Identity
July 2026
The Biggest CPaaS Story of 2026 Isn’t RCS. It’s Identity.
For years, SMS has been the authentication layer of the internet. Every bank login, password reset, healthcare portal, and ride-share app has relied on it. Authentication represents a meaningful portion of enterprise A2P messaging traffic and, by extension, CPaaS revenue.

Last week, AT&T, Verizon, and T-Mobile quietly made one of the most consequential announcements our industry has seen in years.
Together with Aduna, they launched Number Verification—a network API that verifies a mobile number belongs to the device and SIM requesting access, without relying on an SMS one-time passcode.
Many immediately declared:
“SMS OTP is dead.”
I think that’s both right—and wrong.
The real story isn’t the death of SMS. It’s the evolution of trust.
For years, SMS has been the authentication layer of the internet. Every bank login, password reset, healthcare portal, and ride-share app has relied on it. Authentication represents a meaningful portion of enterprise A2P messaging traffic and, by extension, CPaaS revenue.
When all three major U.S. carriers move together toward a network-native alternative, the industry should pay attention.
No, SMS OTP won’t disappear overnight. Enterprises move slowly, and SMS will remain an important fallback for years.
But the direction is clear:
Identity is moving from the messaging layer into the network itself.
At first glance, this looks like a headwind for CPaaS. Fewer authentication messages could mean lower SMS volumes.
I see something different.
The value isn’t disappearing—it’s moving up the stack.
Tomorrow’s communications platforms won’t simply send messages. They’ll orchestrate trusted identity, AI, customer journeys, rich conversations, and commerce.
And AI makes this even more interesting.
Number Verification answers one question:
“Is this the legitimate device?”
The next decade will require answering a much harder one:
“Who—or what—authorized this action?”
As AI agents begin making purchases, changing reservations, and acting on our behalf, proving the phone is legitimate won’t be enough. We’ll need to prove intent.
That’s a much bigger opportunity than replacing SMS passcodes.
My takeaway?
This week’s announcement wasn’t really about authentication.
It was about the beginning of network-native identity.
The companies that thrive over the next decade won’t be those that send the most messages. They’ll be the ones that combine trusted identity, AI, conversation, and commerce into seamless customer experiences.
I think this is one of the most important industry announcements of the year.
What do you think? Is this the beginning of the end for SMS OTP—or simply the next evolution of enterprise communications?