Page updated: 9/23/2026 


Link to FCC's FAQ

Frequently Asked Questions - EAS Cybersecurity Requirements | Federal Communications Commission 


Q: Do the EAS security password requirements (47 CFR § 11.35(d)(1)) apply to all broadcaster equipment? Only EAS devices? All IP-connected equipment in the program chain?


A: The password requirements do not apply to all broadcaster equipment or all IP-connected equipment in the program chain. The password requirements only apply to EAS equipment, studio transmitter link equipment, and any remotely managed equipment that routes, processes, or inserts content into the program stream transmitted by the EAS Participant to the public and subscribers (e.g., audio processors; ad insertion systems; and AM and FM radio and DTV transmitters that are remotely managed). Thus, EAS Participants must implement the rule’s cybersecurity requirements for other equipment beyond just EAS equipment, but are not required to apply the requirements to any remotely managed equipment that does not route, process, or insert content into the EAS Participant’s program stream.


FCC Password Requirements Overview

The FCC has not issued a blanket request for all users to change to non-default passwords. However, they have expanded their Covered List to block high-risk routers and drones due to national security concerns. This action specifically targets foreign-made consumer-grade routers.

 

Key Points

  • High-Risk Devices: The FCC's new restrictions focus on certain routers and drones deemed high-risk.
  • Existing Devices: Devices already in use are not affected by these new restrictions.
  • Password Policy: While the FCC emphasizes the importance of strong passwords, there is no universal mandate for all users to change their passwords to non-default settings.

 

Recommendations for Users

  • Change Default Passwords: Users are encouraged to change default passwords on their devices to enhance security.
  • Use Strong Passwords: Implement passwords that are a mix of letters, numbers, and special characters, ideally 12-15 characters long.
  • Regular Updates: Keep all software and firmware updated to protect against vulnerabilities.

By following these guidelines, users can better secure their devices against potential threats.