Station Compliance›Field Notes
EAS Security
The compliance deadline is getting all the attention, but the second half of FCC 26-38 is where the next several years of equipment decisions get made.
By Mark Shannon ·
FCC 26-38 is two documents in one binding. The first half is the Report and Order that created § 11.35(d) and the September 29 deadline. The second half is a Further Notice of Proposed Rulemaking, and it is the part nobody at a small station has read.
It is worth twenty minutes, because it is where the Commission signals what your next equipment purchase should be able to do.
Nothing in the Further Notice is a requirement. It is a set of proposals open for comment. Do not let anybody sell you equipment on the basis that the FCC "is about to require" any of it — proposals change substantially between notice and order, and some die.
The order lists five directions in its introduction.
Authenticate alerts before they are transmitted. The headline proposal, and the logical successor to § 11.35(d). Securing station equipment stops an attacker who gets into your rack; authenticating alerts stops a forged alert that arrives looking legitimate. The Commission proposes requiring EAS Participants to reject alerts that fail authentication.
A universal alert identification number. A single ID carried across systems so duplicate alerts can be detected and blocked, and so a WEA reaches people who enter an alert area after the alert was first sent, until the emergency ends.
Better geographic accuracy. Eliminating what the Commission calls outdated WEA geotargeting exceptions that cause alerts to land in the wrong places, and expanding geotargeting options for EAS.
Alerts that communicate faster. Seeking comment on symbols matched to the emergency type, and on making earthquake alerts more attention-grabbing.
Removing outdated requirements — including the two that matter most to broadcasters below.
Buried in the last bullet: the Commission proposes allowing EAS capabilities to be implemented in software instead of hardware.
For a small station this is potentially the most consequential thing in the document. The current model is a dedicated encoder/decoder box from a small number of manufacturers, at a price that is a meaningful line item for a station running on a shoestring. A software path changes that market.
The Commission is not naive about the tradeoff, and its own reasoning is worth quoting because it will shape whatever rule emerges. It observes that unlike physical devices, "software platforms have large attack surfaces, including APIs, databases, and remote" interfaces, and that EAS software "may be more prone to cyberattack by virtue of its IP interconnectedness."
So the likely shape of any software-EAS rule is permission plus conditions — and the conditions will look like § 11.35(d) with more teeth. A station that gets its network segmentation right this year is a station that can adopt software EAS when it arrives. One that cannot demonstrate a secured program chain will find the door open and be unable to walk through it.
The Further Notice also tentatively concludes on a 72-hour figure in the context of software resilience against ransomware, viruses and other attacks — a signal that availability requirements will come attached.
The practical advice: do not buy hardware on the assumption software is imminent, and do not delay compliance waiting for it. A Further Notice is the beginning of a process, not the end. But if you are scoping a five-year equipment plan, put a marker down.
The Commission proposes retiring the 90-character maximum versions of WEA messages. This is a carrier-side matter more than a broadcaster one, but it is a useful indicator of direction: the alerting system is being modernised toward richer messages, and the constraints written for 2012 handsets are coming off.
The Commission's framing of the security problem has two halves, and it has now addressed one.
§ 11.35(d) protects the station: your equipment, your credentials, your network boundary. It stops the attacks in the FCC's footnote trail, which all ran through an exposed management interface.
Alert authentication protects the system: it ensures the alert your equipment receives and relays is genuine. The order notes that when the Commission examined this in 2018 it determined legacy EAS may be vulnerable to attack, and the Further Notice asks hard questions about how far authentication can go — whether the audio portion of an EAS message remains susceptible to manipulation and replay even if the header is authenticated.
That question does not have a settled answer, which is why it is a Further Notice and not a rule.
Very little, immediately, and that is the honest answer.
If you want the current obligations rather than the proposed ones, the rule reference covers § 11.35(d) as adopted, and the small-station exemption question covers who it applies to.
Everything on this site is free to read. The Program Chain Compliance Kit is the implementation version — the device-by-device reference, the network patterns for a one-rack station, and the worksheets that leave a paper trail behind the work.
The rules on this site change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.