FCC 47 CFR § 11.35(d) — compliance required by September 29, 2026
Station Compliance

Station Compliance›For affiliate stations

Written to be forwarded

§ 11.35(d) for affiliate stations: what to actually do this week

A new FCC rule covers considerably more of your air chain than most stations have assumed, and the people who have to do the work are usually the people with no engineer to hand it to. This is the working version: what the rule says, what to check, and in what order. We track the Commission's rules for small-market stations full time — this is the one that matters this month.

Reflects the rule as published August 2026. Verify current requirements before relying on any summary.

Networks and associations: this page exists so you have something to send your affiliates without writing it yourself. Forward the link, paste it into a memo, print it for a board packet, run it in a member newsletter — permission is granted in advance, in writing, at the bottom of this page. If you would rather send a version with your own logo on it, email us and we will make you one at no charge.

On this page

The whole rule in ninety seconds

On June 29, 2026 the FCC added a new paragraph (d) to 47 CFR § 11.35. It was published in the Federal Register on July 31, and compliance is required by September 29, 2026.

It asks three things of every EAS Participant:

  1. Strong passwords. Change every default password before the equipment is used to broadcast. "Strong" is defined, not left to judgment: at least 15 characters, not dictionary words, and not reused across other accounts, equipment, applications or services the station uses.
  2. Prompt patching. Test and install security patches and firmware updates promptly after they are released. Note the word test — the rule asks for a practice, not for you to push firmware to a live EAS box the hour it ships.
  3. A firewall, or comparable network segmentation, limiting remote management access to authorized devices and authorized users.

There is no small-station exemption. AM, FM, TV, LPFM, LPTV, Class A, translators and noncommercial stations are all covered. A station with nobody on payroll who owns a soldering iron is held to exactly the same standard as a group-owned cluster.

There is nothing to file. No form, no certification, no deadline to hit at the Commission, nothing to mail. This trips people up because most FCC dates come with paperwork attached. This one does not. You still want a written record — for your own file, because staff turn over and because any exception you take needs a reason attached to it — but it never goes anywhere.

The part almost everybody gets wrong

This is being read at a lot of stations as an EAS box rule. It is not. Read the third category:

In a normal facility that third line takes in automation and playout, audio processing, RDS encoders, the streaming encoder, remote broadcast codecs, transmitter remote control, studio routing and consoles, audio-over-IP endpoints — and the switches, routers and firewalls sitting underneath all of it.

The test to apply to any box: can somebody manage it remotely, and can it change what goes out over the air? If both are true, it is in scope — whatever it is and whoever sold it to you.

Two things in scope are not devices at all, and these are the ones stations miss most reliably:

What to do this week — the checklist

In rough order of how much good it does per minute spent. A station with one rack can get through most of this in an afternoon.

#Do thisWhy it is first
1 Open your router's port forwarding list and read every rule on it. Delete anything nobody can explain. This is where the real exposure almost always is. Most stations have forwarding rules somebody added years ago, pointing at program chain gear, for a reason that stopped applying long ago.
2 Find every Barix box in your STL path and check whether it has a password. In default configuration they have none at all. Not a weak one — none. They are extremely common as STL and remote links.
3 Test it from outside. Take a phone off wifi, onto cellular data, and try to reach your gear's management pages from it. Two minutes, no tools, and it answers the actual question the rule asks: can an unauthorized person on the internet reach a management interface in your chain?
4 Change default passwords on the EAS unit, the STL, automation, processing, the streaming encoder and the transmitter remote. 15 characters minimum, no dictionary words, and a different one on every box. The reuse clause is the one that catches careful stations. One excellent password used on six devices fails the rule.
5 List every vendor portal and cloud account that touches your chain. Change those passwords too, and turn on two-factor wherever it is offered. These are in scope and invisible. Nothing in the rack reminds you they exist.
6 Kill logins for anyone who no longer works there, including contractors and the engineer you used before the current one. Costs nothing, takes minutes, and removes a whole category of risk permanently.
7 Check for firmware updates on the EAS unit and anything else internet-facing. Install them on a schedule you can keep. The patching requirement is ongoing. It does not finish on any date.
8 Write down what you did, what you changed, and anything you could not. One page is fine. For your own file. It is also the only thing that will answer this question in two years when the person who did the work has moved on.

The trap on step 4, worth knowing before you set anything. Some older broadcast gear accepts a long password, silently stores only the first 8 characters, and reports success. You end up with a compliance record that is not true. Test for it: set a 16-character password, then try to log in using only the first 8. If that works, the device is truncating — treat it as an exception, keep it off the public internet, and write down why.

If a device cannot take a 15-character password at all, the rule has a path for you: equivalent robust authentication — multi-factor or cryptographic tokens. Most stations do not know that provision is in there.

If the date has already passed

Finish anyway. That is not a consolation prize, and here is the specific reason it is worth your time:

Nothing gets filed, so nothing gets reported. September 29 is not a date on which a report goes to the FCC and a list is made of who missed it. No such report exists. Exposure arises the way it always has — through an inspection, a complaint, or an actual incident where somebody gets into your chain.

But the 29th is not the last date on the calendar, and this is the part worth telling your stations. Two confirmed dates follow it: ETRS Form One is due from every EAS Participant on October 30, 2026, and the National EAS Test runs November 17 at 2:20 pm Eastern. On that afternoon every station in the country exercises the equipment this rule governs, seven weeks after a security deadline.

Neither is a § 11.35(d) filing and neither is an inspection — we are not going to tell you otherwise, and be wary of anyone who does. Form One has historically covered equipment, location and monitored sources rather than security. But a date on the calendar is the only thing that reliably moves work nobody is chasing you about, and a station running a live nationwide test on gear still carrying factory passwords is in a different position from one that spent an afternoon in October.

Which means a station that finishes this in October is in a genuinely better position than one that decides it has already lost and stops. The work is the same work. The rule does not expire, and the patching requirement was always ongoing rather than a one-time task with a finish line.

It also means the opposite is true, and worth being blunt about: a station that never does any of it does not get away with it — it just does not find out on any particular Tuesday.

What nobody can sell you

This section is here because some vendors are currently implying otherwise, and affiliates are the people most likely to get the call.

This is one of several — the rest of the year

§ 11.35(d) is getting attention because it is new and it has a date on it. It is not the only obligation a small station is carrying right now, and it is not the one most likely to cost you money.

The quarterly issues/programs list is still due at the same four moments every year, and a missing one is a documented, routinely-cited violation with real forfeitures attached — unlike this rule, which has no published fine amount at all. The political file has to be updated immediately, which means the same day, and that obligation runs hardest exactly when everyone is busiest. Sponsorship identification, tower lighting and ASR, RF exposure signage, the biennial ownership report, EEO: all live, all continuous, none of them announced to you by anybody.

The pattern worth taking from this: the FCC obligations that actually cost small stations money are almost never the ones in the trade headlines. They are the recurring, unglamorous ones that nobody sends a reminder about.

Get told when the FCC moves

These rules change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday afternoon. Leave an address and you get an email when something changes that affects a small station. That is the whole service: no pitch, no newsletter you have to read, one click to leave.

Free. No pitch. Your address is not sold or shared. One click to leave.

If you want help

Most stations reading this do not need any. The checklist above is the bulk of the work, and it was written so that it can be done by whoever is there rather than by a specialist.

The full plain-language reference, with the exact regulatory text, the equipment-by-equipment notes and the common questions, is at stationcompliance.com/rule/11-35d/. Also free, also forwardable.

And if you would rather hand it to somebody

We do this remotely for stations that got handed the deadline without an engineer — the audit, the exception documentation, the whole package. $895 for one station, and clusters are substantially less per station because shared infrastructure only gets documented once.

If you would rather run it yourself with better notes than the ones above, the implementation kit has the scope worksheet, verified device notes for Sage, DASDEC, Barix, Comrex, Tieline and Burk, the network patterns, and the exception forms for gear that cannot take a long password — $149, instant download, refunded if it is not useful.

See what is in the kit

Who wrote this

Mark Shannon — 43 years in radio. I operate Power88.FM, I build the traffic and billing software small-market stations run on, and I read the Federal Register so that station managers do not have to. Everything on this site is written from inside a working station rather than from a compliance desk, which is why it tells you which of the eight steps above actually matters and which one you can leave until Thursday.

Questions — including the ones you would rather not ask a vendor, and the ones you think you should already know the answer to: hello@stationcompliance.com or 707-505-8885. A real person answers, and asking does not put you on a call sheet.

Permission to reuse this page — granted in advance.

© 2026 Martian Creative, LLC. You may forward, print, photocopy, reproduce and distribute this page in whole or in part — to your affiliates, your members, your staff or your board — without asking us and without paying anything. That includes reprinting it in a newsletter, a member bulletin or a memo on your own letterhead. No licence to sign, no form to submit, no expiry.

The two things we ask: do not change the substance of what it says about the rule, and do not present it as your own work. An unaltered link or a credit line reading "Reprinted with permission from Station Compliance — stationcompliance.com" covers it.

This grant covers this page and every other free page on this site. It does not cover the paid implementation kit, which is a separate product under its own licence terms.