Support Legal
Verified RCS · SMS · MMS

RCS compliance checklist

Compliance & Security

Quick answer. A compliant US RCS program needs, at minimum: a registered brand and approved use-case/campaign; a verified RCS sender; a clear opt-in call-to-action with all required disclosures; documented, explicit consent (written for marketing); a confirmation message; easy opt-out with STOP honored within 10 business days; an accessible privacy policy and terms; no prohibited (SHAFT) content; and consent/audit records kept for at least five years. The checklist below is the practical version.

The checklist

  1. Register your brand (KYC) and get each campaign / use case approved through the Campaign Registry and carriers.
  2. Verify your RCS sender so every message carries your name, logo, and verification — never a random number.
  3. Publish a clear call-to-action with brand name, message description, frequency, “msg & data rates may apply,” and opt-out instructions.
  4. Capture explicit opt-in — prior express written consent for marketing; prior express consent for transactional — and record the source, method, and timestamp.
  5. Send a confirmation (opt-in) message, and include opt-out instructions on recurring programs.
  6. Honor opt-outs: treat STOP/QUIT/END/CANCEL/UNSUBSCRIBE/OPT OUT/REVOKE as valid, stop within 10 business days, send only one clarification message.
  7. Link a privacy policy and terms from the opt-in, and use data only for the disclosed purpose.
  8. Avoid prohibited SHAFT content (sex, hate, alcohol, firearms, tobacco) and other restricted categories.
  9. Keep consent and opt-out audit logs for at least five years (FTC TSR).
  10. Follow CTIA Messaging Principles, all four carriers’ rules, and Google RBM policies.

Security

Related questions

How verification, consent, and STOP handling actually work on SimplyRCS. Read the trust page →

← All RCS questions