TCPA and SMS Compliance for B2B Sales Outreach: What Changed in 2026
TCPA and SMS Compliance for B2B Sales Outreach: What Changed in 2026
Photo by Mika Baumeister on Unsplash
Quick Answer: TCPA and SMS compliance for B2B sales changed significantly in 2026. The FCC's new rules require explicit prior express written consent for most SMS marketing, even in B2B contexts. Penalties range from $500-$1,500 per unsolicited message. Below, we break down what changed, the new consent requirements, how the rules differ by company size and industry, the mistakes that get sales teams sued, and a 7-step compliance checklist for B2B sales teams using SMS outreach.
On This Page
- What Is the TCPA?
- What Changed in 2026
- B2B vs B2C: Different Rules
- Consent Requirements
- Common Mistakes B2B Teams Make
- Compliance by Company Size and Industry
- The 7-Step Compliance Checklist
- A 30-Day Rollout Plan
- Penalties for Non-Compliance
- Frequently Asked Questions
What Is the TCPA?
The Telephone Consumer Protection Act (TCPA) is a US federal law enacted in 1991 to restrict telemarketing calls and SMS messages. It was written for an era of auto-dialers and fax blasts, but courts and the FCC have steadily extended it to cover text messages, because a text sent by an automated platform to a wireless number is treated the same way a robocall is: an intrusion the recipient didn't ask for, delivered to a device they pay for and carry everywhere.
Key provisions:
- Prior express written consent required for marketing calls/SMS to wireless numbers.
- Do-Not-Call (DNC) list compliance — check the national DNC registry before calling.
- Opt-out mechanism — honor opt-out requests within 10 business days.
- Identification — identify yourself and your company in every message.
- Time restrictions — no calls/SMS before 8am or after 9pm (recipient's local time).
The TCPA is enforced by the FCC, state attorneys general, and private plaintiffs (who can sue for $500-$1,500 per violation). That last enforcement channel is the one that actually keeps sales leaders up at night. The FCC has limited staff and pursues a small number of high-profile cases. State AGs move faster but still focus on the worst offenders. Private plaintiffs — often represented by law firms that specialize in nothing else — file thousands of individual and class-action suits every year, and they don't need to prove they were harmed beyond receiving the message. Because the TCPA is a strict-liability statute in most respects, "we didn't mean to" and "we thought we had consent" are explanations, not defenses. The law cares about what you can document, not what you intended.
It's also worth understanding why the statute has teeth for B2B outreach specifically. Unlike many consumer-protection laws, TCPA doesn't carve out an exception for messages sent to a work phone number, a company-issued mobile device, or a decision-maker's direct line. The wireless number is the trigger, not the relationship. That single design choice is the reason B2B sales and marketing teams — who spent years assuming "business communications" were categorically different from consumer spam — now have to treat SMS outreach with the same rigor as a consumer marketing team would.
What Changed in 2026
In January 2026, the FCC implemented significant updates to TCPA/SMS rules:
1. Explicit Consent Required for All SMS Marketing
Before: Implied consent (e.g., existing business relationship) was sometimes sufficient. After: Explicit prior express written consent is required for ALL SMS marketing, including B2B.
In practice, this closes the loophole sales teams used to rely on: "they gave us their number on a form, so we can text them." A phone number captured for one purpose (say, a demo booking) no longer implies consent for a separate purpose (ongoing SMS nurture). Each use case — appointment reminders, marketing nurture sequences, promotional blasts — increasingly needs its own, purpose-specific consent trail rather than one blanket "we have their number" assumption.
2. One-to-One Consent Rule
Before: A consumer could consent to receive messages from "Company X and its marketing partners." After: Consent must be specific to one sender at a time. "Partners" consent language is no longer valid.
This one matters enormously for B2B teams that buy or rent contact lists, or that run co-marketing campaigns with partners and pool leads. A shared consent form that lists ten "marketing partners" in fine print no longer transfers a usable right to text that contact. If your list vendor's consent language wasn't captured specifically naming your company, you don't have consent — full stop, regardless of how the vendor's contract with you is worded. This is the single biggest reason to treat every purchased or partner-sourced list as unverified until you can trace the actual consent record.
3. Revocation Rights
Before: Consumers could opt out, but the process was sometimes unclear. After: Consumers can revoke consent at any time, through any reasonable means (e.g., "STOP," "unsubscribe," verbal request). Revocation must be honored within 10 business days.
The "any reasonable means" language is deliberately broad. A recipient doesn't have to use your designated STOP keyword — a reply that says "please don't text me again," a verbal request on a follow-up call, or even an email to a different address than the one that sent the text can all count as valid revocation. That means your suppression logic has to be broader than a simple keyword filter; someone on your team needs to be watching for revocation intent in free-text replies, not just exact-match "STOP."
4. Record-Keeping Requirements
Before: No specific record-keeping requirements. After: Businesses must maintain records of consent for at least 5 years, including:
- Date and time of consent
- Method of consent (web form, verbal, written)
- Specific phone number consented
- Specific sender consented to
Five years is a long window for a sales org that changes CRMs, swaps SMS vendors, or gets acquired. The practical implication is that consent records need to live somewhere durable and exportable — not buried in a form-tool's internal database that gets deprovisioned when a subscription lapses. Treat consent records the way you'd treat signed contracts: something you could hand to outside counsel on 48 hours' notice, years after the fact.
5. AI-Generated Messages
Before: No specific rules for AI-generated calls/SMS. After: AI-generated calls/SMS are subject to the same TCPA rules as human-generated messages. Consent is still required.
This closes an argument some outreach platforms tried to make — that a message drafted or personalized by an AI model, rather than typed by a human SDR, sat outside the statute's original intent. It doesn't. The rule is content- and channel-based, not author-based. If an AI-personalized SMS lands on a wireless number without valid consent, it's treated exactly like a manually typed one.
6. Penalties Increased
Before: $500-$1,500 per violation. After: $500-$1,500 per violation, with annual inflation adjustments. As of 2026, the maximum is $1,758 per unsolicited message.
Because the adjustment compounds annually and applies per message (not per campaign, not per recipient), the exposure scales linearly with list size in a way that catches sales leaders off guard. A "small" pilot campaign to a few hundred purchased numbers can still cross six figures in theoretical exposure before anyone notices a pattern of complaints.
B2B vs B2C: Different Rules
TCPA rules apply differently to B2B and B2C, though the gap narrowed sharply in 2026:
B2B SMS (Stricter in 2026)
- Consent: Required for all SMS marketing (even B2B).
- DNC list: Businesses must still check the DNC list, but the FCC has clarified that B2B contacts can be exempt if they have an existing business relationship.
- Opt-out: Must be honored within 10 business days.
- Identification: Must identify yourself and your company.
- Message content: Marketing and promotional content is treated the same as consumer marketing — a discount code, a "book a demo" CTA, or a product announcement all count as marketing, not "informational."
- Frequency: No statutory cap on message count, but excessive frequency is a factor plaintiffs' attorneys and the FCC both weigh when evaluating whether a pattern of messaging looks like harassment rather than legitimate outreach.
- Litigation exposure: B2B lead lists are frequently shared, scraped, or enriched from third-party data providers, which raises the odds that "your" list actually contains numbers you never captured consent for directly — a common source of B2B TCPA suits.
B2C SMS (Always Strict)
- Consent: Required for all SMS marketing.
- DNC list: Must check before calling/texting.
- Opt-out: Must be honored within 10 business days.
- Identification: Must identify yourself and your company.
- Message content: Same strict-liability treatment as B2B in 2026 — there's no separate lighter-touch category for consumer marketing texts.
- Frequency: Consumer-facing programs are more likely to face state-level frequency caps layered on top of federal TCPA rules (for example, some states impose their own telemarketing-specific statutes with additional restrictions).
- Litigation exposure: Consumer plaintiffs' firms actively monitor major brands for TCPA violations because settlements are well-publicized and recruiting class members is straightforward.
Key change for 2026: B2B is no longer exempt from explicit consent requirements. If you're texting a business contact's mobile number for marketing purposes, you need their prior express written consent. The historical assumption that "this is a business number, not a personal cell, so different rules apply" has essentially collapsed — the FCC looks at whether the number is wireless, not who owns the device or whose logo is on the recipient's email signature.
Photo by Brett Jordan on Unsplash
Consent Requirements
To comply with TCPA in 2026, you need prior express written consent for SMS marketing. Here's what counts as valid consent, and what a compliant capture flow actually looks like end to end.
Valid Consent Methods
- Web form with checkbox: A clear, unchecked checkbox (or pre-checked with disclosure) on a web form that says "I agree to receive SMS messages from [Company] at the phone number provided."
- Signed written agreement: A physical or digital document that explicitly authorizes SMS messages.
- Email consent: An email from the recipient explicitly authorizing SMS messages (with their phone number included).
- Verbal consent: Recorded verbal consent (with disclosure that the call is being recorded).
What a Compliant Consent Capture Flow Looks Like
Most B2B teams overthink the mechanics and underthink the documentation. A defensible flow generally has four parts:
- Disclosure before the checkbox. The recipient sees, in plain language, who will text them, roughly how often, and that message/data rates may apply — before they take the action that generates consent.
- An affirmative action. Checking a box, replying with a specific keyword, or signing a form — something that can't be explained away as accidental or assumed.
- A timestamped, attributable record. The system that captures the action logs the exact time, the exact phone number, the exact sender named, and (for web forms) the submitting IP address.
- A confirmation loop. The best-practice pattern — and increasingly the de facto expectation — is to send one confirmation message asking the recipient to reply to activate the subscription, which also happens to generate a second, independent proof point of consent.
Invalid Consent Methods
- Pre-checked boxes (without disclosure)
- Implied consent (e.g., "By providing your phone number, you agree to receive SMS")
- Bundled consent (e.g., "I agree to receive messages from Company X and its partners")
- Third-party consent (e.g., a partner providing your phone number without your knowledge)
- Inference from unrelated activity (e.g., treating a phone number left on a support ticket, an event badge scan, or a business card exchange as marketing consent — none of these are "prior express written consent" for SMS marketing purposes)
- Silence or non-response (e.g., sending a first message that says "reply STOP to opt out" and treating non-reply as consent — consent has to be affirmative and prior, not assumed by default)
Common Mistakes B2B Teams Make
Even sales and marketing teams who know the rules on paper trip over the same handful of practical mistakes:
- Treating enriched or purchased data as pre-consented. A data enrichment or intent-data vendor can tell you a prospect's mobile number with high confidence — but confidence in the number is not the same as consent to text it. Enrichment gives you accurate contact data; it does not give you a legal basis to message that channel.
- Reusing a phone number captured for one purpose across every sequence. A number collected during a support interaction, an event registration, or a free-trial signup often ends up in a general outbound cadence because it's sitting in the same CRM field as everything else. Purpose-specific consent means purpose-specific usage.
- Assuming "existing customer" equals "consented." An existing business relationship can support certain narrow exemptions (informational, transactional messages), but it doesn't automatically authorize promotional SMS. Teams frequently conflate "we've done business with them" with "they said yes to texts."
- Letting SDRs text from personal or unregistered numbers. When individual reps text prospects from personal cell phones or ad hoc numbers outside your compliance and carrier-registration system, you lose the audit trail entirely — and you lose the ability to honor opt-outs centrally, because a STOP sent to one rep's number doesn't suppress the contact everywhere else.
- Not cross-suppressing across channels. A prospect who unsubscribes from email is not automatically suppressed from SMS, and vice versa, unless your systems are wired together. A contact who explicitly says "stop texting me" but keeps getting emailed isn't a TCPA violation on its own, but it's a signal your suppression logic has gaps — and gaps compound into bigger compliance failures over time.
- Forgetting that forwarded or transferred leads carry no new consent. If a lead is handed from a BDR team to an AE, from a marketing campaign to a sales sequence, or from a reseller to your team, the original consent scope travels with the lead — it doesn't reset or expand just because a different team or tool is now sending the message.
- No process for revocation via free text. Automating "STOP" keyword handling is table stakes; the mistake is not also training reps to recognize and log revocation language that arrives as a normal reply, like "please remove me" or "wrong number, stop contacting me."
Compliance by Company Size and Industry
TCPA exposure and the practical steps to manage it look different depending on how a company is built and sells.
Early-Stage Startups (1–20 person go-to-market team)
Early-stage teams tend to run SMS through whatever tool a founder or first SDR picked up quickly, often with consent capture as an afterthought. The risk here isn't usually willful disregard — it's that nobody owns compliance as a job function, so consent records live in scattered spreadsheets or aren't captured at all. The fix at this stage is process, not headcount: pick one SMS-capable outreach platform with built-in consent logging, route every phone number through the same capture flow, and designate one person (even part-time) as the owner of the suppression list.
Growth-Stage SMBs (20–200 person GTM org)
This is where TCPA risk actually peaks in a lot of organizations, because outbound volume is high enough to attract attention but process maturity hasn't caught up. Multiple SDR pods often run semi-independent sequences, contact data gets pulled from several enrichment and list-building tools, and partner or co-marketing lists start blending into the CRM. The priority here is centralizing consent and suppression logic in one system of record so that no individual rep or pod can text a number the broader org has already suppressed.
Enterprise Sales Organizations
Larger B2B sellers usually have legal and RevOps involved, but face a different problem: scale and channel sprawl. A large enterprise might run SMS through a dedicated marketing automation platform, a separate SDR engagement tool, and a customer success platform for renewals — three systems that each think they own the "can we text this number" decision. The practical fix is a single, centrally governed consent and suppression database that every downstream tool checks before sending, rather than three siloed opt-out lists that never sync.
Regulated or High-Litigation-Risk Industries
B2B sellers in financial services, healthcare-adjacent technology, debt collection-adjacent software, and legal services tend to face closer scrutiny — both because their prospects are more likely to know their rights and because plaintiffs' firms specifically watch these verticals. If you sell into these industries, or your own company operates in one, err toward the stricter end of every judgment call in this guide: explicit double opt-in, longer-than-required record retention, and a documented internal review of every SMS template before it goes live.
Agencies and Outsourced SDR Teams
If your SMS outreach runs through an agency, an outsourced SDR shop, or a fractional sales team, the consent obligations don't transfer to the vendor — they stay with the company whose product is being marketed, and often extend to the vendor as well (both can be named in a suit). Any contract with an outsourced outreach partner should specify exactly how consent will be captured, stored, and made available to you, and should give you audit rights over their suppression list.
The 7-Step Compliance Checklist
Here's a step-by-step checklist to ensure your B2B SMS outreach is TCPA-compliant in 2026:
Step 1: Audit Your Current SMS Practices
Review all current SMS campaigns and identify:
- Which contacts you're texting
- How you obtained their phone numbers
- Whether you have documented consent
- Whether you're honoring opt-outs promptly
Go deeper than a surface pass. Pull a sample of at least 100 contacts currently in active SMS sequences and manually trace each one back to its consent source. If you can't find a consent record for a contact within a few minutes of looking, treat that as a signal the whole segment needs review, not just that one record. Document the audit itself — the fact that you performed a systematic review is evidence of good-faith compliance effort if you're ever investigated.
Step 2: Update Your Consent Forms
Ensure all web forms, signup pages, and lead capture mechanisms include:
- A clear, specific consent checkbox for SMS
- Disclosure of the sender's identity
- Disclosure of message frequency
- Disclosure of message/data rates
- A link to your privacy policy
Audit every form on every property that could feed your SMS sequences — not just your primary demo-request form, but webinar registrations, gated content downloads, event sign-ups, and any embedded forms partners host on your behalf. Inconsistent consent language across forms is one of the most common gaps found during compliance reviews.
Step 3: Implement Double Opt-In
For maximum compliance, implement double opt-in:
- User submits phone number via web form.
- System sends a confirmation SMS: "Reply YES to confirm you want to receive messages from [Company]."
- User replies YES.
- System marks the contact as opted-in.
Double opt-in costs you some top-of-funnel volume — not everyone replies to the confirmation text — but the contacts who do confirm are higher-intent, more likely to engage, and dramatically reduce your legal exposure. Treat the drop-off between single and double opt-in as the true cost of doing SMS outreach safely, not as a conversion problem to "fix" by removing the confirmation step.
Step 4: Maintain Consent Records
Keep records of all consent for at least 5 years:
- Date and time of consent
- Method of consent
- Phone number consented
- Sender consented to
- IP address (for web consent)
Store these records somewhere that survives tool changes — a dedicated compliance database, a data warehouse table, or at minimum a regularly exported and archived spreadsheet with version history. Losing consent records because a vendor contract lapsed is treated the same, legally, as never having captured consent at all.
Step 5: Honor Opt-Outs Immediately
Implement a system to process opt-outs within 10 business days (ideally immediately):
- "STOP" keyword auto-reply
- Manual opt-out processing
- Suppression list maintenance
- Cross-channel opt-out (if they opt out via email, suppress SMS too)
Immediate, automated processing is worth the engineering investment even though the statute technically gives you 10 business days — a contact who texts STOP and gets another message three days later because a batch job hasn't run yet is a documented violation and a very sympathetic plaintiff.
Step 6: Check the DNC List
Before sending SMS to any contact, check the national Do-Not-Call registry (free at donotcall.gov). For B2B contacts with an existing business relationship, you may be exempt, but document the relationship.
"Document the relationship" means more than a mental note — capture what the relationship is (existing customer, active opportunity, prior signed contract) and when it started, so you have something concrete to point to if the exemption is ever challenged.
Step 7: Train Your Team
Ensure your sales and marketing teams understand:
- TCPA requirements
- Consent collection best practices
- Opt-out processing
- Penalties for non-compliance
Training works best as a recurring exercise, not a one-time onboarding slide deck. New SDRs join, tools change, and rules get updated — a quarterly refresher, paired with real examples of what a compliant vs. non-compliant message looks like, keeps the policy from decaying into something only the compliance owner remembers.
A 30-Day Rollout Plan
If you're starting from scratch — or realize your current SMS program has gaps — here's a practical sequence for getting to a defensible compliance posture within a month:
Week 1 — Audit and Freeze: Pause any SMS sequences you can't immediately verify have documented consent. Run the audit from Step 1 above. Inventory every tool currently capable of sending SMS on your company's behalf.
Week 2 — Fix Capture: Rewrite consent language on every form and signup flow. Implement or verify double opt-in on your primary SMS capture points. Stand up a centralized suppression list if one doesn't already exist.
Week 3 — Fix Records and Routing: Migrate or export historical consent data into a durable, exportable store. Wire cross-channel suppression so an opt-out in one channel suppresses the contact everywhere. Restrict who and what can send SMS to contacts outside the centralized system.
Week 4 — Train and Resume: Run compliance training for every SDR, AE, and marketer who touches SMS. Resume paused sequences only for segments with verified consent. Schedule a recurring quarterly audit going forward.
Penalties for Non-Compliance
TCPA penalties are severe:
| Violation | Penalty per message |
|---|---|
| Unsolicited SMS without consent | $500-$1,500 |
| Failure to honor opt-out | $500-$1,500 |
| Calling/SMS before 8am or after 9pm | $500-$1,500 |
| Failure to identify yourself | $500-$1,500 |
| Willful violation | Up to $10,000 |
Real examples:
- Dish Network (2017): $280M class-action settlement for TCPA violations.
- Capital One (2024): $190M settlement for robocall violations.
- Walmart (2025): $45M settlement for unsolicited SMS.
The cumulative cost of TCPA violations can be devastating. A single campaign that texts 10,000 contacts without consent could result in $5M-$15M in penalties.
Beyond the headline settlement figures, there are second-order costs that don't show up in a penalty table. Litigation discovery in a TCPA case typically requires producing every consent record, every message log, and every suppression-list change for the period in question — a process that's manageable if your records are centralized and painful (sometimes impossible) if they're scattered across tools and spreadsheets. Insurers who write technology E&O and cyber policies increasingly ask about TCPA/SMS compliance posture during underwriting, and a documented compliance program can materially affect premiums and coverage terms. And reputational cost compounds separately from legal cost: a public TCPA settlement is exactly the kind of story a competitor's sales team will bring up on a call with your prospects.
How MisarReach Helps with TCPA Compliance
MisarReach includes built-in TCPA compliance features:
- Consent tracking: Automatically tracks consent for each contact.
- Opt-out suppression: Immediately suppresses contacts who opt out.
- DNC list checking: Checks the national DNC registry before sending.
- Time restrictions: Prevents SMS from being sent outside 8am-9pm.
- Audit trail: Logs all SMS activity for compliance documentation.
In practice, these features are designed to solve the exact gaps described above. Because consent tracking is attached to the contact record rather than living in a separate spreadsheet, a rep building a new sequence can see at a glance whether a contact has documented SMS consent before adding them — rather than discovering the gap after a message has already gone out. Suppression is centralized across every sequence and every rep, so a STOP reply captured through one campaign automatically protects that contact everywhere else in the platform, including sequences run by a different team. And because the audit trail captures the full history — consent event, every message sent, every reply received, and every suppression change — a compliance review or a discovery request becomes an export rather than a fire drill.
For teams running SMS alongside email and LinkedIn touches, the same underlying suppression logic applies across channels within the platform, which is one of the more common gaps described in the "Common Mistakes" section above — an opt-out in one channel not propagating to the others.
Related Reads
Frequently Asked Questions
Is SMS marketing legal for B2B in 2026?
Yes, but only with prior express written consent. The 2026 FCC rules removed the B2B exemption for SMS marketing consent.
What is prior express written consent?
A clear, documented agreement from the recipient to receive SMS messages from a specific sender. It must be obtained before the first SMS is sent.
How long must I keep consent records?
At least 5 years, per the 2026 FCC rules. Records must include date, time, method, phone number, and sender.
What happens if I text someone without consent?
Penalties range from $500-$1,500 per unsolicited message. A single campaign can result in millions of dollars in penalties.
Can I text a business contact without consent?
No. The 2026 rules require prior express written consent for all SMS marketing, including B2B contacts.
How do I honor opt-out requests?
Implement a system that processes opt-outs within 10 business days (ideally immediately). Common methods: "STOP" keyword auto-reply, manual opt-out processing, suppression list maintenance.
Do I need to check the DNC list for B2B SMS?
Yes, but B2B contacts with an existing business relationship may be exempt. Document the relationship to support the exemption.
What is the penalty for TCPA violations?
$500-$1,500 per unsolicited message, with annual inflation adjustments. As of 2026, the maximum is $1,758 per message. Willful violations can be up to $10,000 per message.
Does buying a contact list from a data provider give me consent to text those numbers?
No. A data or enrichment provider supplying an accurate phone number does not transfer consent to text that number. Consent has to be captured directly for your company, for SMS specifically, and you should assume a purchased or enriched list has zero SMS consent coverage unless you can trace an actual consent record for each number.
Is a reply to a cold email enough consent to follow up by SMS?
No. Replying to an email establishes engagement on that channel, not consent for a different channel. SMS consent needs its own explicit, documented opt-in — you can certainly ask for it in the email reply thread, but the ask and the affirmative response both need to happen before you text.
1 followers

Comments
Sign in to join the conversation
No comments yet. Be the first to share your thoughts!