IRImplementing rule
ADR.AR.C.040AChanges to the information security management system
(a)With regard to changes managed and notified to the competent authority in accordance with the procedure set out in point IS.D.OR.255(a) of the Annex (Part-IS.D.OR) to Delegated Regulation (EU) 2022/1645, the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point ADR.AR.C.005. If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point ADR.AR.C.055.
(b)With regard to other changes requiring an application for approval in accordance with point IS.D.OR.255(b) of the Annex (Part-IS.D.OR) to Delegated Regulation (EU) 2022/1645:
(1)upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval;
(2)the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change;
(3)if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change.
IR · ADR.AR.C.040A — Regulation (EU) No 139/2014 · Regulation (EU) 2023/203 · Aerodromes Easy Access Rules · EAR revision 13 Mar 2026