FCC 47 CFR § 11.35(d) — compliance required by September 29, 2026
Station Compliance

Station Compliance›Equipment

Scope guide

What equipment the FCC security rule actually covers

The rule names EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into programming. That third clause is doing most of the work, and it is the one most stations have read too narrowly.

The test to apply to any device: is it remotely manageable, and can it affect what goes out over the air?

If both are true, it is in scope — whatever kind of box it is, whoever sold it to you, and whether or not it has anything to do with EAS.

In scope

Equipment the rule reaches

Running a television plant? The rule applies identically and on the same date, but the equipment list is longer — master control, playout, the encoder, and the character generator that puts the EAS crawl on screen, which § 11.51(d) requires you to have and which is squarely inside the scope language. The television scope guide covers it device by device.

Equipment notes

Devices with documented, verifiable security behavior worth knowing before you start:

DeviceWhy it is on this list
Barix
Instreamer / Exstreamer
No password protection at all in the default configuration — and a documented incident in which a station's STL was reconfigured by an outsider to pull a different stream. Very common in small-market STL.
Comrex
ACCESS / BRIC-Link
Factory default password comrex, publicly targeted. Two separate passwords, only one of which is the management credential. Port 80 forwarding is the usual real problem.

The kit's device reference also covers DASDEC, Sage ENDEC 3644 (and why Rev 96 matters for more than this rule), Tieline (whose recent firmware ships unique 15-character passwords already), Burk ARC Plus, and Inovonics — plus transmitter sites, audio-over-IP networks, and an eight-step method for anything not listed.

The categories with no verified entries — and why

Some product lines are firmly in scope but carry no per-model entry here, and the reason is a deliberate one.

Automation and playout — StationPlaylist, Zetta, NexGen, Simian, Rivendell, WideOrbit, ProppFrexx and similar are in scope when remotely manageable. Per-product security specifics are not published because these are general-purpose Windows or Linux applications whose exposure depends far more on the host machine and network than on the application itself. Pay attention to remote desktop access to the automation PC, the host OS patch status, any web or API interface, and shared operator logins.

The automation PC is often the single most exposed device in a small-market station — and the least likely to appear on an EAS-focused checklist.

Audio processors — Omnia, Orban Optimod, Wheatstone and similar networked processors are in scope where remotely manageable. Per-model password behavior for these lines has not been verified, and it will not be guessed at here. A guessed number would cause a station to record compliance it does not have.

The credentials that are not on any device

No inventory checklist has a slot for these, and you cannot find them by walking the rack:

The test: does this account let someone change what goes out over the air? If yes, it is a program chain credential and the same standard applies.

Offboarding is where this fails. The specific failure is a contractor who parts ways with the station while their vendor portal login keeps working — because that account lives at the vendor, not on any device you control.

The second interface problem

Changing the web password does not change the other one. Most gear exposes several management paths — web, Telnet or SSH, SNMP, a vendor desktop application, a serial console sometimes bridged onto the network, a front panel PIN — and they frequently keep separate credential stores.

Setting a strong web password on a unit whose Telnet still accepts the factory login leaves the device exactly as open as it was, while producing a compliance record saying you fixed it. This is the most consequential failure mode in the whole exercise, because the paperwork looks correct.

SNMP deserves particular attention. Versions 1 and 2c have no encryption and use community strings as their only credential; public for read and private for write are near-universal defaults. A write-capable SNMP interface on a transmitter remote control is a control path into your program chain protected by a word guessed on the first try. Use SNMPv3 where supported; otherwise change the community strings and restrict SNMP to your management network.

If time is short, work in this order

This ranking reflects real exposure, not equipment cost:

  1. Anything currently port-forwarded to the public internet — regardless of what it is
  2. Barix units — default configuration has no password at all
  3. Any device still on factory credentials — Comrex comrex being a documented, publicly targeted example
  4. Any write-capable SNMP interface still on default community strings
  5. The automation PC, especially with remote desktop exposed
  6. Devices where you changed the web password but never checked Telnet, SSH or SNMP
  7. EAS units not on current firmware — Sage 3644 below Rev 96 in particular
  8. Vendor portal and remote-access accounts belonging to people who have left
  9. Codecs predating current shipping practice — Tieline units older than v3.12.xx
  10. Everything else in the chain

Finding the devices nobody remembers installing

Memory catches what you can remember. These catch what you cannot:

  1. Read the DHCP lease table and ARP table on your router. Anything you cannot identify by name and function is a finding — chase it until you can name it.
  2. Scan yourself from outside the building. From a phone on cellular data, try your public IP on ports 80, 443, 8080, 22, 23 and 3389. Do the transmitter site's IP too.
  3. Walk the rack and read the back panels. Every RJ-45 with a link light is a networked device — including gear that is racked but "not in use".
  4. Review three years of equipment purchases and contractor invoices. Installations that came with remote support almost always came with remote access.

The implementation version

Everything above is scope and method. The Program Chain Compliance Kit is the part that gets it done: a 90-minute start-here path, the verified device reference in full, three network segmentation patterns for a one-rack station, and the worksheets already written — program chain inventory, port-forwarding audit, compliance memo, exception justification forms, patch log, credential and offboarding policy.

See what is in the kit — $149