FCC Adopts Order Mandating EAS Equipment Security
Posted on June 30th, 2026 by adminOn June 25, 2026, the FCC voted to require EAS equipment users to protect against hijacking by cybercriminals and adversaries by using strong passwords, promptly testing and installing security patches issued by equipment manufacturers, and using a network firewall or comparable practice to better limit access to their equipment.
A news release summarized the action, and the Order itself provides important details. While most broadcast stations are already following prudent practices to protect EAS equipment, each station should now determine whether current practices are already compliant or need to be modified.
Under the new rule, EAS Participants are required to employ the following security controls with respect to EAS equipment, studio transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the transmission of the EAS Participant’s programming:
(1) Prior to any use to broadcast to the public, EAS Participants must change any default password, use strong passwords, and change any password if the EAS Participant has reason to believe that the password has been compromised. A strong password is any password that has a minimum of 15 characters and does not use dictionary words. Instead of using a strong password, EAS Participants may use alternative authentication measures, such as look-up secrets, out-of-band devices, single- or multi-factor one-time password devices, or single- or multi-factor cryptographic authentication, that are reasonably sufficient to mitigate the risk of unauthorized access. Passwords employed to comply with this requirement may not be reused for the EAS Participant’s other accounts, equipment, applications, or services.
(2) Install security patches and security-related software and firmware updates issued by equipment manufacturers promptly after those patches or upgrades become available. Security patches and security related software and firmware updates issued by equipment manufacturers may be tested before they are installed, provided that the testing begins promptly and is completed in a timeframe that is consistent with industry best practices.
(3) Use a network firewall or comparable network segmentation practice that limits remote management access to authorized devices and authorized users.
The effective date of the new rule will probably be in September.



