Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.AR.200 Information security management system (ISMS)

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.AR.200Information security management system (ISMS)

(a)In order to achieve the objectives set out in Article 1, the competent authority shall set up, implement and maintain an information security management system (ISMS) which ensures that the competent authority:

(1)establishes a policy on information security setting out the overall principles of the competent authority with regard to the potential impact of information security risks on aviation safety;

(2)identifies and reviews information security risks in accordance with point IS.AR.205;

(3)defines and implements information security risk treatment measures in accordance with point IS.AR.210;

(4)defines and implements, in accordance with point IS.AR.215, the measures required to detect information security events, identifies those which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents;

(5)complies with the requirements contained in point IS.AR.220 when contracting any part of the activities described in point IS.AR.200 to other organisations;

(6)complies with the personnel requirements contained in point IS.AR.225;

(7)complies with the record-keeping requirements contained in point IS.AR.230;

(8)monitors compliance of its own organisation with the requirements of this Regulation and provides feedback on findings to the person referred to in point IS.AR.225 (a) to ensure effective implementation of corrective actions;

(9)protects the confidentiality of any information that the competent authority may have related to organisations subject to its oversight and the information received through the organisation’s external reporting schemes established in accordance with point IS.I.OR.230 of Annex II (Part-IS.I.OR) to this Regulation and point IS.I.OR.230 of Annex I (Part-IS.I.OR) to Delegated Regulation (EU) 2022/1645;

(10)notifies the Agency of changes that affect the capacity of the competent authority to perform its tasks and discharge its responsibilities as defined in this Regulation;

(11)defines and implements procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other competent authorities and agencies, as well as organisations subject to this Regulation, to conduct effective security risk assessments relating to their activities.

(b)In order to continuously meet the requirements referred to in Article 1, the competent authority shall implement a continuous improvement process in accordance with point IS.AR.235.

(c)The competent authority shall document all key processes, procedures, roles and responsibilities required to comply with point IS.AR.200(a) and establish a process for amending this documentation.

(d)The processes, procedures, roles and responsibilities established by the competent authority in order to comply with point IS.AR.200(a) shall correspond to the nature and complexity of its activities, based on an assessment of the information security risks inherent to those activities, and may be integrated within other existing management systems already implemented by the competent authority.

IR · IS.AR.200 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.200Information security management system (ISMS)

Show the text

An information security management system (ISMS) is a systematic approach to establish, implement, operate, monitor, review, maintain and continuously improve the state of information security of an organisation. Its objective is to protect the information assets, such that the operational and safety objectives of an organisation can be reached in a risk-aware, effective and efficient manner. Generally speaking, an ISMS establishes an information security risk management process, based upon the results of information security impact analyses, which basically determine its scope. If information security breaches may cause or contribute to aviation safety consequences, information security requirements need to limit the impact or influence of information security breaches on levels of aviation safety, which are deemed acceptable. Hence, all roles, processes, or information systems, which may cause or contribute to aviation safety consequences, are within the scope of Regulation (EU) 2023/203. The ISMS provides for means to decide on needed information security controls for all architectural layers (governance, business, application, technology, data) and domains (organisational, human, physical, technical). It further allows to manage the selection, implementation, and operation of information security controls. Finally, it allows to manage the governance, risk management and compliance (GRC) within the ISMS scope. The overall risk assessment considers safety consequences influenced by information security risks. These may emerge as threats, hazards, escalation factors that weaken barriers, or direct triggers of existing hazards. When conducting this assessment, both aspects, information security and safety need to be coordinated throughout the process. This ensures mutual understanding of the objectives and the implementation of preventive measures against of all types of threats or weaknesses, as well as mitigating measures. The risk management process is thus based on aviation safety risk assessments and derived information security risk acceptance levels, which are designed to effectively treat and manage information security risks with a potential impact on aviation safety caused by threats exploiting vulnerabilities of information assets in aeronautical systems. Interacting bow-ties is one possible way that allows for a higher-level and non-exhaustive illustration of how different disciplines of risk assessment may need to collaborate to establish a common risk perspective. The below Figure 1 from ICAO Doc 10204 ‘Manual on Aviation Information Security’ illustrates these interactions. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 1: Bow-tie representation of management of aviation safety risks posed by information security threats

In the drawing, the term ‘context’ in the communication between the safety assessment process (SAP) and the information security assessment process (ISAP) carries slightly different notions, which need to be understood and distinguished. In order to satisfy the safety requirements, the SAP will provide context information, such as: the architecture of the systems and the functional descriptions of the elements within the scope, including those related to the barriers. Systems should be understood as the dynamic interaction between people, processes, and products, or services; all identified relevant safety hazards; the top events and their relations (e.g. triggers) to those hazards. In addition to context information, it provides the target likelihood of the related information security successful compromise. This target likelihood is commensurate with the safety objectives related to the severity of the safety consequence. However, it needs to be complemented to include information about the acceptable level of uncertainty, in order to be able to rely adequately on the results of the ISAP. In turn, the ISAP will return context information such as: modification to the architecture of the systems and functional descriptions of the elements modified or added, whether those were safety barriers or other items; additional threats; potentially additional safety hazards; additional direct triggers of hazards; additional escalating factors affecting barriers. In addition to context information, it provides the achieved likelihood of an information security successful compromise. While this likelihood is consistent with the safety objectives set by the SAP, the achieved level of uncertainty also needs to be considered. The interaction between SAP and ISAP is iterative and continues until the safety risk is acceptable, i.e. the target likelihood of the related information security successful compromise has been achieved. The interaction can start from safety consequences identified through the SAP that fall within the scope of the ISMS risk analysis, or from existing information security assessments. ISMS implementation and maintenance An ISMS, as defined in this Regulation, employs the perspectives of governance, risk and compliance, and an approach that combines the safety risk and performance dimensions to determine the information security controls that are appropriate to and compliant with the specific context and can effectively provide the level of protection required to achieve the aviation safety objectives by: Governance perspective refers to providing management direction and leadership aimed to achieve the entity’s own overarching objectives: leadership and commitment of the senior management defining and ensuring the close involvement of the management and a ‘top-down’ ISMS implementation information security and safety objectives aligned and consistent with the entity’s business objectives and monitored by, e.g., management reviews information security policies stating the principles and objectives to be achieved roles, responsibilities, competencies and resources required for an effective ISMS effective, target-group-oriented communication to internal and external stakeholders Risk perspective refers to a key aspect of an ISMS in an aviation safety context according to this Regulation, and serves as a basis for transparent decision-making and prioritisation of controls and risk treatment options. It further refers to the assessment, treatment and monitoring of information security risks in support of the management of aviation safety risks for the key processes and information assets upon which they depend. This includes protection requirements, risk exposure, attitude towards risks and risk acceptance criteria, methods and industry standards. Compliance perspective refers to the compliance with regulatory, legal and contractual requirements. This includes: this Regulation, the entity’s own policies and standards and may further include international or industry standards adopted by the entity from ISO, EUROCAE, etc. This perspective comprises the definition, implementation and maintenance of the required information security provisions whose effectiveness and compliance should be regularly monitored and assured by, e.g., (internal) audits. Based on these perspectives, we may identify the following processes and subject areas that have been shown to be relevant for the establishment of an effective ISMS. These ISMS processes and subject areas can be summarised as follows:

(a)context establishment defining the scope, interfaces, dependencies and requirements of interested parties;

(b)leadership and commitment of the senior management;

(c)information security and safety objectives;

(d)information security policies;

(e)roles, responsibilities, competencies and resources required for an effective ISMS;

(f)communication to internal and external stakeholders to achieve a sufficient level of information security awareness and training of all involved parties;

(g)information security risk management including risk assessment and treatment;

(h)information security incident management establishing processes for the handling of information security incidents and vulnerabilities;

(i)performance & effectiveness monitoring, measurement and evaluation;

(j)internal audits and management reviews;

(k)corrections and corrective actions;

(l)continuous improvement;

(m)relationship with suppliers;

(n)documentation, record-keeping, and evidence collection. Additional critical success factors for the implementation and operation of an ISMS include the following: The ISMS should be integrated with the entity’s processes and overall management structure or even — at least partially, with safeguards for their respective integrity, and as reasonably applicable — with an overarching management system comprising information security, aviation safety and quality management. Information security has to be considered at an early stage in the overall design of processes and procedures, of systems and of information security controls, to be seamlessly integrated, for maximum effectiveness, minimal functional interference and optimised cost. None of these benefits can be achieved by integrating it later. The risk management process determines appropriate characteristics of preventive controls to reach and maintain acceptable risk levels. The incident management process ensures that the organisation detects, reacts and responds to information security incidents in a timely manner. This is achieved by defining responsibilities, procedures, scenarios and response plans in advance to ensure a coordinated, targeted and efficient response. Continuous monitoring and reassessment are undertaken and improvements are made in response. The above-mentioned core components are related to the requirements in this Regulation, for which Figure 2 provides a high-level depiction of the aspects that are more prominent in the implementation phase and those that characterise the operational phase, as well as the review and possible improvement, if the functions do not perform as planned. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 2: Representation of the Part-IS requirements from an ISMS’s life cycle perspective

Plan-Do-Check-Act approach The Plan-Do-Check-Act (PDCA) refers to a process approach that is often used to establish, implement, operate, monitor, review and improve management systems. Figure 3 depicts the PDCA applied to an ISMS. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 3: Plan-Do-Check-Act approach applied to an ISMS

Benefits of an ISMS The benefits of a management system operating in a dynamic, uncertain or unpredictable risk environment are realised in the long term only when the organisation improves existing controls, processes and solutions based on the assessments of risks, performance and maturity as well as the learnings from incidents, audits, non-conformities and their root causes. A successful adoption and deployment of an ISMS allows an entity to: achieve greater assurance to the management and interested parties that its information assets are adequately protected against threats on a continual basis; increase its trustworthiness and credibility providing confidence to interested parties that information security risks with an impact on aviation safety are adequately managed; increase the resilience of the entity’s key processes against unauthorised electronic interactions and maintains the entity’s ability to decide and act; support the timely detection of control gaps, vulnerabilities or deficiencies aimed to prevent information security incidents or at least to minimise their impact; detect and timely react to changes in the entity’s environment including system architecture and threat landscape or the adoption of new technologies; provide a foundation for effective and efficient implementation of a comprehensive information security strategy in times of digital transformation, increasing interconnectivity of systems, emerging information security threats and new technologies. Relation to ISO/IEC 27001 The international standard ISO/IEC 27001 is a widely adopted standard for ISMS which specifies generic requirements for establishing, implementing, maintaining and continually improving an ISMS. It also includes requirements for the assessment and treatment of information security risks. The requirements are applicable to all entities, regardless of type, size or nature. The conformity of an ISMS with the ISO/IEC 27001 standard can be certified by an accredited certification body. ISO/IEC 27001 is compatible with other management system standards (quality, safety, etc.) that have also adopted the structure and terms defined in Annex SL to ISO/IEC Directives, Part 1, Consolidated ISO Supplement. This compatibility allows an entity to operate a single management system that meets the requirements of multiple management system standards. ISO/IEC 27001 allows entities to define their own scope of audit and their own organisational risk appetite. This, in turn, leads to information security requirements that provide the ISMS with criteria for the acceptability of information security risks in line with the entity’s risk appetite (see Figure4). [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 4: Relation between the entity’s risk appetite and the information security objectives

The requirements for an ISMS specified by this Regulation are in most parts consistent and aligned with ISO/IEC 27001; however, this Regulation introduces provisions specific to the context of aviation safety. If an ISO/IEC 27001-based ISMS is already operated by an entity for a different scope and context, it can be adapted and extended to the scope and context of this Regulation in a straightforward manner based on an analysis of the scope and the gaps. In order to take credit from ISO/IEC 27001 certifications to achieve compliance with Part-IS, aviation safety needs to be included in the organisational risk management, with the relevant risk acceptance level determined by the applicable regulation (see Figure 5). Therefore, careful determination of the scope of the ISMS related to aviation safety risks is needed, as it might differ from the one related to the other organisational risks. To allow demonstration of compliance with Regulation (EU) 2023/203, careful delineation between aspects of the ISMS related to aviation safety risks and other organisational risks may be required. This could have an influence upon the decision to integrate ISMSs. [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 5: Introduction of aviation safety aspects in the entity’s risk appetite

PART-IS versus ISO/IEC 27001:2022 cross reference table For a mapping between the Part-IS provisions and the clauses and associated controls in ISO/IEC 27001:2022, refer to Appendix IV.

GM · GM1 IS.AR.200 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/015/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.200(a)(1)Information security management system

Show the text

The competent authority should define and document the scope of the ISMS, by determining activities, processes, supporting systems, and identifying those which may have an impact on aviation safety. The information security policy should be endorsed by the person identified as per IS.AR.225(a) and reviewed at planned intervals or if significant changes occur. Moreover, the policy should cover at least the following aspects with a potential impact on aviation safety by:

(a)committing to comply with applicable legislation, consider relevant standards and best practices;

(b)setting objectives and performance measures for managing information security;

(c)defining general principles, activities, processes for the competent authority to appropriately secure information and communication technology systems and data;

(d)committing to apply ISMS requirements into the processes of the competent authority;

(e)committing to continually improve towards higher levels of information security process maturity as per IS.AR.235;

(f)committing to satisfy applicable requirements regarding information security and its proactive and systematic management and to the provision of appropriate resources for its implementation and operation;

(g)assigning information security as one of the essential responsibilities for all managers;

(h)committing to promote the information security policy through training or awareness sessions within the competent authority to all personnel on a regular basis or upon modifications;

(i)encouraging the implementation of a ‘Just-Culture’ and the reporting of vulnerabilities, suspicious/anomalous events and/or information security incidents;

(j)committing to communicate the information security policy to all relevant parties, as appropriate. Note: A significant change is a notable alteration or modification that has a meaningful impact on the competent authority operations, such as a structural change within the authority due to reorganisations, a change in the business processes (e.g. working from home, use of personal devices), a technological evolution (e.g. distributed computing resources, artificial intelligence/machine learning) or an evolution in the threat landscape.

AMC · AMC1 IS.AR.200(a)(1) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.200(a)(1)Information security management system (ISMS)

Show the text

INFORMATION SECURITY POLICY AND OBJECTIVES The information security policy should suit the competent authority’s purpose and direct its own information security activities. Such policy should contain the needs for information security in the competent authority’s context, a high-level statement of direction and intent of the information security activities, the principles and most important strategic and tactical objectives to be achieved by the ISMS, as well as the general information security objectives or a specification of a framework (who, how) for setting information security objectives. The information security policy should also contain a description of the established ISMS, including roles, responsibilities and references to topic-specific policies and standards. The information security objectives should be: consistent and aligned with the information security policy and consider the applicable information security requirements, derived from the overarching competent authority’s objectives, and the results from the risk assessment and treatment (which, in turn, supports the implementation of the competent authority’s strategic goals and information security policy); regularly reviewed to ensure that they are up to date and still appropriate; measurable if practicable (to be able to determine whether the objective has been met), aimed to be SMART (specific, measurable, attainable, realistic, timely) and aligned with all affected responsible persons. When defining information security objectives, e.g., based on the overarching competent authority’s objectives, the information security requirements or the results of risk assessments, it should be determined how these objectives will be achieved. The degree to which information security objectives are achieved must be measurable. If possible, it should be measured by key performance indicators (KPIs) which have been defined in advance (refer to resources such as COBIT 5 for Information Security). It is recommended to start with the definition of a limited number of information security objectives which are relevant for the competent authority, more of a long-term nature and measurable with a reasonable effort relative to the delivered benefits.

GM · GM1 IS.AR.200(a)(1) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.200(a)(8)Information security management system (ISMS)

Show the text

COMPLIANCE MONITORING When establishing compliance with the provisions under point IS.AR.200(a)(8), the competent authority should implement a function to periodically monitor compliance of the management system with the relevant requirements and adequacy of the procedures including the establishment of an internal audit process and an information security risk management process. Compliance monitoring should include a feedback mechanism of audit findings to the person of the competent authority as identified in IS.AR.225(a) to ensure implementation of corrective actions as necessary.

AMC · AMC1 IS.AR.200(a)(8) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.200(a)(8)Information security management system (ISMS)

Show the text

COMPLIANCE MONITORING For the purpose of compliance monitoring, internal audits should be conducted at planned intervals to provide assurance on the status of the ISMS to the management and to provide information on the following: conformity of the ISMS to the requirements of this Regulation and the competent authority’s own requirements either stated in the information security policy, procedures and contracts or derived from information security objectives or outcomes of the risk treatment process; effective implementation and maintenance of the ISMS. Internal audits should follow an independent approach and a decision-making process based on evidence. Moreover, when setting up an audit programme, the importance of the processes concerned, and definitions of the audit criteria and scopes should be considered. Documented information should be retained evidencing the audit results, their reporting to the relevant management and the audit programme.

GM · GM1 IS.AR.200(a)(8) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.200(a)(9)Information security management system (ISMS)

Show the text

When establishing compliance with the provisions under points IS.AR.200(a)(9), the competent authority should implement and maintain information security controls that are sufficiently robust and effective to protect information and ensure the need-to-know principle (i.e. limiting access to information to only those who need it to perform their duties). It should protect the source of information in accordance with the relevant provisions established in Regulation (EU) 2018/1139. It should also comply with Regulation (EU) No 376/2014.

AMC · AMC1 IS.AR.200(a)(9) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.200(a)(11)Information security management system (ISMS)

Show the text

When establishing compliance with the provisions under point IS.AR.200(a)(11), the competent authority should implement and maintain a process to proactively share applicable and relevant information for performing information security risk assessments with other competent authorities, the Agency and other affected organisations within the scope of this Regulation, as soon as it becomes aware of such information. The competent authority should define and document which kind of information needs to be shared and with whom.

AMC · AMC1 IS.AR.200(a)(11) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.200(c)Information security management system (ISMS)

Show the text

When establishing compliance with the provisions under point IS.AR.200(c), the competent authority should:

(a)provide an outline of the structure of the specific information security personnel (internal and external), including their roles and responsibilities that will be used to manage and maintain the elements included within the scope of the ISMS and will be approved by the person identified in IS.AR.225(a). The competent authority should review the outline of the structure at planned intervals or if significant changes occur (see the Note in AMC1 IS.AR.200(a)(1));

(b)identify and categorise all relevant contracted organisations or qualified entities used to implement the ISMS. The competent authority should define and document procedures for the management of interfaces with all other entities and coordination between the competent authority and other national authorities, contracted organisations or qualified entities;

(c)identify and define all key processes and procedures, and internal and external reporting schemes that will be used to maintain compliance with the objectives of this Regulation over the life cycle of the ISMS. The competent authority may adjust existing processes or procedures for compliance;

(d)identify and document any other information that will be used to maintain compliance with the objectives of this Regulation;

(e)when creating and updating documented information, ensure appropriate identification and description (e.g. a title, date, author, or reference number) as well as a review and an approval for suitability and adequacy;

(f)control the documented information required by the ISMS to ensure that it is:

(1)available and suitable for use, where and when it is needed;

(2)adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity).

AMC · AMC1 IS.AR.200(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.200(c)Information security management system (ISMS)

Show the text

The amount of documented information that should be developed to maintain compliance with the objectives of this Regulation may vary between competent authorities due to various factors, such as size and complexity, or the need for harmonisation with other management processes already in place. As general guidance, taking into account the documents required to comply with point IS.AR.200(a) and the record-keeping requirements referred to in IS.AR.230, the following is a non-exhaustive list of information that should be documented:

(a)information security policy that should include the authority’s information security objectives — see IS.AR.200(a)(1);

(b)responsibilities and accountabilities for roles relevant to information security — see the personnel requirements referred to in points IS.AR.225(a) and (b) and the related AMC and GM;

(c)scope of the ISMS and the interfaces with, and dependencies on, other parties — see IS.AR.200(a)(2) and the information security requirements referred to in points IS.AR.205(a) and (b);

(d)information security risk management process — see the information security requirements referred to in points IS.AR.205 and IS.AR.210;

(e)archive of the risks identified in the information security risk assessment along with the associated risk treatment measures (often referred to as ‘risk register’ or ‘risk ledger’) — see IS.AR.230;

(f)evidence of the competencies necessary for the personnel performing the activities required under this Regulation — see IS.AR.225(c) and the related AMC and GM;

(g)evidence of the current competencies of the personnel performing the activities required under this Regulation — see IS.AR.230(b)(1);

(h)(key) performance indicators derived from evidence of the monitoring and measurement of the ISMS processes.

GM · GM1 IS.AR.200(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.200(d)Information security management system (ISMS)

Show the text

PROPORTIONALITY IN ISMS IMPLEMENTATION When implementing the processes and procedures, as well as establishing the roles and responsibilities required under point IS.AR.200(d), the competent authority should primarily consider the risks that it may be posing to other organisations, as well as its own risk exposure. Other aspects that may be relevant include the authority’s needs and objectives, information security requirements, its own processes, and the size, complexity and structure of the authority, all of which may change over time. INTEGRATION OF ISMS UNDER THIS REGULATION WITH EXISTING MANAGEMENT SYSTEMS A competent authority may take advantage of existing management systems when implementing an ISMS by integrating it with those existing systems. By integrating the ISMS with existing management systems, the competent authority may reduce the effort and costs required to implement and maintain the ISMS, while also ensuring consistency and alignment with the authority’s overall management approach. Below is a non-exhaustive list of potential synergies that can be exploited when integrating the ISMS with an existing management system: Leverage existing policies and procedures: an authority may use its existing policies and procedures as a foundation for its ISMS. This may help to ensure consistency and minimise the need for additional documentation. Align the ISMS with other management systems: an authority may align the ISMS with other management systems, such as safety management systems (SMSs), to ensure that the ISMS is consistent with the authority’s overall management approach. Use existing risk management processes: an authority may use their existing risk management processes to identify and assess the information security risks potentially leading to aviation safety risks. Reuse existing controls: an authority may reuse existing controls, such as access controls or incident management process, to implement the information security controls required by the ISMS. Continuous improvement process: an authority may use the continuous improvement process of existing management systems to improve the ISMS over time.

GM · GM1 IS.AR.200(d) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.200 →

Metis opens with Avioverse in October 2026 · request early access.