
Information security for the aviation sector
Information security for the aviation sector
Starting from October 2025 or February 2026 respectively, aviation organizations must comply with the requirements of EASA Part-IS. In this article, our experts Mario Melmer and Paolo Magrini provide their insight into the new regulations, answer the most important questions and present specific measures that will help your company in meeting the requirements of Part-IS.
The Easy Access Rules for Information Security (Part-IS) are a set of regulations issued by the European Aviation Safety Agency (EASA) that deal with the effects of information security on aviation safety.
It's based on the Delegated Regulation (EU) 2022/1645 and the Implementing Regulation (EU) 2023/203. These rules oblige affected organizations - including airlines, maintenance companies and operators of critical infrastructure - to identify and minimize information security risks if they could endanger aviation safety.
The requirements from Part-IS must be implemented by different authorities and organizations by a specified deadline, depending on their legal basis.
Organizations that are subject to Delegated Regulation (EU) 2022/1645 must implement Part-IS by this date. These include:
Organizations that are subject to Implementing Regulation (EU) 2023/203 must implement the requirements of Part-IS by this date at the latest. These include, among others:
Part-IS requires affected organizations to set up and operate a risk-based, structured information security management system (ISMS). The central requirements can be divided into ten subject areas:
Organizations must fully implement all requirements defined in Part-IS. The specific obligations are set out in the respective annexes to the regulation:
Reduced requirements apply to authorities: They are not obliged to implement the following elements:
This simplification takes account of the fact that authorities do not generally perform operational flight safety tasks, but rather monitor them.
Part-IS is largely based on the international standard ISO/IEC 27001 for information security management systems (ISMS). Nevertheless, there are significant differences in the target group, focus and regulatory implementation:
Industry focus
ISO 27001 is an industry-independent standard for information security. Part-IS, on the other hand, is specifically tailored to the aviation industry and focuses on risks that have a potential impact on aviation safety.
While ISO 27001 is aimed at flexibility and international comparability, Part-IS is a binding, aviation-specific set of rules that is monitored by regulators and focuses on the link between information security and aviation security.
To ensure that you can implement the requirements of Part-IS in a timely and practical manner, two steps are crucial to take:
Our experts have many years of experience in setting up and auditing information security management systems (ISMS) - especially in the aviation sector.
Driven by the passion of our Managing Director Michael Hochenrieder - himself a pilot and flight instructor - our team has intensively analyzed the requirements of Part-IS. Together with aviation organizations, we have worked out what really matters when it comes to practical implementation.
In close cooperation with aviation customers, we have developed an ISMM template that:
The result: an adaptable, audit-proof and ready-to-use tool for your information security documentation.
Get in touch with us – we will accompany you through to the successful implementation of Part-IS.
Head of Information Security at HvS-Consulting
Our specialist for ISMS. He knows what makes an ISMS successful, how to develop it securely and in line with requirements and, above all, how to make it resilient. He's an expert on processes and guidelines that need to be established in your company.
Information Security Consultant at HvS-Consulting
Specialist for ISMS projects in highly regulated industries. In close cooperation with aviation companies from various sectors, he has developed a practical ISMM template concept that specifically addresses the requirements of the EASA Easy Access Rules - Part-IS. He will show you how HvS-Consulting can provide your company with targeted support - even beyond the ISMM.