
Introduction
Introduction: Aviation is becoming increasingly dependent on interconnected digital systems, making cybersecurity an operational and safety issue rather than simply an IT concern. Recent incidents, including ransomware affecting airport systems and attacks involving third-party providers, have demonstrated how a single cyber event can cause flight delays and cancellations, disrupt check-in, boarding, baggage handling or maintenance, compromise sensitive data, and create wider operational and reputational consequences. In response to this changing threat landscape, the EU has established the Part-IS framework through Regulations (EU) 2022/1645 and 2023/203, bringing information-security risk management into the aviation regulatory and safety environment. This article examines what recent cyber incidents reveal about aviation’s vulnerabilities and what Part-IS means in practice for organisations that must now identify, manage, monitor and respond to information-security risks.
In practice, many aviation organisations struggle to find the right balance in their use of ICT. On one end of the spectrum, overly simple solutions—such as loosely structured (Excel) spreadsheets and shared folders—lack governance, ownership, and reliability. They obscure compliance status, introduce version conflicts, and only reveal weaknesses during audits or oversight. On the other end, highly complex ICT systems often promise full control but deliver rigidity, long implementation timelines, high costs, and limited adoption by users. When systems are too heavy, compliance becomes an administrative exercise rather than a management tool.
Part-IS is no longer a future requirement. The European aviation industry has entered a new phase of information-security regulation. Part-IS is no longer simply something organisations need to prepare for most organisations, it already applies.
From 16 October 2025: producers with a Part-21 Subpart G certificate (POA holders), design organisations with a Part-21 Subpart J certificate (DOA holders), and European-certified airports and service providers operating at EASA-certified airports. (Regulation (EU) 2022/1645).
From 22 February 2026: air operators with complex motor-powered aircraft (airlines, non-commercial complex operations, specialised operations), aero-medical centres, maintenance organisations, air traffic management/ANS providers, ATC training organisations, approved training organisations, and U-space service providers. (Regulation (EU) 2023/203).
From 27 March 2031: ground handling organisations at European-certified airports.
For organisations affected, the practical question is therefore no longer whether Part-IS will apply, but whether the organisation is ready to demonstrate compliance in practice.
There are, however, important exceptions and scope limitations. For example, certain organisations operating only particular categories of aircraft or activities may fall outside the regulation. The question is therefore not simply “Are we an aviation organisation?” but “Does our specific approval, activity and operating model fall within the scope of Part-IS?” That scope assessment should be the starting point.
From regulation to implementation
For many organisations, the challenge now moves from understanding the legislation to turning regulatory requirements into an operating management system. Part-IS requires organisations to establish and maintain an Information Security Management System (ISMS) addressing information-security risks that could have an impact on aviation safety. The regulatory framework covers risk assessment and treatment, internal reporting, detection and response, external reporting, personnel, record keeping, the Information Security Management Manual (ISMM), management of changes and continuous improvement. This is important because Part-IS is not simply an instruction to install better firewalls or antivirus software.
The organisation must be able to demonstrate that it understands: What information and systems matter to our aviation activities, what could go wrong, what the consequences could be, and how we will prevent, detect, respond to and recover from those events. That makes Part-IS much closer to an aviation management-system requirement than a conventional IT project. What does an organisation actually need? At a high level, a compliant Part-IS framework should address several building blocks:
Governance and accountability. Someone must have clear responsibility for information security, with appropriate involvement of the accountable manager and management structure.
Risk management. The organisation needs to identify the systems, data, activities, facilities and interfaces that could be exposed to information-security risks affecting aviation safety.
Risk treatment. Identified risks need appropriate controls and mitigation measures. The objective is not to eliminate every cyber risk, but to manage unacceptable risks appropriately.
Incident management. The organisation needs processes for detecting, classifying, responding to and recovering from information-security events and incidents.
Reporting. Part-IS establishes internal and external reporting arrangements, including specific requirements for significant information-security incidents.
Documentation. The ISMS needs to be documented, including through an Information Security Management Manual or equivalent documentation integrated into the organisation’s existing management system.
People and competence. Responsibilities, competence, awareness and appropriate personnel controls form part of the regulatory framework.
Continuous improvement. Part-IS is intended to operate as a continuing management process rather than a one-time certification exercise.
The important point is that these elements need to work together. A beautifully written Information Security Management Manual does not compensate for a risk assessment that nobody uses, just as sophisticated technical controls do not compensate for unclear responsibilities or an ineffective incident-response process.
Don’t build another management system in isolation!
One of the biggest implementation opportunities is integration. Most established aviation organisations already have management systems covering areas such as safety, compliance, quality, occurrence reporting, risk management, training and corrective actions. Part-IS should not automatically become another disconnected layer of administration. Instead, organisations should look for the interfaces.
A cyber incident may simultaneously be:
• an information-security event;
• an operational disruption;
• a safety concern;
• a supplier failure;
• an occurrence requiring reporting;
• and a business-continuity event.
The strongest Part-IS implementation therefore connects information security with the organisation’s existing SMS, compliance-monitoring and quality processes, rather than creating parallel systems that duplicate each other.
The third-party problem
A recent Collins Aerospace/MUSE incident provides an important warning. Modern aviation organisations increasingly depend on external software providers, cloud services, maintenance systems, communication platforms, data services and other digital infrastructure. A supplier may therefore become a critical operational dependency, even when that supplier is not part of the aviation organisation itself. Part-IS explicitly requires organisations to consider relevant interfaces and contracted information-security activities.
This changes the traditional question from: “Is our IT secure?” to: “What happens to our operation if a critical supplier becomes unavailable or compromised?”
That is a much more demanding question — and one that requires more than a supplier’s ISO certificate or a clause in a contract.
The 72-hour clock
Incident reporting is another area where preparation matters. Part-IS establishes an external reporting scheme for qualifying information-security incidents. In practice, the difficult part may not be writing the report. It is deciding when an event crosses the threshold, who makes that decision, who contacts the competent authority, what information is initially available and how the organisation coordinates its different reporting obligations. Waiting for an incident before designing that process is therefore a poor strategy.
A simple reporting decision tree, predefined responsibilities and an exercised response procedure can make a substantial difference when the organisation is operating under pressure. What good implementation looks like. A mature Part-IS implementation should ultimately become visible in the way an organisation operates.
It should be possible to demonstrate that:
• management understands its responsibilities;
• relevant information assets and interfaces are known;
• risks are assessed using a consistent methodology;
• risks are actively treated;
• employees know how to recognise and report information-security events;
• suppliers and outsourced activities are considered;
• incidents can be detected and managed;
• reporting responsibilities are understood;
• documentation reflects actual practice; and
• lessons from incidents, audits and changes feed back into the system.
This is where compliance becomes resilience. The organisations that approach Part-IS merely as a documentation exercise may be able to produce policies and manuals. The organisations that integrate it into their existing safety and operational management processes will be better positioned to demonstrate that the system actually works when something goes wrong.
The real question
With the third application phase already underway, organisations should not begin with “Which documents do we need?” A better starting point is: Where could an information-security failure affect our aviation operation — and how would we know, respond and recover? Once that question has been answered properly, the documentation, responsibilities, risk assessments and procedures begin to make much more sense.
And that is ultimately the purpose of Part-IS: not to make aviation organisations cyber-proof, but to make them capable of identifying, managing and recovering from information-security risks that could affect aviation safety.
DISCLAIMER This article provides a high-level overview and is not a substitute for an organisation-specific Part-IS applicability and compliance assessment.
Photo: 4300streetcar / Wikimedia Commons — CC BY 4.0, changes made in order to fit the layout.projects or unnecessary complexity.
about avada business

Integer euismod lacus magna uisque curd metus luctus vitae pharet auctor mattis semat.




