FCC mandates broadcasters secure program chains and EAS by September 29
The FCC has mandated that broadcasters secure their Emergency Alerting System and broader program chains by September 29. Compliance requirements include the implementation of strong, unique passwords, regular software patching, and the isolation of internet-connected equipment behind network firewalls.
Key Takeaways
- Broadcasters must implement network firewalls or comparable segmentation to isolate Emergency Alerting System (EAS) equipment from general business networks.
- Passwords for any internet-connected program chain component must be unique, non-dictionary based, and at least 15 characters long.
- Mandatory installation of security patches and firmware updates for all EAS hardware and software is required promptly upon release.
- The 2023 Nationwide EAS test found 23% of equipment was either unsupported or running outdated software, driving the shift from voluntary to mandatory rules.
Why It Matters
This mandate transitions the industry from voluntary best practices to strict regulatory enforcement, directly addressing vulnerabilities exposed by recent station hijackings. For the streaming and broadcast ecosystem, it creates a new compliance baseline that necessitates immediate technical audits and potential hardware upgrades, particularly for smaller operators. The inclusion of the entire "program chain"—including studio-transmitter links—means security is no longer an isolated IT concern but a core component of the video delivery infrastructure. Failure to comply by the September deadline could expose entities to significant fines, following the FCC's recent trend of aggressive enforcement regarding broadcast integrity. Expect a surge in demand for managed security services and hardware upgrades as stations scramble to meet the 60-day window.
Additional Context
The FCC’s September 29 deadline follows a surge in sophisticated cyberattacks targeting critical broadcast infrastructure. Per Radio Ink (June 2026), hackers recently exploited unsecured Barix network equipment at stations in Texas and Virginia to broadcast offensive content and unauthorized alert tones. These incidents prompted the Commission to move away from a 2022 proposal for broader, more complex cybersecurity risk management plans in favor of these three targeted, baseline requirements. The FCC estimates these specific measures will cost no more than $1,000 per station, a concession to industry groups like the NAB that raised concerns about the financial burden on small-market broadcasters. Beyond immediate equipment settings, the FCC is also pursuing a Further Notice of Proposed Rulemaking (FNPRM) to modernize the wider alerting ecosystem. According to NewscastStudio (June 2026), the Commission is weighing new requirements for the authentication of all alerts before transmission and the implementation of universal alert identification numbers to block duplicate messages. The FNPRM also explores permitting software-based EAS implementations, which the NAB suggested in a March 2025 petition could improve resilience by allowing for remote updates without taking broadcast systems offline. This regulatory push aligns with a broader national security effort to secure communications supply chains. Per Skadden (August 2026), the FCC recently updated its Covered List to restrict categories of foreign-produced logic-bearing components and robotic systems, citing supply chain vulnerabilities. As broadcasters work to meet the new EAS cybersecurity rules, they are increasingly required to provide detailed hardware and software bills of materials (SBOMs) to ensure their critical infrastructure does not incorporate prohibited foreign technologies that could serve as backdoors for state-sponsored actors.
Read full article at michiganmedia.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source