Skip to content
DEEN
Book a call

Regulation Statutory · EU, Switzerland

EU regulations on information security in aviation (Part-IS).

Short answer

Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research.

01 Triggers

When does Part-IS apply to you?

Part-IS may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.

  • Industry: Aviation (Likely applies): As an aviation organisation - for example an airport, airline, maintenance organisation, CAMO, training organisation or air navigation service provider - you generally fall under the Part-IS information security requirements once your type of organisation reaches the relevant deadline.
  • Activity: Critical infrastructure (applies if additionally: Industry: Aviation) (Recommend individual review): If, as an aviation organisation, you also operate critical infrastructure in air transport (e.g. air navigation services, airport operations), this additionally falls under Part-IS - outside the aviation industry, 'critical infrastructure' alone does not trigger Part-IS, since it is not a general critical-infrastructure regulation.
  • Markets: Switzerland (applies if additionally: Industry: Aviation) (Recommend individual review): For the Swiss market, FOCA implements Part-IS for aviation organisations; the exact legal transposition into the Air Transport Agreement was not examined in this research in the regulation's wording, only via FOCA's information pages. Outside the aviation industry, the Swiss market alone does not trigger Part-IS.

Exceptions

  • Organisations outside the categories named in the regulations (airport operators, apron management services, design/production organisations, air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers) are, per the source status examined, not directly covered.
  • A third regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified in this research only via a secondary source and was not examined for content - it therefore belongs under 'unsicher'.

02 Obligations

What does Part-IS require?

  • Establish and operate an information security management system (ISMS), which per FOCA may be based on ISO/IEC 27001.
  • Identify and assess information security risks with a potential impact on flight safety, and derive suitable measures.
  • Integrate the ISMS into the organisation's existing safety management system (SMS).
  • Train personnel on information security and monitor compliance with the requirements.
  • Report occurrences with an information-security dimension to the competent authority.

03 Evidence

What evidence is needed?

  • Documented ISMS with roles, responsibilities and a risk register.
  • Evidence of the ISMS's integration into the safety management system.
  • Training records for affected personnel.
  • Auditability towards FOCA or EASA as part of ongoing oversight (per the EASA source, monitoring takes place via 'regular audits').

04 Deadlines

Which deadlines apply?

  1. Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645).
  2. Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203).

Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).

05 Penalties

What are the consequences of violations?

The FOCA and EASA pages examined do not state specific fines or sanction provisions for Part-IS. Per EASA, oversight is carried out via regular audits by the competent national authorities and EASA itself; at FOCA, a dedicated Information Security unit within the Protective Measures section has been responsible for this since 1 August 2024. Possible consequences of non-compliance (e.g. conditions or withdrawal of approvals) were not examined in the regulation's text itself as part of this research.

06 Related

What is connected with it?

07 Open

What is still uncertain?

  • The legal transposition of Part-IS in Switzerland via the Air Transport Agreement was not examined in the regulation's wording or the agreement's annex, only via FOCA's information pages, which themselves do not state an explicit legal basis for the transposition. This corresponds to open item 8 in the website's architecture document ('Transposition into the Air Transport Agreement not read in the wording, only FOCA pages. Cross-check.').
  • A third, more recent regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified only via a search result, not examined in full text.
  • Specific sanction or fine provisions for non-compliance were not researched in the regulation's text itself, only the statement on audits on the authorities' pages.
  • Whether there is a de facto certification expectation (rather than mere orientation towards ISO/IEC 27001) was not clarified.

08 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about Part-IS.

Does our ISMS have to be certified to ISO/IEC 27001 to comply with Part-IS?

No. The FOCA page phrases it as an option for orientation ('may be based on ISO/IEC 27001'), not as a certification requirement. Whether certification is worthwhile case by case, or in practice expected by the regulator, was not conclusively clarified in this research and is marked 'pruefen'.

Does Part-IS apply to our Swiss company in the same way as in the EU?

FOCA implements Part-IS in Switzerland; the specific legal basis (transposition via the Air Transport Agreement) was not verified in the wording in this research, only via FOCA's information pages. A robust legal assessment in an individual case requires examining the Air Transport Agreement or consulting FOCA.

Does Part-IS apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light