FAA Cybersecurity Framework for Aviation
FAA Aviation Cybersecurity: Aircraft Cybersecurity Airworthiness (14 CFR Part 25 + ACs + RTCA DO-326A family)

FAA Cybersecurity Framework for Aviation FAA-CSA-NPRM-2024: 2024 FAA NPRM to Codify Cybersecurity as Part 23/25/27/29 Airworthiness Standard

The FAA's August 2024 Notice of Proposed Rulemaking (NPRM) proposes to codify cybersecurity as a standing airworthiness requirement across the 14 CFR Part 23 (normal-category small aeroplanes), Part 25 (transport-category large aeroplanes), Part 27 (normal-category rotorcraft), and Part 29 (transport-category rotorcraft) airworthiness regulations. Currently cybersecurity is addressed through individual Special Conditions imposed on a per-type-certificate basis; the NPRM would harmonise this into standard airworthiness requirements aligned with RTCA DO-326A + EASA Part-IS + EU Commission Implementing Regulation 2023/203 Part-IS. The NPRM addresses: (a) intentional unauthorised electronic interactions (IUEI) airworthiness assessment; (b) security risk acceptance + mitigation for cyber-physical safety effects; (c) continued airworthiness for cybersecurity throughout the aircraft lifecycle including software updates + maintenance + decommissioning; (d) supply chain cybersecurity for aircraft components; (e) Equipment Qualification Test (EQT) cybersecurity considerations. Final rule expected 2025-2026 with phased implementation through 2027-2030.

Maintained by Gerard BlokdykControl text last updated

Other controls in FAA Aviation Cybersecurity: Aircraft Cybersecurity Airworthiness (14 CFR Part 25 + ACs + RTCA DO-326A family)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.