CALEA · LAWFUL INTERCEPT
The Communications Assistance for Law Enforcement Act requires telecommunications carriers to build wiretap capability into their networks. Who’s covered, who isn’t, and what everyone else owes law enforcement instead.
A legal team at a messaging platform gets a letter from a police department citing “CALEA obligations” and demanding real-time access to a user’s communications. The team has three questions: what is CALEA, does it apply to us, and what do we actually have to do? The letter doesn’t answer any of them. Often, neither does the officer who sent it.
The Communications Assistance for Law Enforcement Act is a 1994 law that requires telecommunications carriers to build lawful-intercept capability into their networks, so that a court-ordered wiretap can actually be executed. That’s the whole statute in one sentence. Who counts as a carrier, what the capability must do, and what everyone else owes law enforcement instead is where it gets interesting, and where most of the confusion lives.
By 1994, phone networks were going digital and the FBI could see a future where a wiretap order arrived at a switch that couldn’t technically comply. CALEA (47 U.S.C. 1001-1010) was the answer: it obligates carriers to design their networks so that, when served with a lawful surveillance order, they can isolate the target’s communications and deliver them to the named agency, without capturing anyone else’s traffic and without tipping off the target.
Two things CALEA is not. It’s not a surveillance authorization: the legal authority to intercept comes from a Title III wiretap order or its equivalents, signed by a judge. And it’s not a data-request statute: it governs the capability to intercept in real time, not the handing over of stored records. CALEA is plumbing. The court order is the water.
Three categories, set by the statute and the FCC’s 2005 extension:
Covered entities must build and maintain intercept capability, file System Security and Integrity plans with the FCC, and under section 105, protect the intercept function itself from unauthorized use.
This is the answer the letter-waving detective usually has wrong. CALEA explicitly excludes “information services.” In practice, that means most of the modern internet is outside it:
If you run a platform rather than a network, CALEA almost certainly isn’t your statute. But that’s not the end of the conversation, because being outside CALEA doesn’t mean being outside lawful access. It means the legal process arrives through a different door: subpoenas, court orders, and search warrants under the Stored Communications Act, and Title III wiretap orders that carry their own compliance duty even without CALEA’s pre-built plumbing. Non-carriers don’t owe law enforcement a wiretap-ready network. They owe responses to valid legal process, one request at a time.
| CALEA | ECPA / Stored Communications Act | |
|---|---|---|
| Governs | Network capability for real-time intercept | Legal process for communications and records |
| Applies to | Carriers, facilities-based broadband, interconnected VoIP | Essentially every provider holding user data |
| Trigger | Built in advance, used when a wiretap order arrives | A subpoena, court order, or warrant arriving today |
| Volume | Rare (roughly 2,000 wiretap orders a year, nationwide) | Constant (large platforms handle thousands of requests a month) |
The asymmetry in that last row is the point. For almost every company, the real lawful-access workload isn’t CALEA. It’s the daily stream of law enforcement data requests, each of which has to be verified, scoped, and answered correctly.
CALEA’s quietest section became its most controversial. Salt Typhoon, a Chinese state-sponsored group, spent 2024 inside at least eight U.S. carriers, and among the things it reached was the lawful-intercept infrastructure CALEA required carriers to build. The wiretap system became the wiretap target.
The FCC’s response turned into a live policy reversal. In January 2025, the Commission ruled that CALEA section 105 obligates carriers to secure their entire networks against unlawful access. In November 2025, a reconstituted Commission revoked that ruling as unlawful and ineffective, 2 to 1, arguing the statute never stretched that far and that security is better handled through federal-private collaboration. Congress is still arguing about it. For covered carriers, the practical takeaway: the section 105 duty to secure the intercept function itself never went anywhere; what’s contested is whether CALEA makes the FCC a general network-security regulator.
The episode also settled an old argument by demonstration: mandated access infrastructure is itself an attack surface. Anyone building or answering lawful-access systems now designs with that fact on the table.
Here’s where the two halves of this page meet. Carriers handle CALEA capability plus a heavy stored-records docket. Platforms escape CALEA entirely and still face the docket. Either way, the operational problem is identical: a demand arrives claiming legal authority, and someone has to verify the requester is real, judge whether the process is valid and properly scoped, respond through a channel that isn’t an unencrypted inbox, and keep a record that holds up later. Salt Typhoon made the stakes concrete, and fraudulent requests from compromised agency email accounts make them daily.
That layer is what Kodex is. Kodex is the network where law enforcement data requests get handled the way they should: requesters verified before they see anything, requests tracked from arrival to response, every exchange recorded. The statutes decide what you must build and what you must produce. Kodex is where the producing actually happens.
Related reading: Section 314(b) for financial-institution information sharing, and EU E-evidence for cross-border requests.
See how Kodex verifies every requester →Does CALEA apply to apps and websites?
No. CALEA covers telecommunications carriers, facilities-based broadband providers, and interconnected VoIP providers. Messaging apps, social platforms, email providers, websites, and cloud services are “information services” outside CALEA’s scope. They still must respond to valid legal process, such as subpoenas, court orders, and search warrants under the Stored Communications Act.
Is CALEA the same as a wiretap order?
No. CALEA requires covered carriers to build the technical capability to execute intercepts. The legal authority to intercept anyone’s communications comes separately, from a Title III wiretap order or equivalent signed by a judge. CALEA is the infrastructure; the court order is the authorization.
What is a System Security and Integrity plan?
An SSI plan documents a carrier’s policies and procedures for supervising lawful intercepts and preventing unauthorized surveillance. CALEA-covered carriers must file their SSI plans electronically with the FCC before commencing service and refile within 90 days of a merger, divestiture, or policy change.
Does CALEA cover VoIP?
Partly. Since the FCC’s 2005 extension, interconnected VoIP services, meaning those that connect calls to the public telephone network, are covered by CALEA. VoIP services that do not interconnect with the phone network are not.
What happened with CALEA and Salt Typhoon?
Salt Typhoon, a Chinese state-sponsored hacking group, breached at least eight U.S. carriers in 2024 and reached lawful-intercept systems built under CALEA. In January 2025 the FCC ruled that CALEA section 105 requires carriers to secure their networks against unlawful access; in November 2025 the Commission revoked that ruling, calling it unlawful and ineffective. The narrower duty to secure the intercept function itself remains in force.