# EU regulations on information security in aviation (Part-IS)

> Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research.

- Type: Regulation, Statutory
- Scope: EU, Switzerland
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/easa_partis
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does Part-IS apply to you?

- Industry: Aviation (Likely applies): As an aviation organisation - for example an airport, airline, maintenance organisation, CAMO, training organisation or air navigation service provider - you generally fall under the Part-IS information security requirements once your type of organisation reaches the relevant deadline.
- Activity: Critical infrastructure (applies if additionally: Industry: Aviation) (Recommend individual review): If, as an aviation organisation, you also operate critical infrastructure in air transport (e.g. air navigation services, airport operations), this additionally falls under Part-IS - outside the aviation industry, 'critical infrastructure' alone does not trigger Part-IS, since it is not a general critical-infrastructure regulation.
- Markets: Switzerland (applies if additionally: Industry: Aviation) (Recommend individual review): For the Swiss market, FOCA implements Part-IS for aviation organisations; the exact legal transposition into the Air Transport Agreement was not examined in this research in the regulation's wording, only via FOCA's information pages. Outside the aviation industry, the Swiss market alone does not trigger Part-IS.

## Exceptions

- Organisations outside the categories named in the regulations (airport operators, apron management services, design/production organisations, air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers) are, per the source status examined, not directly covered.
- A third regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified in this research only via a secondary source and was not examined for content - it therefore belongs under 'unsicher'.

## Obligations

- Establish and operate an information security management system (ISMS), which per FOCA may be based on ISO/IEC 27001.
- Identify and assess information security risks with a potential impact on flight safety, and derive suitable measures.
- Integrate the ISMS into the organisation's existing safety management system (SMS).
- Train personnel on information security and monitor compliance with the requirements.
- Report occurrences with an information-security dimension to the competent authority.

## Evidence

- Documented ISMS with roles, responsibilities and a risk register.
- Evidence of the ISMS's integration into the safety management system.
- Training records for affected personnel.
- Auditability towards FOCA or EASA as part of ongoing oversight (per the EASA source, monitoring takes place via 'regular audits').

## Deadlines

- 16 October 2025: Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645).
- 22 February 2026: Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203).

## Penalties

The FOCA and EASA pages examined do not state specific fines or sanction provisions for Part-IS. Per EASA, oversight is carried out via regular audits by the competent national authorities and EASA itself; at FOCA, a dedicated Information Security unit within the Protective Measures section has been responsible for this since 1 August 2024. Possible consequences of non-compliance (e.g. conditions or withdrawal of approvals) were not examined in the regulation's text itself as part of this research.

## Frequently asked questions

**Does our ISMS have to be certified to ISO/IEC 27001 to comply with Part-IS?**
No. The FOCA page phrases it as an option for orientation ('may be based on ISO/IEC 27001'), not as a certification requirement. Whether certification is worthwhile case by case, or in practice expected by the regulator, was not conclusively clarified in this research and is marked 'pruefen'.

**Does Part-IS apply to our Swiss company in the same way as in the EU?**
FOCA implements Part-IS in Switzerland; the specific legal basis (transposition via the Air Transport Agreement) was not verified in the wording in this research, only via FOCA's information pages. A robust legal assessment in an individual case requires examining the Air Transport Agreement or consulting FOCA.

## Open points of the research

- The legal transposition of Part-IS in Switzerland via the Air Transport Agreement was not examined in the regulation's wording or the agreement's annex, only via FOCA's information pages, which themselves do not state an explicit legal basis for the transposition. This corresponds to open item 8 in the website's architecture document ('Transposition into the Air Transport Agreement not read in the wording, only FOCA pages. Cross-check.').
- A third, more recent regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified only via a search result, not examined in full text.
- Specific sanction or fine provisions for non-compliance were not researched in the regulation's text itself, only the statement on audits on the authorities' pages.
- Whether there is a de facto certification expectation (rather than mere orientation towards ISO/IEC 27001) was not clarified.

## Sources

- [EU-Verordnungen zur Informationssicherheit (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is), Bundesamt für Zivilluftfahrt (BAZL), retrieved 24 September 2026
- [EU regulation on information security (Part-IS)](https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is), Bundesamt für Zivilluftfahrt (BAZL), retrieved 24 September 2026
- [IS — Information Security (Regulation Groups)](https://www.easa.europa.eu/en/regulation-groups/information-security), European Union Aviation Safety Agency (EASA), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
