# FCC Implements EAS Cybersecurity Rules

The Federal Communications Commission (FCC) has issued new cybersecurity rules for Emergency Alert System (EAS) equipment that take effect on September 29, 2026. These rules require broadcasters to enhance security measures by implementing unique, strong passwords or alternative authentication methods for all internet-connected program chain equipment. Additionally, broadcasters must update software and hardware and deploy firewalls to protect EAS devices. Third-party program suppliers who insert content directly into EAS equipment are also subject to these requirements. This regulatory change directly impacts procurement strategies for broadcasters and related vendors, emphasizing the need for compliant cybersecurity solutions in EAS equipment acquisitions.

- **Why this matters:** Broadcasters and equipment suppliers must ensure that all EAS devices meet the FCC's cybersecurity standards by the September 29 deadline to maintain compliance and avoid potential enforcement actions.
- Procurement professionals should prioritize sourcing EAS equipment and services that support strong authentication, software/hardware updates, and firewall capabilities.
- Vendors offering cybersecurity solutions tailored to broadcast EAS systems may find increased demand as broadcasters upgrade or replace non-compliant equipment.
- Organizations involved in third-party content insertion must also review their systems to align with the new FCC requirements, influencing contract scopes and vendor selection.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 23, 2026

### Government Entities
- Federal Communications Commission (FCC)

### Sources
- [FCC Issues FAQs on Compliance with New EAS Cybersecurity Rules Taking Effect on September 29 | Broadcast Law Blog](https://www.broadcastlawblog.com/2026/09/articles/fcc-issues-faqs-on-compliance-with-new-eas-cybersecurity-rules-taking-effect-on-september-29) - Broadcast Law Blog