ComplyAir LogoComplyAir
Regulations

Part-IS Compliance: a Practical Guide for Your Organization

#Part-IS#EASA#Cybersecurity#ISMS#Compliance#Regulatory monitoring

Since 22 February 2026, nearly every EASA-approved organization must operate an information security management system (ISMS). Part-IS is no longer a distant deadline: it is a live requirement, and authorities have started checking it in audits.

This guide covers the essentials: who is in scope, which regulations apply, what a compliant ISMS actually contains, and how to organize the work.

For the background and context of the rule, see Part-IS: cybersecurity takes off in aviation.


Part-IS comes as two regulations

Part-IS rests on two complementary texts, with different applicability dates:

RegulationOrganizations coveredApplicable since
Delegated Regulation (EU) 2022/1645Design (DOA) and production (POA) organizations under Regulation 748/2012, aerodromes and apron management service providers under Regulation 139/201416 October 2025
Implementing Regulation (EU) 2023/203Air operators (AOC), CAMOs, Part-145 maintenance organizations, ATOs, FSTD operators, aeromedical centres, ATM/ANS providers, U-space22 February 2026

The substantive requirements are aligned between the two texts; what differs is the scope and the competent authority.


Why a dedicated rule for information security?

Aviation has gone digital: paperless airworthiness records, data exchanged between organizations, operational IT systems, connected maintenance. An attack, or plain data corruption, can now directly affect flight safety.

Part-IS does not try to protect your entire IT estate. Its object is narrow and precise: information security risks with a potential impact on aviation safety. That focus is what separates it from a general cybersecurity program, and it runs through every requirement in the text.


Who is in scope, and who can get out?

In practice, if your organization holds an EASA approval, you are in scope. The list covers most of the industry: AOC holders, DOAs, POAs, CAMOs, Part-145 organizations, ATOs, FSTD operators, aeromedical centres, certified aerodromes, ATM/ANS providers.

Two important nuances:


What Part-IS actually requires

The core obligation fits in one sentence: establish, document and maintain an ISMS. Unpacked, it means:

1. An information security policy, owned by the accountable manager, stating the organization’s commitments.

2. A risk assessment. Identify the elements of your information system whose compromise could affect aviation safety, assess the associated risks, treat them. This is the structuring exercise: everything else flows from it.

3. Incident detection and response. Be able to detect an information security event, respond to it, and recover from it. The text expects working measures, not a paper procedure.

4. Reporting. Incidents with a potential impact on aviation safety must be reported to your competent authority through the existing occurrence-reporting scheme. This is one of the requirements ISO 27001 does not cover.

5. A manual (ISMM) describing your ISMS, its processes, responsibilities, and how it interfaces with your existing management system.

6. People who know what they are doing. Someone must own the ISMS by name, and contracted activities stay your problem: if a provider hosts or processes your critical data, their risks are your risks.

7. Continuous improvement, with reviews and compliance monitoring integrated into your existing audit program.


Already ISO 27001 certified?

Good news: much of the work is done. EASA has published mappings between Part-IS and ISO 27001, and a certified ISMS is a solid foundation.

Three gaps almost always remain:

The efficient approach is to start from what exists and document the deltas, not to build a second, parallel system.


Where to start: a realistic roadmap

  1. Frame the scope. Which approvals do you hold? Which authority is competent? Is a derogation possible, and actually worth it?
  2. Inventory. Systems, data, interfaces and providers whose failure could touch aviation safety.
  3. Assess the risks on that scope, with a method you can defend in an audit.
  4. Write the ISMM, reusing your existing documentation system.
  5. Set up incident detection and reporting, and test the process at least once.
  6. Train the people involved and appoint the ISMS responsible person.
  7. Close the loop with compliance monitoring: Part-IS enters the internal audit program like any other requirement.

Authorities now check Part-IS during audits: see our guide EASA audit: how to prepare.


FAQ

Is Part-IS already applicable? Yes. Since 16 October 2025 for Part 21 organizations and aerodromes (Regulation 2022/1645), and since 22 February 2026 for operators, CAMOs, Part-145s, ATOs and other approved organizations (Regulation 2023/203).

Is my organization in scope? If you hold an EASA approval, in principle yes. A derogation is possible if the organization demonstrates the absence of information security risk to aviation safety, subject to authority approval.

Is ISO 27001 enough? No, but it covers most of the distance. The remaining gaps are typically incident reporting to the authority and the aviation-safety-centered risk assessment.

SMS vs ISMS? The SMS manages operational risks; the ISMS manages information security risks that can impact aviation safety. The two must interface.


Keeping up with Part-IS over time

Part-IS is a living rule: revised AMC, authority guidance, decisions, lessons from the first audit campaigns. It is exactly the kind of transverse requirement a manual regulatory watch misses.

ComplyAir centralizes EASA regulations, Part-IS included, analyzes every amendment and alerts you to what affects your approvals. Request a demo or see our pricing.

← Back to Blog