The traceback rules are really what did that but I think those were in the same bill that mandated STIR/SHAKEN. STIR/SHAKEN just makes spoofing caller ID more difficult.
Are the provisions of STIR not necessary for the traceback rules to be applicable?
My understanding is that without STIR a gateway acting in good faith can't definitively identify malicious traffic, and a gateway acting in bad faith can claim any malicious traffic they forward appeared legitimate.