2026-15601RuleWallet

FCC Bolsters Emergency Alerts Against Cyber Hijackers

Published Date: 7/31/2026

Rule

Summary

In the Report and Order, the Federal Communications Commission (the FCC or the Commission) seeks to preserve the public's trust in the Emergency Alert System (EAS) by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation's adversaries.

Analyzed Economic Effects

5 provisions identified: 3 benefits, 2 costs, 0 mixed.

Estimated industry cost: $26 million/year

The Commission estimates implementation costs for the adopted measures will not exceed $26,198,094 per year in total, based on 25,800 affected entities, 10 hours per entity per year, a $65 mean hourly wage, and mark-ups. This implies an average burden of roughly $1,000+ per entity per year under the Commission's assumptions.

No broad risk-plan or incident-reporting mandate

The Commission declined to adopt the broader cybersecurity risk management plan and incident-reporting proposals from the Alerting Security NPRM. Instead, it adopted only the limited baseline requirements (passwords, patching, segmentation), eliminating requirements to create, update, or annually certify comprehensive risk plans or to report unauthorized access incidents.

Baseline cybersecurity rules for EAS gear

EAS Participants (broadcasters, cable headends, and similar providers) must secure EAS equipment by changing default passwords before use, using strong passwords of at least 15 characters that avoid dictionary words and reuse, or by using alternative authentication meeting NIST guidance. They must also promptly test and install security-related firmware/software patches and use a network firewall or comparable network segmentation to limit remote access.

60-day compliance deadline

EAS Participants must comply with the new cybersecurity requirements within 60 days after the rule's publication in the Federal Register; the rule's effective date is September 29, 2026. The 60-day compliance timeframe applies to changing defaults, patching, and implementing network segmentation or equivalent safeguards.

WEA not covered by these rules

The Commission does not apply these targeted cybersecurity requirements to Wireless Emergency Alerts (WEA) at this time. The Order finds no reported successful WEA attacks and concludes best practices rather than mandatory requirements are currently appropriate for WEA.

Personalized for You

How does this regulation affect your finances?

Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Key Dates

Published Date
Rule Effective
7/31/2026
9/29/2026

Department and Agencies

Department
Independent Agency
Agency
Federal Communications Commission
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register