Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.AR.235 Continuous improvement

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.AR.235Continuous improvement

(a)The competent authority shall assess, using adequate performance indicators, the effectiveness and maturity of its own ISMS. The assessment shall be performed on a predefined calendar basis defined by the competent authority or following an information security incident.

(b)If deficiencies are found following the assessment carried out in accordance with point (a), the competent authority shall take the necessary improvement measures to ensure that the ISMS continues to comply with the applicable requirements and maintains the information security risks at an acceptable level. In addition, the competent authority shall reassess those elements of the ISMS affected by the adopted measures.

IR · IS.AR.235 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.235Continuous improvement

Show the text

The continuous improvement process (CIP), as required by IS.AR.200(b), should aim to continuously improve the effectiveness, suitability and adequacy of the ISMS. This should be achieved by a proactive and systematic assessment of the ISMS and all its elements — including its maturity. The assessment should take into account the outcomes and conclusions of other information security and assurance processes including audits, management reviews, evaluation of performance, effectiveness and maturity, as well as the outcomes of the derived corrective actions and corrections. The steps to be performed should be at least the following:

(a)Identification of improvement opportunities based on the outcomes of the assessment of the ISMS with respect to its suitability, effectiveness, adequacy and, if deemed necessary, efficiency, as well as on any other suggestion for improvement. The assessment should consider performance indicators which reflect its processes and elements and the defined objectives for effectiveness and maturity.

(b)Evaluation of the identified opportunities regarding cost benefit, absence or reduction of undesired effects and achievement of the targeted objectives and intended outcomes.

(c)Proposal on the evaluated improvement opportunities to the management and recommendation of actions to support their review and decision-making.

(d)According to the decision taken under point (c) above, planning, development and implementation of actions and changes to the ISMS, its processes or elements to achieve the improvements.

(e)Evaluation of the effectiveness of the implemented actions and ISMS changes as well as, as applicable, verification that the root cause of identified deficiencies has been eliminated. The management should assess and review the outcomes of the CIP at planned intervals to ensure the continuing effectiveness, adequacy and suitability of the ISMS, to decide on the prioritisation of the implementation of actions and changes, as well as to revise or set new objectives, or targets for continuous improvement.

AMC · AMC1 IS.AR.235 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.235Continuous improvement

Show the text

Point IS.AR.235 covers assurance processes for the ISMS in a manner that can be considered equivalent to the safety assurance in ICAO Doc 9859 ‘Safety Management Manual (SMM)’, which includes performance monitoring and measurement, management of change and continuous improvement of the SMS. In this Regulation: IS.AR.235(a) addresses, using adequate performance indicators, the effectiveness and maturity assessment of the ISMS; IS.AR.235(b) addresses the improvement measures, i.e. corrections and corrective actions, for the deficiencies detected in IS.AR.235(a) and the continuous improvement process. Similar provisions for continuous improvement are provided for in other information management systems such as ISO/IEC 27001 (see Appendix IV to this document). The context and risk environment of competent authorities are never static and therefore require a dynamic adaptation, evolution and change of the competent authority’s objectives, architectures, organisational structures and processes to maintain the information security risks at an acceptable level. Consequently, the ISMS should be considered as an evolving and learning part/element of the competent authority which needs to be continuously monitored and improved to ensure alignment with the competent authority’s safety objectives and effectiveness. The CIP aims to continuously improve the effectiveness, suitability, adequacy and, if deemed necessary, the efficiency of the ISMS. An competent authority may integrate the Part-IS CIP in some other already operated CIP and may apply methods such as Plan-Do-Check-Act (PDCA) Cycle or Define-Measure-Analyse-Improve-Control (DMAIC) (see also GM1 IS.AR.200). The CIP is based on a proactive and systematic assessment of the ISMS and all its elements including the information security processes and controls driven by the ISMS. The assessment should be carried out against organisational targets for desired levels of performance, effectiveness, and maturity. These targets, besides ensuring the achievement of compliance with the requirements under this Regulation, may also aim to include objectives established by the competent authority’s policy or standards and by management decisions. The above-mentioned assessment is based on the outcome of performance evaluations, audits, risk and incident processes, as well as already applied corrective actions and corrections. Some factors that should be considered when performing the assessment are the following: Adequacy refers to whether the system establishes the disciplines needed to manage information security, e.g. by using broadly accepted industry standards, in a sufficient manner with regard to compliance with the requirements of this Regulation. Effectiveness of the ISMS and the effective implementation of processes and controls driven by the ISMS is assessed by analysing whether: the information security risks are managed to achieve the safety objectives; the intended outcomes of the ISMS are achieved, and the requirements or objectives are met; all types of deficiencies, including failures, are managed to fulfil or correctly implement a requirement or control. Efficiency of the ISMS refers to the implementation of streamlined processes; however, efficiency improvements should not adversely impact effectiveness. Identification of improvement opportunities Improvement opportunities may be identified from the results of the CIP assessment or may be introduced as suggestions from other sources. The identification often involves deviations or corrective actions as well as ineffective processes or controls which are not remediated. Suggestions for improvements stem from sources including: Risk management: the results of regularly conducted risk analyses and the subsequent risk treatment are a primary factor in improving the ISMS, where the risk treatment process involves monitoring of the implemented security measures and evaluating their effectiveness. Performance & effectiveness evaluation: conclusions from (key) performance indicators, their measurement, analysis and continued monitoring as well as the result of the assessment of the effectiveness including the outcomes of the subsequently applied corrections and corrective actions Evaluation of maturity including the results of the subsequent corrections and corrective actions Lessons learned from information security incident detection, handling and response process and a potential treatment of a root cause Results of (internal) audits may be used to verify whether the ISMS and controls within the audit scope meet the competent authority’s requirements and to determine where there are potential areas for improvements. Review and evaluation by management of the current action plan, setting or revision of the objectives or decision on improvement opportunities and actions Competent authority’s suggestion programme (suggestions for improvement), reviews, surveys or assessments with employees or feedback from suppliers or interfacing parties Any outcome of this process should be documented. The resulting actions may be integrated into an overarching action plan which is centrally consolidated and periodically reviewed according to the relevant policies. The resulting action plan may be further divided into a tactical, short-/mid-term action plan and a strategic, long-term action plan.

GM · GM1 IS.AR.235 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/015/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.235(a)Continuous improvement

Show the text

(a)ISMS EFFECTIVENESS EVALUATION When complying with IS.AR.235(a), the competent authority should have a process in place to monitor, measure, evaluate and review the effectiveness of its ISMS that defines:

(1)who monitors, measures, analyses and evaluates the results and takes accountable decisions;

(2)when the above steps should be performed;

(3)which methods for monitoring, measurement, analysis and evaluation are applied to ensure comparable and reproducible results. The calendar basis of the assessments should be commensurate with the maximum level of risk established under IS.AR.205. The process to monitor, measure, evaluate and review the effectiveness of its ISMS referred to under AMC1 IS.AR.235(a) should include as a minimum:

(1)the gathering and retention of metrics of the activities, and additional information that could be useful for monitoring purposes;

(2)the analysis of the metrics in order to identify trends and deviations from predefined performance targets.

(b)ISMS MATURITY ASSESSMENT The competent authority should assess the maturity of its ISMS using a suitable maturity model in order to identify areas for improvement to the ISMS. To do so, the competent authority should:

(1)define or adopt a maturity model which represents a set of important and relevant processes and capabilities that are expected to be implemented and maintained;

(2)for each assessed process or capability, ensure that the model defines criteria against which specific aspects, characteristics and effectiveness should be assessed and evaluated when determining a maturity level;

(3)define for each assessed process or capability its desired target maturity level.

(c)For each assessed information security process or capability contained in the maturity model, the competent authority should:

(1)evaluate and justify the current maturity level;

(2)identify any area for improvement it should make to reach the targeted maturity level;

(3)collect and record the evidence regarding strengths and weaknesses of the implemented ISMS and its evaluated maturity.

AMC · AMC1 IS.AR.235(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.235(a)Continuous improvement

Show the text

(a)As general guidance, the elements of the ISMS that should be monitored, measured and evaluated should be, as a minimum:

(1)the risk assessment and treatment process (including risks at the interfaces with other entities);

(2)the management of non-conformities and corrective actions;

(3)the incident and vulnerability management;

(4)the personnel competence management.

(b)Existing maturity models for ISMS maturity evaluation As general guidance, for the definition or the adoption of a maturity model (MM), the following existing models may be considered: Cybersecurity Capability Maturity Model (C2M2), version 1.1: this model was published by the US Department of Energy in 2014. It introduces the notion of Maturity Indicator Levels (MIL) ranging from 0 to 3 and addresses not only performance levels but also performance practices (under Approach Objectives and approach progression) as well as assurance practices (under Management Objectives and institutionalization progression). Systems Security Engineering – Capability Maturity Model (SSE-CMM): published by ISO as ISO 21827 in 2008. It focuses on engineering practices, much less on operational practices that are split in 11 ‘Security Base Practices’, and 11 ‘Project and Organizational Base Practices’. It introduces the notion of five Capability Levels, from ‘Performed Informally’ to ‘Continuously Improving’. NIST Cybersecurity Framework (NIST CSF), version 1.1: published by NIST in April 2018. Although it is not proposed as a MM, the framework defines four ‘Implementation Tiers’, from ‘Partial’ to ‘Adaptive’, which are a qualitative measure of organisational cybersecurity risk management practices. It focuses on the functionality and repeatability of cybersecurity risk management. ATM Cybersecurity Maturity Model, edition 1: published in February 2019 by the EUROCONTROL NM for organisations in the ATM domain. Whilst not being designed for wider application, it can be adapted as necessary. It defines five maturity levels, ranging from ‘Non-existent’ to ‘Adaptive’ inspired by the ‘Tier’ terminology from the NIST CSF. In fact, the model is founded on NIST CSF, together with some elements of ISO/IEC 27001. The following Table 1 maps the MM mentioned above to a hypothetical five-level MM.

Table 1: Mapping matrix of an existing MM to a hypothetical five-level MM

Mapping to a five-level MMC2M2Eurocontrol NMISO 21827NIST CSF 1.1
InitialMIL 0Non-ExistentPerformed Informally
DefinedMIL 1 (Initial)PartialPlanned & TrackedPartial
ImplementedMIL 2 (Identified)DefinedWell definedRisk-Informed
ManagedMIL 3 (Managed)AssuredQuantitatively ControlledRepeatable
ImprovedAdaptiveContinuously ImprovingAdaptive

No specific maturity level is required. However, if and when compliance is achieved, entities will determine which requirements of which models have already been met (mandatory) and can opt to reach a level that is beneficial to the competent authority (voluntary). In the longer term, achieving higher maturity levels may increase the confidence of oversight authorities, which can have an impact upon the level of oversight activities regarding such competent authority.

GM · GM1 IS.AR.235(a) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.AR.235(b)Continuous improvement

Show the text

When a deficiency is identified, the competent authority should react in a timely manner following a defined process leading to a managed status regarding the deficiency, its associated consequences and, if needed, the prevention of its future recurrence or occurrence elsewhere. Based on an evaluation of the impact and extent of the deficiency and the potential consequences on the ISMS, the process should include as criteria for compliance:

(a)deciding on corrections and their implementation without undue delay in order to limit the impact of the deficiency and deal with its consequences as well as, as applicable, to control or eliminate it;

(b)deciding on the need for, and the implementation of, corrective actions to eliminate the cause(s) of, and contributing factors to, the deficiency based on a root cause analysis and an evaluation of actions remediating the cause aimed at being proportionate to the consequences and impact of the deficiency;

(c)verifying the implemented actions:

(1)to be effective and to result in acceptable residual risks;

(2)not to have unintended side effects leading to other deficiencies, new risks, or an ISMS not aligned with the applicable requirements; as well as

(3)for corrective actions, to effectively remediate or eliminate the root cause;

(d)reporting to and reviewing the identified deficiencies, action plan and results of the action taken with the person identified in IS.AR.225(a) and, as necessary, with other involved or affected roles and parties;

(e)documenting as evidence the detected deficiencies, the planned and implemented corrections and/or corrective actions with deadlines and responsible persons, the management feedback, the outcomes of the process step under point (c) above and, if necessary, the change decisions made for the ISMS itself.

AMC · AMC1 IS.AR.235(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.AR.235(b)Continuous improvement

Show the text

The ‘necessary improvement measures’ referred to in IS.AR.235(b) refer to correction or corrective actions to eliminate deficiencies, or actions aimed at improving the effectiveness as well as the maturity of the ISMS. A process satisfying the criteria defined in AMC1 IS.AR.235 should include the following aspects:

(a)identifying the extent, impact, context and triggers of the deficiency, evaluating it according to some established criteria, analysing potential consequences for the ISMS including a potential existence in other areas;

(b)deciding on corrections and their implementation to immediately limit the impact and manage the consequences of the deficiency as well as, as applicable, to control or eliminate it;

(c)deciding on corrective actions required to eliminate the (root) cause(s) of the deficiency that are proportionate to the consequences;

(d)reassessing the elements of the ISMS which may be affected by the implemented actions to ensure that no further risk is introduced;

(e)verifying the implemented actions referred to in AMC1 IS.AR.235(b);

(f)reporting to and reviewing the outcomes of the process steps with the management (see point (d) of AMC1 IS.AR.235(b));

(g)documenting and evidencing the result of the process steps above (see point (e) of AMC1 IS.AR.235(b)).

GM · GM1 IS.AR.235(b) — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/010/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX I — INFORMATION SECURITY — AUTHORITY REQUIREMENTS [PART-IS.AR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.AR.235 →

Metis opens with Avioverse in October 2026 · request early access.