New EAS Security Rules Take Effect Soon

New FCC requirements that are designed to modernize the security of the Emergency Alert System (EAS) will take effect on September 29, 2026. The goal of the new requirements is to help guard against EAS security breaches and to “ensure that EAS Participants secure their equipment to prevent cyberattacks that could result in the transmission of false EAS alerts or disrupt the transmission of legitimate alerts.”

Broadcasters and other EAS Participants are required to take the following three mandatory measures with respect to their EAS equipment, studio transmitter links and any remotely operated EAS equipment.

  1. EAS password requirements. Default passwords must be changed. Specifically, prior to operation of EAS equipment, EAS Participants must change “any default password, use strong passwords, and change any password if the EAS Participant has reason to believe that the password has been compromised.” As an alternative to a strong password, EAS Participants can use other authentication measures to prevent unauthorized access to EAS equipment, including those highlighted by the National Institute of Standards and Technology (NIST).
  2. Firmware and software security patches. EAS Participants must “test and install security patches and security-related software and firmware upgrades issued by equipment manufacturers promptly after those patches or upgrades become available.” The FCC says that security patches are essential to reduce the risk of exploiting known EAS vulnerabilities allowing insertion of false EAS tones or alerts.
  3. Network firewalls. EAS Participants must have appropriate safeguards in place to limit remote access to authorized EAS devices. Specifically, the FCC is mandating that EAS Participants use a network firewall or comparable network segmentation for cybersecurity and to limit remote access by any unintended users.

EAS Participants should review their EAS security practices now and make necessary changes to their EAS equipment before the September 29, 2026, deadline.

Proposed Additional EAS Rule Changes

The FCC is also asking for comments on proposals to make additional changes to the EAS. Comments are due by September 29, 2026.

Among other items, the FCC is asking for input on how best to increase EAS cybersecurity and make EAS and Wireless Emergency Alerts (WEA) more secure against potential cyberattacks. The FCC is considering whether to require additional verification of emergency alerts before they are broadcast. It is also considering allowing stations to use software-based EAS systems instead of dedicated EAS equipment, which could provide broadcasters with greater flexibility.

The FCC is also considering whether emergency alerts should include easily recognizable symbols identifying the type of emergency, removing any necessary alerting requirements to allow for EAS Participants to utilize software-based processing instead of dedicated hardware, and how EAS alerts can be more accurately targeted to the geographic areas that are actually impacted by a given emergency.

For more information about the FCC’s new EAS requirements or the new EAS proposals, contact Paul Cicelski in our Media Practice Group.

Categories: Media