Signal Stack

B2B technology signals above the noise.

Data Platforms · 5 min read

FCC’s EAS Order Leaves Alert Geotargeting Accuracy Optional

The FCC's new Emergency Alert System order locks down equipment security on a fixed deadline, but the question of whether alerts can be targeted to precise locations stays open in a rulemaking docket with no committed date.

The FCC’s June 29, 2026 order forces EAS Participants to lock down equipment against cyberattack, but the companion proposal on alert geotargeting accuracy — the piece most relevant to whether an alert reaches only the people actually in danger — stays a comment-stage idea, not a rule.

That distinction matters for anyone budgeting compliance work around this Order. The Report and Order and Further Notice of Proposed Rulemaking splits cleanly into two tracks: a hard cybersecurity mandate, and a set of open questions about reliability, including how precisely EAS messages can target the people who need them.

What the June 2026 EAS Order Actually Requires

The Order requires EAS Participants — all radio and television stations, cable television systems, satellite radio and television services, and wireline video providers — to secure their equipment against unauthorized access.

Three requirements apply to EAS, studio transmitter link, and remotely managed equipment that routes, processes, or inserts content into an EAS Participant’s programming stream: eliminate default passwords or add equivalent strong authentication, promptly test and install manufacturer security patches, and put a network firewall or comparable segmentation between remote management access and the outside world.

Compliance is due 60 days after the Order publishes in the Federal Register — the clock starts at publication, not at the June 29, 2026 adoption date, so the exact deadline depends on a Federal Register date the evidence does not itself supply.

The table below separates what is already mandatory from what the FNPRM only proposes, since operators planning budgets need to know which line items carry a deadline and which do not.

Requirement Status Timeline
Strong authentication / no default passwords Mandatory (Order) 60 days after Federal Register publication
Prompt patch and firmware installation Mandatory (Order) 60 days after Federal Register publication
Network firewall or segmentation Mandatory (Order) 60 days after Federal Register publication
Detailed CAP location data for geotargeting Proposed only (FNPRM) Comments due 30 days after publication
Universal alert message ID Proposed only (FNPRM) Comments due 30 days after publication

Why Alert Geotargeting Accuracy Remains Unsettled

Alert geotargeting accuracy is the mechanism that decides whether an alert reaches a county, a metro area, or a single affected block. CAP-formatted EAS messages can already carry that granularity, but the Order does not compel any EAS Participant to act on it.

Two other FNPRM items sit next to the location-data proposal: a universal alert message ID meant to stop duplicate alerts, aimed primarily at Wireless Emergency Alerts but under consideration for EAS too, and a proposal to require authentication of every alert before transmission.

Comments on the FNPRM are due 30 days after Federal Register publication, with reply comments due 30 days after that. That comment schedule, not a rule date, is the only timeline the evidence attaches to geotargeting accuracy, which is the practical constraint anyone tracking this docket should plan around.

The Physical-Layer Failure Mode the Order Doesn’t Touch

Protocol-level accuracy is only half of delivery reliability — an alert still has to survive the network path. One described scenario has temperatures hitting over 104°F for 5 days in a row, with grid demand from air conditioning followed by severe storms downing trees and power lines across 3 states.

Under that kind of event, cell towers lose grid power and shift to battery, and backup batteries drain within hours — a failure that cuts the last-mile channel an alert depends on regardless of how precisely it was geotargeted upstream.

That is a distinct failure mode from anything addressed in the FCC Order: a perfectly targeted, authenticated alert still fails to reach a handset or receiver if the delivery network has already lost power.

The source’s recommendation to build multi-channel redundancy rather than relying on mobile alerts alone follows reasonably from that infrastructure-stress pattern, though the evidence does not quantify how often towers actually go dark in a given storm season.

Reliability Benchmarks the EAS Docket Doesn’t Yet Have

Neither the Order nor the FNPRM publishes a numeric reliability target for alert delivery, such as a recovery time objective, against which EAS Participants or vendors could be measured.

For comparison, Microsoft’s business continuity documentation for Power Platform and Dynamics 365 states a recovery point objective near zero and a recovery time objective of less than five minutes for production environments using availability-zone failover — a figure that describes an unrelated SaaS platform, not EAS infrastructure, but illustrates what a vendor-committed reliability number looks like when one is published.

The absence of a comparable published figure for EAS is itself worth noting: without a regulatory or vendor-committed number, reliability claims about alert delivery in this space are not independently checkable from the current record.

Operational Impact and What to Verify

For broadcasters and cable, satellite, and wireline video providers, the near-term obligation is narrow and mechanical: authentication hygiene, patch cadence, and network segmentation, all due within 60 days of Federal Register publication.

Budgeting for anything beyond that — geotargeting upgrades, duplicate-alert suppression, alert authentication infrastructure — should wait for the FNPRM comment record rather than a fixed rollout date, since none of those items carry a compliance deadline in the Order itself.

Organizations operating alert-adjacent notification tooling should also weigh incident-response process maturity alongside protocol compliance. General guidance on incident lifecycles stresses that activity during an outage is not the same as coordinated progress, and that a defined escalation and communication path shortens recovery regardless of which layer failed — a principle that is generic to outage response rather than specific to EAS, but applies directly to any organization whose alert infrastructure depends on both compliant equipment and a functioning physical network.

Before treating any vendor’s alerting claims as settled, check four things: the actual Federal Register publication date that starts the 60-day and 30-day clocks, the FNPRM docket status for the geotargeting and universal-ID proposals, whether a vendor can produce a published recovery time objective comparable to the less than five minutes figure cited for unrelated SaaS platforms, and what backup power and channel redundancy exist for the last mile given documented battery-drain windows measured in hours under sustained heat and storm load.

  • Confirm the Federal Register publication date for the June 29, 2026 Order before assuming the 60-day compliance deadline has started
  • Track the FNPRM docket specifically for the geotargeting-accuracy and universal alert message ID items, both still proposals rather than rules
  • Ask any alerting vendor for a published recovery time objective; none currently exists in the EAS rulemaking record
  • Verify backup power duration for the cell infrastructure an alert depends on, given hours-scale battery drain during sustained storm and heat events