Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Part-IS Explained: EU Aviation Information Security Regulation | Resilience Guard
EASA Part-IS explained

Part-IS: information security is now aviation safety law.

The EU's information security regime for aviation ends the historical separation of cyber from safety. Aerodrome operators have been in scope since 16 October 2025; the wider aviation population follows from 22 February 2026, and applicability is only the start of the obligation.

The regulation

What is Part-IS?

Part-IS is the European Union's information security regime for aviation, established by Delegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203. It requires in scope organisations to implement an information security management system that manages information security risks with a potential impact on aviation safety, integrated with the safety management system rather than run beside it.

The applicability arrives in waves. Aerodrome operators and apron management service providers have been in scope since 16 October 2025. Air operators, maintenance and continuing airworthiness organisations, training organisations and air navigation service providers follow from 22 February 2026, with ground handling service providers brought into scope on a later horizon. Critically, applicability is the start of the obligation, not its discharge: under the phased maturity model an organisation must go on to demonstrate an information security management system that is operationally effective rather than merely documented.

The regime's deeper point is integration. For years aviation information security was an IT function concerned with confidentiality, while safety was managed elsewhere; Part-IS ends that separation as a matter of law, because a ransomware event against maintenance records or a common use passenger platform is a safety relevant event, not an inconvenience. In Switzerland, FOCA oversees Part-IS within its regular safety oversight and expressly allows credit from an ISO 27001 certification, provided aviation safety is built into the risk management, which converts a compliance burden into a single piece of work.

Instruments
DR (EU) 2022/1645, IR (EU) 2023/203
Aerodromes
In scope since 16 Oct 2025
Wider aviation
From 22 Feb 2026
Core duty
ISMS integrated with the SMS
APPLICABILITY IS THE START OF THE OBLIGATION, NOT ITS DISCHARGE16 October 2025Aerodrome operators andapron management providers22 February 2026Air operators, maintenance and CAMO,training organisations, ANSPsLater horizonGround handlingservice providersThen: the phased maturity modelAn ISMS that is operationally effective, not merely documentedDelegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203, integrated with the safety management system.The window between applicability and demonstrated effectiveness is where genuine capability is built.
The Part-IS applicability waves, and the phased maturity expectation that follows each of them: operationally effective, not merely documented.
What it demands

From documented intent to demonstrated capability

An information security management system. Scoped to the information security risks with potential impact on aviation safety: identification, assessment, treatment and continual improvement, with an accountable executive who owns it.
Integration with safety management. One management system view rather than parallel silos, so a cyber event flows into the safety risk picture and the safety culture reaches the information estate.
Incident detection, response and reporting. The capability to detect information security events, respond in a coordinated way, and report per the regime, alongside national duties such as the Swiss 24 hour reporting clock.
Demonstrated effectiveness. The phased maturity model expects evidence: tested response, exercised recovery and records a competent authority can audit, which is exactly the discipline our exercise programmes and cyber resilience practice build.
Coherence with NIS2. Part-IS is not automatically lex specialis to NIS2; the mechanism for crediting Part-IS compliance toward NIS2 is being finalised, so operators should treat the two as complementary until the crediting route is confirmed in national transposition.
Questions

Frequently asked questions

Who is in scope of Part-IS and from when?+

Aerodrome operators and apron management service providers since 16 October 2025; air operators, maintenance and CAMO organisations, training organisations and air navigation service providers from 22 February 2026; ground handling providers on a later horizon.

Is Part-IS the same as ISO 27001?+

No, but they are close relatives. Part-IS requires an ISMS whose scope is aviation safety impact and whose home is the safety management system. In Switzerland, FOCA expressly allows credit from an ISO 27001 certification toward Part-IS, provided aviation safety is built into the risk management.

What does the phased maturity model mean in practice?+

That a documented ISMS is not the finish line. The organisation must progressively demonstrate that the system operates: risks genuinely managed, incidents genuinely handled, and effectiveness evidenced to the competent authority rather than asserted.

How does Part-IS relate to NIS2?+

They overlap for many operators. EASA has confirmed Part-IS is not automatically lex specialis to NIS2, and the route for crediting Part-IS compliance toward NIS2 is being finalised, so the two should be treated as complementary until national transposition confirms the crediting mechanism.

Where should an airport start?+

With the dependency and gap picture: which systems carry safety impact, where the ISMS and SMS meet, and what evidence exists today. Our DAEDALUS framework builds the Part-IS aligned ISMS as one component of the airport's wider resilience operating model.

Explore further

Related services

Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Turn the Part-IS deadline into a capability.

Ask us for a Part-IS gap assessment: your safety relevant systems, your ISMS to SMS integration points, and the evidence a competent authority will ask for.

Book a consultation
All consultations are treated with strict confidentiality.