The FCC released new rules intended to increase security against cyber attacks to broadcast program streams. Broadcasters must comply with the new FCC rules by September 29, 2026. The new rules establish three requirements designed to increase cybersecurity, and will apply to any device in the signal chain that is connected to the internet, which includes EAS, automation systems, processors, STL, RDS encoders, and transmitters:

  • specified password hygiene measures;
  • prompt testing and installation of security patches and upgrades; and
  • limiting remote access via network firewalls or “comparable network segmentation.”

The FCC order states that default passwords for devices must be changed prior to any use to broadcast to the public. Passwords used must employ a minimum of 15 characters, must not use dictionary words, and must not be reused for other accounts, equipment, applications, and services that the station uses. Passwords must also be changed whenever a station “has reason to believe that the password has been compromised.”

The FCC allows stations “to use alternative authentication measures that are reasonably sufficient to mitigate the risk of unauthorized access,” such as single- or multi-factor authentication. These other methods may be utilized as an alternative to the password requirements so long the methods are “equally or more secure.”  The 15-character password requirement has raised some industry concerns because some equipment may not accept such a long string. When in doubt consult your communications attorney for guidance. If something cannot comply, or you believe the steps you have taken meet the requirement in another way, be sure to document that in station records.

Critical to EAS security, the new rules require stations to “install security patches and security-related software and firmware updates issued by equipment manufacturers promptly after those patches or upgrades become available.” Stations have the flexibility to test a patch or upgrade to ensure that it does not introduce performance issues, provided that “the testing begins promptly and is completed in a timeframe that is consistent with industry best practices.”

Securing EAS and other vulnerable equipment on a private network inaccessible to the public internet EAS is crucial to guard against malicious attacks. Consequently, the new rules require stations to “use a network firewall or comparable network segmentation practice that limits remote management access to authorized devices and authorized users.”

The Legal Perspective article in the August 2026 The Signal provides more details about the FCC Order establishing these new rules.


This article is based on the Legal Perspective column in The Signal August 2026 issue.

The post FCC Adopts New EAS Cybersecurity Rules appeared first on The Society of Broadcast Engineers.