IRImplementing rule
EXPLANATORY MEMORANDUM
1.CONTEXT OF THE DELEGATED ACT The current European aviation safety regulatory framework contains a series of requirements which are aimed at reducing the likelihood of an accident happening. This combination of requirements allows that even if an error, mistake and/or deficiency happens, it should not create a hazardous situation that could result in an accident or serious incident. Consequently, an accident or serious incident would only happen in the remote random event of several deficiencies happening simultaneously and, by chance, aligning themselves. The concern is that not enough focus may have been put in properly addressing the situation where existing flaws in different areas are aligned on purpose and exploited by individuals with a malicious intent, no longer being a random event. Such a risk is constantly increasing in the civil aviation environment as the current information systems are becoming more and more interconnected. As a consequence, it is necessary to introduce requirements for the management of information security risks which could have a potential impact on aviation safety. In the particular case of this Delegated Act, the provisions introduced increase the robustness of the management systems and reporting processes and procedures required by Annex II ‘Essential requirements for airworthiness’ and Annex VII ‘Essential requirements for aerodromes’ to Regulation (EU) 2018/1139 for design and production organisations, and for aerodrome operators and providers of apron management services.
2.CONSULTATIONS PRIOR TO THE ADOPTION OF THE ACT In accordance with Article 128(4) of Regulation (EU) 2018/1139, before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law- Making. The draft delegated act was presented to the Air Safety experts group, which includes representatives from the Member States, at its meetings on 17 February and 29 June 2022. The present delegated act is based on EASA Opinion No 03/2021 which contents had been publicly consulted through Notice of Proposed Amendment (NPA) 2019-07 ‘Management of information security risks’ (RMT.0720), published by EASA on 27 May 2019.
3.LEGAL ELEMENTS OF THE DELEGATED ACT Articles 19(1) and 39(1) of Regulation (EU) 2018/1139 empower the Commission to adopt delegated acts, in accordance with Article 128 of that Regulation, laying down detailed rules with regard to organisations responsible for the design and production of products, parts and non-installed equipment, and with regard to organisations responsible for the operation of aerodromes and for the provision of apron management services.
IR — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2022/1645 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025