The ITU Has Specified How to Sign a Call, Not Yet Who to Believe
On 1 October 2026 the ITU set out the state of its work on authenticating calling line identification, and the ordering is the story. The Recommendations that specify how to sign a call have been published since 2020. The two that decide who may issue a certificate and whose certificate another operator should believe — Q.3070 and E.1122 — are still in their approval process.
Sigma Telecom has been an ITU sector member since 2018. We started in Istanbul in 2003, moved into wholesale VoIP in 2014, and now carry 150 million minutes a month over SIP and H.323 across more than 1,000 interconnections into more than 190 countries, watched by a 24/7 NOC. Caller identity is not an abstraction at that layer. It is the field that every argument about fraud eventually reduces to.
This article covers what the ITU announced, what each Recommendation specifies and which an operator can act on today, why the signature was always the easier half of the problem, and what certificate-based CLI authentication will not fix even when fully deployed.
What the ITU announced, and what it did not
The 1 October announcement describes a suite of standards for authenticating CLI using digital public-key certificates. Three Recommendations are published. Associated amendments to three signalling Recommendations specify the protocol extensions that carry the certificate, the signature and the authentication result. Two further Recommendations — Q.3070 from Study Group 11 and E.1122 from Study Group 2 — are in approval. The ITU is co-organising a roundtable with India's Department of Telecommunications on 9 October in New Delhi, alongside India Mobile Congress, to discuss implementation and to present the scope and participation model for a proof of concept.
Nothing in force changed on 1 October. No interconnect agreement reads differently this week, and no operator is obliged to sign anything: a standards body publishing a Recommendation is not a regulator issuing a rule. What the announcement is useful for is the inventory. It tells a carrier which parts of the problem have been specified, which have not, and in what order.
The three Recommendations that already exist
Q.3057, approved April 2020, is the architecture. It defines a PKI model for signalling between operators, with a trusted signalling certification authority as the root of trust, operator certification authorities beneath it, and signalling security gateways at each network border that sign outbound messages and validate inbound ones. It also defines four different models for establishing trust across domains: peer-to-peer, root CA, intermediate CA and bridge CA. That list of four is a tell. An architecture that offers four ways to answer a question is an architecture that has not settled the question.
Q.3062, 2022, specifies the signalling procedures and the structure of a protected message. Q.3063, also 2022, specifies the CLI authentication procedures, with a corrigendum approved in July 2023. These two are the implementable part of the suite: an operator wanting to sign and verify on SIP has had a specification to build against for four years.
Recommendation | What it specifies | Approved | Where it leaves an interconnect |
|---|---|---|---|
Q.3057 | Architecture and trust anchor model | April 2020 | Design reference, no traffic depends on it |
Q.3062 | Signalling procedures, protected message structure | 2022 | Implementable on SIP |
Q.3063 | CLI authentication procedures | 2022 | Implementable on SIP |
Q.763 Amd. 7 and Q.931 Amd. 2 | ISUP and ISDN parameters for certificate, signature, result | December 2023 | Lets a signature survive a non-IP leg |
Q.3070 (draft) | Certificate issuance, cross-border anchor lists | In approval | Not yet usable |
E.1122 (draft) | Governance framework, operational requirements | In approval | Not yet usable |
A signature needs somewhere to travel
The least discussed item in that table is the most operationally interesting. Q.763 Amendment 7, approved in December 2023, adds three parameters to the ISUP Initial Address Message: a certificate parameter, a signature parameter, and an authentication indicator that carries the result of the check. Q.931 Amendment 2 does the equivalent for ISDN, and the ITU lists Q.1902.3 for bearer independent call control as amended on the same basis.
This is the difference between a scheme that works inside one country's IP core and a scheme that could work across a border. An authentication mechanism living only in a SIP header has nowhere to put its signature the moment a call leaves IP, and international routes are not uniformly SIP end to end. STIR/SHAKEN, mandatory on United States networks since June 2021 and extended by an FCC order in May 2022 to gateway providers handling foreign-originated SIP traffic, is a SIP mechanism; its reach ends where SIP ends. Specifying ISUP and ISDN parameters is unglamorous work, and it is the precondition for any of this mattering on a real international route.
The trust anchor is the harder half
Two years ago, Resolution 65 of the World Telecommunication Standardization Assembly, revised in New Delhi in 2024, instructed Study Groups 2 and 11 to develop a procedure for selecting registration authorities, including trusted signalling certification authorities, to support the allocation of digital public certificates used in signalling exchange. Q.3070 and E.1122 are the Recommendations that carry out that instruction. Both are in approval. Neither is in force.
The reason this half is slower is not technical. Signing a message is settled cryptography. Deciding whose signature counts is an allocation question, and telephone numbers are allocated nationally, by separate authorities, country by country. A certificate asserting that an operator is entitled to present a given number range is worth exactly as much as the registry that issued it, and there is no single registry. Q.3057's four inter-domain trust models are four political answers to the same question, and the suite cannot deploy internationally until one is chosen and someone is appointed to administer it.
What a failed check will actually mean. For a long time after deployment begins, an unsigned or unverifiable call will carry almost no information. It may mean the originating operator has not implemented, or the certificate has expired, or an intermediate carrier re-originated the call, or a transcoding step dropped the parameter. Treating absence of a valid signature as evidence of fraud will generate false positives at a rate no wholesale voice operation can absorb. Coverage has to be high before a negative result is worth acting on, and coverage is pairwise: a signature is worth nothing unless the far end validates it.
What this does not fix
It does not touch SMS sender identity. Alphanumeric sender names on A2P traffic are governed by national registries, not by signalling certificates, and the two problems do not share a mechanism. Anyone running wholesale SMS will be dealing with registries country by country regardless of what happens to voice.
It does not answer whether a number should have been presented. Authentication establishes that the operator presenting a number holds a credential for it. It says nothing about whether that operator's customer had any business using it. A call correctly signed by an operator with weak customer due diligence is a correctly signed fraudulent call, which is why numbering-resource obligations and KYC rules sit alongside this work rather than being replaced by it.
It does not survive re-origination. Where an intermediate carrier terminates and re-originates rather than passing signalling through, the signature chain breaks. That is a commercial and architectural choice made hop by hop across a route, and no Recommendation changes it.
What to ask about this now
Ask what happens to the parameters, not whether the platform supports them. Support is a roadmap answer. The operational question is what a switch does with a certificate parameter it does not understand: pass it transparently, or strip it. A route that strips it breaks authentication for every carrier downstream, whether or not anyone on that route has implemented anything.
Ask what the stated policy on a failed check is. The honest answer today is that a failed check is logged and nothing else happens, because coverage is too low for anything else to be safe. A supplier claiming it already blocks on failed CLI authentication across international routes is describing something that would currently block a great deal of legitimate traffic.
Ask who is expected to sign on each route. The entity that signs is the one entitled to the number range, in the country that issued it. For a transit carrier the realistic position is to carry and preserve, not to assert. Clarity about which role a supplier is claiming is more useful than any compliance badge, and it is the sort of thing worth reading alongside a carrier's certifications and the rest of its services.
Frequently asked questions
Did anything become mandatory on 1 October 2026?
No. The ITU published an update on the status of a suite of standards. Recommendations are specifications, not obligations, and no operator is required to implement them. Obligations, where they exist, come from national regulators.
How is this different from STIR/SHAKEN?
STIR/SHAKEN is a SIP-based caller ID authentication framework, mandatory on United States networks since June 2021 and extended by the FCC in May 2022 to gateway providers handling unauthenticated foreign-originated SIP calls. The ITU suite covers the same idea but specifies parameters for ISUP and ISDN as well, so a signature can cross a non-IP leg. This is a statement about reach, not about effectiveness.
Why does an ISUP amendment matter when networks are moving to IP?
Because international routes are mixed. A call can originate on an IP network, cross a TDM interconnect and terminate on IP again. If the signature has no parameter to occupy on the middle leg, it is lost at the first gateway and the far end sees an unauthenticated call. The amendments give it somewhere to sit.
What is a trusted signalling certification authority?
In the Q.3057 architecture it is the root of trust: the authority that issues certificates to operators' own certification authorities, which in turn issue to the signalling security gateways that sign and validate at network borders. Who may act in that role internationally is what Q.3070 and E.1122 are intended to settle.
Does this stop SMS sender ID spoofing?
No. The suite addresses calling line identification in voice signalling. Alphanumeric sender names in A2P messaging are handled through national sender ID registries, which work on a different mechanism and are being introduced country by country on their own timetables.
What should a wholesale buyer do about it today?
Treat it as inventory rather than procurement. Ask whether a supplier's switches pass the new parameters transparently, ask what its stated policy on a failed check is, and treat any claim of enforcement on international routes with scepticism until cross-border trust is settled. No purchasing decision is made urgent by this suite in 2026.
Learn more: international voice services · wholesale SMS · certifications · industry events · contact


