← All insights
compliance mandates6 min read

CALEA at 31: the technical standard gap no one wants to talk about

The Communications Assistance for Law Enforcement Act was passed in a world where communications meant circuit-switched voice, networks were operated by a small number of regulated telecom operators, and the internet was a research network. The statute's core obligation — that covered entities must build and maintain capability for lawful intercept — has not changed. The network architectures to which that obligation applies have changed beyond recognition. The result is a growing and largely undiscussed gap between what CALEA technically requires and what modern compliance looks like in practice.

What the statute actually says versus what regulators have specified

CALEA imposes a capability obligation: covered telecom operators must have the technical capability to intercept communications as authorised by law, to deliver content and call-identifying information to law enforcement, and to do so without degrading service to non-intercepted users. The statute does not specify how this must be implemented technically — it delegates that to industry standards bodies and, where they fail to produce adequate standards, to the FCC.

The FCC's capability specifications, most recently updated in the early 2000s for broadband, have not been meaningfully updated to address 5G SA core architectures, virtualised network functions, edge computing deployments, or the integration of communications into application-layer platforms. Operators building modern infrastructure are required to comply with a statutory obligation against capability specifications that predate the technology they are deploying.

Where the gap is most acute

Three areas stand out. First, 5G NR non-public networks: private 5G deployments operated under CBRS or licensed spectrum by enterprises are covered entities under some interpretations of CALEA but operate in a regulatory grey zone where no clear capability specification has been issued. Second, network slicing: the CALEA obligation attaches to communications, not to network elements, but the delivery of intercepted content from a specific slice in a multi-tenant core is technically non-trivial and not addressed in current specifications. Third, application-layer OTT services: communications that traverse the carrier network but are delivered as application-layer services remain in disputed CALEA territory despite two decades of regulatory attention to the question.

Each of these is not a small edge case. CBRS private networks are being deployed at scale by enterprises across healthcare, manufacturing, and logistics. Network slicing is a core commercial feature of 5G SA. OTT communications account for the majority of voice and messaging traffic on many networks.

What operators should do in the gap

In the absence of clear specifications, operators have two choices: wait for regulatory clarity and risk enforcement exposure in the interim, or document their interpretive position — what they believe the obligation requires, how they have implemented against that interpretation, and what technical constraints exist — and engage proactively with regulatory staff.

The second approach is more defensible. Regulators generally distinguish between operators who have engaged in good faith with ambiguous requirements and those who have ignored them. A documented interpretive position, reviewed by regulatory counsel and maintained with evidence of implementation, provides meaningful protection even where the technical specification is unclear. It also positions the operator to contribute constructively to the specification development process when the FCC eventually addresses the gaps.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →