Yes, for many organisations.

Under EASA Part-IS, the following entities must implement an ISMS aligned to aviation requirements:

  • Air operators (AOC holders)
  • CAMOs
  • Ground handling service providers
  • Aerodromes
  • ANSPs
  • Continuing airworthiness entities
    Even outside EASA states, many regulators follow ICAO guidance to strengthen cyber resilience.