The Federal Floor: TCPA Has No B2B Exemption Either
Much like CAN-SPAM on the email side, the TCPA is sometimes assumed to be a consumer-only statute. It is not. Per Leadium's compliance guide, the TCPA itself carries no business-to-business exemption. What does exist is a separate, narrower rule, the FTC's Telemarketing Sales Rule, which exempts most B2B-to-B2B calls specifically from the national Do Not Call registry requirement. That is a real exemption, but it is a different rule covering a different requirement, and confusing the two is a common and costly mistake for any company assuming its B2B status clears every compliance bar at once.
Business Cell Phones Still Need Consent
The detail that trips up the most SaaS outbound programs, per Leadium's guidance, is that business cell phones still require prior express written consent for autodialed or AI-voiced calls, regardless of the B2B exemption covering the Do Not Call registry specifically. A number being a work cell phone does not, on its own, remove the consent requirement for automated contact. Any outbound program relying on autodialers or AI voice tools needs to treat business mobile numbers with the same consent discipline as consumer numbers, not a relaxed standard.
The National DNC Registry and the Re-Scrub Rule
The national Do Not Call registry holds more than 200 million numbers, per Leadium's data, and calling lists must be re-scrubbed against it at least every 31 days. That re-scrub cadence is not a one-time compliance checkbox, it is an ongoing operational requirement, and a list that was clean 60 days ago is not presumptively clean today. Programs that treat DNC scrubbing as a launch-time task rather than a recurring one are carrying risk they likely do not realize they still have.
Texas SB140: A State Law That Moved Past the Federal Floor
Texas SB140, effective September 1, 2025, is reported by Leadium to narrow permitted calling windows to 9am to 9pm Monday through Saturday and noon to 9pm Sunday, Central time, extend coverage explicitly to texts and images rather than voice calls alone, require a $10,000 surety bond, and allow penalties up to $5,000 per violation with a private right of action. This is a detailed, specific set of figures from a secondary compliance-guide source rather than the primary statute text itself, and given how directly the surety bond and penalty figures affect operating decisions, they are worth confirming against the actual Texas statute before a program finalizes its compliance posture around them.
Other States Moving the Same Direction
Texas is not an outlier, per Leadium's coverage. Florida and Oklahoma run similar damage regimes in the $500 to $1,500 per call range, and Oregon, Virginia, Maine, and Washington all expanded their own "mini-TCPA" statutes during 2025. The pattern across all of them points the same direction: state legislatures are actively narrowing what federal TCPA law leaves open, not leaving the compliance floor where it sat a few years ago, which means a program compliant with federal TCPA rules alone may still be exposed at the state level depending on where its prospects are located.
Why This Matters More for SMS Consent Than for Calling, Given Our Model
VA Horizon's SaaS demo engine runs on SMS conversations handled by Human + AI SDRs, not outbound calling, which changes which pieces of this patchwork matter most. Texas SB140's extension of its rules to texts and images specifically, not just voice calls, is the most directly relevant detail for a text-based model, and it reinforces the same point made in the companion demo confirmation workflows guide: consent has to be captured properly at the start of the conversation and carried through every SMS touch that follows, including confirmation messages, rather than treated as a one-time formality.
What This Means for Vendor Selection
If you are evaluating an outsourced appointment-setting vendor rather than running outbound in-house, consent practice is a fair, specific question to ask before signing anything, not an afterthought to raise after a compliance complaint arrives. Ask directly how consent is captured for the channel the vendor actually uses, whether that is SMS, voice, or email, whether lists are re-scrubbed against the national DNC registry on a real cadence rather than a one-time pass, and whether the vendor can speak specifically to the state-level rules relevant to where your prospects are located. A vendor that cannot answer those questions concretely is a vendor asking you to carry compliance risk you did not agree to. The pay-per-appointment contract red flags and questions-before-signing guides in VA Horizon's shared B2B guide library cover the rest of that vetting conversation in more depth.
What this means for you
- The TCPA itself has no B2B exemption, and business cell phones still require prior express written consent for autodialed or AI-voiced contact regardless of B2B status, per Leadium's guidance.
- Texas SB140, effective September 1, 2025, is reported to extend coverage to texts and images, narrow calling windows, and allow penalties up to $5,000 per violation, figures worth verifying against the actual statute text.
- Florida, Oklahoma, Oregon, Virginia, Maine, and Washington have all moved on similar state-level rules in 2025, meaning federal TCPA compliance alone does not guarantee state-level compliance.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
