Part-IS — Information security requirements for Part-145, Part-CAMO and Part-147 organisations

Part-IS — established by Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 — requires approved aviation…

Regulation section Source-backed

Part-IS — established by Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 — requires approved aviation organisations, including Part-145, Part-CAMO, and Part-147 organisations, to identify and manage information security risks with a potential impact on aviation safety through an Information Security Management System (ISMS), applicable from 22 February 2026.

What it means in practice

Part-IS extends the management-system logic that organisations already know from 145.A.200 and CAMO.A.200 into the information security domain. The organisation must identify the information systems and data whose compromise could affect aviation safety, assess the associated information security risks, treat those risks, and detect, respond to, and recover from information security incidents. The outcome obligation is an Information Security Management System (ISMS) proportionate to the organisation's size and the complexity of its activities.

For a maintenance or continuing airworthiness environment, the affected assets typically include electronic maintenance and airworthiness records, maintenance data subscriptions and distribution, electronic technical logs, tooling and test software, training and examination management systems, and the interfaces with contracted and subcontracted organisations. An incident that corrupts maintenance data or airworthiness records is a safety issue, not only an IT issue — that is the core mindset shift Part-IS requires.

Key requirements

The organisation must establish, implement, and maintain an ISMS covering: information security risk assessment and treatment; incident detection, response, and recovery; reporting of incidents and vulnerabilities with a potential aviation safety impact to the competent authority (and, where applicable, through the occurrence-reporting channels of Regulation (EU) No 376/2014); competence and awareness of personnel; and continuous improvement of the system. An accountable manager retains overall responsibility, and the ISMS must be documented — either in a standalone information security management manual or integrated into existing expositions such as the MOE or CAME.

Integration rather than duplication is the intended approach: EASA's AMC/GM to Part-IS and the Easy Access Rules for Information Security explicitly allow the ISMS to be built on, and interface with, the existing safety management system established under 145.A.200, CAMO.A.200, or the equivalent organisation requirements. Organisations already operating ISO/IEC 27001-based security management can leverage that structure, provided the aviation-safety risk lens and the regulatory reporting obligations are added.

Who is affected and when

Part-IS applies to most organisations holding approvals under the EASA system, including Part-145 maintenance organisations, Part-CAMO continuing airworthiness management organisations, Part-147 maintenance training organisations, CAOs, design and production organisations, operators, and others within the scope of Regulation (EU) 2018/1139. Regulation (EU) 2022/1645 (covering organisations whose oversight sits with EASA and certain authority requirements) applies from 16 October 2025, and Regulation (EU) 2023/203 (covering the broader set of organisations and competent authorities) applies from 22 February 2026.

Organisations should not wait for their next audit cycle: the competent authorities assess Part-IS implementation as part of continuing oversight, and the CAME/MOE (or separate ISMS manual) must reflect the new processes. Derogations exist for some organisations whose activities are assessed as presenting a lower information security risk profile, subject to competent authority agreement.

Common compliance gaps

Early findings cluster around three areas: treating Part-IS as an IT department task disconnected from the safety management system; failing to cover contracted and subcontracted activities (maintenance data providers, software suppliers, cloud-hosted record systems) in the information security risk assessment; and having no workable internal path for staff to report information security events so they reach both the ISMS and, where safety-relevant, the external reporting channel. The same just-culture principles that apply to safety reporting under 145.A.202 and CAMO.A.202 should apply to information security reporting.

Sources

Was this page helpful?