FCC 47 CFR § 11.35(d) — ETRS Form One due October 30 · National EAS Test November 17
Station Compliance

For stations without an engineer

Most stations think the new FCC security rule is about their EAS box.

It isn't. It covers your STL, your automation, your processing, your RDS encoder, your transmitter remote control — and the network underneath all of it.

Compliance was required September 29, 2026. Not there yet? You are not alone, and it is still worth doing properly. There was nothing to file, so nothing records that you missed it — what counts is getting it done and keeping the record of when. What to do first.

The rule's actual language. It applies to EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the broadcaster's programming.

The station that changes the password on its EAS box and calls it finished has not complied.

On June 29, 2026 the FCC adopted a new paragraph (d) to 47 CFR § 11.35. It requires three things of every EAS Participant: strong passwords of at least 15 characters, prompt installation of security patches, and a firewall or comparable network segmentation limiting remote management access.

There is no small-station exemption. AM, FM, TV, LPFM, LPTV, Class A, translators and noncommercial stations are all covered. Compliance has been required since September 29, 2026, and the patching and password duties carry on from there.

What this kit is

A practical implementation guide written by a broadcast professional, for the person who was handed this deadline without an engineer to hand it to.

Equipment the rule actually reaches

Four documents

DocumentWhat it does
Start HereThe 90-minute version. Six actions that address most of your real exposure in a single afternoon.
Compliance GuideWhat the rule says and what it covers. The alternative-authentication path for gear that can't take 15 characters. Three network segmentation patterns for a one-rack station.
Device Quick ReferenceVerified security behavior of common broadcast gear — Sage, DASDEC, Barix, Comrex, Tieline, Burk, Inovonics — plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed.
Worksheets & TemplatesProgram chain inventory, port-forwarding audit, compliance memo, short-password device records, patch log, credential and offboarding policy.

Four things you'll find that most stations miss

Barix units ship with no password at all

Not a weak default — no password protection in the default configuration. A broadcaster running Barix between studio and transmitter had those units reconfigured by an outsider to pull a different stream. Graphic content went to air, and the attacker changed the management password so the station couldn't restore its own settings. Barix is common in small-market STL.

Comrex codecs ship with the password comrex

Comrex has publicly warned customers about this after learning of a website encouraging attackers to break into Comrex codecs using manufacturer defaults.

Your gear may be silently truncating passwords

Some devices accept a 16-character password, save it without error, and quietly store only the first eight. It looks exactly like success. The kit shows you the two-minute test that catches it.

Changing the web password doesn't change the other one

Most gear has more than one way in — web, Telnet, SSH, SNMP, a vendor app, a front panel PIN — and they often keep separate credentials. Set a strong web password on a unit whose Telnet still takes the factory login and you have changed nothing, except that your paperwork now says you fixed it. SNMP is the common case: public and private are guessed on the first try.

Get it

Compliance Kit

$149

Instant download

  • All four documents
  • Every worksheet and template
  • Verified device reference
  • Use across all stations you own
Buy the kit — $149

Done For You

$895 per station

Remote, scheduled this week

  • We inventory your program chain with you
  • Port-forwarding audit and remediation
  • Passwords set, firmware reviewed
  • Short-password devices resolved and recorded
  • Completed memo for your files
Book a station

What a Done For You session looks like, and cluster pricing: $395 for each additional station at the same site.

Two honest notes

The rule does not require you to file anything. There is no new recordkeeping or reporting obligation attached to § 11.35(d). The one exception is if a piece of equipment can’t meet the password requirement and can’t be replaced: the FCC’s FAQ says that needs a waiver, and a waiver is a request you file. If someone tells you the rule itself makes you file something, they’re selling you something. The kit includes documentation templates because every device decision needs a record and staff turn over — not because the FCC asks for them.

This isn't legal advice. It's an implementation guide written by a broadcast professional. It isn't a compliance certification or a security audit, and it doesn't guarantee any regulatory outcome. For contested questions, talk to your communications counsel or an SBE-certified broadcast engineer. Your station remains responsible for its own compliance.

Questions stations actually ask

What is 47 CFR § 11.35(d)?

It is the FCC's program chain security rule for EAS Participants, adopted in 2026. It requires stations to secure the equipment that carries and shapes their programming — not only their EAS box — and compliance has been required since September 29, 2026. The full reference is here.

Does the rule only cover EAS equipment?

No, and this is the most commonly misread part of it. The rule reaches EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into programming. That third clause takes in automation and playout, audio processing, RDS encoders, streaming encoders, remote broadcast codecs, transmitter remote control, studio routing, and the network gear underneath them. The scope guide goes device by device.

Is there a small-station, LPFM or noncommercial exemption?

No. The requirements apply to every EAS Participant — AM, FM, TV, LPFM, LPTV, Class A and noncommercial alike — and the rule does not scale by staff size, revenue or market. The FCC considered the argument that small stations lack the budget and expertise, and rejected it in the order itself.

Do I have to file anything with the FCC?

No. § 11.35(d) creates no new recordkeeping or reporting obligation — no form, no certification, no filing deadline. The one exception is a device that can neither take a strong password nor be replaced: the FCC’s route for that is a waiver, which you request. Documentation is still worth keeping, because every device decision needs a record and staff turn over, but it is for your own file rather than for the Commission. ETRS Form One is still due October 30, 2026, as a separate obligation that exists regardless of this rule — the dates that follow the 29th.

What if a device will not accept a 15-character password?

The FCC's FAQ of September 21, 2026 gives three routes. Use an alternative authentication measure on the device itself that provides equal or better security than a strong password: one-time passwords, multi-factor or cryptographic authentication, look-up secrets. Replace the device. Or obtain a waiver from the Commission. A firewall or VPN in front of the device does not count toward the password requirement; the FAQ says so in as many words. The kit's short-password device record documents which route you took. The password requirement, in detail.

What if my station missed September 29, 2026?

You did not miss a filing, because there was nothing to submit. What changed on September 29 is that a station out of compliance is out of compliance, and its equipment posture is something an inspection, a complaint or an incident can reach. The work is the same as it was the week before: do it now, and keep the record of when. What to do first.

What is in the Program Chain Compliance Kit?

The compliance guide, a verified device reference for common broadcast equipment, three network segmentation patterns sized for a one-rack station, and the worksheets: program chain inventory, port-forwarding audit, compliance memo, short-password device records, and patch log. $149 for radio, $249 for the television edition.

Who writes this?

Mark Shannon, 43 years in broadcasting, owner and program director of Power88.FM, who does his own rack work at a station with no engineer on staff. More about who writes this and what it is not.

Free reference — no purchase, no email required

The kit is the implementation version. The scope and the rule itself are published here in full, because a station that reads these and decides it can handle the work alone is a station that got helped, and because being the one who tells the truth about this rule is the whole positioning.

Get told when the FCC moves

Rules change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.

Free. No pitch. Your address is not sold or shared. One click to leave.