Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

IS.I.OR.255 Changes to the information security management system

Implementing Regulation (EU) 2023/203 · Regulations (EU) 2023/203 and 2022/1645 · EAR revision 5 Dec 2025

IRImplementing rule

IS.I.OR.255Changes to the information security management system

(a)Changes to the ISMS may be managed and notified to the competent authority in a procedure developed by the organisation. That procedure shall be approved by the competent authority, except for declared organisations.

(b)With regard to changes to the ISMS not covered by the procedure referred to in point (a), the organisation shall apply for and obtain an approval issued by the competent authority, except for declared organisations, for which an approval is not required. With regard to those changes:

(1)the application shall be submitted before any such change takes place, in order to enable the competent authority to determine continued compliance with this Regulation and to amend, if necessary, the organisation certificate and related terms of approval attached to it;

(2)the organisation shall make available to the competent authority any information it requests to evaluate the change;

(3)the change shall be implemented only upon receipt of a formal approval by the competent authority, except for declared organisations, which may implement the change immediately;

(4)the organisation shall operate under the conditions prescribed by the competent authority during the implementation of such changes.

IR · IS.I.OR.255 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2025/2293 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

AMCAcceptable means of compliance

AMC1 IS.I.OR.255Changes to the information security management system

Show the text

Without prejudice to the communication of changes as required for each organisation in the corresponding implementing regulation for the domain as listed in point Article 2(1) of Regulation (EU) 2023/203, the procedure referred to in IS.I.OR.255(a) should take into account the criticality of the changes when proposing how they will be managed. In particular, those changes that could have an impact on the achievement or maintenance of compliance with the provisions under Part-IS, or which could lead to an unacceptable level of risk (e.g. as per the guidance provided in GM1 IS.I.OR.205(c)), should be subjected to scrutiny. Upon establishment of this procedure, any further changes to it should be subject to approval by the competent authority. Where prior approval is sought from the competent authority for a change not covered by an approved procedure, or where no such approved procedure exists, the organisation should provide at least the following information: the nature and purpose of the change; the implementation plan of the change; the verification plan of the change; the potential impact on aviation safety introduced by the change. A significant deviation from the original implementation plan during the change process is an event that should be reported to the competent authority as this deviation may require reconsidering the change impact.

AMC · AMC1 IS.I.OR.255 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM1 IS.I.OR.255Changes to the information security management system

Show the text

Point IS.I.OR.255 is structured as follows: Point (a) introduces the possibility for the organisation to agree with the competent authority that changes to the ISMS can be implemented without prior approval as long as these changes are covered in a change procedure. Point (b) introduces an obligation of prior approval (by the competent authority) for changes not covered by the procedure mentioned above, and indicates how those changes should be handled. The organisation should consider the establishment of a procedure in order to manage and notify changes to the competent authority as provided for under IS.I.OR.255(a). In case of lack of any approved procedure, the organisation will have, for any change, to apply for and obtain an approval as required under IS.I.OR.255(b). In any case, all changes should be notified to the competent authority upon implementation.

GM · GM1 IS.I.OR.255 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

GMGuidance material

GM2 IS.I.OR.255Changes to the information security management system

Show the text

RELATION BETWEEN CHANGES TO THE ISMS AND CONTINUOUS IMPROVEMENT Changes stemming from the continuous improvement process established by the organisation (see IS.I.OR.260) should be handled as any other change according to the guidelines in AMC1 IS.I.OR.255 and GM1 IS.I.OR.255.

EXAMPLE OF CHANGES THAT MAY HAVE AN IMPACT ON THE ISMS Below are some examples of changes that may have an impact on the ISMS, or which could lead to an unacceptable level of risk and therefore should be subject to scrutiny by the competent authority according to the provisions established under IS.I.OR.255:

(a)Changes to the scope of the ISMS, interfaces or related policies: The organisation expands its business functions, and integrates another company within its organisational structure. The organisation has identified non-conformities indicating an incorrect scope. The organisation amends its information security policy and/or information security objectives with a potential impact on aviation safety. Changes to the interfaces of the organisation resulting e.g. from modification in the insourced or outsourced activities.

(b)Changes in responsibilities and accountability as well as in the organisational structure involving the implementation and continuing monitoring of compliance with this Regulation: The accountable manager has delegated certain responsibilities under Part-IS to a person or a group of persons. The organisation contracts information security management activities as per IS.I.OR.235.

(c)Changes to the methodology used for risk management: The organisation changes the classification for likelihood or impact in their risk management methodology e.g. to obtain more granularity. The organisation implements changes to their risk treatment methodology. The organisation integrates its information security risk management into existing management systems.

(d)Changes to the security event management process: The organisation decides to contract security event management activities. The organisation changes the process to notify security events and the criteria to escalate to higher management for a quicker resolution. The organisation changes its policy for mitigating vulnerabilities. The organisation changes its incident recovery procedure.

EXAMPLE OF CHANGES THAT DO NOT HAVE AN IMPACT ON THE ISMS Not all operational changes related to information security have an impact on the ISMS, therefore not all changes are required to be reported to the competent authority, following the provisions established under IS.I.OR.255. The following scenarios may be representative of such changes: After a successfully detected security event which could have easily evolved to an incident, the organisation decides to roll out an extensive cyber security awareness campaign for all employees. Update in the staff training programme and/or training content as a result of the continuous improvement processes established within the organisation. The organisation replaces the software tool that it uses for encrypting sensitive files with another software solution. The organisation has decided to make an internal restructuring for business reasons, changing the names of departments or sections, without making any changes in the responsibilities and accountability (e.g. accountable manager) involving the ISMS of the organisation. The organisation decides to update an existing preventive control e.g. configuring a new firewall in its internal network.

GM · GM2 IS.I.OR.255 — Regulations (EU) 2023/203 and 2022/1645 · ED Decision 2023/009/R · Part-IS Easy Access Rules · EAR revision 5 Dec 2025

All rules in ANNEX II — INFORMATION SECURITY — ORGANISATION REQUIREMENTS [PART-IS.I.OR]

Consolidated from the EASA Easy Access Rules (revision 5 Dec 2025, extracted 17 Aug 2026) for convenience. Not the official publication — verify against the Official Journal of the European Union and the EASA publications before operational use.

Ask Metis about IS.I.OR.255 →

Metis opens with Avioverse in October 2026 · request early access.