Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

Article 4 Requirements arising from other Union legislation

Delegated Regulation (EU) 2022/1645 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

Article 4Requirements arising from other Union legislation

1.Where an organisation referred to in Article 2 complies with security requirements laid down in Article 14 of Directive (EU) 2016/1148 of the European Parliament and of the Council that are equivalent to the requirements laid down in this Regulation, compliance with those security requirements shall be considered to constitute compliance with the requirements laid down in this Regulation.

2.Where an organisation referred to in Article 2 is an operator or an entity referred to in the national civil aviation security programmes of Member States laid down in accordance with Article 10 of Regulation (EC) No 300/2008 of the European Parliament and of the Council, the cybersecurity requirements contained in Point 1.7 of the Annex to Implementing Regulation (EU) 2015/1998 are considered to be equivalent to the requirements laid down in this Regulation, except as regards point IS.D.OR.230 of the Annex to this Regulation that shall be complied with.

3.The Commission, after consulting EASA and the Cooperation Group referred to in Article 11 of Directive (EU) 2016/1148, may issue guidelines for the assessment of the equivalence of requirements laid down in this Regulation and Directive (EU) 2016/1148.

IR · Article 4 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2022/1645 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 Article 4(1)Requirements arising from other Union legislation

Show the text

Pursuant to Article 44 of Directive (EU) 2022/2555 (the NIS 2 Directive), the previous Directive

(EU)2016/1148 (the NIS Directive) was repealed with effect from 18 October 2024. In accordance with the NIS2 Directive, references to the repealed Directive shall be construed as references to Directive (EU) 2022/2555 and shall be read in accordance with the correlation table set out in its Annex III. In accordance with this table, references to Article 14 of Directive (EU) 2016/1148 shall be now read as references to Article 21 and Article 23 of Directive (EU) 2022/2555. For an exact correlation, please refer to Annex III to Directive (EU) 2022/2555. To ensure legal certainty, the equivalence of any requirements should be assessed by the competent authority against the requirements of the national legislation when Directive (EU) 2022/2555 is transposed. When utilising this equivalence, organisations should consider the following: The equivalence between Regulation (EU) 2022/1645 and Directive (EU) 2022/2555 requirements as assessed by the competent authority. Possible differences in the perimeter of applicability of the rules, in particular as regards the elements that are within the scope under the two different frameworks. The competent authority will decide whether or not the measures implemented by the organisation under the NIS framework can be considered sufficient for satisfying requirements of similar nature under this rule.

GM · GM1 Article 4(1) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/013/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 Article 4(2)Requirements arising from other Union legislation

Show the text

Notwithstanding the equivalence between the requirements in Regulation (EU) 2022/1645 and the cybersecurity requirements contained in point 1.7 of the Annex to Regulation (EU) 2015/1998, in order to ensure effective management of safety consequences by leveraging the requirements of Regulation (EU) 2015/1998, organisations need to consider the differences in the scope of the rules in terms of which elements are covered under the two different regulatory frameworks. Taking the example of an airport operator, elements such as body scanners, X-ray machines and anti-RPAS systems fall under the scope of the requirements of point 1.7 of the Annex to Regulation

(EU)2015/1998. Elements such as runway lighting control systems and safety training databases fall under the scope of aviation safety rules. On the other hand, the protection of information and the verification of trustworthiness and identity can be considered element that overlap between the two frameworks. Consequently, an organisation that has developed a system in accordance with point 1.7 of the Annex to Regulation (EU) 2015/1998 can use it to address safety issues by extending the scope of the system, where necessary, to ensure that all safety-related elements are included. Moreover, compliance with point IS.D.OR.230 has to be ensured.

GM · GM1 Article 4(2) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/013/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in Cover Regulation to Delegated Regulation (EU) 2022/1645

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about Article 4 →

Metis opens with Avioverse in October 2026 · request early access.