---
titel: "IT for aviation: Part-IS, operations, joint ventures · SACOSI"
url: https://sacosi.ch/en/industries/aviation
seite: /en/industries/aviation
stand: 2026-09-24
beschreibung: "IT strategy for airlines, airports and aviation operators: Part-IS, ISMS under ISO 27001, Operations Control Center, proven with Discover and FraAlliance."
---

> Knowledge version of the page https://sacosi.ch/en/industries/aviation. It contains the full text, including what is shortened or collapsible on the page itself. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner, Zürich.

# IT in aviation.

**Short answer:** In aviation, an IT outage immediately affects flight operations. Since October 2025 and February 2026, the EU information security requirements (Part-IS) have required aviation organisations to operate a dedicated information security management system, implemented in Switzerland by the Federal Office of Civil Aviation (FOCA). This is the environment from which the term Situational Awareness comes, and my own work: building the IT for Discover Airlines and the IT for FraAlliance, both with IT am Main.

## Why is IT critical in aviation?

- Flight operations do not tolerate outages in the Operations Control Center.
- Group standards, shareholders and supervisory authorities impose requirements at the same time.
- New companies must deliver from day one.

## Which rules typically need to be checked?

Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this.

### [Part-IS (aviation information security)](https://sacosi.ch/en/regulation#partis)

**Switzerland:** Implemented by the Federal Office of Civil Aviation (FOCA). **EU:** Since 16 October 2025 and 22 February 2026, depending on the organisation.

### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001)

**Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually.

### [NIS2 Directive](https://sacosi.ch/en/regulation#nis2)

**Switzerland:** Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services. **EU:** Transposed into national law, in Germany since 6 December 2025.

### [Reporting obligation for cyberattacks (ISG)](https://sacosi.ch/en/regulation#isg)

**Switzerland:** Applies since 1 April 2025 to operators of critical infrastructure. **EU:** Does not apply.

### [Swiss Federal Act on Data Protection (FADP)](https://sacosi.ch/en/regulation#revdsg)

**Switzerland:** Applies since 1 September 2023. **EU:** Does not apply directly.

### [EU General Data Protection Regulation (GDPR)](https://sacosi.ch/en/regulation#dsgvo)

**Switzerland:** Applies to Swiss companies that offer goods or services to individuals in the EU or monitor their behaviour. **EU:** Applies since 25 May 2018.

## What aviation mandates lie behind this?

Two programmes within the Lufthansa Group environment, both delivered with IT am Main.

- **Discover Airlines, 2021 to 2026:** building IT from an empty office, growth to around 2’200 employees, network connection of the Operations Control Center, a prepared handover to the group IT function.
- **FraAlliance, from 2022:** standalone IT for the joint venture of Fraport and Lufthansa in under four months.

## How can I help?

### [Situation picture for investments](https://sacosi.ch/en/investors)

IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort.

### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto)

Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team.

### [Compliance roadmap](https://sacosi.ch/en/regulation)

Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX.

### [Scaling architecture](https://sacosi.ch/en/it-architecture)

A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget.

Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation).

## What is the situation in your company?

Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile.

CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English
