In European aviation regulations, you often see “competent authority”. It is not a single entity: it is the “regulator & controller” link in the system, the one that issues approvals and oversees that actors follow the rules.
In the European architecture, the competent authority is most often national (France, Germany, etc.), while EASA and the Commission play other roles.
Under the EASA framework, Member States designate “one or more entities” as the competent authority, with the powers and responsibilities needed for:
➡️ In plain terms: the competent authority is “the enforcer + the certifier” (in the administrative sense), not “the author of the law”.
The “Basic Regulation” (the foundation of the system) describes a single European aviation safety system where the Commission, the Agency (EASA), and the Member States cooperate to ensure compliance with the rules.
The Commission adopts:
within the framework set by the Basic Regulation — these are what create/adjust applicable obligations.
The Commission “puts the rule into legal stone”.
EASA is the EU agency dedicated to aviation safety: it harmonises, develops technical rules, supports oversight, and participates in certification in certain scopes.
Concretely, EASA produces in particular:
EASA “draws the method and the technique”, and coordinates European alignment.
In most cases, they:
This is exactly what Air Ops (EU) No 965/2012 formalises: Member States must designate the competent authority and its responsibilities for certification and oversight.
Because European law has to answer a simple question:
Which country is responsible for overseeing this actor?
The regulations therefore set attachment rules (typical examples in Air Ops 965/2012):
In practice, a competent authority has 4 main missions (and this is what operators and organisations experience):
Example (Part-IS): EASA publishes “oversight” guidelines for competent authorities, to homogenise how ISMS are controlled.
In France, the DGAC is the administration in charge of civil aviation (safety, security, air traffic control, regulation, etc.).
And for certification and safety oversight, the DSAC (Direction de la Sécurité de l’Aviation Civile) is the central actor: it ensures compliance with regulatory provisions and acts in the certification and oversight of operators on the basis of international and European regulation.
➡️ So when an EASA text says “competent authority” and your organisation/operator is overseen in France, you are, in most cases, in the DGAC / DSAC ecosystem (with the relevant services/levels depending on your activity).
In aviation, “being compliant” does not just mean having obtained a certificate: it means remaining compliant over time… while the texts evolve.
EU regulations live through amendments and corrections. The challenge is not to miss an applicable amendment.
Oversight is not theoretical: the regulations explicitly provide for mechanisms of limitation, suspension, or withdrawal of certificates/approvals depending on the case and severity.
And some texts even frame transition deadlines: for example, in Part-21 (Regulation (EU) No 748/2012 as amended), if certain non-conformities are not closed after a given date, the certificate may be revoked, limited, or suspended.
Tracking amendments “by hand” works… until the day you miss an applicable change, a deadline, or an update to means of compliance.
A tool like ComplyAir can strongly reduce that risk by helping to: