The FAA's August 2024 Notice of Proposed Rulemaking (NPRM) proposes to codify cybersecurity as a standing airworthiness requirement across the 14 CFR Part 23 (normal-category small aeroplanes), Part 25 (transport-category large aeroplanes), Part 27 (normal-category rotorcraft), and Part 29 (transport-category rotorcraft) airworthiness regulations. Currently cybersecurity is addressed through individual Special Conditions imposed on a per-type-certificate basis; the NPRM would harmonise this into standard airworthiness requirements aligned with RTCA DO-326A + EASA Part-IS + EU Commission Implementing Regulation 2023/203 Part-IS. The NPRM addresses: (a) intentional unauthorised electronic interactions (IUEI) airworthiness assessment; (b) security risk acceptance + mitigation for cyber-physical safety effects; (c) continued airworthiness for cybersecurity throughout the aircraft lifecycle including software updates + maintenance + decommissioning; (d) supply chain cybersecurity for aircraft components; (e) Equipment Qualification Test (EQT) cybersecurity considerations. Final rule expected 2025-2026 with phased implementation through 2027-2030.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.