The FCC has released a Frequently Asked Questions document to clarify new cybersecurity requirements for Emergency Alert System (EAS) equipment, which take effect on September 29. The rules mandate that broadcasters implement 15-character passwords, firewalls, and updated software across their program chains to prevent unauthorized access and false alerts.
The immediate implication of these rules is a mandatory technical overhaul for stations using legacy hardware that cannot support modern authentication strings. By extending liability to third-party program suppliers, the FCC is effectively forcing a security standard across the entire content delivery ecosystem, not just at the point of transmission. This shift reflects a broader regulatory focus on hardening public infrastructure against sophisticated spoofing and cyberattacks. Industry professionals should monitor the results of the nationwide EAS test on November 17, as the FCC will likely use the associated ETRS Form One filings to identify and penalize non-compliant stations.
The FCC's EAS cybersecurity mandate arrives amid a broader federal push to harden broadcast infrastructure against intrusion. In August 2025, the FCC adopted a Report and Order requiring EAS participants to implement specific cybersecurity measures including password complexity, firewall deployment, and timely software updates, with the rules codified under 47 CFR Part 11. The September 29 effective date gives broadcasters a narrow window to audit their entire program chain, from EAS encoders and decoders to any third-party automation systems that interface with alert distribution. Stations that rely on legacy EAS equipment lacking firmware update paths face a binary choice: replace hardware or seek a waiver before the compliance deadline.
The regulatory backdrop extends beyond the FCC's own rulemaking. In March 2025, the Cybersecurity and Infrastructure Security Agency issued a joint advisory with the FCC warning that EAS equipment had been targeted by threat actors exploiting default credentials and unpatched vulnerabilities, citing incidents where unauthorized EAS messages were triggered at broadcast stations. That advisory directly informed the FCC's decision to mandate 15-character minimum passwords and require stations to maintain written cybersecurity plans. The November 17 nationwide EAS test, which will require all participants to file ETRS Form One within 45 days, is expected to serve as the first enforcement checkpoint for the new rules.
Broadcasters evaluating compliance options are also weighing how EAS cybersecurity intersects with their broader IP-based distribution infrastructure. The transition to ATSC 3.0 introduces new attack surfaces for alert delivery, and the FCC has signaled it will address ATSC 3.0 EAS cybersecurity requirements in a separate proceeding as Next Gen TV deployment expands. For stations already operating ATSC 3.0 lighthouse arrangements, the current rules apply to both their ATSC 1.0 and 3.0 signal chains, meaning a single compliance gap on either path could trigger enforcement action. Equipment manufacturers including Sage Alerting Systems and Trilithic have issued firmware updates to support the new password-length and logging requirements, but stations using discontinued hardware from vendors like Monroe Electronics may need to budget for full encoder replacement before the deadline.
The FCC has issued new FAQs to help broadcasters comply with cybersecurity rules effective September 29. These mandates, including 15-character passwords and firewall requirements, aim to prevent unauthorized access and false emergency alerts. This shift forces a technical overhaul of legacy hardware and extends security liability to third-party content suppliers.
The new FCC EAS cybersecurity rules take effect on September 29.
Broadcasters must implement 15-character passwords. Single dictionary words of 15 letters or more are prohibited, and equipment unable to support this length requires replacement or alternative verification like multi-factor authentication.
Yes, third-party program suppliers that insert content directly into the transmission stream must comply with the new security standards.
The nationwide EAS test is scheduled for November 17, and participants must file ETRS Form One within 45 days of the test.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source