FAQ

Aero Compliance Solutions

5.0 Stars - Based on 2 User Reviews
Views: 1317Published On: 15. June 2025

FAQ

FAQ2025-11-25T07:29:36+01:00
Who is / what is the European Union Aviation Safety Agency (EASA)?2025-08-19T14:00:53+02:00

The European Union Aviation Safety Agency (EASA) is the regulatory authority responsible for civil aviation safety in Europe. EASA develops regulations, monitors compliance, and issues certifications, including standards for cybersecurity and Part-IS.

EASA Official Website

How do you become EASA Part-IS compliant?2026-06-25T16:25:17+02:00

Becoming Part-IS compliant follows a fairly logical path, even if the detail differs from one organisation to the next. Most begin with a gap analysis to see how their current setup measures against the regulation. From there, the typical steps are:

  • Define the scope and decide who is accountable for information security.
  • Carry out an information security risk assessment, with a clear focus on risks that could affect aviation safety.
  • Document everything in an Information Security Management Manual, often shortened to ISMM.
  • Put detection, reporting and incident response processes in place.
  • Train your staff so everyone involved understands their responsibilities.
  • Review and audit the system so you can show it works in practice.

Because Part-IS is an ongoing system rather than a one off task, many organisations bring in specialist support. Aero Compliance Solutions works with aviation operators through each of these stages, from the first gap analysis to a working ISMS.

Does EASA Part-IS apply to operators based outside the EU?2026-06-25T16:25:14+02:00

It can. Part-IS is an EU regulation, so it applies directly to organisations operating under the EASA system. If you are based outside the EU but hold an EASA approval, for example a maintenance organisation working under a bilateral agreement, you may still be expected to meet Part-IS or an equivalent standard.

The exact position depends on the terms of the bilateral agreement between your country and the EU, so it is worth confirming which EASA regulations are recognised for your specific approval. As a general rule, if your business touches the European aviation system through a certificate or approval, it is safer to assume Part-IS is relevant until you have confirmed otherwise.

What were the EASA Part-IS deadlines?2026-06-25T16:25:11+02:00

There were two applicability dates. The first, 16 October 2025, applied to aerodrome operators and to design and production organisations under Delegated Regulation (EU) 2022/1645. The second, 22 February 2026, applied to the wider aviation population, including AOC holders, CAMOs, Part-145 maintenance organisations, training organisations and air navigation service providers under Implementing Regulation (EU) 2023/203.

Both dates have now passed, so Part-IS is enforceable. It is worth knowing that EASA expects compliance to mature over time using its Present, Suitable, Operational and Effective model. Organisations are generally given an 18 month window from their applicability date to reach the operational and effective levels, so many businesses still have work to do even though the headline deadline is behind them.

Is ISO 27001 certification enough for Part-IS compliance?2026-06-25T16:25:06+02:00

This is one of the most common questions, and the short answer is no, not on its own. ISO 27001 is a strong starting point because much of it aligns with what Part-IS expects from an ISMS. The key difference is focus. ISO 27001 is built around protecting information in general, while Part-IS is built around aviation safety, which means you have to show how an information security risk could affect the safe operation of aircraft.

If you already hold ISO 27001, you can take credit for a lot of the groundwork, but you still need to fold aviation safety into your risk management and meet the specific Part-IS requirements that ISO 27001 does not cover. EASA has published mapping guidance to help organisations bridge the gap between the two.

What happens if you do not comply with EASA Part-IS?2026-06-25T16:24:58+02:00

Because Part-IS is now in force, non-compliance is treated as a regulatory matter. During an audit, a national aviation authority can raise findings and require a corrective action plan. Continued failure to address those findings can lead to increased oversight, financial penalties depending on the jurisdiction, and in serious cases restrictions or suspension of your approvals, which can affect your ability to operate.

There is also the reputational side. If a security incident happens alongside weak governance, the damage to trust can outlast any fine. The practical takeaway is to keep your ISMS active and auditable rather than treating it as a one off project. Tools such as AeroScan can help by scanning your IT infrastructure and producing a clear list of action items, which makes ongoing compliance much easier to demonstrate.

What is EASA?2025-08-19T14:14:07+02:00

EASA stands for the European Union Aviation Safety Agency. It is the regulatory authority responsible for civil aviation safety across Europe, setting rules, standards, and guidelines for airlines, maintenance organizations, and aviation service providers. EASA oversees compliance with regulations such as Part-IS, ensures Safety Management Systems (SMS) are in place, and provides certification for aviation organizations to maintain safe and secure operations.

Learn more about EASA and its role

What is Part-IS?2025-08-19T14:11:48+02:00

Part-IS refers to the EASA (European Union Aviation Safety Agency) regulation for Information Systems and Safety Management in aviation organizations. It is part of EASA’s compliance framework, ensuring aviation companies have proper Information Security Management Systems (ISMS) and Safety Management Systems (SMS) in place to protect operations, data, and safety-critical processes.

Read the complete guide on Part-IS for aviation organizations

What is aviation cybersecurity?2025-08-19T14:04:04+02:00

Aviation cybersecurity is the practice of protecting aviation systems, data, and communications from cyber threats. It ensures compliance with EASA Part-IS and secures safety management systems (SMS).

Aviation Cybersecurity – EASA

What is a cyber attack?2025-08-19T14:02:42+02:00

A cyber attack is any attempt to gain unauthorized access, steal data, or disrupt digital systems. In aviation, these can compromise ISMS, SMS, and operational safety.

Cyber Attacks Explained – CSO Online

What is a supply chain attack?2025-08-19T14:02:08+02:00

A supply chain attack targets vulnerabilities in third-party vendors or partners to access an organization’s systems. Aviation operators must secure their suppliers to maintain safety and compliance.

Supply Chain Attacks – CISA

What is ransomware?2025-08-19T14:01:24+02:00

Ransomware is malware that encrypts files or systems and demands a ransom for access. In aviation, ransomware can disrupt operations and compromise safety-critical data.

Ransomware explained – Kaspersky

What is MFA?2025-08-19T14:00:15+02:00

MFA stands for Multi-Factor Authentication. It requires users to provide two or more verification factors to access a system, such as a password and a code sent to a mobile device. MFA is crucial for aviation cybersecurity.

Read more about MFA from Microsoft

What is a Safety Management System (SMS)2025-11-25T04:04:05+01:00

A Safety Management System (SMS) is a structured, organisation-wide approach to managing safety risks. In aviation organisations it provides the framework to identify hazards, assess and mitigate risks, monitor performance, and continually improve safety outcomes. An SMS brings together policies, procedures, roles & responsibilities, reporting systems, risk management and assurance activities.

Why is an SMS important for aviation organisations?2025-11-25T04:03:53+01:00

Aviation operations are inherently complex and high-risk. An SMS ensures that safety is integral, not an add-on. By having formal processes to capture hazards, perform risk assessments, trigger corrective and preventive actions, and monitor performance, organisations can reduce incidents, improve operational resilience, and maintain regulatory compliance. ACS emphasises that newer regulations such as EASA Part‑IS require integration of information security frameworks with SMS frameworks – showing that safety and security are now tightly interconnected.

How does SMS differ from usual safety procedures or checklist culture?2025-11-25T04:03:42+01:00

Traditional safety procedures or checklists are often reactive and task-based (e.g., “did we complete the checklist?”). An SMS is proactive and systemic: it embeds hazard identification, risk management, safety assurance and continuous improvement in organisational culture and processes. It moves beyond procedural compliance to performance-based monitoring and improvement. In other words, it provides “control & oversight”, “stability & security” and constant attention to emerging threats.

What Is ISMS2025-11-25T04:06:11+01:00

An Information Security Management System (ISMS) is a structured framework that helps aviation organisations protect their information, systems, digital assets, and operational data from security threats. It ensures confidentiality, integrity, and availability of critical information through policies, risk management, processes, monitoring, and continuous improvement.

Why is an ISMS important in the aviation industry?2025-11-25T07:28:00+01:00

Aviation is highly dependent on digital systems – flight operations, maintenance, navigation, crew management, dispatch, and communication platforms. A cyberattack or data breach can disrupt flight safety, ground operations, or regulatory compliance.

EASA Part-IS now mandates that operators, airlines, CAMOs, ground handlers, and ANSPs have a formal ISMS in place to manage information-security risks in an integrated, systematic way.

Is an ISMS required by aviation regulators?2025-11-25T07:27:51+01:00

Yes, for many organisations.

Under EASA Part-IS, the following entities must implement an ISMS aligned to aviation requirements:

  • Air operators (AOC holders)
  • CAMOs
  • Ground handling service providers
  • Aerodromes
  • ANSPs
  • Continuing airworthiness entities
    Even outside EASA states, many regulators follow ICAO guidance to strengthen cyber resilience.
How can Aero Compliance Solutions help with ISMS implementation?2025-11-25T07:27:39+01:00

Aero Compliance Solutions specialises in helping aviation organisations meet EASA Part-IS requirements.

Their services typically include:

  • Gap analysis
  • Information-security risk assessments
  • Policy and procedure development
  • Integration of ISMS with existing SMS
  • Supplier chain and interface control mapping
  • Incident-response planning
  • Compliance monitoring

Their structured aviation-specific approach ensures organisations achieve compliance and real-world resilience.

Go to Top