Yes, for many organisations.
Under EASA Part-IS, the following entities must implement an ISMS aligned to aviation requirements:
- Air operators (AOC holders)
- CAMOs
- Ground handling service providers
- Aerodromes
- ANSPs
- Continuing airworthiness entities
Even outside EASA states, many regulators follow ICAO guidance to strengthen cyber resilience.

