Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.D.OR.235 Contracting of information security management activities

Delegated Regulation (EU) 2022/1645 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.D.OR.235Contracting of information security management activities

(a)The organisation shall ensure that when contracting any part of the activities referred to in point IS.D.OR.200 to other organisations, the contracted activities comply with the requirements of this Regulation and the contracted organisation works under its oversight. The organisation shall ensure that the risks associated with the contracted activities are appropriately managed.

(b)The organisation shall ensure that the competent authority can have access upon request to the contracted organisation to determine continued compliance with the applicable requirements laid down in this Regulation.

IR · IS.D.OR.235 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2022/1645 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.235Contracting of information security management activities

Show the text

Organisations may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points IS.D.OR.205 and IS.D.OR.210. Instead, information security management activities are subject to the specific provisions of IS.D.OR.235 because matters relating to these activities can have a major impact on the organisation. Therefore the objectives of point IS.D.OR.235 are:

(a)to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the organisation facilities, or when being transmitted between the organisation and contracted organisations, or being remotely accessed by contracted organisations;

(b)to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the organisation, in the frame of the provision of information security management activities;

(c)to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.

GM · GM1 IS.D.OR.235 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM2 IS.D.OR.235Contracting of information security management activities

Show the text

(a)The contracting of information security management activities is a means to allocate tasks from the contracting organisation to third parties (contracted organisations). The contracting organisation remains responsible for the oversight of the contracted organisation(s) and accountable for compliance with this Regulation.

(b)A contract could take the form of a written agreement, letter of agreement, service letter agreement, memorandum of understanding, etc. as appropriate for the contracted activities.

GM · GM2 IS.D.OR.235 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM3 IS.D.OR.235Contracting of information security management activities

Show the text

EXAMPLES The following Table 1 provides some examples of information security management activities that may be contracted in relation to the provisions referred to as in IS.D.OR.200.

Table 1: Examples of information security management activities that may be contracted

IS.D.OR.200 points related to activitiesExample of contracted activity
(a)(1): establishes a policy on information security setting out the overall principles of the organisation with regard to the potential impact of information security risks on aviation safety;Information security policy drafting and consultancy
(a)(2): identifies and reviews information security risks in accordance with point IS.D.OR.205;Identify activities, facilities and resources. Identify interfaces with other organisations which could be exposed to information security risks. Perform risk analysis or part of it, e.g. identify and classify information security risks.
(a)(3) defines and implements information security risk treatment measures in accordance with point IS.D.OR.210;Define, develop and implement measures. Verify the initial and the continued effectiveness of the implemented measures (e.g. red-team/blue-team exercises, penetration testing, vulnerability scanning, etc.). Communicate to the involved stakeholders the outcome of the risk assessment and their responsibilities as part of the risk treatment process.
(a)(4): implements an information security internal reporting scheme in accordance with point IS.D.OR.215;Define, develop and implement an internal reporting scheme to enable the collection and evaluation of information security events and vulnerabilities of equipment, processes and services.
(a)(5): defines and implements, in accordance with point IS.D.OR.220, the measures required to detect information security events, identifies those events which are considered incidents with a potential impact on aviation safety except as permitted by point IS.D.OR.205 (e), and responds to, and recovers from, those information security incidents;Define, develop and implement measures to detect events. Define, develop and implement measures to respond to any event conditions. Define, develop and implement measures aimed at recovering from information security incidents. Implement immediate reaction measures to a information security incident or vulnerability as notified by the competent authority.
(a)(6): implements the measures that have been notified by the competent authority as an immediate reaction to an information security incident or vulnerability with an impact on aviation safety;
(a)(7): takes appropriate action, in accordance with point IS.D.OR.225, to address findings notified by the competent authority;Identify root cause. Define corrective action plan. Provide evidence of the corrective actions implemented to close the finding.
(a)(8): implements an external reporting scheme in accordance with point IS.D.OR.230 in order to enable the competent authority to take appropriate actions;Define, develop and implement an external reporting scheme to enable the communication of the information security incidents and vulnerabilities of equipment, processes and services to the competent authority and when required to the design approval holder or the organisation responsible for the design.
(a)(9): complies with the requirements contained in point IS.D.OR.235 when contracting any part of the activities described in point IS.D.OR.200 to other organisations;Not applicable
(a)(10):complies with the personnel requirements contained in point IS.D.OR.240;Activities of the accountable manager / head of design organisation in the frame of the provisions for a ‘common responsible person’ as referred to in IS.D.OR.240 Compliance monitoring as foreseen by IS.D.OR.240 Contracted organisation to ensure that sufficient personnel is on duty to perform the activities related to this Regulation Define, develop and deliver adequate training to achieve the competencies required by the staff. Perform pre-employment checks
(a)(11):complies with the record-keeping requirements contained in point IS.D.OR.245;Define, develop and implement secured archiving. Provision of secure data centre (as a service) Provision of records updates
(a)(12):monitors compliance of the organisation with the requirements of this Regulation and provides feedback on findings to the accountable manager / head of design organisation to ensure effective implementation of corrective actions;Compliance monitoring (as foreseen by IS.D.OR.240) including the execution of independent audits
(a)(13):protects, without prejudice to applicable incident reporting requirements, the confidentiality of any information that the organisation may have received from other organisations, according to its level of sensitivity.Define, develop and implement solutions to protect the confidentiality of any information.
(b): In order to continuously meet the requirements referred to in Article 1, the organisation shall implement a continuous improvement process in accordance with point IS.D.OR.260.Execute independent effectiveness and maturity assessments. Define, develop and implement the necessary improvement measures.
(c): The organisation shall document, in accordance with point IS.D.OR.250, all key processes, procedures, roles and responsibilities required to comply with point IS.D.OR.200(a), and shall establish a process for amending this documentation. Changes to those processes, procedures, roles and responsibilities shall be managed in accordance with point IS.D.OR.255.Production of documentation to detail all key processes, procedures, roles and responsibilities required to comply with point IS.D.OR.200(a) (e.g. information security policies, general description of the staff, procedures to specify compliance). Define, develop and implement processes for approving amendments and changes.

GM · GM3 IS.D.OR.235 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.235(a)Contracting of information security management activities

Show the text

PRIOR ASSESSMENT The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the organisation, and may therefore be carried out in different ways, such as:

(a)in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers;

(b)review of the information security certifications granted by external and impartial auditors to the potential suppliers;

(c)review of self-assessment questionnaires compiled by the potential suppliers; RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following:

(a)identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers;

(b)identification of the information security requirements of the organisation that are applicable to the contracted organisation;

(c)evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the contracting organisation;

(d)assessment of risks that may be introduced by the contracted organisation. This agreed risk assessment should also consider the roles and responsibilities of the contracting and contracted organisation as well as their interfaces.

GM · GM1 IS.D.OR.235(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.235(a)Contracting of information security management activities

Show the text

(a)OVERSIGHT OF THE CONTRACTED ORGANISATION In order to exercise oversight of the contracted organisation, the organisation under Part-IS should have:

(1)a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation;

(2)a structured process to follow the expected execution of the contract that includes:

(i)definition and agreement of the scope of the activities;

(ii)definition of the roles and responsibilities of the parties (i.e. contracting and contracted organisation).

(iii)definition and review of key performance indicators;

(iv)reaction to deviation from contractual obligations;

(v)performance of compliance audits, according to the predefined scope and objectives, with the aim of evaluating operational and associated assurance activities.

(vi)provision of feedback on the result of the compliance audits both within the organisation and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the contracting organisation should reach the accountable manager or, in the case of design organisations, the head of the design organisation, or delegated person(s) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the organisation to conduct compliance audits of the contracted organisation should be included in the contract between the parties.

(b)MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES In order to properly manage the risks associated with the contracted activities, the organisation should meet the following criteria:

(1)A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted.

(2)There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the organisation under Part-IS and the contracted organisation.

(3)The organisation establishes and maintains appropriate information security communication channels with the contracted organisation.

AMC · AMC1 IS.D.OR.235(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM2 IS.D.OR.235(a)Contracting of information security management activities

Show the text

AUDIT OF CONTRACTED ORGANISATIONS The following aspects should be considered by the organisation when auditing a supplier contracted to perform information security management activities: the scope of the audit as well as the objective should be limited to processes, resources (i.e. contracted organisation personnel, systems/equipment, networks) and data used for the execution of Part-IS contracted activities; compliance and/or implementation audits should be done at the contracting organisation’s discretion; findings identified during an audit should be addressed through a remediation plan with a time frame to be validated by the contracting organisation.

GM · GM2 IS.D.OR.235(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.D.OR.235(b)Contracting of information security management activities

Show the text

In order to ensure access by the competent authority to the contracted organisation upon request, the organisation under Part-IS should ensure that such a requirement or clause is included in the contractual documentation. The competent authority’s access to the contracted organisations should be at least equivalent to that granted to the contracting organisation and, in any case, sufficient to ensure the assessment of continued compliance of the contracted activities with the applicable requirements.

AMC · AMC1 IS.D.OR.235(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.D.OR.235(b)Contracting of information security management activities

Show the text

Access to the contracted organisation means to have visibility of evidence for compliance of the contracted activities (such as artefacts, documents, independent certifications). Evidence of compliance could be achieved either by transfer of documents and/or access to information at the premises in accordance with the ‘audit scope’ as defined in the contract. In those cases where the organisation would use commercial off-the-shelf services with standard contractual clauses as part of the contracted information security management activities, the organisation should consider whether these clauses provide sufficient access to the required information. The opportunity to visit the premises should be evaluated considering different aspects such as the sensitivity of the related information or the practical accessibility to the contracted organisation (e.g. the contracted organisation is a service provider with distributed resources).

GM · GM1 IS.D.OR.235(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.D.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.D.OR.235 →

Metis opens with Avioverse in October 2026 · request early access.