TRS Aviation Consulting GmbH
  • Services
    • Document Management Services
    • Minimum Equipment Lists
    • Non-commercial complex aircraft operations
    • Consulting
  • Escape Routes
  • Compliance Management
  • About us
  • Contact
  • Search
  • Menu Menu

EASA Part-IS – Upcoming Mandatory Information Security Requirements for Air Operators

Newsletter
Category: Regulation Update
Title: EASA Part-IS Compliance Requirements
Date of Issue: July 2025
Applicability: CAT & NCC Operators 

Overview

EASA has introduced a new regulatory framework, Part-IS, to ensure aviation organisations manage information security risks that could impact flight safety. Part-IS is therefore considered a safety regulation.
This framework will become legally binding for most air operators, including Commercial Air Transport (CAT) and Non-Commercial Complex (NCC) operators, under the Implementing Regulation (EU) 2023/203.

Compliance Deadline: 22 February 2026

Who Is Affected?

The regulation applies to the following organisations:

  • Air Operators holding an AOC (CAT operations)
  • NCC Operators
  • Approved Training Organisations (ATO)
  • Part-CAMO organisations
  • Part-145 maintenance organisations (with some exclusions)
  • Operators of FSTD, medical examiners, ATCO training organisations, etc.

What Must Be Done – Step by Step

Step 1: Conduct a Gap Analysis

Compare your current management system with the Part-IS baseline

Focus areas:

  • Roles and responsibilities
  • Existing cyber protection measures
  • Interfaces with IT, third parties, CAMO, Maintenance

Step 2: Create your Information Security Documentation

This is your core document and must include:

  • Scope and boundaries of your Information Security Management System (ISMS)
  • Information security policy
  • Identified threats and initial risk assessments
  • Mitigation and response procedures
  • Reporting structures (internal + external)
  • Change management, recordkeeping, external interfaces
  • Compliance monitoring procedure

The required documentation does not have to be a standalone manual. As is part of the Safety Management System (SMS) it can also be included as a dedicated section within OM A Chapter 3, or any other company SMS documentation.

Step 3: Staff Preparation and Training

Inform and train:

  • Accountable Manager
  • Nominated Persons
  • Cybersecurity-responsible staff

Prepare reporting procedures.

Step 4: Compliance Monitoring and Readiness Review

  • Conduct an internal audit and risk re-assessment
  • Document findings and actions

TRS Recommendations

TRS recommends to:

  • Assess your organisation’s current level of information security preparedness
  • Develop and submit Part-IS documentation well before the compliance deadline
  • Plan a structured implementation in line with the Part-IS “Present, Suitable, Operating, Effective” model

We assist our clients in:

  • Developing and aligning documentation with Part-IS requirements
  • Conducting implementation audits
11. July 2025/by Lazo-Flores
Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.trsc.de/wp-content/uploads/2021/06/trs-logo-bold.svg 0 0 Lazo-Flores https://www.trsc.de/wp-content/uploads/2021/06/trs-logo-bold.svg Lazo-Flores2025-07-11 12:22:492025-07-11 13:20:16EASA Part-IS – Upcoming Mandatory Information Security Requirements for Air Operators
Lost Communication & Emergency Descent Procedures · Part-SERA Update Holdover Time Guidelines – Winter 2025–2026
Scroll to top

This site uses cookies. By continuing to use the site, you agree to the use of cookies.

Accept all cookiesReject all cookiesSettings

Cookie and Privacy Settings



How we use cookies

We can request cookies that are set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to improve your user experience and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your settings. Note that blocking some types of cookies may affect your experience on our websites and the services we can offer.

Necessary website cookies

These cookies are absolutely necessary in order to provide you with the services and functions available on our website.

Da diese Cookies für die auf unserer Webseite verfügbaren Dienste und Funktionen unbedingt erforderlich sind, hat die Ablehnung Auswirkungen auf die Funktionsweise unserer Webseite. Sie können Cookies jederzeit blockieren oder löschen, indem Sie Ihre Browsereinstellungen ändern und das Blockieren aller Cookies auf dieser Webseite erzwingen. Sie werden jedoch immer aufgefordert, Cookies zu akzeptieren / abzulehnen, wenn Sie unsere Website erneut besuchen.

Since these cookies are absolutely necessary for the services and functions available on our website, the rejection will affect the functionality of our website. You can block or delete cookies at any time by changing your browser settings and forcing all cookies on this website to be blocked. However, you will always be asked to accept / reject cookies when you visit our website again.

We will provide you with a list of the cookies stored on our domain by your computer. For security reasons, we cannot show you cookies that are stored by other domains. You can see this in the security settings of your browser.

Other external services

We also use various external service such as Google Web Fonts. Since these providers may save your personal data, you can deactivate them here. Please note that deactivating these cookies can significantly impair the functionality and appearance of our website. The changes will take effect after reloading the page.

Privacy Policy

You can read about our cookies and privacy settings in detail in our privacy policy.

Privacy Statement
Matomo

Opt-out complete; your visits to this website will not be recorded by the Web Analytics tool. Note that if you clear your cookies, delete the opt-out cookie, or if you change computers or Web browsers, you will need to perform the opt-out procedure again.

You may choose to prevent this website from aggregating and analyzing the actions you take here. Doing so will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.

The tracking opt-out feature requires cookies to be enabled.

Accept settings Don't accept settings