Regulations
EASA Part-IS: Aviation ISMS, Present & Suitable
EASA Part-IS compliance (Regulations (EU) 2023/203 and 2022/1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.
TL;DR
Part-IS is the EASA information-security framework for aviation organisations (Part-145, CAMO, operators, design, production, aerodromes, ground handling, and more). It requires an ISMS focused on information-security risks with a potential impact on aviation safety. Organisations under Delegated Regulation (EU) 2022/1645 have had to be at Present and Suitable since 16 October 2025; those under Implementing Regulation (EU) 2023/203 since 22 February 2026. Recognised compliance then requires the Operating level.
What does Part-IS cover for an aviation organisation?
As soon as an organisation holds an EASA approval or declaration within the scope of Regulations (EU) 2023/203 or 2022/1645, it must manage information-security risks that could affect aviation safety. The term “information security” (not only “cybersecurity”) deliberately covers analogue and physical threats as well as digital ones.
Which deadlines and levels apply?
| Instrument | Typical organisations | Applicability | Expected at day 0 |
|---|---|---|---|
| Delegated Regulation (EU) 2022/1645 | Design, production (Part 21), aerodromes, apron | 16 October 2025 | Present + Suitable, then operate |
| Implementing Regulation (EU) 2023/203 | Part-145, CAMO, operators, ATO, ATM/ANS, U-space… | 22 February 2026 | Present + Suitable, then operate |
| Part-IS.AR (authorities) | Competent authorities | 22 February 2026 | Progressive oversight using PSOE checklists |
Declared organisations (NCC, SPO, apron, ground handling) are in scope; they do not seek prior approval of the ISMM or the change procedure (amended by Delegated Regulation (EU) 2025/22; the implementing-regulation amendment is still pending).
How CISAPP structures Part-IS preparation
CISAPP's Part-IS catalogue follows Present and Suitable self-assessment criteria (aligned with competent-authority / Part-IS TF G-03 checklists and ILT templates). Each requirement maps to the shared NIST 800-53 control library so evidence already collected for ISO 27001 or NIS2 can be reused. An FR/EN audit questionnaire documents compliance level and supports the package for the competent authority.
FAQ
Part-IS is the EASA information-security rule set introduced by Implementing Regulation (EU) 2023/203 and Delegated Regulation (EU) 2022/1645. It requires in-scope aviation organisations to manage information-security risks with a potential impact on aviation safety through an ISMS (policy, risk management, incidents, reporting, personnel, records, ISMM, changes and continuous improvement).
Sources
- EASA FAQ — Information Security (Part-IS) — EASA
- Easy Access Rules for Information Security (December 2025 revision) — EASA, 2025-12-05
- Implementing Regulation (EU) 2023/203 — EUR-Lex
- Delegated Regulation (EU) 2022/1645 — EUR-Lex
- Part-IS assessment templates (ILT / CAA-NL) — ILT, 2025-10-15
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours