For stations without an engineer
It isn't. It covers your STL, your automation, your processing, your RDS encoder, your transmitter remote control — and the network underneath all of it.
The rule's actual language. It applies to EAS equipment, studio-transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the broadcaster's programming.
The station that changes the password on its EAS box and calls it finished has not complied.
On June 29, 2026 the FCC adopted a new paragraph (d) to 47 CFR § 11.35. It requires three things of every EAS Participant: strong passwords of at least 15 characters, prompt installation of security patches, and a firewall or comparable network segmentation limiting remote management access.
There is no small-station exemption. AM, FM, TV, LPFM, LPTV, Class A, translators and noncommercial stations are all covered. Compliance is required September 29, 2026.
A practical implementation guide written by a broadcast professional, for the person who was handed this deadline without an engineer to hand it to.
| Document | What it does |
|---|---|
| Start Here | The 90-minute version. Six actions that address most of your real exposure in a single afternoon. |
| Compliance Guide | What the rule says and what it covers. The alternative-authentication path for gear that can't take 15 characters. Three network segmentation patterns for a one-rack station. |
| Device Quick Reference | Verified security behavior of common broadcast gear — Sage, DASDEC, Barix, Comrex, Tieline, Burk, Inovonics — plus a universal method for anything not listed. |
| Worksheets & Templates | Program chain inventory, port-forwarding audit, compliance memo, exception justification forms, patch log, credential and offboarding policy. |
Not a weak default — no password protection in the default configuration. A broadcaster running Barix between studio and transmitter had those units reconfigured by an outsider to pull a different stream. Graphic content went to air, and the attacker changed the management password so the station couldn't restore its own settings. Barix is common in small-market STL.
comrexComrex has publicly warned customers about this after learning of a website encouraging attackers to break into Comrex codecs using manufacturer defaults.
Some devices accept a 16-character password, save it without error, and quietly store only the first eight. It looks exactly like success. The kit shows you the two-minute test that catches it.
Instant download
Remote, scheduled this week
Cluster and group pricing available. If you operate more than one facility, get in touch before buying.
No-questions refund. If the kit isn't useful to your station, reply to your receipt and we'll refund it. No forms, no explanation required.
The rule does not require you to file anything. There is no new recordkeeping or reporting obligation attached to § 11.35(d). If someone tells you otherwise, they're selling you something. The kit includes documentation templates because exceptions need justification and staff turn over — not because the FCC asks for them.
This isn't legal advice. It's an implementation guide written by a broadcast professional. It isn't a compliance certification or a security audit, and it doesn't guarantee any regulatory outcome. For contested questions, talk to your communications counsel or an SBE-certified broadcast engineer. Your station remains responsible for its own compliance.