IRImplementing rule
ARGH.GEN.136Immediate reaction to an information security incident or vulnerability with an impact on aviation safety
(a)The competent authority shall implement a system for the collection, analysis, and dissemination of information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by ground handling organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State concerned to increase the coordination and compatibility of reporting schemes.
(b)The Agency shall implement a system for the analysis of any relevant safety-significant information received pursuant to point ARGH.GEN.125(c), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, equipment, persons or organisations subject to Regulation (EU) 2018/1139 and its delegated and implementing acts.
(c)Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact of the information security incident or vulnerability on aviation safety.
(d)Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and its delegated and implementing acts. The competent authority shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. [point ARGH.GEN.136 applicable from 27 March 2031 — Regulation (EU) 2025/23]
IR · ARGH.GEN.136 — Regulations (EU) 2025/23 and 2025/24 · Regulation (EU) 2025/23 · Ground Handling Easy Access Rules · EAR revision 5 Nov 2025