What CableLabs raised with the industry on August 18 wasn't about Wi-Fi 7 speed competition, but about how to keep older devices connected in homes. Worldwide, more than 23 billion Wi-Fi devices are in use, and homes contain a mix of devices from different generations, budget hardware, and software that can't be updated. The organization called on the industry to prioritize implementing RSN Override (RSNO) on both access points (APs) and clients, in order to avoid cases where older devices lose connectivity when access points combine Wi-Fi 7 with WPA3.
WPA3-Personal Compatibility Mode (PCM) itself was already included in the 2025 WPA3 Specification v3.5. What's new here is that CableLabs has explicitly identified a chicken-and-egg problem: if few clients support RSNO, APs have little incentive to enable it, and if APs don't use it, client-side implementation doesn't progress either. Settings designed to ensure compatibility can also result in Wi-Fi 7 features being unavailable depending on a device's generation. Beyond checking for a "Wi-Fi 7 compatible" label, deployers need to separately examine which band falls back to what.
The Misunderstanding Around Older Devices in Transition Mode
WPA3-Personal Transition Mode advertises multiple authentication methods—such as WPA2's PSK and WPA3's SAE—within the same RSN Element (RSNE). This mechanism is meant to accommodate both new and old devices on a single SSID, but some older devices cannot ignore authentication and key management (AKM) methods or cipher information they don't recognize. They may misinterpret this information and fail to connect to the AP.
With Wi-Fi 7, falling back to WPA2-only to avoid this problem doesn't solve it while preserving Wi-Fi 7 functionality. In its response to The Register, CableLabs explained that before Wi-Fi 7, reverting to WPA2-only was an option when compatibility issues arose. However, under Wi-Fi Alliance specifications, PSK-based AKM cannot be used for connections utilizing EHT or MLO—Extremely High Throughput and Multi-Link Operation, respectively. This traditional workaround can restore connectivity, but the result no longer operates as Wi-Fi 7.
Cisco's migration guide likewise states that using Wi-Fi 7 Personal on its products requires SAE-EXT-KEY, GCMP-256, PMF, and Beacon Protection. This doesn't necessarily reflect every vendor's UI or default settings, but it's a concrete implementation example showing that WPA3 configuration for Wi-Fi 7 can't be handled with the same assumptions as conventional transition mode.
Separating Information Between Standard RSNE and Override
PCM separates information into a standard RSNE that older devices read and RSN Override information intended for newer devices. On 2.4GHz and 5GHz, the standard RSNE carries WPA2-Personal's AKM 2 and CCMP-128, while the RSNE Override carries base WPA3's AKM 8, CCMP-128, and PMF required. A further RSNE Override 2 for Wi-Fi 7 advertises AKM 24 and GCMP-256.
6GHz is designed differently. Since WPA2/PSK isn't permitted there, the standard RSNE carries base WPA3's AKM 8 and CCMP-128, while Wi-Fi 7 requirements for EHT/MLO are separated into RSNE Override 2. By splitting this information, requirements that older devices can't understand are hidden from them, while newer devices are still advertised the necessary WPA3 and Wi-Fi 7 conditions.
| Band | Standard RSNE | Override side | Where RSNO-unsupported devices connect |
|---|---|---|---|
| 2.4GHz / 5GHz | WPA2-Personal (AKM 2, CCMP-128) | Base WPA3, Wi-Fi 7 AKM 24 & GCMP-256 | Connects via WPA2-Personal, equivalent to Wi-Fi 6 |
| 6GHz | Base WPA3 (AKM 8, CCMP-128) | Wi-Fi 7 EHT/MLO requirements | Connects via base WPA3, equivalent to Wi-Fi 6E |
As the table shows, the "fallback destination" differs between 2.4GHz/5GHz and 6GHz. In the former case, devices can connect via WPA2-Personal, but WPA2/PSK cannot be used on 6GHz. RSNO-unsupported devices that support 6GHz can connect using base WPA3-Personal, but cannot use Wi-Fi 7's EHT/MLO.
How Far Down Do Devices Without Wi-Fi 7 Fall Back?
The Wi-Fi Alliance's WPA3 Specification v3.5 requires AKM 24 and GCMP-256 for APs and stations that enable EHT or MLO. Since PSK AKM cannot be used for EHT/MLO connections, if a device can't find an acceptable AKM, it may disable EHT/MLO and fall back to HE—that is, Wi-Fi 6.
Blurring the distinction between bands here leads to mistaken explanations of compatibility. Devices on 2.4GHz and 5GHz that can't understand RSNO can still connect as WPA2-Personal, but without EHT/MLO, resulting in Wi-Fi 6 equivalence. On 6GHz, by contrast, they connect as base WPA3-Personal, resulting in Wi-Fi 6E equivalence without EHT/MLO. Neither fallback can be substituted for the other—you can't apply the former's fallback to 6GHz, nor describe the latter as falling back to WPA2.
The Android Open Source Project's hostapd also includes a general configuration example for RSN overriding. It places WPA-PSK, CCMP, and PMF optional in the standard RSNE, and SAE, GCMP-256, and PMF required in the override. For Wi-Fi 7, SAE-EXT-KEY and GCMP-256 are added. While this isn't an exact reproduction of the values the Wi-Fi Alliance defined for PCM, it demonstrates that security information shown to different device generations can indeed be separated at the configuration level.
Keeping a Single SSID vs. Splitting Off a Legacy SSID
The Wi-Fi Alliance's deployment guide treats PCM as a workaround setting to avoid interoperability problems with older devices. Because a single SSID and single password can be maintained, users don't need to choose a different network to connect to. However, newer devices that don't support RSNO also fall back to the legacy method. The cost of maintaining compatibility is that some devices can't unlock their full capabilities.
The alternative is a dual-SSID approach, splitting a WPA3 main SSID from a WPA2 SSID for legacy devices. This approach allows devices on the main SSID to run on WPA3. However, users must choose the correct SSID, and managing multiple SSIDs and passwords adds overhead. In homes, this risks users connecting to the wrong network; in organizations, it adds deployment and operational complexity.
| Approach | Connection convenience | How newer devices are handled | Operational burden |
|---|---|---|---|
| Single SSID via PCM | Single SSID and password can be maintained | RSNO-unsupported devices fall back to the legacy method | No SSID selection needed by users |
| Dual-SSID | Users must choose between old and new device networks | Main SSID can be kept isolated as WPA3 | Increased SSID selection and management |
Enabling PCM doesn't mean every device becomes WPA3, nor that every device runs Wi-Fi 7. What deployers need to weigh is how many older devices they need to continue supporting, and what connection conditions to grant newer devices.
Breaking the Chicken-and-Egg Problem in Implementation
Along with calling for RSNO support on both APs and clients, CableLabs urged verification of whether devices with older chipsets can correctly process larger management frames when Beacon and Probe Response frames grow longer. Even if RSNO alone is implemented, connectivity problems remain if surrounding management frames can't be handled by older hardware.
At the same time, CableLabs has not disclosed specific figures, ratios, or product lists for devices lacking RSNO support. Beyond the qualitative description of "many devices," it remains unclear exactly which products are affected. As a result, RSNO support cannot be inferred merely from a "Wi-Fi 7 compatible" product label.
The Wi-Fi CERTIFIED 7 certification program launched in January 2024. Going forward, when updating APs or replacing devices, what needs to be verified isn't the Wi-Fi 7 label itself, but whether certification documentation or vendor materials specify RSNO support, and whether the expected fallback behavior on 2.4GHz/5GHz versus 6GHz actually holds true.
