The definitive TCPA compliance checklist for eCommerce & SaaS in 2026.
Every SMS marketing program that touches U.S. consumers operates under the Telephone Consumer Protection Act. Violations carry statutory damages of $500–$1,500 per message — enough to turn a single non-compliant blast into a seven-figure class action. Use this checklist as an operator-focused reference; pair it with counsel for anything customer-specific.

- Consent must be prior, express, written, and unbundled — pre-checked boxes are the #1 defect.
- Under the 2025 FCC rule, any reasonable revocation ends consent across every marketing program within 10 business days.
- You must keep audit-ready consent evidence for four years — the burden of proof is on the sender.
- Quiet hours (8am–9pm local) apply per recipient time zone, not sender time zone.
- Capture prior express written consent
- Honor revocation immediately
- Respect quiet hours and calling windows
- Maintain audit-ready records
- Use double opt-in for high-risk surfaces
- Sync with DNC and reassigned-number checks
- Operationalize continuous monitoring
- Common defects we see in the wild
- Frequently asked questions
1. Capture prior express written consent
For any marketing SMS or autodialed call under the TCPA, you must obtain prior express written consent before the first message goes out.
Standalone opt-in
The SMS opt-in must not be pre-checked or bundled with an unrelated agreement. A single consent form should not cover multiple sellers.
Clear disclosure
State the seller's name, the type of messages (marketing, transactional, recurring), that consent is not a condition of purchase, and that message and data rates may apply.
Message frequency
Disclose the expected message frequency (e.g. up to 8 msgs/month). Vague or missing frequency language is the most common cited defect in TCPA complaints.
Signed record
Retain a timestamped, verifiable record of the consent — form snapshot, IP, user agent, exact disclosure text, and the phone number entered.
2. Honor revocation immediately
Recipients can revoke consent by any reasonable means. Under 2025 FCC rulemaking, revocation must be honored within 10 business days and cannot be limited to a single keyword.
Accept STOP + reasonable variants
Accept STOP, END, CANCEL, UNSUBSCRIBE, QUIT — plus free-form revocation (e.g. 'please stop texting me'). Do not require an exact keyword.
One confirmation only
You may send one confirmation SMS after opt-out. Any further marketing message is a per-violation risk.
Suppress across programs
A STOP on one campaign must suppress the number across all marketing programs unless the recipient explicitly opted into multiple, separately consented programs.
10 business day cap
Log the revocation timestamp and confirm your ESP applies suppression well inside the 10-business-day window.
3. Respect quiet hours and calling windows
8am – 9pm local time
Marketing calls and texts must land between 8:00am and 9:00pm in the recipient's local time zone.
Time zone by area code
Determine the local time from the recipient's stated address; fall back to area code only when address is unknown.
State-level windows
Several states (FL, OK, WA) restrict windows further. Confirm your ESP supports per-state quiet hours.
4. Maintain audit-ready records
In TCPA litigation, the defendant carries the burden of proving consent. Records must survive four years — the federal TCPA statute of limitations.
Immutable consent log
Store consent events append-only. Include: phone number, timestamp, IP, user agent, exact disclosure text version, source URL, campaign, and the double opt-in confirmation (when used).
Revocation log
Log every STOP and free-form revocation the same way. Include the channel it arrived on.
Retention
Keep consent and revocation evidence for at least four years after the last message sent.
Vendor changes
When you switch ESPs, migrate consent evidence, not just phone numbers.
5. Use double opt-in for high-risk surfaces
Checkout SMS boxes
Checkout and lead magnet forms are the highest-litigated opt-in surfaces. A confirmation reply loop mitigates disputed consent claims.
Purchased and enriched data
Do not send marketing SMS to numbers you did not collect directly with express written consent — even if a data broker labels them opt-in.
6. Sync with DNC and reassigned-number checks
National DNC
Marketing calls (including autodialed) must scrub against the National Do-Not-Call Registry every 31 days.
Internal DNC
Maintain an internal DNC list for anyone who has revoked consent from your company.
Reassigned Numbers Database
Check the FCC Reassigned Numbers Database before dialing older opt-ins. A safe-harbor defense exists only when you can prove the query.
7. Operationalize continuous monitoring
Version your disclosures
Every disclosure text change is a new consent version. Tie each opt-in event to the version live at the moment of collection.
Audit forms on every release
Regressions on checkout forms (a re-added default-check, a missing frequency line) are the most common source of new TCPA exposure. Scan on every deploy.
Board-visible risk score
Track TCPA-specific risk alongside GDPR, WCAG, and CCPA in one exec view so remediation actually gets prioritized.
Common defects we see in the wild
Across thousands of ConsentTensor scans, five defects account for the majority of open TCPA exposure. Fixing these takes hours, not weeks.
- 1Pre-checked SMS opt-in at checkout — plaintiff-firm bait, and disqualifies the consent entirely.
- 2Missing message-frequency disclosure (e.g. no 'up to 8 msgs/mo' line near the opt-in).
- 3STOP handling limited to a single exact keyword instead of accepting reasonable variants and free-form language.
- 4No versioning on the disclosure text — impossible to prove what a user agreed to on a given date.
- 5Marketing sends outside 8am–9pm in the recipient's time zone due to ESP defaults set to sender time zone.
Frequently asked questions
Does TCPA apply to transactional messages?+
Order confirmations, shipping updates, and 2FA fall outside the marketing consent standard — but only if they contain zero promotional content. A shipping SMS that tacks on a discount code converts it into a marketing message and requires prior express written consent.
Do we need double opt-in?+
The TCPA does not require it, but double opt-in is the single strongest litigation defense. It also produces a clean, timestamped confirmation record you can hand to opposing counsel.
What about purchased or enriched phone lists?+
Do not send marketing SMS to numbers you did not collect directly with express written consent. Broker-labeled 'opt-in' data is a leading source of class-action exposure.
How long do we need to keep consent records?+
At least four years after the last message sent — matching the federal TCPA statute of limitations. Some state analogs (like FTSA in Florida) reach further; retain seven years to be safe.
Run this checklist against your live site.
ConsentTensor runs every item above continuously — form disclosures, revocation handling, quiet-hour configuration, and record-keeping evidence — with alerts the moment something regresses.
This checklist provides compliance guidance for informational purposes and is not legal advice. Consult qualified counsel for jurisdiction-specific questions.