The EU's information security regime for aviation ends the historical separation of cyber from safety. Aerodrome operators have been in scope since 16 October 2025; the wider aviation population follows from 22 February 2026, and applicability is only the start of the obligation.
Part-IS is the European Union's information security regime for aviation, established by Delegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203. It requires in scope organisations to implement an information security management system that manages information security risks with a potential impact on aviation safety, integrated with the safety management system rather than run beside it.
The applicability arrives in waves. Aerodrome operators and apron management service providers have been in scope since 16 October 2025. Air operators, maintenance and continuing airworthiness organisations, training organisations and air navigation service providers follow from 22 February 2026, with ground handling service providers brought into scope on a later horizon. Critically, applicability is the start of the obligation, not its discharge: under the phased maturity model an organisation must go on to demonstrate an information security management system that is operationally effective rather than merely documented.
The regime's deeper point is integration. For years aviation information security was an IT function concerned with confidentiality, while safety was managed elsewhere; Part-IS ends that separation as a matter of law, because a ransomware event against maintenance records or a common use passenger platform is a safety relevant event, not an inconvenience. In Switzerland, FOCA oversees Part-IS within its regular safety oversight and expressly allows credit from an ISO 27001 certification, provided aviation safety is built into the risk management, which converts a compliance burden into a single piece of work.
Aerodrome operators and apron management service providers since 16 October 2025; air operators, maintenance and CAMO organisations, training organisations and air navigation service providers from 22 February 2026; ground handling providers on a later horizon.
No, but they are close relatives. Part-IS requires an ISMS whose scope is aviation safety impact and whose home is the safety management system. In Switzerland, FOCA expressly allows credit from an ISO 27001 certification toward Part-IS, provided aviation safety is built into the risk management.
That a documented ISMS is not the finish line. The organisation must progressively demonstrate that the system operates: risks genuinely managed, incidents genuinely handled, and effectiveness evidenced to the competent authority rather than asserted.
They overlap for many operators. EASA has confirmed Part-IS is not automatically lex specialis to NIS2, and the route for crediting Part-IS compliance toward NIS2 is being finalised, so the two should be treated as complementary until national transposition confirms the crediting mechanism.
With the dependency and gap picture: which systems carry safety impact, where the ISMS and SMS meet, and what evidence exists today. Our DAEDALUS framework builds the Part-IS aligned ISMS as one component of the airport's wider resilience operating model.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Ask us for a Part-IS gap assessment: your safety relevant systems, your ISMS to SMS integration points, and the evidence a competent authority will ask for.
Book a consultation