separation request pursuant to 47 U.S.C. § 345 and
Part 64, Subpart II of this chapter, regardless of whether the line separation is technically or operationally
feasible.
        (4) Account locks. A CMRS provider shall offer customers, at no cost, the option to lock their
accounts to prohibit the CMRS provider from processing requests to change the customer’s SIM. A
CMRS provider shall not fulfill a SIM change request until the customer deactivates the lock on the
account, except if the SIM change request was made in connection with a legitimate line separation
request pursuant to 47 U.S.C. § 345 and Part 64, Subpart II of this chapter, regardless of whether the line
separation is technically or operationally feasible. The process to activate and deactivate an account lock
must not be unduly burdensome for customers such that it effectively inhibits customers from
implementing their choice. A CMRS provider may activate a SIM change lock on a customer’s account
when the CMRS provider has a reasonable belief that the customer is at high risk of fraud, but must
provide the customer with clear notification that the account lock has been activated with instructions on
how the customer can deactivate the account lock, and promptly comply with the customer’s legitimate
request to deactivate the account lock.
         (5) Notice of account protection measures. A CMRS provider must provide customers with
notice, using clear and concise language, of any account protection measures the CMRS provider offers,
including those to prevent SIM swap fraud. A CMRS provider shall make this notice easily-accessible
through the CMRS provider’s website and application.
       (6) Procedures to resolve fraudulent SIM changes. A CMRS provider shall, at no cost to
customers:
        (i) maintain a clearly disclosed, transparent, and easy-to-use process for customers to report
fraudulent SIM changes;
       (ii) promptly investigate and take reasonable steps within its control to remediate fraudulent SIM
changes; and
        (iii) promptly provide customers, upon request, with documentation of fraudulent SIM changes
involving their accounts.
        (7) Employee training. A CMRS provider shall develop and implement training for employees to
specifically address fraudulent SIM change attempts, complaints, and remediation. Training shall
include, at a minimum, how to identify potentially fraudulent SIM change requests, how to identify when
a customer may be the victim of SIM swap fraud, and how to direct potential victims and individuals
making potentially fraudulent requests to employees specifically trained to handle such incidents.
        (8) SIM change recordkeeping. A CMRS provider shall establish processes to reasonably track,
and maintain for a minimum of three years, the total number of SIM change requests it received, the
number of successful SIM change requests, the number of failed SIM change requests, the number of
successful fraudulent SIM change requests, the average time to remediate a fraudulent SIM change, the
total number of complaints received regarding fraudulent SIM change requests, the authentication
measures the CMRS provider has implemented, and when those authentication measures change. A
CMRS provider shall provide such data and information to the Commission upon request.

        (9) Compliance. Paragraph (h) may contain information-collection and/or recordkeeping
requirements. Compliance with paragraph (h) will not be required until this subparagraph is removed or
contains a compliance date, which will not occur until the later of: i) [INSERT DATE SIX MONTHS
                                                   66
                               Federal Communications Commission                           FCC 23-95

AFTER THE EFFECTIVE DATE OF THIS REPORT AND ORDER]; or ii) after the Office of
Management and Budget completes review of any information collection requirements in paragraph (h)
that the Wireline Competition Bureau determines is required under the Paperwork Reduction Act or the
Wireline Competition Bureau determines that such review is not required. The Commission directs the
Wireline Competition Bureau to announce a compliance date for this paragraph (h) by subsequent Public
Notice and to cause this paragraph to be revised accordingly.

                                                 67
                                    Federal Communications Commission                               FCC 23-95

                                                APPENDIX B
                                     Final Regulatory Flexibility Analysis

       1.      As required by the Regulatory Flexibility Act of 1980, as amended (RFA),1 an Initial
Regulatory Flexibility Analysis (IRFA) was incorporated into the Protecting Consumers from SIM Swap
and Port-Out Fraud Notice of Proposed Rulemaking (SIM Swap and Port-Out Fraud Notice) released in
September 2021.2 The Commission sought written public comment on the proposals in the SIM Swap
and Port-Out Fraud Notice, including comment on the IRFA. The comments received are discussed
below. This Final Regulatory Flexibility Analysis (FRFA) conforms to the RFA.3
         A.         Need for, and Objectives of, the Report and Order
         2.      The Report and Order establishes protections to address SIM swap and port-out fraud.
With SIM swap fraud, a bad actor impersonates a customer of a wireless provider and convinces the
provider to reassign the customer’s SIM from the customer’s device to a device controlled by the bad
actor. Similarly, with port-out fraud, the bad actor impersonates a customer of a wireless provider and
convinces the provider to port the customer’s telephone number to a new wireless provider and a device
that the bad actor controls.4 Both fraudulent practices transfer the victim’s wireless service to the bad
actor, allow the bad actor to gain access to information associated with the customer’s account, and
permit the bad actor to receive the text messages and phone calls intended for the customer.
        3.       The rules adopted in the Report and Order aim to foreclose these fraudulent practices
while preserving the relative ease with which customers can obtain legitimate SIM changes and number
ports. Specifically, the Report and Order revises the Commission’s CPNI and LNP rules to require that
wireless providers use secure methods of authenticating customers prior to performing SIM changes and
number ports. This requirement is reinforced by other rules, including that wireless providers adopt
processes for responding to failed authentication attempts, institute employee training for handling SIM
swap and port-out fraud, and establish safeguards to prevent employees who receive inbound customer
communications are unable to access CPNI in the course of that customer interaction until after customers
have been authenticated. The Report and Order also adopts rules that will enable customers to act to
prevent and address fraudulent SIM changes and number ports, including requiring that wireless providers
notify customers regarding SIM change and port-out requests, offer customers the option to lock their
accounts to block processing of SIM changes and number ports, and give advanced notice of available
account protection mechanisms. Additionally, the Report and Order establishes requirements to
minimize the harms of SIM swap and port-out fraud when it occurs, including requiring wireless
providers to maintain a clear process for customers to report fraud, promptly investigate and remediate
fraud, and promptly provide customers with documentation of fraud involving their accounts. Finally, to
ensure wireless providers track the effectiveness of authentication measures used for SIM change
requests, the Report and Order requires that providers keep records of SIM change requests and the
authentication measures they use.
         B.         Summary of Significant Issues Raised by Public Comments in Response to the IRFA
        4.       There were no comments that directly addressed the proposed rules and policies
presented in the SIM Swap and Port-Out Fraud Notice IRFA. However two commenters discussed the

1 5 U.S.C. § 603.
                The RFA, 5 U.S.C. §§ 601–612, has been amended by the Small Business Regulatory
Enforcement Fairness Act of 1996 (SBREFA), Pub. L. No. 104-121, Title II, 110 Stat. 857 (1996).
2 SIM Swap and Port-Out Fraud Notice, 36 FCC Rcd at 14152-14161, para. 6., Appx. B.

3 5 U.S.C. § 604.

4 FCC, Port-Out Fraud Targets Your Private Accounts, https://www.fcc.gov/port-out-fraud-targets-your-private-

accounts (last updated July 10, 2023).

                                                       68
                                    Federal Communications Commission                                    FCC 23-95

potential impact of rules on small carriers. The Competitive Carriers Association (CCA) advocated that
the Commission adopt security measures that give providers flexibility to account for the constraints with
which many small providers operate.5 The Rural Wireless Association (RWA) called for uniform
standards for port-out authentication to prevent potential anticompetitive activities and increased costs for
small providers in the event that larger providers hold small providers to standards that are difficult or
costly to implement.6 The approach taken by the Report and Order addresses these comments by setting
baseline requirements that build on existing mechanisms that many wireless providers already use to
establish a uniform framework across the mobile wireless industry, while giving wireless providers the
flexibility to deliver the most advanced, appropriate, and cost-effective fraud protection measures
available.
         C.           Response to Comments by the Chief Counsel for Advocacy of the Small Business
                      Administration
         5.     Pursuant to the Small Business Jobs Act of 2010, which amended the RFA, the
Commission is required to respond to any comments filed by the Chief Counsel for Advocacy of the
Small Business Administration (SBA), and to provide a detailed statement of any change made to the
proposed rules as a result of those comments.7 The Chief Counsel did not file any comments in response
to the proposed rules in this proceeding.
         D.           Description and Estimate of the Number of Small Entities to Which the Rules Will
                      Apply
        6.      The RFA directs agencies to provide a description of, and where feasible, an estimate of
the number of small entities that may be affected by the rules adopted herein.8 The RFA generally
defines the term “small entity” as having the same meaning as the terms “small business,” “small
organization,” and “small governmental jurisdiction.”9 In addition, the term “small business” has the
same meaning as the term “small business concern” under the Small Business Act.10 A “small business
concern” is one which: (1) is independently owned and operated; (2) is not dominant in its field of
operation; and (3) satisfies any additional criteria established by the SBA.11
        7.        Small Businesses, Small Organizations, Small Governmental Jurisdictions. Our actions,
over time, may affect small entities that are not easily categorized at present. We therefore describe, at
the outset, three broad groups of small entities that could be directly affected herein.12 First, while there
are industry specific size standards for small businesses that are used in the regulatory flexibility analysis,
according to data from the Small Business Administration’s (SBA) Office of Advocacy, in general a
small business is an independent business having fewer than 500 employees.13 These types of small
5 See CCA Comments at 6.

6 See RWA Comments at 12-14.

7 5 U.S.C. § 604(a)(3).

8 Id. § 604 (a)(4).

9 Id. § 601(6).

10 Id. § 601(3) (incorporating by reference the definition of “small-business concern” in the Small Business Act, 15

U.S.C. § 632). Pursuant to 5 U.S.C. § 601(3), the statutory definition of a small business applies “unless an agency,
after consultation with the Office of Advocacy of the Small Business Administration and after opportunity for public
comment, establishes one or more definitions of such term which are appropriate to the activities of the agency and
publishes such definition(s) in the Federal Register.”
11 15 U.S.C. § 632.

12 See 5 U.S.C. § 601(3)-(6).

13 SBA, Office of Advocacy, “What’s New With Small Business?,” https://advocacy.sba.gov/wp-

content/uploads/2023/03/Whats-New-Infographic-March-2023-508c.pdf (Mar. 2023).

                                                         69
                                   Federal Communications Commission                                   FCC 23-95

businesses represent 99.9% of all businesses in the United States, which translates to 33.2 million
businesses.14
         8.       Next, the type of small entity described as a “small organization” is generally “any not-
for-profit enterprise which is independently owned and operated and is not dominant in its field.”15 The
Internal Revenue Service (IRS) uses a revenue benchmark of $50,000 or less to delineate its annual
electronic filing requirements for small exempt organizations.16 Nationwide, for tax year 2020, there
were approximately 447,689 small exempt organizations in the U.S. reporting revenues of $50,000 or less
according to the registration and tax data for exempt organizations available from the IRS.17
         9.       Finally, the small entity described as a “small governmental jurisdiction” is defined
generally as “governments of cities, counties, towns, townships, villages, school districts, or special
districts, with a population of less than fifty thousand.”18 U.S. Census Bureau data from the 2017 Census
of Governments19 indicate there were 90,075 local governmental jurisdictions consisting of general
purpose governments and special purpose governments in the United States.20 Of this number, there were
36,931 general purpose governments (county,21 municipal, and town or township22) with populations of

14 Id.

15 See 5 U.S.C. § 601(4).

16 The IRS benchmark is similar to the population of less than 50,000 benchmark in 5 U.S.C § 601(5) that is used to

define a small governmental jurisdiction. Therefore, the IRS benchmark has been used to estimate the number of
small organizations in this small entity description. See Annual Electronic Filing Requirement for Small Exempt
Organizations – Form 990-N (e-Postcard), “Who must file,” https://www.irs.gov/charities-non-profits/annual-
electronic-filing-requirement-for-small-exempt-organizations-form-990-n-e-postcard. We note that the IRS data
does not provide information on whether a small exempt organization is independently owned and operated or
dominant in its field.
17 See Exempt Organizations Business Master File Extract (EO BMF), “CSV Files by Region,”

https://www.irs.gov/charities-non-profits/exempt-organizations-business-master-file-extract-eo-bmf. The IRS
Exempt Organization Business Master File (EO BMF) Extract provides information on all registered tax-
exempt/non-profit organizations. The data utilized for purposes of this description was extracted from the IRS EO
BMF data for businesses for the tax year 2020 with revenue less than or equal to $50,000 for Region 1-Northeast
Area (58,577), Region 2-Mid-Atlantic and Great Lakes Areas (175,272), and Region 3-Gulf Coast and Pacific Coast
Areas (213,840) that includes the continental U.S., Alaska, and Hawaii. This data does not include information for
Puerto Rico.
18 5 U.S.C. § 601(5).

19 13 U.S.C. § 161.The Census of Governments survey is conducted every five (5) years compiling data for years
ending with “2” and “7”. See also Census of Governments, https://www.census.gov/programs-
surveys/cog/about.html.
20 U.S. Census Bureau, 2017 Census of Governments – Organization Table 2.     Local Governments by Type and
State: 2017 [CG1700ORG02], https://www.census.gov/data/tables/2017/econ/gus/2017-governments.html. Local
governmental jurisdictions are made up of general purpose governments (county, municipal and town or township)
and special purpose governments (special districts and independent school districts). See also tbl.2. CG1700ORG02
Table Notes_Local Governments by Type and State_2017.
21 Id. at tbl.5.
              County Governments by Population-Size Group and State: 2017 [CG1700ORG05],
https://www.census.gov/data/tables/2017/econ/gus/2017-governments.html. There were 2,105 county governments
with populations less than 50,000. This category does not include subcounty (municipal and township)
governments.
22 Id. at tbl.6.
             Subcounty General-Purpose Governments by Population-Size Group and State: 2017
[CG1700ORG06], https://www.census.gov/data/tables/2017/econ/gus/2017-governments.html. There were 18,729
municipal and 16,097 town and township governments with populations less than 50,000.

                                                        70
                                   Federal Communications Commission                                  FCC 23-95

less than 50,000 and 12,040 special purpose governments—independent school districts23 with enrollment
populations of less than 50,000.24 Accordingly, based on the 2017 U.S. Census of Governments data, we
estimate that at least 48,971 entities fall into the category of “small governmental jurisdictions.”25
                    1.    Providers of Telecommunications and Other Services
          10.      Wired Telecommunications Carriers. The U.S. Census Bureau defines this industry as
establishments primarily engaged in operating and/or providing access to transmission facilities and
infrastructure that they own and/or lease for the transmission of voice, data, text, sound, and video using
wired communications networks.26 Transmission facilities may be based on a single technology or a
combination of technologies. Establishments in this industry use the wired telecommunications network
facilities that they operate to provide a variety of services, such as wired telephony services, including
VoIP services, wired (cable) audio and video programming distribution, and wired broadband Internet
services.27 By exception, establishments providing satellite television distribution services using facilities
and infrastructure that they operate are included in this industry.28 Wired Telecommunications Carriers
are also referred to as wireline carriers or fixed local service providers.29
        11.     The SBA small business size standard for Wired Telecommunications Carriers classifies
firms having 1,500 or fewer employees as small.30 U.S. Census Bureau data for 2017 show that there
were 3,054 firms that operated in this industry for the entire year.31 Of this number, 2,964 firms operated
with fewer than 250 employees.32 Additionally, based on Commission data in the 2022 Universal Service
Monitoring Report, as of December 31, 2021, there were 4,590 providers that reported they were engaged
23 Id. at tbl.10.
               Elementary and Secondary School Systems by Enrollment-Size Group and State: 2017
[CG1700ORG10], https://www.census.gov/data/tables/2017/econ/gus/2017-governments.html. There were 12,040
independent school districts with enrollment populations less than 50,000. See also tbl.4. Special-Purpose Local
Governments by State Census Years 1942 to 2017 [CG1700ORG04], CG1700ORG04 Table Notes_Special Purpose
Local Governments by State_Census Years 1942 to 2017.
24 While the special purpose governments category also includes local special district governments, the 2017 Census

of Governments data does not provide data aggregated based on population size for the special purpose governments
category. Therefore, only data from independent school districts is included in the special purpose governments
category.
25 This total is derived from the sum of the number of general purpose governments (county, municipal and town or

township) with populations of less than 50,000 (36,931) and the number of special purpose governments -
independent school districts with enrollment populations of less than 50,000 (12,040), from the 2017 Census of
Governments - Organizations tbls.5, 6 & 10.
26 U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
27 Id.

28 Id.

29 Fixed Local Service Providers include the following types of providers: Incumbent Local Exchange Carriers

(ILECs), Competitive Access Providers (CAPs) and Competitive Local Exchange Carriers (CLECs), Cable/Coax
CLECs, Interconnected VOIP Providers, Non-Interconnected VOIP Providers, Shared-Tenant Service Providers,
Audio Bridge Service Providers, and Other Local Service Providers. Local Resellers fall into another U.S. Census
Bureau industry group and therefore data for these providers is not included in this industry.
30 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

31 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
32 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.

                                                        71
                                   Federal Communications Commission                                   FCC 23-95

in the provision of fixed local services.33 Of these providers, the Commission estimates that 4,146
providers have 1,500 or fewer employees.34 Consequently, using the SBA’s small business size standard,
most of these providers can be considered small entities.
         12.     Local Exchange Carriers (LECs). Neither the Commission nor the SBA has developed a
size standard for small businesses specifically applicable to local exchange services. Providers of these
services include both incumbent and competitive local exchange service providers. Wired
Telecommunications Carriers35 is the closest industry with an SBA small business size standard.36 Wired
Telecommunications Carriers are also referred to as wireline carriers or fixed local service providers.37
The SBA small business size standard for Wired Telecommunications Carriers classifies firms having
1,500 or fewer employees as small.38 U.S. Census Bureau data for 2017 show that there were 3,054 firms
that operated in this industry for the entire year.39 Of this number, 2,964 firms operated with fewer than
250 employees.40 Additionally, based on Commission data in the 2022 Universal Service Monitoring
Report, as of December 31, 2021, there were 4,590 providers that reported they were fixed local exchange
service providers.41 Of these providers, the Commission estimates that 4,146 providers have 1,500 or
fewer employees.42 Consequently, using the SBA’s small business size standard, most of these providers
can be considered small entities.
        13.     Incumbent Local Exchange Carriers (Incumbent LECs). Neither the Commission nor the
SBA have developed a small business size standard specifically for incumbent local exchange carriers.
Wired Telecommunications Carriers43 is the closest industry with an SBA small business size standard.44
The SBA small business size standard for Wired Telecommunications Carriers classifies firms having
1,500 or fewer employees as small.45 U.S. Census Bureau data for 2017 show that there were 3,054 firms

33 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf. https://docs.fcc.gov/public/attachments/DOC-
379181A1.pdf
34 Id.

35 See U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
36 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

37 Fixed Local Exchange Service Providers include the following types of providers: Incumbent Local Exchange

Carriers (ILECs), Competitive Access Providers (CAPs) and Competitive Local Exchange Carriers (CLECs),
Cable/Coax CLECs, Interconnected VOIP Providers, Non-Interconnected VOIP Providers, Shared-Tenant Service
Providers, Audio Bridge Service Providers, Local Resellers, and Other Local Service Providers.
38 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

39 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
40 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
41 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
42 Id.

43 See U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
44 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

45 Id.

                                                        72
                                   Federal Communications Commission                                   FCC 23-95

in this industry that operated for the entire year.46 Of this number, 2,964 firms operated with fewer than
250 employees.47 Additionally, based on Commission data in the 2022 Universal Service Monitoring
Report, as of December 31, 2021, there were 1,212 providers that reported they were incumbent local
exchange service providers.48 Of these providers, the Commission estimates that 916 providers have
1,500 or fewer employees.49 Consequently, using the SBA’s small business size standard, the
Commission estimates that the majority of incumbent local exchange carriers can be considered small
entities.
        14.      Competitive Local Exchange Carriers (Competitive LECs). Neither the Commission nor
the SBA has developed a size standard for small businesses specifically applicable to local exchange
services. Providers of these services include several types of competitive local exchange service
providers.50 Wired Telecommunications Carriers51 is the closest industry with an SBA small business size
standard. The SBA small business size standard for Wired Telecommunications Carriers classifies firms
having 1,500 or fewer employees as small.52 U.S. Census Bureau data for 2017 show that there were
3,054 firms that operated in this industry for the entire year.53 Of this number, 2,964 firms operated with
fewer than 250 employees.54 Additionally, based on Commission data in the 2022 Universal Service
Monitoring Report, as of December 31, 2021, there were 3,378 providers that reported they were
competitive local exchange service providers.55 Of these providers, the Commission estimates that 3,230
providers have 1,500 or fewer employees.56 Consequently, using the SBA’s small business size standard,
most of these providers can be considered small entities.
        15.     Interexchange Carriers (IXCs). Neither the Commission nor the SBA have developed a
small business size standard specifically for Interexchange Carriers. Wired Telecommunications

46 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
47 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
48 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
49 Id.

50 Competitive Local Exchange Service Providers include the following types of providers: Competitive Access

Providers (CAPs) and Competitive Local Exchange Carriers (CLECs), Cable/Coax CLECs, Interconnected VOIP
Providers, Non-Interconnected VOIP Providers, Shared-Tenant Service Providers, Audio Bridge Service Providers,
Local Resellers, and Other Local Service Providers.
51 See U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
52 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

53 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
54 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
55 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
56 Id.

                                                        73
                                   Federal Communications Commission                                   FCC 23-95

Carriers57 is the closest industry with an SBA small business size standard.58 The SBA small business
size standard for Wired Telecommunications Carriers classifies firms having 1,500 or fewer employees as
small.59 U.S. Census Bureau data for 2017 show that there were 3,054 firms that operated in this industry
for the entire year.60 Of this number, 2,964 firms operated with fewer than 250 employees.61
Additionally, based on Commission data in the 2022 Universal Service Monitoring Report, as of
December 31, 2021, there were 127 providers that reported they were engaged in the provision of
interexchange services. Of these providers, the Commission estimates that 109 providers have 1,500 or
fewer employees.62 Consequently, using the SBA’s small business size standard, the Commission
estimates that the majority of providers in this industry can be considered small entities.
         16.      Local Resellers. Neither the Commission nor the SBA have developed a small business
size standard specifically for Local Resellers. Telecommunications Resellers is the closest industry with
an SBA small business size standard.63 The Telecommunications Resellers industry comprises
establishments engaged in purchasing access and network capacity from owners and operators of
telecommunications networks and reselling wired and wireless telecommunications services (except
satellite) to businesses and households.64 Establishments in this industry resell telecommunications; they
do not operate transmission facilities and infrastructure.65 Mobile virtual network operators (MVNOs) are
included in this industry.66 The SBA small business size standard for Telecommunications Resellers
classifies a business as small if it has 1,500 or fewer employees.67 U.S. Census Bureau data for 2017
show that 1,386 firms in this industry provided resale services for the entire year.68 Of that number, 1,375
firms operated with fewer than 250 employees.69 Additionally, based on Commission data in the 2022
Universal Service Monitoring Report, as of December 31, 2021, there were 207 providers that reported

57 See U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
58 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

59 Id.

60 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
61 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
62 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
63 See U.S. Census Bureau, 2017 NAICS Definition, “517911 Telecommunications Resellers,”

https://www.census.gov/naics/?input=517911&year=2017&details=517911.
64 Id.

65 Id.

66 Id.

67 13 CFR § 121.201, NAICS Code 517911 (as of 10/1/22, NAICS Code 517121).

68 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517911,
https://data.census.gov/cedsci/table?y=2017&n=517911&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
69 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.

                                                        74
                                   Federal Communications Commission                                   FCC 23-95

they were engaged in the provision of local resale services.70 Of these providers, the Commission
estimates that 202 providers have 1,500 or fewer employees.71 Consequently, using the SBA’s small
business size standard, most of these providers can be considered small entities.
         17.      Toll Resellers. Neither the Commission nor the SBA have developed a small business
size standard specifically for Toll Resellers. Telecommunications Resellers72 is the closest industry with
an SBA small business size standard. The Telecommunications Resellers industry comprises
establishments engaged in purchasing access and network capacity from owners and operators of
telecommunications networks and reselling wired and wireless telecommunications services (except
satellite) to businesses and households. Establishments in this industry resell telecommunications; they
do not operate transmission facilities and infrastructure.73 Mobile virtual network operators (MVNOs) are
included in this industry.74 The SBA small business size standard for Telecommunications Resellers
classifies a business as small if it has 1,500 or fewer employees.75 U.S. Census Bureau data for 2017
show that 1,386 firms in this industry provided resale services for the entire year.76 Of that number, 1,375
firms operated with fewer than 250 employees.77 Additionally, based on Commission data in the 2022
Universal Service Monitoring Report, as of December 31, 2021, there were 457 providers that reported
they were engaged in the provision of toll services.78 Of these providers, the Commission estimates that
438 providers have 1,500 or fewer employees.79 Consequently, using the SBA’s small business size
standard, most of these providers can be considered small entities.
         18.     Wireless Telecommunications Carriers (except Satellite). This industry comprises
establishments engaged in operating and maintaining switching and transmission facilities to provide
communications via the airwaves.80 Establishments in this industry have spectrum licenses and provide
services using that spectrum, such as cellular services, paging services, wireless Internet access, and
wireless video services.81 The SBA size standard for this industry classifies a business as small if it has
1,500 or fewer employees.82 U.S. Census Bureau data for 2017 show that there were 2,893 firms in this
70 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
71 Id.

72 See U.S. Census Bureau, 2017 NAICS Definition, “517911 Telecommunications Resellers,”

https://www.census.gov/naics/?input=517911&year=2017&details=517911.
73 Id.

74 Id.

75 13 CFR § 121.201, NAICS Code 517911 (as of 10/1/22, NAICS Code 517121).

76 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms for

the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517911,
https://data.census.gov/cedsci/table?y=2017&n=517911&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
77 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
78 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf. https://docs.fcc.gov/public/attachments/DOC-
379181A1.pdf
79 Id.

80 See U.S. Census Bureau, 2017 NAICS Definition, “517312 Wireless Telecommunications Carriers (except

Satellite),” https://www.census.gov/naics/?input=517312&year=2017&details=517312.
81 Id.

82 13 CFR § 121.201, NAICS Code 517312 (as of 10/1/22, NAICS Code 517112).

                                                        75
                                   Federal Communications Commission                                   FCC 23-95

industry that operated for the entire year.83 Of that number, 2,837 firms employed fewer than 250
employees.84 Additionally, based on Commission data in the 2022 Universal Service Monitoring Report,
as of December 31, 2021, there were 594 providers that reported they were engaged in the provision of
wireless services.85 Of these providers, the Commission estimates that 511 providers have 1,500 or fewer
employees.86 Consequently, using the SBA’s small business size standard, most of these providers can be
considered small entities.
          19.      Satellite Telecommunications. This industry comprises firms “primarily engaged in
providing telecommunications services to other establishments in the telecommunications and
broadcasting industries by forwarding and receiving communications signals via a system of satellites or
reselling satellite telecommunications.”87 Satellite telecommunications service providers include satellite
and earth station operators. The SBA small business size standard for this industry classifies a business
with $38.5 million or less in annual receipts as small.88 U.S. Census Bureau data for 2017 show that 275
firms in this industry operated for the entire year.89 Of this number, 242 firms had revenue of less than
$25 million.90 Additionally, based on Commission data in the 2022 Universal Service Monitoring Report,
as of December 31, 2021, there were 65 providers that reported they were engaged in the provision of
satellite telecommunications services.91 Of these providers, the Commission estimates that approximately
42 providers have 1,500 or fewer employees.92 Consequently, using the SBA’s small business size
standard, a little more than half of these providers can be considered small entities.
        20.      All Other Telecommunications. This industry is comprised of establishments primarily
engaged in providing specialized telecommunications services, such as satellite tracking, communications
telemetry, and radar station operation.93 This industry also includes establishments primarily engaged in
providing satellite terminal stations and associated facilities connected with one or more terrestrial
systems and capable of transmitting telecommunications to, and receiving telecommunications from,

83 U.S. Census Bureau, 2017 Economic Census of the United States, Employment Size of Firms for the U.S.: 2017,

Table ID: EC1700SIZEEMPFIRM, NAICS Code 517312,
https://data.census.gov/cedsci/table?y=2017&n=517312&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
84 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
85 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
86 Id.

87 See U.S. Census Bureau, 2017 NAICS Definition, “517410 Satellite Telecommunications,”

https://www.census.gov/naics/?input=517410&year=2017&details=517410.
88 13 CFR § 121.201, NAICS Code 517410.

89 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Sales, Value of Shipments, or

Revenue Size of Firms for the U.S.: 2017, Table ID: EC1700SIZEREVFIRM, NAICS Code 517410,
https://data.census.gov/cedsci/table?y=2017&n=517410&tid=ECNSIZE2017.EC1700SIZEREVFIRM&hidePrevie
w=false.
90 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard. We also note that according to the U.S. Census Bureau glossary, the terms receipts and
revenues are used interchangeably, see https://www.census.gov/glossary/#term_ReceiptsRevenueServices.
91 Federal-State Joint Board on Universal Service, Universal Service Monitoring Report at 26, Table 1.12 (2022),

https://docs.fcc.gov/public/attachments/DOC-391070A1.pdf.
92 Id.

93 See U.S. Census Bureau, 2017 NAICS Definition, “517919 All Other Telecommunications,”

https://www.census.gov/naics/?input=517919&year=2017&details=517919.

                                                        76
                                    Federal Communications Commission                                 FCC 23-95

satellite systems.94 Providers of Internet services (e.g. dial-up ISPs) or Voice over Internet Protocol
(VoIP) services, via client-supplied telecommunications connections are also included in this industry.95
The SBA small business size standard for this industry classifies firms with annual receipts of $35 million
or less as small.96 U.S. Census Bureau data for 2017 show that there were 1,079 firms in this industry that
operated for the entire year.97 Of those firms, 1,039 had revenue of less than $25 million.98 Based on this
data, the Commission estimates that the majority of “All Other Telecommunications” firms can be
considered small.
                 2.          Internet Service Providers
         21.      Wired Broadband Internet Access Service Providers (Wired ISPs).99 Providers of wired
broadband Internet access service include various types of providers except dial-up Internet access
providers. Wireline service that terminates at an end user location or mobile device and enables the end
user to receive information from and/or send information to the Internet at information transfer rates
exceeding 200 kilobits per second (kbps) in at least one direction is classified as a broadband connection
under the Commission’s rules.100 Wired broadband Internet services fall in the Wired
Telecommunications Carriers industry.101 The SBA small business size standard for this industry
classifies firms having 1,500 or fewer employees as small.102 U.S. Census Bureau data for 2017 show that
there were 3,054 firms that operated in this industry for the entire year.103 Of this number, 2,964 firms
operated with fewer than 250 employees.104
        22.      Additionally, according to Commission data on Internet access services as of December
31, 2018, nationwide there were approximately 2,700 providers of connections over 200 kbps in at least
one direction using various wireline technologies.105 The Commission does not collect data on the

94 Id.

95 Id.

96 13 CFR § 121.201, NAICS Code 517919 (as of 10/1/22, NAICS Code 517810).

97 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Sales, Value of Shipments, or

Revenue Size of Firms for the U.S.: 2017, Table ID: EC1700SIZEREVFIRM, NAICS Code 517919,
https://data.census.gov/cedsci/table?y=2017&n=517919&tid=ECNSIZE2017.EC1700SIZEREVFIRM&hidePrevie
w=false.
98 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard. We also note that according to the U.S. Census Bureau glossary, the terms receipts and
revenues are used interchangeably, see https://www.census.gov/glossary/#term_ReceiptsRevenueServices.
99 Formerly included in the scope of the Internet Service Providers (Broadband), Wired Telecommunications

Carriers and All Other Telecommunications small entity industry descriptions.
100 47 CFR § 1.7001(a)(1).

101 See U.S. Census Bureau, 2017 NAICS Definition, “517311 Wired Telecommunications Carriers,”

https://www.census.gov/naics/?input=517311&year=2017&details=517311.
102 13 CFR § 121.201, NAICS Code 517311 (as of 10/1/22, NAICS Code 517111).

103 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Employment Size of Firms

for the U.S.: 2017, Table ID: EC1700SIZEEMPFIRM, NAICS Code 517311,
https://data.census.gov/cedsci/table?y=2017&n=517311&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
104 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
105 IAS Status 2018, Fig. 30 (The technologies used by providers include aDSL, sDSL, Other Wireline, Cable

Modem and FTTP). Other wireline includes: all copper-wire based technologies other than xDSL (such as Ethernet
                                                                                                 (continued….)
                                                        77
                                    Federal Communications Commission                                 FCC 23-95

number of employees for providers of these services, therefore, at this time we are not able to estimate the
number of providers that would qualify as small under the SBA’s small business size standard. However,
in light of the general data on fixed technology service providers in the Commission’s 2022
Communications Marketplace Report,106 we believe that the majority of wireline Internet access service
providers can be considered small entities.
         23.     Wireless Broadband Internet Access Service Providers (Wireless ISPs or WISPs).107
Providers of wireless broadband Internet access service include fixed and mobile wireless providers. The
Commission defines a WISP as “[a] company that provides end-users with wireless access to the
Internet[.]”108 Wireless service that terminates at an end user location or mobile device and enables the
end user to receive information from and/or send information to the Internet at information transfer rates
exceeding 200 kilobits per second (kbps) in at least one direction is classified as a broadband connection
under the Commission’s rules.109 Neither the SBA nor the Commission have developed a size standard
specifically applicable to Wireless Broadband Internet Access Service Providers. The closest applicable
industry with an SBA small business size standard is Wireless Telecommunications Carriers (except
Satellite).110 The SBA size standard for this industry classifies a business as small if it has 1,500 or fewer
employees.111 U.S. Census Bureau data for 2017 show that there were 2,893 firms in this industry that
operated for the entire year.112 Of that number, 2,837 firms employed fewer than 250 employees.113
          24.    Additionally, according to Commission data on Internet access services as of December
31, 2018, nationwide there were approximately 1,209 fixed wireless and 71 mobile wireless providers of
connections over 200 kbps in at least one direction.114 The Commission does not collect data on the
number of employees for providers of these services, therefore, at this time we are not able to estimate the
number of providers that would qualify as small under the SBA’s small business size standard. However,
based on data in the Commission’s 2022 Communications Marketplace Report on the small number of
large mobile wireless nationwide and regional facilities-based providers, the dozens of small regional
facilities-based providers and the number of wireless mobile virtual network providers in general,115 as

(Continued from previous page)
over copper, T-1/DS-1 and T3/DS-1) as well as power line technologies which are included in this category to
maintain the confidentiality of the providers.
106 See Communications Marketplace Report, GN Docket No. 22-203, 2022 WL 18110553 at 10, paras. 26-27, Figs.

II.A.5-7. (2022) (2022 Communications Marketplace Report).
107 Formerly included in the scope of the Internet Service Providers (Broadband), Wireless Telecommunications

Carriers (except Satellite) and All Other Telecommunications small entity industry descriptions.
108 Federal Communications Commission, Internet Access Services: Status as of December 31, 2018 (IAS Status

2018), Industry Analysis Division, Office of Economics & Analytics (September 2020). The report can be accessed
at https://www.fcc.gov/economics-analytics/industry-analysis-division/iad-data-statistical-reports.
109 See 47 CFR § 1.7001(a)(1).

110 See U.S. Census Bureau, 2017 NAICS Definition, “517312 Wireless Telecommunications Carriers (except

Satellite),” https://www.census.gov/naics/?input=517312&year=2017&details=517312.
111 13 CFR § 121.201, NAICS Code 517312 (as of 10/1/22, NAICS Code 517112).

112 U.S. Census Bureau, 2017 Economic Census of the United States, Employment Size of Firms for the U.S.: 2017,

Table ID: EC1700SIZEEMPFIRM, NAICS Code 517312,
https://data.census.gov/cedsci/table?y=2017&n=517312&tid=ECNSIZE2017.EC1700SIZEEMPFIRM&hidePrevie
w=false.
113 Id.The available U.S. Census Bureau data does not provide a more precise estimate of the number of firms that
meet the SBA size standard.
114 See IAS Status 2018, Fig. 30.

115 2022 Communications Marketplace Report , 2022 WL 18110553 at 27, paras. 64-68.

                                                         78
                                   Federal Communications Commission                                  FCC 23-95

well as on terrestrial fixed wireless broadband providers in general,116 we believe that the majority of
wireless Internet access service providers can be considered small entities.
         25.     Internet Service Providers (Non-Broadband). Internet access service providers using
client-supplied telecommunications connections (e.g., dial-up ISPs) as well as VoIP service providers
using client-supplied telecommunications connections fall in the industry classification of All Other
Telecommunications.117 The SBA small business size standard for this industry classifies firms with
annual receipts of $35 million or less as small.118 For this industry, U.S. Census Bureau data for 2017
show that there were 1,079 firms in this industry that operated for the entire year.119 Of those firms, 1,039
had revenue of less than $25 million.120 Consequently, under the SBA size standard a majority of firms in
this industry can be considered small.
          E.        Description of Projected Reporting, Recordkeeping, and Other Compliance
                    Requirements for Small Entities
         26.      This Report and Order adopts rules that could result in increased, reduced, or otherwise
modified recordkeeping, reporting, or other compliance requirements for affected providers of service,
including small wireless providers. Specifically, it requires that wireless providers use secure methods of
authenticating customers prior to performing SIM changes and number ports, and to review and update
these authentication methods as needed, but at least annually. It requires wireless providers to adopt
processes for customer notification and response to failed authentication attempts, institute employee
training for handling SIM swap and port-out fraud, and establish safeguards to prevent employees who
receive inbound customer communications from accessing CPNI in the course of that customer
interaction until after customers have been authenticated. The Report and Order also adopts rules
requiring that wireless providers notify customers regarding SIM change and port-out requests, offer
customers the option to lock their accounts to block processing of SIM changes and number ports, and
give advanced notice of available account protection mechanisms. Additionally, the Report and Order
requires wireless providers to maintain a clear process for customers to report fraud, promptly investigate
and remediate fraud, and promptly provide customers with documentation of fraud involving their
accounts. Finally, the Report and Order requires that providers keep records of SIM change requests and
the authentication measures they use.
        27.      We are cognizant that, in some instances, strict prescriptive requirements to prevent SIM
swap and port-out fraud could be technically and economically infeasible for wireless providers to
implement, particularly for smaller providers. The Commission does not have sufficient information on
the record to determine whether small entities will be required to hire professionals to comply with its
decisions or to quantify the cost of compliance for small entities. However, the record reflects that many
wireless providers have already developed and implemented some form of the customer authentication
requirements in the Report and Order, minimizing cost implications for small entities. We also permit

116 Id. at 8, para. 22.

117 See U.S. Census Bureau, 2017 NAICS Definition, “517919 All Other Telecommunications,”

https://www.census.gov/naics/?input=517919&year=2017&details=517919.
118 13 CFR § 121.201, NAICS Code 517919 (as of 10/1/22, NAICS Code 517810).

119 U.S. Census Bureau, 2017 Economic Census of the United States, Selected Sectors: Sales, Value