ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]
Implementing Regulation (EU) 2023/203 · Information Security (Part-IS) · Regulations (EU) 2023/203 and 2022/1645 · IS.AR.100 – IS.AR.235
On this page
IS.AR.100 Scope
This Part establishes the management requirements to be met by the competent authorities referred to in Article 2(2) of this Regulation.
IS.AR.200 Information security management system (ISMS)
In order to achieve the objectives set out in Article 1, the competent authority shall set up, implement and maintain an information security management…
GM1 IS.AR.200 Information security management system (ISMS)
AMC1 IS.AR.200(a)(1) Information security management system
GM1 IS.AR.200(a)(1) Information security management system (ISMS)
AMC1 IS.AR.200(a)(8) Information security management system (ISMS)
GM1 IS.AR.200(a)(8) Information security management system (ISMS)
AMC1 IS.AR.200(a)(9) Information security management system (ISMS)
AMC1 IS.AR.200(a)(11) Information security management system (ISMS)
AMC1 IS.AR.200(c) Information security management system (ISMS)
GM1 IS.AR.200(c) Information security management system (ISMS)
GM1 IS.AR.200(d) Information security management system (ISMS)
IS.AR.205 Information security risk assessment
The competent authority shall identify all the elements of its own organisation which could be exposed to information security risks.
GM1 IS.AR.205 Information security risk assessment
AMC1 IS.AR.205(a) Information security risk assessment
GM1 IS.AR.205(a) Information security risk assessment
AMC1 IS.AR.205(b) Information security risk assessment
GM1 IS.AR.205(b) Information security risk assessment
GM2 IS.AR.205(b) Information security risk assessment
AMC1 IS.AR.205(c) Information security risk assessment
GM1 IS.AR.205(c) Information security risk assessment
AMC1 IS.AR.205(d) Information security risk assessment
IS.AR.210 Information security risk treatment
The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, shall implement them in a…
IS.AR.215 Information security incidents — detection, response and recovery
Based on the outcome of the risk assessment carried out in accordance with point IS.AR.205 and the outcome of the risk treatment performed in accordance…
GM1 IS.AR.215 Information security incidents — detection, response and recovery
AMC1 IS.AR.215(a) Information security incidents — detection, response and recovery
GM1 IS.AR.215(a) Information security incidents — detection, response and recovery
AMC1 IS.AR.215(b) Information security incidents — detection, response and recovery
GM1 IS.AR.215(b) Information security incidents — detection, response and recovery
AMC1 IS.AR.215(c) Information security incidents — detection, response and recovery
GM1 IS.AR.215(b) &(c) Information security incidents — detection, response and recovery
GM1 IS.AR.215(c) Information security incidents— detection, response and recovery
IS.AR.220 Contracting of information security management activities
The competent authority shall ensure that when contracting any part of the activities referred to in point IS.AR.200 to other organisations, the…
AMC1 IS.AR.220 Contracting of information security management activities
GM1 IS.AR.220 Contracting of information security management activities
GM2 IS.AR.220 Contracting of information security management activities
GM3 IS.AR.220 Contracting of information security management activities
GM4 IS.AR.220 Contracting of information security management activities
GM5 IS.AR.220 Contracting of information security management activities
IS.AR.225 Personnel requirements
The competent authority shall: have a person who has the authority to establish and maintain the organisational structures, policies, processes, and…
GM1 IS.AR.225 Personnel requirements
AMC1 IS.AR.225(a) Personnel requirements
GM1 IS.AR.225(a) Personnel requirements
AMC1 IS.AR.225(b) Personnel requirements
GM1 IS.AR.225(b) Personnel requirements
AMC1 IS.AR.225(c) Personnel requirements
GM1 IS.AR.225(c) Personnel requirements
AMC1 IS.AR.225(d) Personnel requirements
GM1 IS.AR.225(d) Personnel requirements
IS.AR.230 Record-keeping
The competent authority shall keep records of its information security management activities (1) The competent authority shall ensure that the following…
AMC1 IS.AR.230(a)(1)(iv) &(a)(4) Record-keeping
GM1 IS.AR.230(a)(1)(iv) &(a)(4) Record-keeping
IS.AR.235 Continuous improvement
The competent authority shall assess, using adequate performance indicators, the effectiveness and maturity of its own ISMS.
AMC1 IS.AR.235 Continuous improvement
GM1 IS.AR.235 Continuous improvement
AMC1 IS.AR.235(a) Continuous improvement
GM1 IS.AR.235(a) Continuous improvement
Appendix I Examples of threat scenarios with a potential harmful impact on safety
The following is a non-exhaustive list of examples of information security threat scenarios with a potential harmful impact on safety that may be…
Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0
Part-IS main task Activity type Reference Management, Operational Part-IS EU e-CF NIST CSF 2.0 Competence areas &
Appendix III Examples of aviation services and interfaces
AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of risk…
Appendix IV Part-IS requirements mapping to ISO/IEC 27001:2022 clauses and controls, and considerations on differences
Although Part-IS does not credit ISO/IEC 27001 certification, the practices and methods typically adopted for implementing and maintaining an ISMS under…
Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.
Metis opens with Avioverse in October 2026 · request early access.