The FCC Order, adopting new requirements for broadcasters to secure their EAS (and their entire program chain) to prevent false emergency alerts, has been published in the Federal Register, and every station has until September 29, 2026 to get into compliance. No matter how large or small your operation or the operation you work for is, this will require new password security practices, regular technical updates of EAS systems, and putting the EAS equipment behind a firewall isolated from other office systems connected to the Internet. The effective date of these new obligations is September 29, 2026, which is 60 days after the order was published in the Federal Register.
This article provides you with a few resources to better understand your station’s responsibility. Again, it doesn’t matter where your station is located, whether you are TV or radio, commercial or non-commercial educational, one station or a cluster, these new rules apply to every station licensed by the FCC.
Resource #1: September 1st, the NAB and the National Alliance of State Broadcasters Associations (NASBA) hosted a free webinar to help stations understand the new requirements and how to prepare your station for compliance. Watch a recording of the webinar here
Resource #2:
Washington D.C. attorney David Oxenford, who specializes in FCC regulations, wrote a very insightful blog that I highly recommend you read here: https://www.broadcastlawblog.com/2026/07/articles/fcc-adopts-order-to-secure-eas-system-broadcasters-program-chain-must-be-behind-firewall-soon/
Resource #3:
Jeff Welton from Nautel hosted a really good 60 minute webinar on July 16th titled IT Security; Safety and Compliance. I highly recommend watching the recording here: https://www.youtube.com/watch?v=vr2Dxk7YpLM In the webinar, Jeff explores the intersection of IT security, operational safety, and compliance for broadcast facilities. Broadcasters can learn what they need to know about protecting networks, transmitters, and connected devices from cybersecurity risks, including practical measures for hardening systems and educating staff. You’ll gain insights into how to assess vulnerabilities, implement sensible safeguards, and align your station’s practices with industry best practices to help keep your broadcast operations secure and compliant in an increasingly connected world.
Resource #4:
The Alabama Broadcasters Association Engineering Academy published this article about updating all passwords and firmware in your air chain equipment in their Monday Morning Coffee & Technical Notes newsletter:
Under the upcoming FCC cybersecurity rules, broadcasters must promptly review and install software and hardware patches for internet-connected equipment in the program chain to prevent known security risks from giving bad actors access to the station’s program chain or EAS systems.
For EAS equipment, the DasDec unit must be using version 5.4 or higher and for Sage Endec the unit must be using version 96.00 or higher. Sage issued some guidelines for implementing new passwords and firmware updates for Sage Endecs. One important note if you are changing your ENDEC’s password to meet the new FCC requirements, do not use the ampersand (&) or plus (+) character in your new password. Sage will release a free update later this year that fixes some bugs, but you do not need to wait for that update to implement the new password requirements if you avoid those characters. Click here for information on implementing the update in Sage Endec.
For other air chain devices, including processors, STL equipment, and transmitters, contact the manufacturers for guidance on password management and firmware versions.
The Commission stated in its rulemaking that stations should use passwords of at least 15 characters, with no dictionary words or station references.
Vermont Association of Broadcasters
