Policy · 80 days ago
The compliance burden has moved into the trusted path itself. The FCC is now making security a licensing and operating requirement for systems that carry emergency alerts and for the terminals that land submarine cables, and it reaches third-party suppliers as part of that trust chain.
The new rules require stronger passwords, faster patching, firewalls, and alert authentication for EAS and WEA participants. The Commission also adopted the first major update to submarine cable rules in decades, with cybersecurity standards tied to licensing reviews for undersea cable providers and landing-station operators.
That shifts the baseline from informal hygiene to enforceable controls around systems that can spoof public warnings or disrupt critical communications. It also widens supply-chain scrutiny beyond the primary operator to the vendors and terminal equipment that sit between the cable and U.S. facilities.
3 sources covering this story
The Record from Recorded Future
FCC votes to toughen rules in bid to better protect undersea cables
In an unprecedented move, the FCC also said it plans to mandate that owners and operators of submarine line terminal equipment (SLTE) be licensed.
FCC requires emergency-alert distributors to secure their systems
More than a decade after a high-profile hacking campaign, the commission is moving from recommending basic security protocols to requiring them.
FCC passes new cybersecurity rules for emergency systems, undersea cables
The new rules would overhaul national emergency systems to protect against hijacking and update federal security review rules for undersea cables providers.
Part of the PlainSec briefing for 2026-06-27