To give you the best possible experience please select your preference.
The industry treats regulatory complexity as a tax on growth — a cost to minimise, delay, or push onto whichever partner will absorb it most cheaply. That instinct is backwards, and it's costing operators deals they should be winning. A service provider that has already solved compliance in a given market can launch there faster than a competitor who hasn't started — which makes readiness a speed advantage, not an overhead line. This matters directly for anyone already relying on global wholesale SIP trunking to expand across markets, since the underlying voice infrastructure and the regulatory permission to use it are two separate problems — and only one of them scales on its own.
BLUF: Framing compliance as a cost to control, rather than a launch-speed variable to manage, leads operators to under-invest in exactly the capability that would let them move faster than competitors.
Ask most operators why they haven't expanded into a new market, and "regulatory complexity" comes up early. Rarely do they mean the rules themselves are unreasonable. What they mean is that the process of proving compliance — licensing, registrations, documentation — feels slow and unpredictable. That perception, not the regulation itself, is the actual barrier. And perception is exactly the kind of barrier a well-prepared competitor can turn into an advantage.
Global operators don't face one compliance regime; they face several, each with a different scope, trigger, and enforcement body. Three examples illustrate the range — presented here as regional cases, not as a universal checklist.
The Network and Information Security Directive 2 (NIS2) entered into force in January 2023, with EU member states required to transpose it into national law by 17 October 2024 — a deadline several countries missed, extending enforcement timelines into 2026 in some jurisdictions. It applies to digital infrastructure providers, which includes telecom operators, and notably extends beyond EU borders: a non-EU operator providing critical services into the EU can still fall in scope. Non-compliance carries fines of up to EUR 10 million or 2% of global annual turnover for essential entities, alongside mandatory 24-hour and 72-hour incident reporting windows.
The US Federal Communications Commission (FCC) mandates caller ID authentication through the STIR/SHAKEN framework. Critically, the obligation doesn't stop at providers who have fully implemented it: every voice service provider, regardless of implementation status, must file a Robocall Mitigation Plan in the FCC's Robocall Mitigation Database (RMD). Providers not listed in the RMD have had their traffic blocked by other carriers since September 2021, and annual recertification requirements are tightening further through 2026.
Australia's original Telecommunications Sector Security Reforms, in force since 2018, have been streamlined into the Security of Critical Infrastructure Act via the Telecommunications Security and Risk Management Program (TSRMP) Rules, which commenced on 4 April 2025. Carriers and designated carriage service providers must maintain a written risk management program and demonstrate "competent supervision and effective control" over their networks, with the Australian Communications and Media Authority (ACMA) holding expanded enforcement powers over industry codes.
Strategic Insight: Each of these frameworks requires a different kind of evidence — incident logs for NIS2, traceback cooperation for STIR/SHAKEN, documented risk management for TSRMP — but all three reward operators who can produce it on demand rather than reconstruct it under pressure. Enreach's Call Recording capability supports the audit trail that underpins several of these obligations.
BLUF: The most common objection our partners raise about compliance isn't cost — it's speed, and that perception is usually wrong once the actual comparison is made.
Across the operators and integrators we work with globally, the recurring pushback on compliance work is rarely "it's too expensive." It's "it's too slow." In practice, when licensing, registration, and KYC (Know Your Customer) processes already sit on an existing regulatory footprint, launching a compliant voice service in a new market typically takes weeks, not the several months it takes to build that footprint from zero. The gap between perceived and actual speed is the whole argument for treating compliance readiness as infrastructure, not paperwork.
We haven't observed a consistent regional pattern in how partners approach this — the "too slow" objection surfaces roughly as often from teams in mature European markets as from those expanding into Asia-Pacific or the Middle East. That consistency is itself informative: the friction is structural, not cultural.
Before quoting a customer on a new-market voice deployment, confirm:
Auto-diagnostic: If your team can't answer "how long would it take us to launch compliant voice in a new market tomorrow" in under a minute, compliance is still being treated as paperwork rather than infrastructure.
| Dimension | EU — NIS2 | US — STIR/SHAKEN & RMD | Australia — TSRMP |
|---|---|---|---|
| Primary focus | Cybersecurity risk management, incident reporting | Caller ID authentication, robocall mitigation | Network security, risk management program |
| Enforcement body | National competent authorities, ENISA coordination | Federal Communications Commission (FCC) | Australian Communications and Media Authority (ACMA) |
| Applies beyond national borders? | Yes — non-EU providers serving the EU | Applies to any provider in the US call path | Applies to carriers and designated service providers |
| Core evidence required | Documented risk measures, 24h/72h incident reports | RMD filing, robocall mitigation plan | Written risk management program |
| Maximum penalty | Up to EUR 10 million or 2% of global turnover | Loss of ability to exchange traffic with other providers | Civil penalties, direction powers under the SOCI Act |
NIS2 is the EU's updated cybersecurity directive for critical and digital infrastructure sectors, including telecom. It can apply to non-EU organisations if they provide critical or important services into the EU, so operators serving European customers from outside the bloc should check their exposure.
If your traffic touches the US call path at any point, you likely have Robocall Mitigation Database filing obligations even without full STIR/SHAKEN implementation, since the FCC's "reasonable steps" standard applies broadly across the chain.
TSRMP builds on and streamlines the original 2018 Telecommunications Sector Security Reforms into the Security of Critical Infrastructure Act framework, commencing April 2025, with expanded ACMA enforcement powers rather than replacing the underlying obligations entirely.
Yes, when the licensing, registration, and evidence-gathering work is already in place with an infrastructure partner rather than started from scratch for each new deployment, launch timelines compress from months to weeks.
Within a few weeks of building on an already-compliant regulatory footprint, your team could be quoting new-market voice deployments that a less-prepared competitor simply can't match on speed. Talk to the Enreach for Service Providers team.