[{"data":1,"prerenderedAt":308},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-part-is":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":60,"entities":243,"extension":248,"faq":249,"keywords":268,"meta":274,"navigation":275,"ogImage":276,"path":59,"persona":277,"publishedAt":276,"regulation":278,"relatedFeatures":279,"relatedPages":282,"seo":285,"shortTitle":58,"slug":278,"sources":286,"stem":304,"tldr":305,"updatedAt":306,"__hash__":307},"regulations_en\u002Fen\u002Fregulations\u002Fpart-is.md","EASA Part-IS: Aviation ISMS, Present & Suitable | CISAPP","CISAPP",{"type":108,"value":109,"toc":236},"minimark",[110,115,123,142,146,216,219,223,226],[111,112,114],"h2",{"id":113},"what-does-part-is-cover-for-an-aviation-organisation","What does Part-IS cover for an aviation organisation?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"As soon as an organisation holds an EASA approval or declaration within the scope of Regulations (EU) 2023\u002F203 or 2022\u002F1645, it must manage information-security risks that could affect aviation safety."," The term “information security” (not only “cybersecurity”) deliberately covers analogue and physical threats as well as digital ones.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,139],"ul",{},[130,131,132],"li",{},"Two acts: Implementing Regulation (EU) 2023\u002F203 and Delegated Regulation (EU) 2022\u002F1645 (aligned IS.I.OR \u002F IS.D.OR organisation requirements).",[130,134,135],{},"PSOE levels: Present and Suitable by the applicability date, then Operating for recognised compliance.",[130,137,138],{},"Typical start-up deliverables: ISMM, change procedure (IS.OR.255), initial risk assessment, compliance-monitoring report.",[130,140,141],{},"Compatible with an existing ISO 27001 ISMS once aviation safety is integrated into risk management.",[111,143,145],{"id":144},"which-deadlines-and-levels-apply","Which deadlines and levels apply?",[147,148,150],"comparison-table",{"caption":149},"Part-IS applicability and PSOE levels",[151,152,153,172],"table",{},[154,155,156],"thead",{},[157,158,159,163,166,169],"tr",{},[160,161,162],"th",{},"Instrument",[160,164,165],{},"Typical organisations",[160,167,168],{},"Applicability",[160,170,171],{},"Expected at day 0",[173,174,175,190,203],"tbody",{},[157,176,177,181,184,187],{},[178,179,180],"td",{},"Delegated Regulation (EU) 2022\u002F1645",[178,182,183],{},"Design, production (Part 21), aerodromes, apron",[178,185,186],{},"16 October 2025",[178,188,189],{},"Present + Suitable, then operate",[157,191,192,195,198,201],{},[178,193,194],{},"Implementing Regulation (EU) 2023\u002F203",[178,196,197],{},"Part-145, CAMO, operators, ATO, ATM\u002FANS, U-space…",[178,199,200],{},"22 February 2026",[178,202,189],{},[157,204,205,208,211,213],{},[178,206,207],{},"Part-IS.AR (authorities)",[178,209,210],{},"Competent authorities",[178,212,200],{},[178,214,215],{},"Progressive oversight using PSOE checklists",[116,217,218],{},"Declared organisations (NCC, SPO, apron, ground handling) are in scope; they do not seek prior approval of the ISMM or the change procedure (amended by Delegated Regulation (EU) 2025\u002F22; the implementing-regulation amendment is still pending).",[111,220,222],{"id":221},"how-cisapp-structures-part-is-preparation","How CISAPP structures Part-IS preparation",[116,224,225],{},"CISAPP's Part-IS catalogue follows Present and Suitable self-assessment criteria (aligned with competent-authority \u002F Part-IS TF G-03 checklists and ILT templates). Each requirement maps to the shared NIST 800-53 control library so evidence already collected for ISO 27001 or NIS2 can be reused. An FR\u002FEN audit questionnaire documents compliance level and supports the package for the competent authority.",[116,227,228,229,232,233,235],{},"See also ",[230,231,50],"a",{"href":51}," and ",[230,234,54],{"href":55},".",{"title":237,"searchDepth":238,"depth":238,"links":239},"",2,[240,241,242],{"id":113,"depth":238,"text":114},{"id":144,"depth":238,"text":145},{"id":221,"depth":238,"text":222},[58,244,245,246,247],"EASA","ISMS","PSOE","ISMM","md",[250,253,256,259,262,265],{"q":251,"a":252},"What is Part-IS?","Part-IS is the EASA information-security rule set introduced by Implementing Regulation (EU) 2023\u002F203 and Delegated Regulation (EU) 2022\u002F1645. It requires in-scope aviation organisations to manage information-security risks with a potential impact on aviation safety through an ISMS (policy, risk management, incidents, reporting, personnel, records, ISMM, changes and continuous improvement).",{"q":254,"a":255},"Who is in scope?","Including Part-145 and CAMO organisations (except Part-ML-only), certain air operators (Part-ORO), ATOs, aero-medical centres, FSTD operators, ATM\u002FANS, U-space, design and production (Part 21), aerodromes and apron management, plus certain declared organisations (NCC, SPO, apron, ground handling). Out of scope include DTOs, Part-ML-only organisations and declared DOA holders. ELA2 exemptions apply. Check Article 2 of each regulation.",{"q":257,"a":258},"What is the PSOE model?","Present, Suitable, Operating and Effective. By the applicability date, the organisation must have established the ISMS foundation (Present and Suitable) and start operating it. Part-IS compliance is recognised when the authority also concludes Operating. Effective is continuous improvement (IS.OR.260); no specific maturity level is mandated.",{"q":260,"a":261},"What are the applicability dates?","16 October 2025 for organisations under Delegated Regulation (EU) 2022\u002F1645 (design, production, aerodromes). 22 February 2026 for those under Implementing Regulation (EU) 2023\u002F203 (maintenance, CAMO, operators, ATM\u002FANS, etc.) and for authority requirements (Part-IS.AR). Both deadlines have passed: the focus is now on operating the ISMS and reaching the Operating level.",{"q":263,"a":264},"Is ISO 27001 or NIS2 compliance enough?","No. An ISO 27001 ISMS can be adapted, but Part-IS adds aviation-safety-specific requirements. Part-IS is not a lex specialis under NIS2: an organisation may need to comply with both. NIS2 compliance does not automatically mean Part-IS compliance; equivalence in effect is verified by the competent authority.",{"q":266,"a":267},"Does CISAPP help with Part-IS?","Yes. The Part-IS framework is part of the multi-framework compliance module, with FR\u002FEN audit questionnaires aligned to Present and Suitable criteria (competent-authority \u002F Part-IS TF G-03 checklists), NIST 800-53 control mappings, and an evidence register shared with ISO 27001 or NIS2.",[58,269,270,271,272,246,273],"EASA Part-IS","aviation ISMS","IS.OR","Present Suitable Part-IS","aviation information security",{},true,null,"entreprise","part-is",[280,281],"Multi-framework compliance","Evidence register",[283,284],"iso-27001","nis2",{"title":105,"description":60},[287,290,294,297,299],{"label":288,"url":289,"publisher":244},"EASA FAQ — Information Security (Part-IS)","https:\u002F\u002Fwww.easa.europa.eu\u002Fen\u002Fthe-agency\u002Ffaqs\u002Finformation-security-part",{"label":291,"url":292,"publisher":244,"date":293},"Easy Access Rules for Information Security (December 2025 revision)","https:\u002F\u002Fwww.easa.europa.eu\u002Fen\u002Fdocument-library\u002Feasy-access-rules\u002Fonline-publications\u002Feasy-access-rules-information-security","2025-12-05",{"label":194,"url":295,"publisher":296},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg_impl\u002F2023\u002F203\u002Foj","EUR-Lex",{"label":180,"url":298,"publisher":296},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg_del\u002F2022\u002F1645\u002Foj",{"label":300,"url":301,"publisher":302,"date":303},"Part-IS assessment templates (ILT \u002F CAA-NL)","https:\u002F\u002Fenglish.ilent.nl\u002Fdocuments\u002Faviation\u002Fcaa-nl\u002Fforms\u002Fpart-is-assessment-templates","ILT","2025-10-15","en\u002Fregulations\u002Fpart-is","Part-IS is the EASA information-security framework for aviation organisations (Part-145, CAMO, operators, design, production, aerodromes, ground handling, and more). It requires an ISMS focused on information-security risks with a potential impact on aviation safety. Organisations under Delegated Regulation (EU) 2022\u002F1645 have had to be at Present and Suitable since 16 October 2025; those under Implementing Regulation (EU) 2023\u002F203 since 22 February 2026. Recognised compliance then requires the Operating level.","2026-09-21","lhbsCHhJZ_CX1r8uBVGS2m5sXFWzOtp6g596hWhFwlE",1791391138798]