Regulations

EASA Part-IS: Aviation ISMS, Present & Suitable

EASA Part-IS compliance (Regulations (EU) 2023/203 and 2022/1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.

TL;DR

Part-IS is the EASA information-security framework for aviation organisations (Part-145, CAMO, operators, design, production, aerodromes, ground handling, and more). It requires an ISMS focused on information-security risks with a potential impact on aviation safety. Organisations under Delegated Regulation (EU) 2022/1645 have had to be at Present and Suitable since 16 October 2025; those under Implementing Regulation (EU) 2023/203 since 22 February 2026. Recognised compliance then requires the Operating level.

What does Part-IS cover for an aviation organisation?

As soon as an organisation holds an EASA approval or declaration within the scope of Regulations (EU) 2023/203 or 2022/1645, it must manage information-security risks that could affect aviation safety. The term “information security” (not only “cybersecurity”) deliberately covers analogue and physical threats as well as digital ones.

Which deadlines and levels apply?

Part-IS applicability and PSOE levels
InstrumentTypical organisationsApplicabilityExpected at day 0
Delegated Regulation (EU) 2022/1645Design, production (Part 21), aerodromes, apron16 October 2025Present + Suitable, then operate
Implementing Regulation (EU) 2023/203Part-145, CAMO, operators, ATO, ATM/ANS, U-space…22 February 2026Present + Suitable, then operate
Part-IS.AR (authorities)Competent authorities22 February 2026Progressive oversight using PSOE checklists

Declared organisations (NCC, SPO, apron, ground handling) are in scope; they do not seek prior approval of the ISMM or the change procedure (amended by Delegated Regulation (EU) 2025/22; the implementing-regulation amendment is still pending).

How CISAPP structures Part-IS preparation

CISAPP's Part-IS catalogue follows Present and Suitable self-assessment criteria (aligned with competent-authority / Part-IS TF G-03 checklists and ILT templates). Each requirement maps to the shared NIST 800-53 control library so evidence already collected for ISO 27001 or NIS2 can be reused. An FR/EN audit questionnaire documents compliance level and supports the package for the competent authority.

See also ISO 27001 and NIS2.

FAQ

Part-IS is the EASA information-security rule set introduced by Implementing Regulation (EU) 2023/203 and Delegated Regulation (EU) 2022/1645. It requires in-scope aviation organisations to manage information-security risks with a potential impact on aviation safety through an ISMS (policy, risk management, incidents, reporting, personnel, records, ISMM, changes and continuous improvement).

Sources

  1. EASA FAQ — Information Security (Part-IS) — EASA
  2. Easy Access Rules for Information Security (December 2025 revision) — EASA, 2025-12-05
  3. Implementing Regulation (EU) 2023/203 — EUR-Lex
  4. Delegated Regulation (EU) 2022/1645 — EUR-Lex
  5. Part-IS assessment templates (ILT / CAA-NL) — ILT, 2025-10-15

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account