← All insights
compliance mandates6 min read

CALEA at 30: Why broadband LI compliance is still a patchwork

Congress enacted CALEA in 1994 to ensure that as telecommunications networks went digital, law enforcement retained the technical capability to conduct court-authorised intercepts. Thirty years later, the law remains on the books — but the networks it was written to govern bear almost no resemblance to the networks telecom operators actually operate. The result is a compliance landscape where every operator has CALEA obligations, and almost no two operators meet them the same way.

CALEA's broadband extension: what the 2006 order actually required

In 2006, the FCC extended CALEA's reach to cover providers of two-way interconnected VoIP services and broadband internet access service. The extension was significant: it brought a new category of operator under the law's intercept mandate for the first time. What it did not do was establish a technically precise standard for what broadband LI compliance actually looked like.

Unlike the 1994 statute — which had the benefit of a relatively uniform PSTN architecture to work with — the 2006 extension inherited a fragmented ecosystem. Cable operators, DSL providers, fixed wireless ISPs, and fibre deployments all have different network architectures, different equipment vendors, and different traffic management approaches. The FCC's order defined the obligation. It did not define the implementation.

The VoIP and VoLTE intercept gap

VoIP intercept alone presents a multi-option problem. Telecom operators can perform passive interception on the signalling and content interfaces of their IMS network, use active X interfaces on P-CSCF and S-CSCF elements, or deploy passive probes on the packet gateway interfaces. Each option has different scaling characteristics, different security implications, and different coverage for edge cases.

VoLTE roaming makes the problem significantly harder. When a subscriber is roaming on a visited network using S8 Home Routing — the de facto standard for VoLTE roaming — the signalling terminates at the home network IMS while the call content may traverse only the visited network. This means neither the home nor the visited operator has complete access to both signalling and content at a single intercept point. Satisfying regulatory requirements in this scenario requires coordination between operators that most compliance frameworks were not built to handle.

Probe architectures: coverage versus security risk

Passive probes connected to S5/S8 or SGi interfaces can intercept GTP-encapsulated VoLTE traffic in the visited network. They can decapsulate GTP, interpret SIP/RTP content, and deliver intercept output in standardised formats. From a coverage standpoint, probes are effective.

The security tradeoff is real, however. Passive probes that aggregate traffic at a network boundary create exactly the kind of intercept collection point that sophisticated adversaries — as Salt Typhoon demonstrated — will target. A probe-based LI architecture that is not itself secured to modern standards introduces the same class of vulnerability that CALEA was designed to give law enforcement access to. The tool becomes the attack surface.

Thirty years of CALEA, and the standard hasn't kept up

The networks of 2024 bear almost no resemblance to those CALEA was designed for. Network function virtualisation, 5G network slicing, edge computing deployments, and end-to-end encryption at more layers of the stack have all fundamentally changed where intercept is technically feasible and what it actually captures.

5G network slicing, in particular, creates a new class of compliance question: if a target's traffic is isolated in a network slice, what constitutes compliant intercept? The CALEA framework provides no answer. Neither do the current FCC rules. Telecom operators operating 5G infrastructure are carrying obligations that were written for a circuit-switched world and have not been meaningfully updated to address the architecture they are actually running.

What modern broadband LI architecture actually requires

The gap between CALEA's regulatory text and modern network architecture is not going to close through FCC rulemaking alone. Telecom operators need to make implementation decisions now, under existing obligations, against networks the law was not written to anticipate.

  • Probe-free intercept approaches where signalling redirection can be used to route target traffic through intercept-capable elements without creating persistent aggregation points.
  • S8HR-aware delivery that coordinates between home and visited network to ensure complete IRI and content delivery for roaming intercepts.
  • Software-defined LI management that can adapt to 5G slice architectures without requiring hardware-based probe deployment in each slice.
  • Continuous compliance assessment against current network configuration — not against a static baseline established at initial deployment.
  • Standards participation to shape the next round of technical requirements before they become retroactive compliance obligations.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →