2019 TRACED Act Spurs Global STIR/SHAKEN Vetting as STI-GA Taps Numeracle
STI-GA has engaged Numeracle to build a global vetting framework for non-U.S. governance authorities that want to interoperate with the STIR/SHAKEN call authentication ecosystem. This introduces rigorous identity, governance, and certificate security assessments plus ongoing monitoring, closing a major cross-border spoofing vector for cybersecurity teams.
Key Takeaways
- STI-GA has engaged Numeracle to build a global vetting framework for non-U.S.
- governance authorities that want to interoperate with the STIR/SHAKEN call authentication ecosystem.
- This introduces rigorous identity, governance, and certificate security assessments plus ongoing monitoring, closing a major cross-border spoofing vector for cybersecurity teams.
Key Intelligence
Key Facts
- 1STI-GA, under ATIS, selected Numeracle on July 23, 2026 to develop a global vetting framework for Non-Jurisdictional Governance Authorities (NJGAs) seeking interoperability with the U.S. STIR/SHAKEN ecosystem.
- 2The framework covers identity verification, governance structure, certificate-management security, and alignment with STI-GA policies, plus ongoing monitoring for continued compliance.
- 3STIR/SHAKEN was mandated domestically by the TRACED Act of 2019 and has since become the foundation for global call authentication efforts.
- 4The move aims to secure cross-border connections and ensure that participating governance authorities maintain sufficient controls to uphold the integrity of interconnected authentication frameworks.
- 5Numeracle will design and implement the assessment process to evaluate NJGAs’ readiness for secure cross-border authentication.
Who's Affected
Analysis
For cybersecurity professionals battling caller ID spoofing, the STI-GA’s move to vet foreign governance authorities before they can interconnect with the U.S. STIR/SHAKEN ecosystem is a direct defense upgrade. It means that international calls claiming to be authenticated will soon be backed by a verified chain of trust—not just a hope that the issuing body has good intentions. The framework’s emphasis on certificate-management security and ongoing monitoring directly addresses the risk of a weak link in the global authentication fabric.
The Secure Telephone Identity Governance Authority (STI-GA) has selected Numeracle to design and implement a comprehensive vetting framework for Non-Jurisdictional Governance Authorities (NJGAs) that seek interoperability with the U.S. STIR/SHAKEN ecosystem. This move, announced on July 23, 2026, marks a pivotal step in extending the call authentication standards mandated by the TRACED Act of 2019 beyond domestic borders. As global adoption of STIR/SHAKEN accelerates, the lack of a consistent cross-border governance mechanism has become a critical vulnerability. The new framework aims to close that gap by establishing rigorous evaluation criteria focused on identity verification, governance structures, certificate-management security, and policy alignment with STI-GA requirements.
The Secure Telephone Identity Governance Authority (STI-GA) has selected Numeracle to design and implement a comprehensive vetting framework for Non-Jurisdictional Governance Authorities (NJGAs) that seek interoperability with the U.S.
The TRACED Act catalyzed the deployment of STIR/SHAKEN within the United States, requiring voice service providers to authenticate caller ID and combat robocalls and illegal spoofing. Now, with international regulators and operators pursuing similar authentication architectures, the need for interoperability is urgent. Without a unified vetting process, a foreign governance authority could introduce systemic risks—ranging from lax certificate issuance to insufficient oversight of service providers—that undermine trust in the entire authentication chain. The STI-GA's selection of Numeracle signals a proactive move to erect a global gatekeeping function that preserves the integrity of the U.S. ecosystem while enabling legitimate international calls to be securely authenticated.
Numeracle, a specialist in call trust and identity management, will lead the development of a multi-faceted assessment process. The framework will scrutinize an NJGA’s legal identity, board and management structure, financial viability, operational resilience, and security controls surrounding the issuance and management of digital certificates. This is not a one-time audit; the program includes ongoing monitoring to ensure continued compliance as threats evolve. By formalizing these requirements, the STI-GA creates a clear pathway for foreign authorities to interconnect, but also sets a high bar that may slow integration for entities with weaker governance. This trade-off between security and speed will be a defining tension as the framework rolls out.
From a market perspective, this development validates Numeracle’s growing role as a critical infrastructure partner in the anti-robocall ecosystem. It also underscores the maturation of STIR/SHAKEN from a domestic regulatory obligation to a global standard. Telecom operators, cloud communications providers, and enterprises that rely on international calling will be directly affected. Those that have already aligned with STI-GA policies stand to benefit from smoother cross-border call completion and enhanced consumer trust, while those outside the framework may face increased scrutiny or blocked calls.
What to Watch
The announcement carries significant implications for cybersecurity and legal compliance professionals. For cybersecurity teams, the introduction of a global vetting framework reduces the attack surface for caller ID spoofing at international interconnection points. It raises the assurance level that incoming authenticated calls are genuinely legitimate, not just authenticated by an unknown authority. For legal and compliance roles, the framework extends U.S. regulatory expectations across borders, creating a de facto international governance standard that may influence regulatory regimes in other countries. It also introduces new contractual and liability considerations for carriers and service providers that interface with vetted NJGAs.
Looking ahead, the STI-GA and Numeracle will need to engage with a broad set of stakeholders, including foreign regulators, international standards bodies like the ITU, and privacy advocates. The framework’s success will hinge on its transparency, adaptability to diverse legal environments, and the willingness of global governance authorities to submit to external evaluation. As 2027 approaches, expect to see the first NJGAs complete the vetting process, setting precedents that will shape the future of global call authentication.
Sources
Sources
Based on 2 source articles- caribbeanherald.comSTI - GA Selects Numeracle to Develop Global Vetting Framework for Cross - Border STIR / SHAKEN GovernanceJul 23, 2026
- jamaicantimes.comSTI - GA Selects Numeracle to Develop Global Vetting Framework for Cross - Border STIR / SHAKEN GovernanceJul 23, 2026
Cite This Page
"2019 TRACED Act Spurs Global STIR/SHAKEN Vetting as STI-GA Taps Numeracle." Cyber Intelligence Brief, August 3, 2026. https://getcyberbrief.com/story/sti-ga-numeracle-stir-shaken-global-vetting-cyber
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |