Station Compliance›Field Notes
EAS Security
Several broadcaster groups asked the Commission for relief on exactly these grounds. The order answers them directly, in a paragraph worth reading before you assume the rule is somebody else's problem.
By Mark Shannon ·
If you run a two-person AM station in a market nobody has heard of, the reasonable first question about any new FCC rule is whether it applies to you at all. Plenty do not. The main studio rule went away. Ownership reporting scales with how much there is to report. Even the EEO rules exempt an employment unit with fewer than five full-time employees.
So it is worth being direct about this one: 47 CFR § 11.35(d) has no small-station exemption, no rural exemption, no noncommercial exemption, and no revenue threshold. If you are an EAS Participant, it applies to you in full on September 29, 2026.
That is not an inference. The Commission was asked for exactly that relief, and said no in the order.
The argument was made, forcefully, by people who represent precisely the stations this site is written for.
Native Public Media told the Commission its member stations "have neither the resources, nor the expertise to shoulder that responsibility properly." The National Translator Association wrote that "the vast majority of EAS Participants are very small operations, operated by nonprofits, municipalities, religious entities, and other similar groups, often on shoestring budgets." A commenter in the proceeding put it more bluntly still: "many small stations have near zero budget for any actual I.T. security support."
These are not strawmen the FCC constructed to knock down. They are real comments from real organizations, and the order quotes them at length before disagreeing with them.
Here is the passage that settles it, from paragraph 23:
But that concern cuts both ways. Smaller broadcasters with fewer security protections in place are often a more attractive target for bad actors, as the recent attacks on small radio broadcasters demonstrate.
And then, a few lines later, the sentence that closes the door:
We conclude that all EAS Participants can and must implement the cybersecurity safeguards we adopt today.
The Commission's reasoning is that the requirements it actually adopted are much narrower than what it originally proposed. The 2022 proposal would have required a full cybersecurity risk management plan and an annual certification filed with the Commission. That is the version small broadcasters were reacting to. What survived is three concrete things — change the default passwords, install the patches, put a firewall in front of it — and the FCC's position is that a station without the budget for a risk-management program can still do those three.
The FCC also rejected the idea that education alone would be enough. The NAB and Cox Media Group argued the Commission should keep encouraging good practice rather than mandate it. The order's answer: education is valuable, but "not sufficient, on its own," because the Commission had already tried that repeatedly — a Public Notice in November 2025, another in August 2022, an email to EAS Participants in April 2020 — and "successful attacks have continued into 2026."
The order puts a number on it, which is unusual and useful.
The Commission estimated 10 hours per EAS Participant as a reasonable average burden across all three requirements, applied to roughly 25,800 entities, for a total industry cost near $26 million a year. It also concluded that installing security patches "can be accomplished in the normal course of business and at little or no additional cost," and that the only line item likely to mean real money is the firewall or network segmentation, for stations that do not already have one.
Two honest observations about that estimate.
First, 10 hours is not obviously wrong for a station with a small, well-documented rack. If you know what is in your program chain and you have the passwords, a focused afternoon plus a second session for the network work is a realistic shape.
Second, it assumes you already know what is in your program chain. In practice that inventory is the part that takes longest, because the port-forwarding rule somebody added in 2016 to check the STL from home is not written down anywhere, and the person who added it does not work there any more. The FCC is estimating the work; it is not estimating the archaeology.
It does not mean the rule is one-size-fits-all in its substance. The requirements are written to scale:
So the rule bends to the size of the facility. What it does not do is skip anyone.
There is a comment in the record that is worth sitting with, because it is the least comfortable thing in the whole proceeding. A commenter told the Commission that the problem is not stations trying and failing to comply. It is that owners "either aren't aware of the risks at all, or — equally likely — they simply do not care; gambling that the FCC will never actually enforce any rules against them."
Whether or not that is a fair characterisation, it is now on the record in a rulemaking where the Commission adopted rules anyway. A station betting on non-enforcement is making a different bet after September 29 than it was making before, because before there was no rule to enforce.
If you have been waiting to find out whether this applies to you, it does, and the answer has been settled since June. The practical starting points, in order of how much exposure they remove per hour spent:
The free reference on what § 11.35(d) requires covers the rule text line by line, and the equipment guide covers what counts as "program chain" in a small facility.
Everything on this site is free to read. The Program Chain Compliance Kit is the implementation version — the device-by-device reference, the network patterns for a one-rack station, and the worksheets that leave a paper trail behind the work.
The rules on this site change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.