Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

21.B.20A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety

Annex I · Regulation (EU) No 748/2012 · EAR revision 27 Nov 2025

IRImplementing rule

21.B.20AImmediate reaction to an information security incident or vulnerability with an impact on aviation safety

(a)The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. [applicable from 22 February 2026 – Regulation (EU) 2023/203]

(b)The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point 21.B.15(c) and, without undue delay, provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, that is necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, control and monitoring units (CMUs), CMU components, non-installed equipment, and persons or organisations that are subject to Regulation (EU) 2018/1139 and its delegated and implementing acts. [applicable from 22 February 2026 – Regulation (EU) 2024/1110]

(c)Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. [applicable from 22 February 2026 – Regulation (EU) 2023/203]

(d)Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. [applicable from 22 February 2026 – Regulation (EU) 2023/203]

IR · 21.B.20A — Regulation (EU) No 748/2012 · Regulation (EU) 2024/1110 · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

AMCAcceptable means of compliance

AMC1 21.B.20AImmediate reaction to an information security incident or vulnerability with an impact on aviation safety

Show the text

(a)To appropriately collect and analyse information related to information security incidents and vulnerabilities with a potential impact on aviation safety, the competent authority should implement means that ensure the necessary confidentiality.

(b)When disseminating information related to information security incidents and vulnerabilities with a potential impact on aviation safety, the competent authority should properly select the appropriate recipient(s) to prevent the content of a report from being exploited to the detriment of aviation safety, by revealing, for instance, uncorrected vulnerabilities. [applicable from 22 February 2026 – ED Decision 2023/10/R]

AMC · AMC1 21.B.20A — Regulation (EU) No 748/2012 · ED Decision 2023/010/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

GMGuidance material

GM1 21.B.20AImmediate reaction to an information security incident or vulnerability with an impact on aviation safety

Show the text

When deemed necessary, a two-step mechanism could be used: a report alerting about the information security event or incident and the availability of additional data that would require controlled and confidential distribution. This report should only alert recipients of the urgency and the necessity for organisations and competent authorities to establish further communication through secure means. Therefore, the report should consist of two parts: one limited to mostly public information and one containing the sensitive data that should be restricted to the recipients who need to know. Wherever possible, reports should be based on an agreed taxonomy. [applicable from 22 February 2026 – ED Decision 2023/10/R]

GM · GM1 21.B.20A — Regulation (EU) No 748/2012 · ED Decision 2023/010/R · Initial Airworthiness Easy Access Rules · EAR revision 27 Nov 2025

All rules in SECTION B — PROCEDURES FOR COMPETENT AUTHORITIES

Consolidated from the EASA Easy Access Rules (revision 27 Nov 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about 21.B.20A →

Metis opens with Avioverse in October 2026 · request early access.