TCPA SMS Compliance: What U.S. Marketers Must Fix Now

TCPA SMS Compliance: What U.S. Marketers Must Fix Now

Three things determine whether your SMS program survives legal scrutiny in 2026: prior express written consent (PEWC) for every marketing text, completed A2P 10DLC Brand and Campaign registration with The Campaign Registry (TCR), and an opt-out workflow that processes STOP requests fast. Miss any one of these, and you’re exposed to statutory damages, carrier blocking, or both.
Marketing messages require PEWC. Transactional and informational texts (appointment reminders, delivery updates, one-time passcodes) only need prior express consent, a lower bar. Carriers won’t deliver a single message from an unregistered 10DLC number as of February 1, 2025, according to industry reporting on the 2026 compliance landscape. And the FCC now requires opt-outs to be honored using any reasonable method, not just an exact “STOP” keyword, with a federal floor of 10 business days for processing (real-time is the safer practice).
Run this before your next campaign:
- Confirm TCR Brand and Campaign registration is active and approved.
- Audit your opt-in language against PEWC disclosure requirements.
- Export your consent logs and check they include timestamps, IP addresses, and disclosure text.
- Send a live test STOP message and confirm suppression happens immediately, not on a batch job.
Key Takeaways
TCPA SMS compliance in 2026 requires PEWC for marketing texts, active TCR/A2P 10DLC registration, and opt-out processing fast enough to beat the federal 10-business-day floor.
| Point | Details |
|---|---|
| Match consent to message type | Use PEWC for marketing texts and prior express consent for transactional messages only. |
| Register before you send | Complete TCR Brand and Campaign registration, since carriers block unregistered 10DLC traffic entirely. |
| Process opt-outs fast | Honor any reasonable opt-out method and aim for real-time suppression, not the 10-day federal floor. |
| Apply the strictest state rule | Treat Florida, Texas, Oklahoma, Washington, and Maryland statutes as your baseline for any recipient in those states. |
| Keep exportable consent logs | Store timestamp, IP, disclosure text, and capture method so records survive a discovery request. |
Table of Contents
- What TCPA SMS Compliance Actually Requires
- Building Opt-In and Opt-Out Flows That Hold Up in Discovery
- A2P 10DLC, TCR Registration, and CTIA Content Rules
- State Mini-TCPA Laws Add Another Layer of Risk
- What Your Consent Log Needs to Survive a Subpoena
- Your Pre-Send Checklist Before Every Campaign
- How Firmanager Supports Compliant Two-Way Texting
- What Actually Matters in TCPA Compliance Right Now
- Sources
What TCPA SMS Compliance Actually Requires
The TCPA treats a text message as a “call.” That single interpretive fact, confirmed in FCC rulings on telemarketing restrictions, is why every SMS marketing rule in this article exists. If your platform sends an automated or prerecorded-equivalent text to promote a product or service, it falls under the same restrictions as a telemarketing call.
The distinction that trips up most marketing teams is PEWC versus prior express consent. PEWC applies to any message with a marketing or promotional purpose, meaning your opt-in has to be a signed or electronically equivalent agreement that clearly discloses what the recipient is signing up for. Prior express consent, the lighter standard, covers transactional and informational texts like shipping confirmations or appointment reminders. Businesses often collect one kind of consent and then use it for the other, which is one of the fastest ways to end up in a class action.
The legal landscape shifted again in 2026. The Eleventh Circuit vacated the FCC’s “one-to-one consent” rule, which had required a separate consent record for every individual seller. That rule is no longer federally mandated, but don’t treat this as a green light. Carriers and TCR vetting still enforce seller-specific consent expectations in practice, according to legal analysis of the vacatur. The court removed a federal requirement; it didn’t remove the operational reality that carriers reject campaigns lacking clear, traceable consent.
The financial exposure is what makes this more than a compliance checkbox exercise:
- Statutory damages can be substantial per message under the TCPA’s private right of action.
- A single flawed campaign sent to a large number of recipients can generate very high potential exposure before a court even examines actual harm.
- The FCC’s Enforcement Bureau lists unwanted calls and texts among its top consumer complaint categories, and it actively investigates deceptive or unlawful text campaigns.
Plaintiffs’ attorneys know these numbers as well as you do. That’s why sloppy consent records, not malicious intent, drive most TCPA settlements.
Building Opt-In and Opt-Out Flows That Hold Up in Discovery
A consent record only protects you if it can survive a lawyer picking it apart line by line. That means your opt-in disclosure and your opt-out workflow both need to be built for scrutiny, not just for conversion.
Your PEWC disclosure needs these elements every time:
- Sender identity stated clearly, not buried in fine print below a signup button.
- Message types the recipient will receive (promotions, alerts, appointment reminders).
- Frequency disclosure, even if it’s a range like “up to 4 messages per month.”
- A statement that consent is not a condition of purchase, required because you cannot force someone to accept marketing texts to buy something.
- An affirmative action, like an unchecked checkbox the recipient checks themselves. Pre-checked boxes are a documented liability in TCPA litigation.
Pro Tip: Screenshot every version of your opt-in form the day it goes live, and store it with a timestamp. When a lawsuit references a form from 14 months ago, you need proof of exactly what language existed then, not what your form looks like today.
Every opt-in event should generate a log entry with these fields: timestamp in UTC, the source URL where consent was captured, the exact disclosure text shown to the recipient, the IP address, the user agent string, the capture method (web form, point-of-sale, SMS keyword), and the checkbox state at submission. Skipping any one of these fields weakens your defense the moment a plaintiff’s attorney requests records.

Opt-outs work the other direction but demand the same rigor. The FCC’s Second Report and Order on unlawful text messages confirms that recipients can revoke consent using any reasonable method, not just the word “STOP.” A reply saying “please stop texting me” or “unsubscribe” counts. You’re required to send one confirmation message acknowledging the opt-out and then go silent. The federal floor for processing is 10 business days, but real-time suppression is the standard serious SMS platforms build toward, because a 10-business-day lag means you could legally send five more messages to someone who already opted out.
A2P 10DLC, TCR Registration, and CTIA Content Rules
Legal compliance and carrier delivery are two separate risk categories, and this is the section most marketers underestimate. You can have a perfectly compliant consent record and still watch every message get blocked because you skipped carrier registration entirely, a point echoed in operational messaging guidance for U.S. businesses.
Since February 1, 2025, U.S. carriers block unregistered A2P 10DLC traffic outright. Registration happens in two stages with The Campaign Registry:
- Brand registration verifies your business identity, EIN, and industry classification.
- Campaign registration verifies the specific use case (marketing, two-factor authentication, customer care) and the sample messages you intend to send.
Carriers typically request sample message templates, your opt-in capture flow description, and your privacy policy URL during vetting. Approval timelines vary by campaign type and brand trust score, but expect anywhere from a few days to a couple of weeks for standard marketing campaigns.
CTIA’s Messaging Principles and Best Practices govern content through what the industry calls the SHAFT categories: Sex, Hate, Alcohol, Firearms, and Tobacco. Campaigns touching these categories, along with cannabis, debt collection, and certain financial services, get flagged or blocked even when the underlying legal consent is airtight. Carriers apply these filters independently of TCPA law, which means a technically compliant campaign in a restricted vertical can still fail delivery entirely.
TCR trust scores compound this. Higher scores unlock higher throughput and better deliverability, and those scores are influenced by complaint rates, opt-out ratios, and registration completeness. In practice, this creates a carrier-enforced consent standard that goes beyond what federal law technically demands.
State Mini-TCPA Laws Add Another Layer of Risk
Federal TCPA compliance is the floor, not the ceiling. Several states have passed their own telemarketing statutes with tighter windows and steeper penalties, and they apply based on the recipient’s location, not your business address.
- Florida’s Telephone Solicitation Act (FTSA) restricts calling and texting hours and has generated a wave of class actions due to its private right of action.
- Texas SB 140 expanded telemarketing restrictions with penalties that can exceed federal TCPA damages in certain circumstances.
- Oklahoma’s Telephone Solicitation Act (OTSA) mirrors Florida’s structure with its own statutory damages.
- Washington’s Commercial Electronic Mail Act (CEMA) extends beyond email to cover text-based commercial messages.
- Maryland’s Telephone Consumer Protection Act (MTCPA) adds state-level enforcement on top of federal rules.
The practical fix is to apply the strictest applicable rule to every recipient rather than trying to track five separate rule sets manually. Maintain a per-state suppression list, cap message frequency to the most conservative state threshold in your active list, and treat purchased or scraped contact lists as high-risk by default; consent obtained through a third party rarely meets PEWC standards, and state mini-TCPA statutes are where plaintiffs’ firms increasingly file first.
What Your Consent Log Needs to Survive a Subpoena
An audit-defensible consent record isn’t complicated, but it has to be complete every single time, according to documented best practices for consent metadata.
| Field | Why it matters |
|---|---|
| Timestamp (UTC) | Establishes exactly when consent was captured relative to the message sent. |
| Source URL | Proves where the consent form lived, tying it to a specific campaign or page. |
| Disclosure text shown | The exact wording the recipient saw, not the current version of your form. |
| IP address | Corroborates the geographic and device origin of the consent action. |
| User agent | Confirms the device and browser used, useful for disputing bot-generated signups. |
| Capture method | Distinguishes web form, SMS keyword, point-of-sale, or verbal consent. |
| Opt-out events | Timestamped record of every STOP or revocation request and confirmation sent. |
Retain these records in an exportable format (CSV or JSON works fine) and be able to produce them within 30 days if requested during discovery. Pro Tip: Don’t wait for a subpoena to test your export function. Run a dry export every quarter and confirm every field populates correctly, because a broken export during active litigation looks like concealment even when it’s just a bug.
If you use a third-party SMS vendor, ask for proof of TCR registration status, documentation of their CTIA compliance posture, and confirmation that consent logs export in a standard format. A tool built for suppression list hygiene helps here, since duplicate or stale records are a common source of consent-tracking errors.
Your Pre-Send Checklist Before Every Campaign
Run through this sequence before any campaign goes live, prioritized by what actually gets you sued fastest:
- Confirm TCR registration status is active for the specific campaign type you’re sending.
- Audit consent records for the segment you’re targeting, spot-checking a sample for complete metadata.
- Check suppression lists against state-specific opt-outs and federal STOP requests.
- Review timezone restrictions so messages don’t land outside permitted sending hours.
- Run your content through a SHAFT filter to catch category triggers before carriers do.
- Verify your business insurance covers TCPA-related claims, since general liability policies often exclude them.
Beyond the pre-send list, run these validation tests on a recurring basis, not just once at launch:
- Send a live STOP test message monthly and time how fast suppression actually happens.
- Test opt-out across every channel you use (SMS reply, web form, customer service) to confirm they all sync to one suppression source.
- Export your full consent record set and check for missing fields before you need it in a legal context.
- Pull a delivery sample report from your carrier dashboard to catch registration or content issues early.
If resources are limited, fix TCR registration and STOP processing first. Everything else matters, but those two failures cause outright message blocking and immediate legal exposure the fastest. A platform with SLA-driven messaging cadence helps enforce frequency caps automatically instead of relying on manual review.
How Firmanager Supports Compliant Two-Way Texting
Service businesses running field crews, dispatch schedules, and customer follow-ups need SMS that works operationally and holds up legally. Firmanager builds compliance into the workflow rather than treating it as a separate task:
- Two-way texting built into the platform’s customer communication tools, so consent and message history live alongside the job record.
- Automated consent logging that timestamps opt-in events and stores disclosure text without a separate spreadsheet.
- Compliance tracking across HSE requirements and communication workflows in one login.
- Automated suppression so a STOP reply updates instantly across every future campaign, not just the one it replied to.
Service businesses lose more deals to slow, inconsistent follow-up than they ever lose to a compliance fine, but the fastest way to invite that fine is treating texting as an afterthought bolted onto a CRM that wasn’t built for it.
Firmanager’s platform centralizes CRM, work orders, and messaging so consent records don’t live in three disconnected tools. Case studies from service business teams using two-way SMS inside Firmanager will be added here as they become available.
What Actually Matters in TCPA Compliance Right Now
Most compliance guides treat TCPA as a legal problem to solve once with a lawyer-approved checkbox. That’s outdated thinking. The Eleventh Circuit’s vacatur of the one-to-one consent rule proves the legal ground keeps shifting, but carrier enforcement through TCR vetting has become the more consistent, day-to-day constraint on your program.

The conventional advice, “get consent and you’re covered,” undersells how much of this risk now lives in operational execution rather than legal theory. A business can have flawless consent language and still get blocked for skipping registration, or get sued because their opt-out took nine days when a plaintiff’s attorney argued it should have taken zero.
Prioritize the boring stuff first: registration status, export-ready logs, and a STOP flow you’ve actually tested. Legal nuance matters, but it rarely bankrupts a business as fast as a broken suppression list does.
— KaiosMedia
Sources
- Targeting and Eliminating Unlawful Text Messages — Federal Register
- Telephone Consumer Protection Act
- Beancount
- FCC Enforcement Bureau priorities — Unlawful communications
Recommended
Run your whole business in one place
CRM, quotes, work orders, invoicing, expenses, HR and HSE — one login, every device. Free-forever plan.
Start free →