For stations without an engineer
It isn't. It covers your STL, your automation, your processing, your RDS encoder, your transmitter remote control — and the network underneath all of it.
Compliance was required September 29, 2026. Not there yet? You are not alone, and it is still worth doing properly. There was nothing to file, so nothing records that you missed it — what counts is getting it done and keeping the record of when. What to do first.
The rule's actual language. It applies to EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the broadcaster's programming.
The station that changes the password on its EAS box and calls it finished has not complied.
On June 29, 2026 the FCC adopted a new paragraph (d) to 47 CFR § 11.35. It requires three things of every EAS Participant: strong passwords of at least 15 characters, prompt installation of security patches, and a firewall or comparable network segmentation limiting remote management access.
There is no small-station exemption. AM, FM, TV, LPFM, LPTV, Class A, translators and noncommercial stations are all covered. Compliance has been required since September 29, 2026, and the patching and password duties carry on from there.
A practical implementation guide written by a broadcast professional, for the person who was handed this deadline without an engineer to hand it to.
| Document | What it does |
|---|---|
| Start Here | The 90-minute version. Six actions that address most of your real exposure in a single afternoon. |
| Compliance Guide | What the rule says and what it covers. The alternative-authentication path for gear that can't take 15 characters. Three network segmentation patterns for a one-rack station. |
| Device Quick Reference | Verified security behavior of common broadcast gear — Sage, DASDEC, Barix, Comrex, Tieline, Burk, Inovonics — plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed. |
| Worksheets & Templates | Program chain inventory, port-forwarding audit, compliance memo, short-password device records, patch log, credential and offboarding policy. |
Not a weak default — no password protection in the default configuration. A broadcaster running Barix between studio and transmitter had those units reconfigured by an outsider to pull a different stream. Graphic content went to air, and the attacker changed the management password so the station couldn't restore its own settings. Barix is common in small-market STL.
comrexComrex has publicly warned customers about this after learning of a website encouraging attackers to break into Comrex codecs using manufacturer defaults.
Some devices accept a 16-character password, save it without error, and quietly store only the first eight. It looks exactly like success. The kit shows you the two-minute test that catches it.
Most gear has more than one way in — web, Telnet, SSH, SNMP, a vendor app, a front panel PIN — and they often keep separate credentials. Set a strong web password on a unit whose Telnet still takes the factory login and you have changed nothing, except that your paperwork now says you fixed it. SNMP is the common case: public and private are guessed on the first try.
Instant download
Remote, scheduled this week
What a Done For You session looks like, and cluster pricing: $395 for each additional station at the same site.
The rule does not require you to file anything. There is no new recordkeeping or reporting obligation attached to § 11.35(d). The one exception is if a piece of equipment can’t meet the password requirement and can’t be replaced: the FCC’s FAQ says that needs a waiver, and a waiver is a request you file. If someone tells you the rule itself makes you file something, they’re selling you something. The kit includes documentation templates because every device decision needs a record and staff turn over — not because the FCC asks for them.
This isn't legal advice. It's an implementation guide written by a broadcast professional. It isn't a compliance certification or a security audit, and it doesn't guarantee any regulatory outcome. For contested questions, talk to your communications counsel or an SBE-certified broadcast engineer. Your station remains responsible for its own compliance.
It is the FCC's program chain security rule for EAS Participants, adopted in 2026. It requires stations to secure the equipment that carries and shapes their programming — not only their EAS box — and compliance has been required since September 29, 2026. The full reference is here.
No, and this is the most commonly misread part of it. The rule reaches EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into programming. That third clause takes in automation and playout, audio processing, RDS encoders, streaming encoders, remote broadcast codecs, transmitter remote control, studio routing, and the network gear underneath them. The scope guide goes device by device.
No. The requirements apply to every EAS Participant — AM, FM, TV, LPFM, LPTV, Class A and noncommercial alike — and the rule does not scale by staff size, revenue or market. The FCC considered the argument that small stations lack the budget and expertise, and rejected it in the order itself.
No. § 11.35(d) creates no new recordkeeping or reporting obligation — no form, no certification, no filing deadline. The one exception is a device that can neither take a strong password nor be replaced: the FCC’s route for that is a waiver, which you request. Documentation is still worth keeping, because every device decision needs a record and staff turn over, but it is for your own file rather than for the Commission. ETRS Form One is still due October 30, 2026, as a separate obligation that exists regardless of this rule — the dates that follow the 29th.
The FCC's FAQ of September 21, 2026 gives three routes. Use an alternative authentication measure on the device itself that provides equal or better security than a strong password: one-time passwords, multi-factor or cryptographic authentication, look-up secrets. Replace the device. Or obtain a waiver from the Commission. A firewall or VPN in front of the device does not count toward the password requirement; the FAQ says so in as many words. The kit's short-password device record documents which route you took. The password requirement, in detail.
You did not miss a filing, because there was nothing to submit. What changed on September 29 is that a station out of compliance is out of compliance, and its equipment posture is something an inspection, a complaint or an incident can reach. The work is the same as it was the week before: do it now, and keep the record of when. What to do first.
The compliance guide, a verified device reference for common broadcast equipment, three network segmentation patterns sized for a one-rack station, and the worksheets: program chain inventory, port-forwarding audit, compliance memo, short-password device records, and patch log. $149 for radio, $249 for the television edition.
Mark Shannon, 43 years in broadcasting, owner and program director of Power88.FM, who does his own rack work at a station with no engineer on staff. More about who writes this and what it is not.
The kit is the implementation version. The scope and the rule itself are published here in full, because a station that reads these and decides it can handle the work alone is a station that got helped, and because being the one who tells the truth about this rule is the whole positioning.
comrex default — two passwords, and why forwarding port 80 is the real problem.Rules change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.