Home > EASA Part-IS: The New Era of Aviation Cybersecurity is Here

EASA Part-IS: The New Era of Aviation Cybersecurity is Here

EASA Part-IS: The New Era of Aviation Cybersecurity is Here

Critical Deadlines Approaching for Aviation Organisations
The aviation industry is entering a new regulatory era with EASA Part-IS (Information Security) coming into force, and time is running out for many organisations to achieve compliance. With deadlines as early as October 2025, aviation entities across Europe must act now to meet stringent new information security requirements designed to protect the increasingly digital aviation ecosystem.


What is EASA Part-IS?

EASA Part-IS is a comprehensive regulation introduced by the European Union Aviation Safety Agency to strengthen information security management across the aviation sector. In an era where aircraft systems, air traffic management, and operational infrastructure are increasingly interconnected and digital, this regulation recognises a fundamental truth: cybersecurity is now a safety issue.

The regulation, formally known as Implementing Regulation (EU) 2023/203, establishes mandatory requirements for organisations to manage information security risks that could impact the safety of aircraft, systems, and operations. It’s not just about protecting data—it’s about ensuring that cyber threats cannot compromise aviation safety.


Who Needs to Comply?

Part-IS has a broad scope covering virtually all aviation safety organisations, including:

  • Air Operators (airlines and commercial aviation companies)

  • Approved Maintenance Organisations (Part-145 and Part-M)

  • Continuing Airworthiness Management Organisations (CAMOs)

  • Design and Production Organisations

  • Airports and Air Navigation Service Providers

  • Ground Handling Service Providers

If your organisation plays any role in aviation safety, there’s a strong likelihood you fall within the scope of this regulation. The reach is intentionally comprehensive because modern aviation safety depends on the integrity of interconnected systems across the entire industry.


The Compliance Deadlines

Different organisation types face different implementation deadlines:

  • 16 October 2025: Organisations under the Delegated Regulation, including airports and design/production organisations

  • 22 February 2026: Organisations under the Implementing Regulation, such as air operators, CAMOs, and Part-145 maintenance organisations

These dates are rapidly approaching, and organisations should already be well into their compliance journey. The complexity of implementing a full Information Security Management System (ISMS) means that last-minute preparation is not a viable strategy.


Key Requirements Under Part-IS

The regulation mandates a structured approach to information security centred around several core components:

Information Security Management System (ISMS)

Organisations must establish and maintain a comprehensive ISMS that integrates with their existing safety management systems. This framework provides the foundation for managing information security as a continuous process rather than a one-time project.

Security Risk Assessment and Treatment

Part-IS requires systematic identification and assessment of information security risks to aviation safety. Organisations must evaluate potential threats, assess their likelihood and impact, and implement appropriate controls to mitigate risks to acceptable levels.

Detection, Response & Recovery

It’s not enough to prevent incidents—organisations must also be prepared to detect security breaches, respond effectively, and recover operations whilst maintaining safety. This requires documented procedures, trained personnel, and regular testing.

Reporting Requirements

Both internal and external reporting mechanisms must be established. This includes reporting significant information security events to relevant authorities and maintaining transparent communication channels within the organisation.

Information Security Management Manual (ISMM)

Organisations must document their information security policies, procedures, and responsibilities in a comprehensive manual that serves as the reference document for all security activities.


Bostonair Technical Training is a Part 147 Approved Organisation (EASA & UK CAA), recognised for delivering trusted, industry-compliant training to aviation professionals worldwide

Enrol today to ensure compliance with EASA Part-IS.