Part-IS Requirements, Scope and Deadlines
Who Regulations (EU) 2022/1645 and (EU) 2023/203 apply to, the dates they apply from, and how long the records are kept.
Dionysis Kefalas16 min readFor Part-145, CAMO and Air Ops staff
Part 1 of 4 in Part-IS Implementation Show parts
- 1Part-IS Requirements, Scope and Deadlines
- 2Aviation Information Security, Explained
- 3Aviation Cyber Incidents and Their Lessons
- 4Part-IS Shop-Floor Practice and Reporting
Quotes checked on against EASA Easy Access Rules for Information Security (Regulations (EU) 2022/1645 and (EU) 2023/203) — 5 Dec 2025 revision.
On this page
A record the line cannot open
A release certificate in a mailbox. A maintenance record on a shared drive. A planning screen the line cannot open. Implementing Regulation (EU) 2023/203 is the regulation that sets the tasks for those organisations and for the competent authorities.
This Regulation sets out the requirements to be met by the organisations and competent authorities in order:
(a)to identify and manage information security risks with potential impact on aviation safety which could affect information and communication technology systems and data used for civil aviation purposes,
(b)to detect information security events and identify those which are considered information security incidents with potential impact on aviation safety,
(c)to respond to, and recover from, those information security incidents.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Delegated Regulation (EU) 2022/1645 is the other regulation in the same book. Its subject matter and its scope are quoted below. The application date is not in either Article 1.
The dates
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from 16 October 2025.
Quoted word for word from Delegated Regulation (EU) 2022/1645, Easy Access Rules for Information Security, 5 Dec 2025 revision.
The second sentence is the application date for Delegated Regulation (EU) 2022/1645. The first sentence is not that date.
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from 22 February 2026.
However, as regards the case of the EGNOS air navigation service provider subject to Regulation (EU) 2017/373 it shall apply from 1 January 2026.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
The second sentence is the application date for Implementing Regulation (EU) 2023/203. The third sentence is a different case, not the date for every organisation.
Each application date in those two articles is earlier than the day this page was checked, so those sentences are in force. There is no separate date table.
Who Delegated Regulation (EU) 2022/1645 applies to
This Regulation sets out the requirements to be met by the organisations referred to in Article 2 in order to identify and manage information security risks with potential impact on aviation safety which could affect information and communication technology systems and data used for civil aviation purposes and to detect information security events and identify those which are considered information security incidents with potential impact on aviation safety and respond to, and recover from, those information security incidents.
Quoted word for word from Delegated Regulation (EU) 2022/1645, Easy Access Rules for Information Security, 5 Dec 2025 revision.
The organisations that sentence refers to are in the next quote.
1.This Regulation applies to the following organisations:
(a)production organisations and design organisations subject to Subparts G and J of Section A of Annex I (Part 21) to Regulation (EU) No 748/2012, except design and production organisations that are solely involved in the design and/or production of ELA2 aircraft as defined in Article 1(2), point (j) of Regulation (EU) No 748/2012;
(b)aerodrome operators and apron management service providers subject to Annex III ‘Part Organisation Requirements (Part-ADR.OR)’ to Regulation (EU) No 139/2014.
[…]
2.This Regulation is without prejudice to information security and cybersecurity requirements laid down in point 1.7 of the Annex to Commission Implementing Regulation (EU) 2015/1998 and in Article 14 of Directive (EU) 2016/1148 of the European Parliament and of the Council.
Quoted word for word from Delegated Regulation (EU) 2022/1645, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Point (a) is production organisations and design organisations. The exception is written in the point. Point (b) is aerodrome operators and apron management service providers. Maintenance organisations, CAMOs and air operators are not named in points (a) or (b).
The text omitted at […] is not in force on the day this page was checked, so it is not quoted. Paragraph 2 is in force.
Who Implementing Regulation (EU) 2023/203 applies to
1.This Regulation applies to the following organisations:
(a)maintenance organisations subject to Section A of Annex II (Part-145) to Regulation (EU) No 1321/2014(), except those solely involved in the maintenance of aircraft in accordance with Annex Vb (Part-ML) to Regulation (EU) No 1321/2014;
(b)continuing airworthiness management organisations (CAMOs) subject to Section A of Annex Vc (Part-CAMO) to Regulation (EU) No 1321/2014, except those solely involved in the continuing airworthiness management of aircraft in accordance with Annex Vb (PartML) to Regulation (EU) No 1321/2014;
(c)air operators subject to Annex III (Part-ORO) to Regulation (EU) No 965/2012(), except those solely involved in the operation of any of the following:
(i)an ELA 2 aircraft as defined in Article 1(2), point (j) of Regulation (EU) No 748/2012();
(ii)single-engine propeller-driven aeroplanes with a Maximum Operational Passenger Seating Configuration of 5 or less that are not classified as complex motor-powered aircraft, when taking off and landing at the same aerodrome or operating site and operating under Visual Flight Rules (VFR) by day rules;
(iii)single-engine helicopters with a Maximum Operational Passenger Seating Configuration of 5 or less that are not classified as complex motor-powered aircraft, when taking off and landing at the same aerodrome or operating site and operating under VFR by day rules.
(d)approved training organisations (ATOs) subject to Annex VII (Part-ORA) to Regulation (EU) No 1178/2011(), except those solely involved in training activities of ELA2 aircraft as defined in Article 1(2), point (j) of Regulation (EU) No 748/2012, or solely involved in theoretical training;
(e)aircrew aero-medical centres subject to Annex VII (Part-ORA) to Regulation (EU) No 1178/2011;
(f)flight simulation training device (FSTD) operators subject to Annex VII (Part-ORA) to Regulation (EU) No 1178/2011, except those solely involved in the operation of FSTDs for ELA2 aircraft as defined in Article 1(2), point (j) of Regulation (EU) No 748/2012;
(g)air traffic controller training organisations (ATCO TOs) and ATCO aero-medical centres subject to Annex III (Part ATCO.OR) to Regulation (EU) 2015/340();
(h)organisations subject to Annex III (Part-ATM/ANS.OR) to Regulation (EU) 2017/373(), except the following service providers:
(i)air navigation service providers holding a limited certificate in accordance with point ATM/ANS.OR.A.010 of that Annex;
(ii)flight information service providers declaring their activities in accordance with point ATM/ANS.OR.A.015 of that Annex;
(i)U-space service providers and single common information service providers subject to Regulation (EU) 2021/664().
(j)approved organisations involved in the design or production of ATM/ANS systems and ATM/ANS constituents subject to Commission Implementing Regulation (EU) 2023/1769.
2.This Regulation applies to the competent authorities, including the European Union Aviation Safety Agency (‘the Agency’), referred to Article 6 of this Regulation and in Article 5 of Delegated Regulation (EU) 2022/1645.
3.This Regulation also applies to the competent authority responsible for the issuance, continuation, change, suspension or revocation of aircraft maintenance licences in accordance with Annex III (Part-66) to Regulation (EU) No 1321/2014.
3a. This Regulation also applies to the competent authority designated in accordance with Annex I (Part-AR.UAS) to Commission Implementing Regulation (EU) 2024/1109.
[…]
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Read the letter that names the organisation. The exception sits inside that letter. Do not copy one letter's exception onto another. Point (h) contains its own points (i) and (ii). The next point of the article is also marked (i).
Point (a) is maintenance organisations. Point (b) is continuing airworthiness management organisations (CAMOs). Point (c) is air operators, and the exceptions are the whole of points (i), (ii) and (iii). Point (d) is approved training organisations (ATOs). Point (e) is aircrew aero-medical centres. Point (f) is flight simulation training device (FSTD) operators. Point (g) is air traffic controller training organisations (ATCO TOs) and ATCO aero-medical centres. Point (h) is organisations subject to Annex III (Part-ATM/ANS.OR), except the service providers named in points (i) and (ii) of that point. Point (i) is U-space service providers and single common information service providers. Point (j) is approved organisations involved in the design or production of ATM/ANS systems and ATM/ANS constituents subject to Commission Implementing Regulation (EU) 2023/1769.
Paragraph 2 is the competent authorities, including the Agency. Paragraph 3 is the aircraft maintenance licence authority. Paragraph 3a is the Part-AR.UAS authority. The limits are in the quote.
1.The organisations referred to in Article 2(1) shall comply with the requirements of Annex II (PartIS.I.OR) to this Regulation.
2.The competent authorities referred to in Article 2(2), (3) and (3a) shall comply with the requirements of Annex I (Part-IS.AR) to this Regulation.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
[…]
(e)Without prejudice to the obligation to comply with the reporting requirements laid down in Regulation (EU) No 376/2014 and the requirements laid down in point IS.I.OR.200(a)(13), the organisation may be approved by the competent authority not to implement the requirements referred to in points (a) to (d) and the related requirements contained in points IS.I.OR.205 through IS.I.OR.260, if it demonstrates to the satisfaction of that authority that its activities, facilities and resources, as well as the services it operates, provides, receives and maintains, do not pose any information security risks with a potential impact on aviation safety neither to itself nor to other organisations. The approval shall be based on a documented information security risk assessment carried out by the organisation or a third party in accordance with point IS.I.OR.205 and reviewed and approved by its competent authority.
The continued validity of that approval will be reviewed by the competent authority following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Point (e) is an approval not to implement the requirements it lists. Two duties stay outside that approval, and the test for the approval is in the same point. So is the later review of the approval.
Other Union security requirements
1.Where an organisation referred to in Article 2(1) complies with security requirements laid down in accordance with Article 14 of Directive (EU) 2016/1148 that are equivalent to the requirements laid down in this Regulation, compliance with those security requirements shall be considered to constitute compliance with the requirements laid down in this Regulation.
2.Where an organisation referred to in Article 2(1) is an operator or an entity referred to in the national civil aviation security programmes of Member States laid down in accordance with Article 10 of Regulation (EC) No 300/2008 of the European Parliament and of the Council, the cybersecurity requirements contained in point 1.7 of the Annex to Regulation (EU) 2015/1998 shall be considered to be equivalent with the requirements laid down in this Regulation, except as regards point IS.I.OR.230 of Annex II to this Regulation that shall be complied with as such.
[…]
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Paragraph 1 is the case of equivalent requirements under Directive (EU) 2016/1148. Paragraph 2 is the civil aviation security programme case, and it keeps one point of this regulation outside that equivalence. The quote stops before the later paragraphs.
The points in Annex II
Annex II (PartIS.I.OR) is the annex Article 4 names for the organisations referred to in Article 2(1). The points, by their titles, are these. A title is not the duty. Where this guide states a duty, the sentence is quoted above or below.
How long records are kept
IS.I.OR.245 does not set one retention period.
(a)The organisation shall keep records of its information security management activities
(1)The organisation shall ensure that the following records are archived and traceable:
(i)any approval received and any associated information security risk assessment in accordance with point IS.I.OR.200(e;)
(ii)contracts for activities referred to in point IS.I.OR.200(a)(9);
(iii)records of the key processes referred to in point IS.I.OR.200(d);
(iv)records of the risks identified in the risk assessment referred to in point IS.I.OR.205 along with the associated risk treatment measures referred to in point IS.I.OR.210;
(v)records of information security incidents and vulnerabilities reported in accordance with the reporting schemes referred to in points IS.I.OR.215 and IS.I.OR.230;
(vi)records of those information security events which may need to be reassessed to reveal undetected information security incidents or vulnerabilities.
(2)The records referred to in point (1)(i) shall be retained at least until 5 years after the approval has lost its validity.
(3)The records referred to in point (1)(ii) shall be retained at least until 5 years after the contract has been amended or terminated.
(4)The records referred to point (1)(iii), (iv) and (v) shall be retained at least for a period of 5 years.
(5)The records referred to in point (1)(vi) shall be retained until those information security events have been reassessed in accordance with a periodicity defined in a procedure established by the organisation.
(b)The organisation shall keep records of qualification and experience of its own staff involved in information security management activities
(1)The personnel’s qualification and experience records shall be retained for as long as the person works for the organisation, and for at least 3 years after the person has left the organisation.
[…]
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
The periods are not the same. Points (2) and (3) are 5-year clocks, and each one starts from the event that point names. Point (4) is at least 5 years, and that point names no starting event. Point (5) does not state a 5-year period. Point (b)(1) is the staff record, and it is not one of those 5-year clocks.
Reporting to the competent authority
(a)The organisation shall implement an information security reporting system that complies with the requirements laid down in Regulation (EU) No 376/2014 and its delegated and implementing acts if that Regulation is applicable to the organisation.
(b)Without prejudice to the obligations of Regulation (EU) 376/2014, the organisation shall ensure that any information security incident or vulnerability, which may represent a significant risk to aviation safety, is reported to their competent authority. Furthermore:
(1)Where such an incident or vulnerability affects an aircraft or associated system or component, the organisation shall also report it to the design approval holder;
(2)Where such an incident or vulnerability affects a system or constituent used by the organisation, the organisation shall report it to the organisation responsible for the design of the system or constituent.
(c)The organisation shall report the conditions referred to in point (b) as follows:
(1)a notification shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, as soon as the condition has been known to the organisation;
(2)a report shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, as soon as possible, but not exceeding 72 hours from the time the condition has been known to the organisation, unless exceptional circumstances prevent this.
The report shall be made in the form defined by the competent authority and shall contain all relevant information about the condition known to the organisation;
(3)a follow-up report shall be submitted to the competent authority and, if applicable, to the design approval holder or to the organisation responsible for the design of the system or constituent, providing details of the actions the organisation has taken or intends to take to recover from the incident and the actions it intends to take to prevent similar information security incidents in the future.
The follow-up report shall be submitted as soon as those actions have been identified, and shall be produced in the form defined by the competent authority.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
Point (a) is the reporting system, and it applies only where Regulation (EU) No 376/2014 applies to the organisation. Point (b) is which conditions are reported, and to whom. Point (c) is the notification, the report and the follow-up. The time limit and its exception are in point (c)(2).
The definitions in Article 3
For the purpose of this Regulation, the following definitions shall apply:
(1)‘information security’ means the preservation of confidentiality, integrity, authenticity and availability of network and information systems;
(2)‘information security event’ means an identified occurrence of a system, service or network state indicating a possible breach of the information security policy or failure of information security controls, or a previously unknown situation that can be relevant for information security;
(3)‘incident’ means any event having an actual adverse effect on the security of network and information systems as defined in Article 4(7) of Directive (EU) 2016/1148;
(4)‘information security risk’ means the risk to organisational civil aviation operations, assets, individuals, and other organisations due to the potential of an information security event. Information security risks are associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets;
(5)‘threat’ means a potential violation of information security which exists when there is an entity, circumstance, action or event that could cause harm;
(6)‘vulnerability’ means a flaw or weakness in an asset or a system, procedures, design, implementation, or information security measures that could be exploited and results in a breach or violation of the information security policy.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
How these words show up in the work is the next guide. This page does not restate them.
Where to read it yourself
The quotes on this page were checked against the EASA Easy Access Rules for Information Security, revision label 2025-12-05. That book is a free download from the EASA website. The same book also holds the acceptable means of compliance and the guidance material. This guide quotes the regulations, not that guidance.
This is the first guide in the Part-IS series. The next one takes the words in Article 3 and shows how each one fails in a maintenance, CAMO or operations workflow. Another guide in the series is the incident record. The last one is the shop-floor practice, including the internal reporting scheme that feeds the external clock quoted above.
Educational content, not regulatory compliance advice. Verify against the current regulation text before relying on it.
In this series
Related
Written by Dionysis Kefalas. Retired Hellenic Air Force Captain and founder of Avioverse. About the author
Metis opens with Avioverse in October 2026 · request early access.