Station Compliance›Field Notes
Television
The Commission required 3.0 broadcasters to comply with the EAS rules when it authorised the standard. What has changed since is the size of the attack surface.
By Mark Shannon ·
If you have deployed ATSC 3.0, or you are planning to, the question worth asking about the September 29 security deadline is not whether 3.0 brings extra obligations. It does not. The question is how much more the same three requirements are protecting.
When the Commission authorised ATSC 3.0 as the next-generation broadcast television standard, it required 3.0 broadcasters to comply with the EAS rules. That has been settled since the authorisation, and § 73.3801 carries the simulcast obligations that sit alongside it.
§ 11.35(d) then applies to every EAS Participant without distinction — no separate 3.0 rule, no separate date, no exemption for a facility mid-transition. Strong passwords, prompt patching, and a firewall or comparable network segmentation limiting remote management access, by September 29, 2026.
So the compliance answer is short. The engineering answer is not.
A legacy plant has a limited number of network-connected devices, and the video path between them is baseband or transport stream over dedicated links. A 3.0 plant is IP from end to end: the gateway, the scheduler, the broadcast core, the links to the transmitter, and the management interfaces on all of it.
That means:
None of this is a criticism of 3.0. It is the point of 3.0. But a requirement to limit remote management access to authorised devices and users is doing considerably more work in a plant where nearly everything is remotely manageable.
The practical implication: if you are building or expanding a 3.0 facility this year, do the segmentation design now, as part of the build, rather than retrofitting it in September. Retrofitting network segmentation into a running plant is the expensive version of this work, and the deadline does not care which version you chose.
The Further Notice attached to the same order — the half nobody reads — proposes allowing EAS capabilities to be implemented in software instead of hardware. For television that is potentially significant, and it points directly at 3.0-style architectures.
The Commission is not naive about the tradeoff. Its own reasoning notes that unlike physical devices, software platforms have large attack surfaces including APIs, databases and remote interfaces, and that EAS software may be more prone to cyberattack by virtue of its IP interconnectedness. It also tentatively lands on a 72-hour figure in the context of resilience against ransomware and other attacks.
Read that as a signal about direction. Any future software-EAS rule will come with security conditions attached, and those conditions will look like § 11.35(d) with more teeth.
Which means the segmentation work you do this month is not a one-off. A station that can demonstrate a properly segmented plant is a station positioned to adopt whatever comes out of that docket. One that cannot will find the door open and be unable to walk through it.
Nothing in a Further Notice is a requirement, though, and proposals change substantially between notice and order. Do not buy anything on the strength of one. The full rundown of what was proposed is here.
ATSC 3.0 changes nothing about what § 11.35(d) requires and a great deal about what it is worth. The station getting the most out of this deadline is the one with the most IP in its air chain, which is precisely the station that finds the work largest.
The TV scope guide covers the full television equipment list, and the rule reference covers the three requirements in detail.
Everything on this site is free to read. The Program Chain Compliance Kit is the implementation version — the device-by-device reference, the network patterns for a one-rack station, and the worksheets that leave a paper trail behind the work.
The rules on this site change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.