EASA Part-IS — Information Security in Aviation
EASA (European Union Aviation Safety Agency) Part-IS (Information Security) regulations establish information security requirements for aviation organizations under the EASA regulatory framework. Part-IS requires organizations to establish an Information Security Management System (ISMS) to protect aviation safety from information security threats. Applies to organizations holding EASA approvals including airlines, maintenance organizations, design organizations, and air traffic management providers. Effective October 2025 (large organizations) and 2026 (smaller entities).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Part-IS.AR: Authority Requirements
| Code | Title |
|---|---|
| IS.AR.200 | Management System for Information Security Oversight |
| IS.AR.205 | Oversight of Organisations |
| IS.AR.210 | Findings and Corrective Actions |
| IS.AR.215 | Information Security Incident Response |
Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645)
| Code | Title |
|---|---|
| IS.D.OR.200 | Information Security Management System |
| IS.D.OR.205 | Information Security Risk Assessment |
| IS.D.OR.210 | Information Security Risk Treatment |
| IS.D.OR.215 | Personnel Requirements |
| IS.D.OR.220 | Information Security Risk Management Process |
| IS.D.OR.225 | External Reporting of Information Security Events |
| IS.D.OR.230 | Internal Reporting Scheme |
Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203)
| Code | Title |
|---|---|
| IS.I.OR.200 | Information Security Management System |
| IS.I.OR.205 | Information Security Risk Assessment |
| IS.I.OR.210 | Information Security Risk Treatment |
| IS.I.OR.215 | Personnel Requirements |
| IS.I.OR.220 | Information Security Risk Management |
| IS.I.OR.225 | External Reporting |
| IS.I.OR.230 | Internal Reporting Scheme |
Maps to 495 other frameworks
Frequently Asked Questions
What is EASA Part-IS — Information Security in Aviation?
EASA Part-IS — Information Security in Aviation is a compliance framework from European Union with 3 domains and 18 controls. EASA (European Union Aviation Safety Agency) Part-IS (Information Security) regulations establish information security requirements for aviation organizations under the EASA regulatory framework. Part-IS requires organizations to establish an Information Security Management System (ISMS) to protect aviation safety from information security threats. Applies to organizations holding EASA approvals including airlines, maintenance organizations, design organizations, and air traffic management providers. Effective October 2025 (large organizations) and 2026 (smaller entities). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EASA Part-IS — Information Security in Aviation have?
EASA Part-IS — Information Security in Aviation has 18 controls organised across 3 domains. The largest domains are Part-IS.D.OR: Organisation Requirements (Delegated Regulation EU 2022/1645) (7 controls), Part-IS.I.OR: Organisation Requirements (Implementing Regulation EU 2023/203) (7 controls), Part-IS.AR: Authority Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EASA Part-IS — Information Security in Aviation map to?
EASA Part-IS — Information Security in Aviation maps to 495 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (50% coverage), TISAX — Trusted Information Security Assessment Exchange (50% coverage), South Korea ISMS-P (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EASA Part-IS — Information Security in Aviation compliance?
Start your EASA Part-IS — Information Security in Aviation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EASA Part-IS — Information Security in Aviation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 18 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required