Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.AR.225 Personnel requirements

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.AR.225Personnel requirements

The competent authority shall:

(a)have a person who has the authority to establish and maintain the organisational structures, policies, processes, and procedures necessary to implement this Regulation. This person shall:

(1)have authority to fully access the resources necessary for the competent authority to perform all the tasks required by this Regulation;

(2)possess the delegation of power required to perform the assigned duties;

(b)have a process in place to ensure that they have sufficient personnel on duty to perform the activities covered by this Annex;

(c)have a process in place to ensure that the personnel referred to in point (b) have the necessary competence to perform their tasks;

(d)have a process in place to ensure that personnel acknowledge the responsibilities associated with the assigned roles and tasks;

(e)ensure that the identity and trustworthiness of the personnel who have access to information systems and data subject to the requirements of this Regulation are appropriately established.

IR · IS.AR.225 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225Personnel requirements

Show the text

The objectives of the requirements contained in point IS.AR.225 are:

(a)to ensure that an effective organisational structure is in place in order to comply with the requirements of this Regulation;

(b)to provide trust to other organisations with whom they share risks.

GM · GM1 IS.AR.225 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.225(a)Personnel requirements

Show the text

The person referred to in point IS.AR.225(a) is normally intended to be a manager in the authority who, by virtue of his or her position, has overall responsibility for information security management and has sufficient authority to plan and allocate the relevant budgetary resources and initiatives in accordance with the financial control model of the Member State. This person is not necessarily required to be knowledgeable on technical matters; however, he or she should be aware of the overarching objectives of this Regulation and its implications for the authority. The authority should make sure that this person has direct access to the highest-ranking executive in the authority and has the necessary funding allocation for the activities under this Regulation.

AMC · AMC1 IS.AR.225(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225(a)Personnel requirements

Show the text

The person referred to in point IS.AR.225 (a) should be capable of managing the authority’s information security strategy and its implementation to ensure the achievement of the objectives described in Article 1. According to the European Cybersecurity Skills Framework (ECSF) published by ENISA in September 2022, this person may be described for instance as: (Chief) Information Security Officer, Cybersecurity Programme Director or Information Security Manager. However, it should be noticed that these descriptions and the related skills do not consider the aviation safety perspective that is required in Article 1.

GM · GM1 IS.AR.225(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.225(b)Personnel requirements

Show the text

SUFFICIENT PERSONNEL To determine the sufficiency of the personnel, the following elements should be taken into consideration:

(a)the organisational structures, policies, processes and procedures subject to information security management;

(b)the amount of coordination required with other organisations, contractors and suppliers;

(c)the level of risk associated with the activities performed by the authority.

AMC · AMC1 IS.AR.225(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225(b)Personnel requirements

Show the text

SUFFICIENT PERSONNEL For the purpose of this Regulation, personnel refers to the combination of the personnel directly employed by the authority, as well as the personnel contracted as specified in IS.AR.220. The activities reported in Appendix II, on the main tasks stemming from the implementation of Part-IS, should be considered when establishing the organisational structure necessary to comply with the requirements of this Regulation.

GM · GM1 IS.AR.225(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.225(c)Personnel requirements

Show the text

NECESSARY COMPETENCE

(a)To determine the competence needed by the personnel performing the activities, the following elements should be taken into consideration:

(1)work roles and the associated tasks;

(2)required knowledge, skills and abilities.

(b)As part of the process to ensure that personnel maintain the necessary competence, the Member State, or the competent authority on its behalf, should:

(1)assess the personnel qualifications and experience with respect to the required competence for the assigned work roles to identify gaps;

(2)align the personnel qualifications and experience to the expected competence to fulfil their roles by organising adequate learning programmes for existing members of personnel, by recruiting new resources, or by a combination thereof;

(3)maintain the personnel competence during the time they are assigned to the work role.

AMC · AMC1 IS.AR.225(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225(c)Personnel requirements

Show the text

NECESSARY COMPETENCE AND TRAINING PROGRAMME A training programme should start from the identification of the competence required by the personnel for each role, followed by the identification of the gaps between the existing competence and the required one. In order to develop the list of competencies, a competent authority may use, as initial guidance, an existing cybersecurity competence framework such as the European e-Competence Framework (e-CF) or the NICE (National Initiative for Cybersecurity Education) based on the NIST Cybersecurity Framework (NIST CSF). In Appendix II, the main tasks of this Regulation are listed and mapped to the competencies derived from the EU e-CF or, for ease of mapping, to the functions and categories of the NIST CSF. This mapping may be used to establish a baseline to identify the aforementioned competence gaps. However, it should be noticed that existing cybersecurity/information security competence frameworks typically focus primarily on the protection of standard information technologies; therefore, the proposed list of competencies may need to be adapted to the technologies or integrated with and processes used in the organisation. The bridging of the identified gaps should be seen as the objective of the training programme, which should further include the scope, content, methods of delivery (e.g. classroom training, e-learning, notifications, on-the-job training) and frequency of training that best meet the authority’s needs considering the size, scope, required competencies, and complexity of the organisation. The competent authority may also identify professional certification schemes that cover a number of necessary competencies; therefore, it may decide to recognise these certifications as sufficient to cover the establishment of proper qualifications and experience for the certified personnel. Finally, as information security/cybersecurity evolves due to the rise of new threats, the authority should periodically review the adequacy of the training programme.

GM · GM1 IS.AR.225(c) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/015/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.225(d)Personnel requirements

Show the text

ACKNOWLEDGEMENT OF RESPONSIBILITIES Regarding any assigned role and task, the authority should specify all information security responsibilities an employee has in a clear and transparent manner. As part of this, all personnel performing the activities required under this Regulation should acknowledge, in a traceable and verifiable manner, understanding of the assigned roles and the associated information security responsibilities.

AMC · AMC1 IS.AR.225(d) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225(d)Personnel requirements

Show the text

ACKNOWLEDGEMENT OF RESPONSIBILITIES Acknowledgement of receipt such as a valid electronic or wet signature, confirmation email, etc., is a traceable proof of acceptance.

GM · GM1 IS.AR.225(d) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.225(e)Personnel requirements

Show the text

IDENTITY AND TRUSTWORTHINESS For the personnel who have access to information systems and data subject to the requirements of Part-IS, the identity should be determined on the basis of documentary evidence. To establish the trustworthiness of such personnel, the competent authority should have a documented process and appropriate criteria to ensure that individuals can be trusted to perform their role.

AMC · AMC1 IS.AR.225(e) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.225(e)Personnel requirements

Show the text

IDENTITY AND TRUSTWORTHINESS

(a)Trustworthiness may be established, for example, by:

(1)prior to employment, a background check carried out in accordance with the applicable rules of Union and national law. This check may include verification of:

(i)education, previous employment and any gaps in the previous years;

(ii)absence of criminal record;

(iii)any other relevant information or intelligence considered relevant to the suitability of a person to work in the expected role;

(2)during employment, monitoring the employee’s commitment and conduct. Note: The absence of criminal record may be verified by means of a certificate issued by the responsible authority in the Member State in accordance with Regulation (EU) 2016/1191. In the case of prospective foreign employees, the above checks may be carried out on the basis of equivalent certificates issued by the country of origin, such as a ‘certificate of good conduct’.

(b)Furthermore, the process and criteria to establish personnel’s trustworthiness may have to consider whether:

(1)the information systems and data to be accessed have been associated with a high severity of the safety consequences with the risk assessment process under IS.AR.205;

(2)controls or mitigating measures for risk treatment identified during the risk analysis rely on organisational/operational procedures — for instance, correct configuration and administration of information technologies, database operations, information security monitoring, etc. In such cases, the personnel who have administrator rights or unsupervised and unlimited access to the systems and data mentioned above in (a)(1), or the personnel who applies the measures under above point (b)(2), may be subject to more stringent criteria.

(c)Intelligence and any other relevant information may be gathered by screening and analysing public sources such as social media and websites, within the limits set by relevant national laws and regulations.

(d)Competent authorities may also be subject to Regulation (EU) 2015/1998 that requires successful completion of background checks for personnel in certain roles, as well as a mechanism for the ongoing review of these checks. In such cases the organisation may considered suitable for the establishment of the personnel’s identity and trustworthiness required under Part-IS, in relation to their role, the process and the relevant criteria defined in Regulation (EU) 2015/1998 for standard and enhanced background checks. However, it should be noted that compliance with the provisions for the establishment of identity and trustworthiness under Part-IS does not constitute compliance with the provisions on background checks as defined in Regulation (EU) 2015/1998.

GM · GM1 IS.AR.225(e) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.225 →

Metis opens with Avioverse in October 2026 · request early access.