SEO Title
EASA Part-IS Regulations To Bolster Civil Aviation Data Security
Subtitle
Safety-focused European Information Security Management Systems requirement comes fully into effect later this month
Subject Area
Teaser Text
On February 22, the second wave of a new mandatory EU aviation regulatory framework for Information Security Management Systems (ISMS) comes into effect.
Content Body

The second wave of a new mandatory European aviation regulatory framework for information security management systems (ISMS) comes into effect on Sunday. An extension of existing safety regulations, EASA Part-IS (information security) will establish additional requirements for managing information security risks, focusing on safeguarding operations and strengthening resilience in civil aviation.

Although similar to existing protocols, Part-IS requirements also include a risk-based approach to protect digital assets and operations that—if compromised—could negatively impact aviation safety.

Recognizing that increased reliance on data requires heightened cybersecurity safeguarding EASA is implementing Part-IS in two phases. The first compliance deadline of Oct. 16, 2025, applied to EASA-approved organizations such as airlines, airport operators, air navigation service providers, maintenance organizations, and other industry stakeholders.

The February 22 deadline will also see other bodies such as aviation authorities required to take extra steps toward safeguarding and monitoring data. In practical terms, this will include conducting risk analysis of potential cyber attacks, creating a security plan, training to identify potential problems, and a robust incident response procedure.

According to EASA, an organization may use an existing cybersecurity competency framework to develop its necessary Part-IS competencies. Although no specific risk-assessment framework is mandated, the regulator recommends a combination of methodologies, including assessing potential threats to assets alongside analysis of safety consequences.

Expert Opinion
False
Ads Enabled
True
Used in Print
False
Writer(s) - Credited
Charlotte Bailey
Solutions in Business Aviation
0
Header Image Caption Override
The EU Aviation Safety Agency will acquire EASA-approved organizations to comply with the new digital resilience measures.
AIN Publication Date
World Region
----------------------------