New FCC Security Obligations Must be Implemented by Sept. 29
posted on 8.11.2026The FCC published its order requiring certain measures to secure stations’ program chain in the Federal Register on July 31. It’s intended to enhance the security of the nation’s Emergency Alert System (EAS) by protecting stations’ EAS equipment as well as their program chain.
The move starts a 60-day clock for broadcasters to implement stronger passwords and firewalls, as well as update software and hardware, to protect a station from malicious actors who might hack on-air programming and send false EAS alerts, for example. The deadline to implement the measures is Sept. 29.
“By that date, the FCC requires that broadcasters have strong passwords for any part of their program chain that is connected to the internet, that they have the latest security updates installed in all hardware and software, and that they put all access to their program chain behind a firewall,” said attorney David Oxenford with TAB Associate member law firm Wilkinson Barker Knauer.
“The first obligation is straightforward – the broadcaster must adopt strong password security to ensure that access to their program chain is not easily compromised,” said Oxenford. “This includes the obligation to change default passwords prior to the use of any equipment or software that has access to the station’s programming chain.”
Oxenford notes the second obligation is also one that should be relatively straightforward – broadcasters must quickly install updates or patches to their EAS equipment. “Broadcasters will need to promptly review software and hardware patches and get them installed to make sure that identified security risks cannot be exploited to give bad actors access to station’s program chain or EAS systems,” said Oxenford.
The final requirement is the one to which some broadcasters may need to devote more time and resources to reach compliance. “The FCC will require that broadcasters put all EAS and programming equipment connected to the Internet behind a network firewall, or that they use other ‘comparable network segmentation practices’ to limit remote access to these systems,” said Oxenford. “Basically, EAS systems need to be isolated from general purpose business networks so that unauthorized external access is not possible.”
In its Order, the FCC held that the first two requirements should be easy to implement, but the third concerning firewalls may be more difficult for smaller stations that do not have such. “We do not expect that this will be burdensome or time-consuming for EAS Participants to identify because firewalls are widely recognized as a basic and cost-effective cybersecurity safeguard appropriate even for organizations with limited resources,” the FCC said in its Order.
“Now that the compliance deadline is set for September 29, broadcasters need to move quickly to implement these requirements,” said Oxenford. He recommends stations talk to engineering staff and consultants now to ensure the FCC’s deadline is met.
Questions? Contact TAB’s Michael Schneider or call (512) 322-9944.
« Back to Latest News