Quick answer: If you resell US telecommunications — minutes, numbers, or text messaging — the FCC's CPNI rules apply to you as the carrier of your customers, not to your platform vendor. Devotel Orbit maintains the register where you record the consent decisions and run the annual §64.2009(e) certification lifecycle (draft → certified → filed); the filing itself happens between you and the FCC. The CPNI runbook is the contract-level reference; this post walks the certification as a narrative, day zero to filing.
What CPNI is, and why it binds the carrier/reseller layer
Customer Proprietary Network Information is the data a carrier accumulates while delivering service: call detail records, usage patterns, billing information. The FCC's CPNI rules (47 CFR §64.2001–§64.2011) say that data cannot be used lightly — marketing use requires a notice-and-approval exchange with the customer, and the carrier certifies annually, under an officer's signature, that its procedures protect it.
The binding layer matters here. If you operate as a telecommunications carrier toward your downstream customers — a reseller, a wholesale buyer, a white-label operator — the obligation follows that role, not the brand on your API key. Your customers read you as their carrier. The FCC does too. Orbit's role is bounded on purpose: it keeps the auditable register and the lifecycle machinery, and it deliberately never sends the customer notices (that notice is between you and your customer), never notifies law enforcement on a breach on your behalf, and never files with the FCC for you. The register attests what happened; the decisions stay yours.
The §64.2009(e) lifecycle, phase by phase
The certification is due with the FCC by March 1 of the year after the calendar year it covers, and EB Docket 06-36 tracks the filing. On Orbit, the lifecycle runs as three states, and the register enforces the order: a filing cannot be recorded before a signed certification exists.
Phase 1 — Open (`draft`). An owner or admin opens the certification for the calendar year: the signing officer's name and title, the compliance statement, and the year's counts — the complaint summary (improper-access attempts, improper-disclosure complaints), the law-enforcement notification tally, and what you did about them. One certification per calendar year; a duplicate year is rejected, so the register stays one row per year.
Phase 2 — Consent decisions feed the year's evidence. Independent of the certification row, your §64.2007/§64.2008 consent register keeps the current decision per customer — opted_in, opted_out, pending (the 30-day opt-out window), or not_asked — and the posture summary computes who currently permits marketing use. The certification you sign at year-end certifies the procedures behind exactly these records, so the consent register and the certification wheel are two halves of the same control.
Phase 3 — Certify (`certified`). The officer signs: name, title, the statement, and the explicit compliant: true attestation. This is the legal act — the register's job is to bind the signature to the year's evidence with timestamps.
Phase 4 — File (`filed`). You file with the FCC yourself, then record the outcome: the filing reference (an ECFS number) and the timestamp. The deadline math is computed for you — the attestation returns filed_within_window: true when the filing precedes the March‑1 deadline, and an unfiled certification past it shows as overdue in the summary. Skipping straight to filed is rejected.
A day-zero-to-filing timeline, end to end
Suppose you cover calendar year 2026. A realistic arc:
- 2026-01-05 — Open. Your compliance lead opens the 2026 certification as
draftwith the complaint summary zeroed. The register now holds the year's row; nothing else is due for months. - All year — Record consent decisions. As customers give or decline marketing-use approval — signup opt-ins, the 30-day opt-out notices your team sends — the decisions land in the consent register. The posture summary keeps a live count of
marketing_permitted. - 2026-08-20 — A tightening event. A data-broker attempt is investigated and terminated; the year's
actions_takenand complaint counts are updated as part of the same register of record, so the certification ends the year telling the truth about it. - 2027-02-10 — Certify. With March 1 six weeks out, the officer reviews the draft, signs, and the record moves to
certified— timestamped at the signer's instant. - 2027-02-22 — File. The certification goes to the FCC; the returned ECFS reference is recorded with the filing timestamp. The attestation confirms
filed_within_window: true— certified at 2027‑02‑10, filed at 2027‑02‑22, deadline 2027‑03‑01. - Any time — Export the attestation. A single signed artifact covering the certification, the complaint summary, the law-enforcement count, and the filing timeline — the row that goes into your audit binder when the auditor, or EB, asks.
The failure mode this walkthrough exists to prevent is the register of record arriving at February with nothing in it: no year's row opened, consent decisions living in a spreadsheet or a mailbox, and a March‑1 deadline that was noticed in the wrong month. The lifecycle is visible from day zero precisely so the deadline is never a surprise.
The boundary: Orbit supplies the surface, the carrier files
Certification rests on an ownership line that is worth stating plainly. Orbit maintains the CPNI register — the consent decisions, the certification wheel, the signed attestation — as tenant-owned records. The carrier-side acts stay carrier-side: the customer notices are between you and your customer, the §64.2011 law-enforcement notifications on a breach are yours to make, and the FCC filing is made by you (the register holds its reference and timestamp). Two carve-outs the boundary deliberately preserves, so the evidence stays accurate rather than flattering: Orbit never sends the §64.2008 notice for you, and it never files with the Commission on your behalf.
That is also the right way to read the attestation export: it proves the lifecycle ran — signature, counts, deadline, filing — and says nothing about the lawfulness of the decisions it records. Both belong in your binder; only one is Orbit's to produce.
The runbook is the destination
This post is the narrative walkthrough. The reference — every endpoint, field, state transition, and the attestation response shape — lives in the CPNI docs page, and the full request/response schemas (regenerated from the live API) are under API Reference → Compliance. When a customer-facing attorney, an auditor, or a procurement reviewer asks how you run CPNI certification, the answer is that page, and the register behind it.