Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Implementing Regulation (EU) 2023/203 · Information Security (Part-IS) · Regulations (EU) 2023/203 and 2022/1645 · IS.AR.100 – IS.AR.235

On this page
  1. IS.AR.100 Scope

    This Part establishes the management requirements to be met by the competent authorities referred to in Article 2(2) of this Regulation.

  2. IS.AR.200 Information security management system (ISMS)

    In order to achieve the objectives set out in Article 1, the competent authority shall set up, implement and maintain an information security management…

    GM1 IS.AR.200 Information security management system (ISMS)

    AMC1 IS.AR.200(a)(1) Information security management system

    GM1 IS.AR.200(a)(1) Information security management system (ISMS)

    AMC1 IS.AR.200(a)(8) Information security management system (ISMS)

    GM1 IS.AR.200(a)(8) Information security management system (ISMS)

    AMC1 IS.AR.200(a)(9) Information security management system (ISMS)

    AMC1 IS.AR.200(a)(11) Information security management system (ISMS)

    AMC1 IS.AR.200(c) Information security management system (ISMS)

    GM1 IS.AR.200(c) Information security management system (ISMS)

    GM1 IS.AR.200(d) Information security management system (ISMS)

  3. IS.AR.205 Information security risk assessment

    The competent authority shall identify all the elements of its own organisation which could be exposed to information security risks.

    GM1 IS.AR.205 Information security risk assessment

    AMC1 IS.AR.205(a) Information security risk assessment

    GM1 IS.AR.205(a) Information security risk assessment

    AMC1 IS.AR.205(b) Information security risk assessment

    GM1 IS.AR.205(b) Information security risk assessment

    GM2 IS.AR.205(b) Information security risk assessment

    AMC1 IS.AR.205(c) Information security risk assessment

    GM1 IS.AR.205(c) Information security risk assessment

    AMC1 IS.AR.205(d) Information security risk assessment

    GM1 IS.AR.205(d) Information security risk assessment

    GM2 IS.AR.205(d) Information security risk assessment

  4. IS.AR.210 Information security risk treatment

    The competent authority shall develop measures to address unacceptable risks identified in accordance with point IS.AR.205, shall implement them in a…

    GM1 IS.AR.210 Information security risk treatment

    AMC1 IS.AR.210(a) Information security risk treatment

  5. IS.AR.215 Information security incidents — detection, response and recovery

    Based on the outcome of the risk assessment carried out in accordance with point IS.AR.205 and the outcome of the risk treatment performed in accordance…

    GM1 IS.AR.215 Information security incidents — detection, response and recovery

    AMC1 IS.AR.215(a) Information security incidents — detection, response and recovery

    GM1 IS.AR.215(a) Information security incidents — detection, response and recovery

    AMC1 IS.AR.215(b) Information security incidents — detection, response and recovery

    GM1 IS.AR.215(b) Information security incidents — detection, response and recovery

    AMC1 IS.AR.215(c) Information security incidents — detection, response and recovery

    GM1 IS.AR.215(b) &(c) Information security incidents — detection, response and recovery

    GM1 IS.AR.215(c) Information security incidents— detection, response and recovery

  6. IS.AR.220 Contracting of information security management activities

    The competent authority shall ensure that when contracting any part of the activities referred to in point IS.AR.200 to other organisations, the…

    AMC1 IS.AR.220 Contracting of information security management activities

    GM1 IS.AR.220 Contracting of information security management activities

    GM2 IS.AR.220 Contracting of information security management activities

    GM3 IS.AR.220 Contracting of information security management activities

    GM4 IS.AR.220 Contracting of information security management activities

    GM5 IS.AR.220 Contracting of information security management activities

  7. IS.AR.225 Personnel requirements

    The competent authority shall: have a person who has the authority to establish and maintain the organisational structures, policies, processes, and…

    GM1 IS.AR.225 Personnel requirements

    AMC1 IS.AR.225(a) Personnel requirements

    GM1 IS.AR.225(a) Personnel requirements

    AMC1 IS.AR.225(b) Personnel requirements

    GM1 IS.AR.225(b) Personnel requirements

    AMC1 IS.AR.225(c) Personnel requirements

    GM1 IS.AR.225(c) Personnel requirements

    AMC1 IS.AR.225(d) Personnel requirements

    GM1 IS.AR.225(d) Personnel requirements

    AMC1 IS.AR.225(e) Personnel requirements

    GM1 IS.AR.225(e) Personnel requirements

  8. IS.AR.230 Record-keeping

    The competent authority shall keep records of its information security management activities (1) The competent authority shall ensure that the following…

    GM1 IS.AR.230 Record-keeping

    AMC1 IS.AR.230(a)(1)(iv) &(a)(4) Record-keeping

    GM1 IS.AR.230(a)(1)(iv) &(a)(4) Record-keeping

    AMC1 IS.AR.230(c) &(d) Record-keeping

    GM1 IS.AR.230(c) &(d) Record-keeping

  9. IS.AR.235 Continuous improvement

    The competent authority shall assess, using adequate performance indicators, the effectiveness and maturity of its own ISMS.

    AMC1 IS.AR.235 Continuous improvement

    GM1 IS.AR.235 Continuous improvement

    AMC1 IS.AR.235(a) Continuous improvement

    GM1 IS.AR.235(a) Continuous improvement

    AMC1 IS.AR.235(b) Continuous improvement

    GM1 IS.AR.235(b) Continuous improvement

  10. Appendix I Examples of threat scenarios with a potential harmful impact on safety

    The following is a non-exhaustive list of examples of information security threat scenarios with a potential harmful impact on safety that may be…

  11. Appendix II Main tasks stemming from the implementation of Part-IS mapped to the EU e-CF and the NIST CSF 2.0

    Part-IS main task Activity type Reference Management, Operational Part-IS EU e-CF NIST CSF 2.0 Competence areas &

  12. Appendix III Examples of aviation services and interfaces

    AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of risk…

  13. Appendix IV Part-IS requirements mapping to ISO/IEC 27001:2022 clauses and controls, and considerations on differences

    Although Part-IS does not credit ISO/IEC 27001 certification, the practices and methods typically adopted for implementing and maintaining an ISMS under…

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.100 – IS.AR.235 →

Metis opens with Avioverse in October 2026 · request early access.

ShareLinkedInX