StreamingMemeStreamingMemeBuyers Guide
AboutLeaderboardsEventsSubmit News
Subscribe
StreamingMemeStreamingMeme

StreamingMeme is the streaming technology industry news aggregator.

Explore

Buyers GuideLeaderboardsEventsSubmit News

Stay updated

Weekly digest of new companies and streaming news.

Categories

Encoding & SoftwareVideo Delivery & CDNStreaming PlatformsAI for VideoProduction HardwareBusiness NewsMonetization & Ad TechRegulatory & Policy

© 2026 StreamingMeme. All rights reserved.

AboutPrivacy PolicyTermsContact
EncodingCDNPlatformsAI & VideoHardwareBusinessAd TechPolicy

Daily Brief

The streaming industry in your inbox every morning.

← Regulatory & Policy
PolicyRegulatory ActionSeptember 23, 2026

FCC clarifies EAS cybersecurity rules ahead of September 29 deadline

FCC clarifies EAS cybersecurity rules ahead of September 29 deadline
Broadcast Law Blog

The FCC has released a Frequently Asked Questions document to clarify new cybersecurity requirements for Emergency Alert System (EAS) equipment, which take effect on September 29. The rules mandate that broadcasters implement 15-character passwords, firewalls, and updated software across their program chains to prevent unauthorized access and false alerts.

Key Takeaways

  • Equipment unable to support 15-character passwords requires replacement or the use of alternative verification like multi-factor authentication.
  • Password requirements apply to all devices in the program chain, even those already protected by a firewall.
  • Single dictionary words of 15 letters or more are prohibited as standalone passwords to prevent simple cracking attempts.
  • Third-party program suppliers that insert content directly into the transmission stream must also comply with these security standards.

Why It Matters

The immediate implication of these rules is a mandatory technical overhaul for stations using legacy hardware that cannot support modern authentication strings. By extending liability to third-party program suppliers, the FCC is effectively forcing a security standard across the entire content delivery ecosystem, not just at the point of transmission. This shift reflects a broader regulatory focus on hardening public infrastructure against sophisticated spoofing and cyberattacks. Industry professionals should monitor the results of the nationwide EAS test on November 17, as the FCC will likely use the associated ETRS Form One filings to identify and penalize non-compliant stations.

Additional Context

The FCC's EAS cybersecurity mandate arrives amid a broader federal push to harden broadcast infrastructure against intrusion. In August 2025, the FCC adopted a Report and Order requiring EAS participants to implement specific cybersecurity measures including password complexity, firewall deployment, and timely software updates, with the rules codified under 47 CFR Part 11. The September 29 effective date gives broadcasters a narrow window to audit their entire program chain, from EAS encoders and decoders to any third-party automation systems that interface with alert distribution. Stations that rely on legacy EAS equipment lacking firmware update paths face a binary choice: replace hardware or seek a waiver before the compliance deadline.

The regulatory backdrop extends beyond the FCC's own rulemaking. In March 2025, the Cybersecurity and Infrastructure Security Agency issued a joint advisory with the FCC warning that EAS equipment had been targeted by threat actors exploiting default credentials and unpatched vulnerabilities, citing incidents where unauthorized EAS messages were triggered at broadcast stations. That advisory directly informed the FCC's decision to mandate 15-character minimum passwords and require stations to maintain written cybersecurity plans. The November 17 nationwide EAS test, which will require all participants to file ETRS Form One within 45 days, is expected to serve as the first enforcement checkpoint for the new rules.

Broadcasters evaluating compliance options are also weighing how EAS cybersecurity intersects with their broader IP-based distribution infrastructure. The transition to ATSC 3.0 introduces new attack surfaces for alert delivery, and the FCC has signaled it will address ATSC 3.0 EAS cybersecurity requirements in a separate proceeding as Next Gen TV deployment expands. For stations already operating ATSC 3.0 lighthouse arrangements, the current rules apply to both their ATSC 1.0 and 3.0 signal chains, meaning a single compliance gap on either path could trigger enforcement action. Equipment manufacturers including Sage Alerting Systems and Trilithic have issued firmware updates to support the new password-length and logging requirements, but stations using discontinued hardware from vendors like Monroe Electronics may need to budget for full encoder replacement before the deadline.

In short

The FCC has issued new FAQs to help broadcasters comply with cybersecurity rules effective September 29. These mandates, including 15-character passwords and firewall requirements, aim to prevent unauthorized access and false emergency alerts. This shift forces a technical overhaul of legacy hardware and extends security liability to third-party content suppliers.

FAQ

What is the deadline for the new FCC EAS cybersecurity rules?

The new FCC EAS cybersecurity rules take effect on September 29.

What are the new password requirements for EAS equipment?

Broadcasters must implement 15-character passwords. Single dictionary words of 15 letters or more are prohibited, and equipment unable to support this length requires replacement or alternative verification like multi-factor authentication.

Do these cybersecurity rules apply to third-party suppliers?

Yes, third-party program suppliers that insert content directly into the transmission stream must comply with the new security standards.

When is the next nationwide EAS test?

The nationwide EAS test is scheduled for November 17, and participants must file ETRS Form One within 45 days of the test.


Read full article at broadcastlawblog.com

Enjoy our coverage?

Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.

Add as preferred source

Related Articles

Federal Register: FCC mandates digital signatures and universal IDs to modernize emergency alerts
Radio World: FCC software-based EAS proposal targets hardware replacement for broadcast stations
Akin Gump Strauss Hauer & Feld LLP: FCC equipment authorization rules to mandate hardware and software transparency
Tech Policy Press: EU AI Act transparency rules take effect, mandating synthetic content watermarks
Legal Dive: California mandates AI provenance tools as new transparency law takes effect
Get this in your inbox → Subscribe

Newest

1 day ago
TechCrunch: Synthesia interactive AI avatars expand into agentic enterprise roleplay tools
1 day ago
The Hollywood Reporter: Academy CEO defends Oscars YouTube broadcast deal as viewership shifts global
1 day ago
Liverpool Echo: Social media content moderation fails to stop covert filming of women
1 day ago
The Post: Park Road Post Production restoration brings Queen concert to 4K cinemas
1 day ago
Women Love Tech: Adobe AI creative agents automate production across Premiere and Frame.io
1 day ago
StreetInsider: AIMarX programmatic advertising platform expands to CTV and automotive sectors
1 day ago
Belfast Telegraph: TikTok Alabama settlement mandates non-personalized feeds and 100 million dollar payment
1 day ago
Coyote Gulch: Hyperscale data center backlash intensifies as AI energy demands surge
1 day ago
PPC Land: Only 2.4% of websites fully block automated bot traffic
1 day ago
Playbox Technology: PlayBox Technology launches Celebro Play to centralize legacy broadcast infrastructure
1 day ago
PlayBox Technology: PlayBox Technology launches Celebro Play media orchestration for FAST and OTT
1 day ago
SiliconANGLE: CoreWeave AI cloud transition faces production conversion and liquidity tests
1 day ago
ProVideo Coalition: GoPro Mission 1 Pro ILS faces criticism over deceptive framerate labeling
1 day ago
RedShark News: DJI and Insta360 capture 93% of handheld smart camera market share
1 day ago
ProVideo Coalition: Retouch4me Lab Video plugin automates film emulation for DaVinci Resolve
1 day ago
Oracle: Oracle details LiveKit Agents OCI deployment for real-time voice AI
1 day ago
n1n.ai: AWS agentic video intelligence architecture replaces static pipelines to cut costs
1 day ago
YouTube: Generative AI production costs plummet 99% as synthetic content floods platforms
1 day ago
MDPI: Nagoya University uses iPhone LiDAR to improve VR scene reconstruction
1 day ago
PPC Land: Contextual advertising adoption surges as privacy rules restrict behavioral targeting

Upcoming Events

Sep
29–1
SCTE TechExpoAtlanta
Sep
29–30
SportsPro AI+TechLondon
Sep
29–1
VidSummitDallas, TX
Sep
29–1
SCTE TechExpoAtlanta
Oct
5–7
CABSATDubai
View all events →

Top Sources

  1. 1.Sports Video Group19
  2. 2.SVG Europe17
  3. 3.Advanced Television15
  4. 4.TVNewsCheck14
  5. 5.TV[BE]urope14
  6. 6.TM Broadcast13
  7. 7.MediaPost13
  8. 8.Broadband TV News12
Full leaderboards →