Beginning September 29, 2026, new FCC cybersecurity requirements take effect for Emergency Alert System (EAS) Participants, including radio and television broadcasters.

The new rules are intended to protect broadcast facilities and the Emergency Alert System from unauthorized access, cyberattacks, and the transmission of false emergency alerts.

New password requirements

The FCC now requires broadcasters to secure EAS equipment, studio–transmitter link (STL) equipment, and other remotely managed equipment that routes, processes, or inserts content into the station's programming.

When passwords are used to secure covered equipment, they must:

  • Be at least 15 characters long
  • Not contain dictionary words
  • Not be reused for other accounts, equipment, applications, or services
  • Replace any factory or default password before equipment is used to broadcast
  • Be changed whenever there is reason to believe the password has been compromised

The FCC also permits other authentication methods that provide comparable protection against unauthorized access.

More than passwords

Keep covered equipment updated. Security patches and security-related software and firmware updates issued by equipment manufacturers must be installed promptly. Updates may be tested before deployment, provided testing begins promptly and is completed within a timeframe consistent with industry best practices.

Protect equipment from unauthorized network access. Covered equipment must be protected by a firewall or comparable network-segmentation method that limits remote management access to authorized users and authorized devices.

These requirements apply not only to EAS encoder/decoders, but also to STL equipment and remotely managed equipment that routes, processes, or inserts content into the station's programming.

Generate an FCC-compliant password

The generator on this page creates random passwords that meet the FCC's password requirements: 15 or more characters with no dictionary words.

Generate a different password for each device or system. FCC rules prohibit reusing a password used to comply with these requirements across other accounts, equipment, applications, or services.

Important: generating a compliant password addresses only the password portion of the FCC's cybersecurity requirements. Broadcasters remain responsible for complying with the FCC's requirements for software and firmware updates, network security, and access control.

Need help getting your station compliant?

MaxxKonnect can help. Broadcast cybersecurity isn't simply an IT issue. It requires an understanding of how broadcast systems, EAS equipment, STLs, automation, audio-over-IP networks, remote control systems, processors, codecs, transmitters, and other critical systems work together.

The broadcast engineers at MaxxKonnect are uniquely qualified to help stations evaluate their facilities and bring their systems into compliance with the FCC's new cybersecurity requirements. We can assist with:

  • Identifying equipment covered by the new FCC requirements
  • Reviewing and securing equipment credentials
  • Identifying default, weak, or reused passwords
  • Reviewing firmware and software versions and security updates
  • Evaluating firewalls, VLANs, network segmentation, and remote-access methods
  • Identifying equipment unnecessarily exposed to the public internet
  • Securing EAS, STL, automation, AoIP, codec, processing, remote-control, and other broadcast systems
  • Documenting findings and recommended corrective actions
  • Helping stations maintain compliance with applicable FCC technical rules and regulations

Whether you operate one station or an entire group, MaxxKonnect can help evaluate your facility, identify potential compliance issues, and develop a practical path forward without disrupting your broadcast operation.

Don't wait until an FCC inspection to find out there's a problem.

About the rule

These requirements were adopted in FCC 26-38, Modernization of the Nation's Alerting Systems / Protecting the Nation's Communications Systems from Cybersecurity Threats, and are incorporated into 47 CFR § 11.35(d).