A DASDEC can meet the password rule. Check that yours does.
Digital Alert Systems says every current DASDEC software version supports passwords up to 16 characters, with no update needed. That is good news, and it is also the easiest thing in your rack to mistake for being finished. Vendor capability is not station compliance.
Verified against Digital Alert Systems' public statements of July 2026 and trade-press coverage. Reflects the rule as published July 31, 2026, and the FCC's FAQ of September 21, 2026.
Verified. Digital Alert Systems stated publicly in July 2026 that all current DASDEC software versions support passwords up to 16 characters, satisfying the 15-character minimum without a software update. The platform also:
Requires replacement of factory-default passwords on first login
Blocks commonly used and prohibited passwords
Prevents password reuse
Alerts administrators when a password exceeds 180 days
Locks accounts after repeated failed logins
Supports enterprise SSO for multi-facility groups
What the statement does not tell you
Everything above describes what the software can do. None of it tells you what your unit is doing today, and that is the question 47 CFR § 11.35(d) asks. Three things are still yours to confirm:
That your unit is actually on a current software version. The statement covers current versions. We have not verified what older versions do, so a unit that has not been updated in a while is one to check, not one to assume.
That the factory default was in fact replaced. A first-login prompt only helps if someone answered it with a real password. A DASDEC commissioned long ago by someone else may not have been set up the way you would set it up today.
That it sits behind your firewall. A strong password does not make an internet-facing management interface acceptable, and the rule has a separate segmentation requirement that the password does nothing for.
About the default password
This page does not print the factory credential for the DASDEC. We have not verified it against manufacturer documentation, and a remembered default is exactly the kind of detail that is right on most units and wrong on yours. Take it from the manual for your unit.
What is verified is more useful anyway: current DASDEC software requires the factory default to be replaced on first login. So on a current unit the question is not "is it still on the default" so much as "who answered that prompt, with what, and does anyone here still know it".
The features only help if someone uses them
The platform's protections are real, and each one comes with something for the station to do:
The 180-day alert goes to administrators. Make sure the person it reaches still works with you and will act on it. An alert nobody reads changes nothing.
Account lockout works in both directions. It slows down someone guessing, and it can also lock out your own engineer. Know who can unlock the unit before you need them at two in the morning.
Enterprise SSO moves the credential off the box. If your group signs in that way, the account that reaches your DASDEC lives in the group's directory, not on the unit. When someone leaves, that is where their access has to end.
Do this today
Find the software version and confirm it is current. Record the version and the date you checked.
Look at every account on the unit, not just the one you log in with. Confirm each has a password someone set deliberately, and remove accounts that belong to nobody who still works with you.
Set a strong password of 15 or 16 characters on every account that can change the unit's configuration.
Confirm the DASDEC is not reachable from the public internet. Check your router for port-forwarding rules and DMZ assignments pointing at it. Then check from outside — a phone on cellular data, not station Wi-Fi.
Then confirm the password on your own unit
The documented limit is 16 characters, so a longer password from a generator is not one to paste in and trust. Two minutes settles it:
Set a random password of 15 or 16 characters.
Confirm it saves without error.
Log out, and log back in with the full password.
Then try logging in with only the first 8. If that works, something is truncating your password — a failure that looks exactly like success.
Keeping the unit off the public internet is essential, but it satisfies the separate segmentation requirement, not the password one: the FCC's FAQ says a firewall or VPN in front of the device is not enough, and the device itself must use a strong password or an alternative authentication measure. An EAS box is in scope however it is managed, so turning off its web interface does not take it out of the rule either. Record what you checked, and when, in your own file.
Don't stop at the web password
Most networked broadcast gear offers more than one way in — web, Telnet, SSH, SNMP, a vendor application, a serial console, sometimes a front panel. These frequently keep separate credential stores. We have not verified which management paths on the DASDEC share a credential and which do not, so do not assume: setting a strong web password on a unit whose other paths still accept the factory login changes nothing except your paperwork, which now says you fixed it.
List every management path your unit offers — the manual is the place to start — then verify each one separately: log in through it, confirm the new credential works, and confirm the old one does not.
The rest of your rack
The DASDEC is one entry. The Program Chain Compliance Kit covers verified security behavior for Sage ENDEC, Barix, Comrex, Tieline, Burk and Inovonics, plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed — with the inventory, port audit and short-password device records already written.