Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

Appendix III Examples of aviation services and interfaces

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

AppendixAppendix

Appendix IIIExamples of aviation services and interfaces

AVIATION SERVICES The following is a non-exhaustive and non-complete list of aviation services that can be used as a basis to identify the scope of the risk assessment for the organisation. aerodrome & ATM-MET service providers aeronautical digital mapping services aeronautical information management (AIM) – external, national, regional airports air traffic control (ATC) – external, superior air traffic management (ATM) approach (APP) & area control (ACC) Services – ER ACC, APP ACC cargo and passenger loading civil & state airspace user (AU) operations centres communication infrastructure flight information services / traffic information services (FIS/TIS) data integrator fuel calculation navigation infrastructure – ground-based, satellite-based non-ATM meteorological (MET) service providers mass & balance calculation non-aviation users (external) regional & sub-regional airspace management (ASM) and air traffic flow & capacity management (ATFCM) static aeronautical data services sub-regional demand & capacity balancing (DCB) common service providers surveillance infrastructure – airport, en-route, terminal manoeuvring area (TMA) route planning time reference services (external) tower (TWR) services

INTERFACES Below are some examples of data exchange at the interfaces between organisations interacting in different functional chains, which can be used as a basis for identifying the scope of the risk assessment for the organisation. Note 1: These examples are graphical representations based on the ‘Examples of ecosystem data exchange’ provided in EUROCAE ED-201A, Appendix B - Tables B-14, which can be consulted for further information. Note 2: Although it is not an organisation, an aircraft has been included in all these examples for the sake of completeness of the description of the data exchange. The aircraft should be considered as an element within the scope of the ISMS of the organisation to which it belongs (typically the airline). Any data exchange between aircraft and other systems within the organisation should take into account existing security measures that may have been evaluated as part of aircraft certification (see also GM1 IS.I.OR.205(c)). [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 1: Interfaces of other organisations with an airline operator [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 2: Interfaces of an airline operator with other organisations [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 3: Interfaces of other organisations with a maintenance service provider [Figure or form omitted from this preview — available in the Avioverse workspace library.] Figure 4: Interfaces of a maintenance service provider with other organisations

APPENDIX · Appendix III — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2025/014/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX II — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.I.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about Appendix III →

Metis opens with Avioverse in October 2026 · request early access.