Station Compliance›47 CFR § 11.35(d)
Plain-language reference
Three requirements, one date, and considerably more equipment in scope than most stations have assumed. This page is the reference; nothing on it is behind a paywall.
Reflects the rule as published August 2026. Verify current requirements before relying on any summary.
On June 29, 2026 the FCC adopted a new paragraph (d) to 47 CFR § 11.35. It was published in the Federal Register on July 31, 2026, and compliance is required by September 29, 2026.
It requires three things of every EAS Participant: strong passwords, prompt patching, and a firewall or comparable network segmentation limiting remote management access.
It applies to EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the broadcaster's programming.
That last clause is where most stations have scoped this wrong. It is not a rule about EAS boxes. It is a rule about the program chain, and the EAS box is one device on it.
Before any use to broadcast to the public, EAS Participants must change any default password, use strong passwords, and change a password whenever there is reason to believe it has been compromised.
The standard for "strong" is specific:
There is an alternative path. A station may instead implement equivalent robust authentication — multi-factor authentication or cryptographic tokens are the examples given. This matters for older equipment that cannot accept a long password, and it is the provision most stations do not know exists.
Test and install security patches and security-related software and firmware upgrades promptly after they become available.
Note the word test. The rule does not ask you to apply a firmware update to a live EAS unit the hour it ships. It asks for a practice, which is a different and more achievable thing — and it means the obligation is ongoing, not something that finishes on September 29.
Use a network firewall or comparable network segmentation practice that limits remote management access to authorized devices and authorized users.
In a one-rack station this is usually less work than it sounds, and it is almost always the requirement that does the most real good — most of the genuine exposure in a small facility is a port-forwarding rule somebody added years ago for a reason that no longer applies.
Every EAS Participant. There is no small-station exemption. AM, FM, TV, LPFM, LPTV, Class A, translators and noncommercial stations are all covered. The rule does not scale by staff size, revenue or market rank, and a station with no engineer on payroll is held to the same standard as a group-owned cluster.
The rule names three categories. The first two are unambiguous. The third is the one to read carefully:
| Category | What it takes in |
|---|---|
| EAS equipment | Your encoder/decoder — DASDEC, Sage ENDEC, and equivalents. |
| Studio-transmitter link | The STL and any backup path, including IP codecs used as STL. |
| Any remotely managed equipment that routes, processes, or inserts content | Automation and playout, audio processing, RDS encoders, streaming encoders, remote broadcast codecs, transmitter remote control and networked exciters, studio routing and consoles, audio-over-IP endpoints — and the switches, routers and firewalls underneath all of it. |
The test to apply to any device: is it remotely manageable, and can it affect what goes out over the air? If both are true, it is in scope — whatever kind of box it is and whoever sold it to you.
Two categories of credential are in scope but are not devices at all, and they are the ones stations most reliably miss:
This section exists because several vendors are currently implying otherwise.
No filing. § 11.35(d) imposes no new recordkeeping or reporting obligation. There is no form, no certification, no filing deadline, and nothing to send the Commission. If someone tells you the FCC requires you to file a compliance document for this rule, they are selling you something.
There is still a good reason to write down what you did — exceptions need justification, staff turn over, and the person who set the passwords is not always the person answering the question two years later. But that record is for your own file.
No certification exists. Nobody can certify your station compliant with this rule, because the FCC has established no certification scheme for it. Any offer of "FCC-approved" or "certified compliant" status for § 11.35(d) is describing something that does not exist.
No published fine amount. There is no verified forfeiture figure specific to § 11.35(d). The five-figure number that circulates in trade coverage generally attaches to public file violations, which are a different rule. Ask anyone quoting you a number for the citation.
| Date | What happened |
|---|---|
| June 29, 2026 | FCC adopted the Report and Order adding § 11.35(d) |
| July 31, 2026 | Published in the Federal Register |
| September 29, 2026 | Compliance required |
| Ongoing | Patching and credential hygiene are continuing obligations, not a one-time task |
| October 30, 2026 | ETRS Form One due from every EAS Participant — a separate, pre-existing obligation, not a § 11.35(d) filing |
| November 17, 2026 | National EAS Test, 2:20 pm ET, FEMA via IPAWS — the whole industry exercises this equipment on one afternoon |
| November 19, 2026 | ETRS Form Two, 48 hours after the test |
| January 4, 2027 | ETRS Form Three |
No. See above — there is no reporting or recordkeeping obligation attached to this rule.
Almost certainly not. The firewall requirement is one of three, and it applies to the whole program chain rather than to the EAS unit alone. A station whose EAS box is protected while its STL codec sits on a forwarded port has not met the segmentation requirement.
Use the alternative-authentication path if the device supports MFA or cryptographic tokens. If it supports neither, document the limitation, keep the device off the public internet, and record the justification in your own file. A device that silently truncates a long password is the dangerous case — it accepts 16 characters, stores 8, and produces a compliance record that is not true. Set a 16-character password and then try logging in with only the first 8; if that works, the device is truncating.
It can be, if it is actually limiting remote management access rather than forwarding ports to your gear. The question the rule asks is functional, not brand-based: can an unauthorized person on the internet reach a management interface in your chain? Check by trying it from a phone on cellular data.
If it is powered and networked, treat it as in scope. Dormant equipment is the least likely to have had its firmware touched and the most likely to still carry a factory credential.
Some common broadcast equipment has documented, verifiable security behavior worth knowing before you start:
comrex, which the manufacturer has publicly warned about after learning attackers were being encouraged to use it.The Program Chain Compliance Kit is the implementation version of this page: a 90-minute start-here path, a verified device reference for common broadcast gear, three network segmentation patterns for a one-rack station, and the worksheets — inventory, port-forwarding audit, compliance memo, exception justifications — already written.