Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.AR.220 Contracting of information security management activities

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.AR.220Contracting of information security management activities

The competent authority shall ensure that when contracting any part of the activities referred to in point IS.AR.200 to other organisations, the contracted activities comply with the requirements of this Regulation and the contracted organisation works under its oversight. The competent authority shall ensure that the risks associated with the contracted activities are appropriately managed.

IR · IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.220Contracting of information security management activities

Show the text

(a)OVERSIGHT OF THE CONTRACTED ORGANISATION In order to exercise oversight of the contracted organisation, the competent authority should have:

(1)a process to ensure compliance with the provisions regarding contracted activities contained in this Regulation;

(2)a structured process to follow the expected execution of the contract that includes:

(i)definition and agreement of the scope of the activities;

(ii)definition of the roles and responsibilities of the parties (i.e. competent authority and contracted organisation);

(iii)definition and review of KPIs;

(iv)reaction to deviation from contractual obligations;

(v)performance of compliance audits, according to predefined scope and objectives, with the aim of evaluating operational and associated assurance activities;

(vi)provision of feedback on the result of the compliance audits both within the competent authority and to the contracted organisation, and response to findings. The feedback on the outcome of the compliance audits within the competent authority should reach the person of the competent authority as identified in IS.AR.225(a) to ensure proper monitoring of the response to findings (i.e. implementation of corrective actions) or, if deemed necessary, termination of the contract. Note: The right of the competent authority to conduct compliance audits of the contracted organisation should be included in the contract between the parties.

(b)MANAGEMENT OF THE RISKS ASSOCIATED WITH THE CONTRACTED ACTIVITIES In order to properly manage the risks associated with the contracted activities, the competent authority should meet the following criteria:

(1)A prior assessment of the suppliers is conducted before outsourcing any information security management activities. The assessment should evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the activities to be contracted.

(2)There is an assessment of the risks associated with the provision of the contracted activities that has been agreed between the competent authority and the contracted organisation.

(3)The competent authority establishes and maintains appropriate information security communication channels with the contracted organisation.

AMC · AMC1 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.220Contracting of information security management activities

Show the text

Competent authorities may decide to outsource certain activities to suppliers, both for their own operational needs and for the purpose of complying with this Regulation (information security management activities). Activities contracted for operational needs may fall within the scope of Part-IS and therefore the relevant information security risks have to be managed in accordance with the requirements in points IS.AR.205 and IS.AR.210. Instead, information security management activities are subject to the specific provisions of IS.AR.220 because matters relating to these activities can have a major impact on the competent authority. Therefore the objectives of point IS.AR.220 are:

(a)to protect critical and sensitive information and assets when being handled by organisations contracted for the provision of information security management activities (including organisations in the supply chain) at either their facilities or the competent authority facilities, or when being transmitted between the competent authority and contracted organisations, or being remotely accessed by contracted organisations;

(b)to prevent information security risks from being introduced through products and services developed or provided by the contracted organisations to the competent authority, in the frame of the provision of information security management activities;

(c)to ensure that information security risks are managed throughout all the stages of the relation with the contracted organisations.

GM · GM1 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM2 IS.AR.220Contracting of information security management activities

Show the text

(a)The contracting of information security management activities is a means to allocate tasks from the competent authority to third parties (contracted organisations). The competent authority remains responsible for the oversight of the contracted organisation(s) and accountable for compliance with this Regulation.

(b)A contract could take the form of a written agreement, letter of agreement, service letter agreement, memorandum of understanding, etc. as appropriate for the contracted activities.

GM · GM2 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM3 IS.AR.220Contracting of information security management activities

Show the text

EXAMPLES The following Table 1 provides some examples of information security management activities that may be contracted in relation to the provisions referred to as in IS.AR.200.

Table 1: Examples of information security management activities that may be contracted

IS.AR.200 points related to activitiesExample of contracted activity
(a)(1): establishes a policy on information security setting out the overall principles of the competent authority with regard to the potential impact of information security risks on aviation safety;Information security policy drafting and consultancy
(a)(2): identifies and reviews information security risks in accordance with point IS.AR.205;Identify activities, facilities and resources. Identify interfaces with other organisations which could be exposed to information security risks. Perform risk analysis or part of it, e.g. identify and classify information security risks.
(a)(3): defines and implements information IS.AR.215 security risk treatment measures in accordance with point IS.AR.210;Define, develop and implement measures. Verify the initial and the continued effectiveness of the implemented measures (e.g. red-team/blue-team exercises, penetration testing, vulnerability scanning, etc.). Communicate to the involved stakeholders the outcome of the risk assessment and their responsibilities as part of the risk treatment process.
(a)(4): defines and implements, in accordance with point IS.AR.215, the measures required to detect information security events, identifies those which are considered incidents with a potential impact on aviation safety, and responds to, and recovers from, those information security incidents;Define, develop and implement measures to detect events. Define, develop and implement measures to respond to any event conditions. Define, develop and implement measures aimed at recovering from information security incidents.
(a)(5): complies with the requirements contained in point IS.AR.220 when contracting any part of the activities described in point IS.AR.200 to other organisations;Not applicable
(a)(6): complies with the personnel requirements contained in point IS.AR.225;Contracted organisation to ensure that sufficient personnel is on duty to perform the activities related to this Regulation Define, develop and deliver adequate training to achieve the competencies required by the staff. Perform pre-employment checks.
(a)(7): complies with the record-keeping requirements contained in point IS.AR.230;Define, develop and implement secured archiving. Provision of secure data centre (as a service) Provision of records updates
(a)(8): monitors compliance of its own organisation with the requirements of this Regulation and provides feedback on findings to the person referred to in point IS.AR.225(a) to ensure effective implementation of corrective actions;Compliance monitoring activities including the planning and the execution of independent audits
(a)(9): protects the confidentiality of any information that the competent authority may have related to organisations subject to its oversight and the information received through the organisation’s external reporting schemes established in accordance with point IS.I.OR.230 of Annex II (Part-IS.I.OR) to this Regulation and point IS.D.OR.230 of the Annex (Part-IS.D.OR) to Delegated Regulation (EU) 2022/1645;Define, develop and implement solutions to protect the confidentiality of any information.
(a)(10): notifies the Agency of changes that affect the capacity of the competent authority to perform its tasks and discharge its responsibilities as defined in this Regulation;Not applicable
(a)(11): defines and implements procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other competent authorities and agencies, as well as organisations subject to this Regulation, to conduct effective information security risk assessments relating to their activities.Not applicable
(b): In order to continuously meet the requirements referred to in Article 1, the competent authority shall implement a continuous improvement process in accordance with point IS.AR.235.Execute independent effectiveness and maturity assessments. Define, develop and implement the necessary improvement measures.
(c): The competent authority shall document all key processes, procedures, rolesand responsibilities required to comply with point IS.AR.200(a)Production of documentation to detail all key processes, procedures, roles and responsibilities required to comply with point IS.AR.200(a) (e.g. information security policies, general description of the staff, procedures to specify compliance). Define, develop and implement processes for approving amendments and changes.

GM · GM3 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM4 IS.AR.220Contracting of information security management activities

Show the text

PRIOR ASSESSMENT The purpose of the prior assessment is to evaluate suppliers’ competencies, sustainability as well as qualifications in relation to the information security activities to be contracted. This prior assessment may need to be carried out taking into account other legal requirements or procurement procedures that apply to the competent authority, and may therefore be carried out in different ways, such as:

(a)in case of public bids, inclusion of eligibility requirements in the procurement documents for the potential suppliers;

(b)review of the information security certifications granted by external and impartial auditors to the potential suppliers;

(c)review of self-assessment questionnaires compiled by the potential suppliers. RISK ASSESSMENT ASSOCIATED WITH THE PROVISION OF THE CONTRACTED ACTIVITIES The risk assessment should take into account the maturity level of the contracted organisation, and should consider the following:

(a)identification and assessment of critical and sensitive information and assets that may be shared with, or provided by, external suppliers;

(b)identification of the information security requirements of the authority that are applicable to the contracted organisation;

(c)evaluation, by means of a supplier assessment, of the ability of the contracted organisation (both existing and new contracted organisations) to meet the information security requirements of the authority;

(d)assessment of risks that may be introduced by the contracted organisation. This agreed risk assessment should also consider the roles and responsibilities of the parties (i.e. competent authority and contracted organisation) as well as their interfaces.

GM · GM4 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM5 IS.AR.220Contracting of information security management activities

Show the text

AUDIT OF CONTRACTED ORGANISATIONS The following aspects should be considered by the authority when auditing a supplier contracted to perform information security management activities: the scope of the audit as well as the objective should be limited to processes, resources (i.e. contracted organisation personnel, systems/equipment, networks) and data used for the execution of Part-IS contracted activities; compliance and/or implementation audits should be done at the authority’s discretion; findings identified during an audit should be addressed through a remediation plan with a time frame to be validated by the authority.

GM · GM5 IS.AR.220 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.220 →

Metis opens with Avioverse in October 2026 · request early access.