EASA Part-IS Oversight: The Deadlines That Have Passed, and the Ones Still Ahead

George Spiteri
EASA Part-IS Oversight: The Deadlines That Have Passed, and the Ones Still Ahead

If your organisation is inside the scope of Part-IS, the two headline dates are already behind you. That is precisely why this is the moment to pay attention. The applicability date was never the finish line — it was the starting gun for an assessment process that your competent authority is running right now, on a calendar that is not fully in your control.

This article sets out what the competent authority is actually looking for, where you sit on their assessment ladder, and — the part most organisations underestimate — which dates are still ahead of you.

 

The dates that have already passed

Two regulations create Part-IS, and they carry different dates:

RegulationPartApplies fromWho it Catches
Commission Delegated Regulation (EU) 2022/1645Part-IS.D.OR16 October 2025Part-21 design and production organisations (excluding those working only with ELA2 aircraft), aerodrome operators and apron management service providers
Commission Implementing Regulation (EU) 2023/203Part-IS.I.OR (organisations) and Part-IS.AR (authorities)22 February 2026Part-145 maintenance organisations, Part-CAMO, air operators, ATOs, aero-medical centres, FSTD operators, ATCO training organisations, ATM/ANS providers, U-space and CIS providers, and organisations designing or producing ATM/ANS systems — subject to the exclusions in Article 2(1)

Both regulations carry exclusions, and they matter. Under Regulation (EU) 2022/1645, organisations solely involved in the design or production of ELA2 aircraft are out. Under Regulation (EU) 2023/203, Article 2(1) excludes — among others — Part-145 organisations solely maintaining aircraft covered by Part-ML; CAMOs solely managing Part-ML aircraft; approved training organisations providing solely theoretical training or training solely on ELA2 aircraft; FSTD operators solely operating ELA2 FSTDs; air navigation service providers holding a limited certificate under ATM/ANS.OR.A.010; and flight information service providers declaring under ATM/ANS.OR.A.015. Read Article 2(1) against your own approval before assuming you are in scope — or out of it.

 

Note the split carefully, because it is frequently reported the wrong way round. Continuing airworthiness organisations — Part-145 and Part-CAMO — sit under the Implementing Regulation, with the 22 February 2026 date. Design and production organisations and aerodromes sat under the Delegated Regulation and were caught four months earlier.

 

Being past the date is not the same as being compliant

This is the single most important idea in the EASA guidance, and it is the one that catches Accountable Managers off guard.

Compliance with Part-IS is not something you achieve by hitting a date. It is a verdict your competent authority issues about you, after it has completed a sequence of assessments. The Part-IS Implementation Task Force guidelines on the oversight approach — Part-IS TF G-03, revision 1, adopted 26 August 2025 — state it plainly: the organisation will only be deemed to have reached Part-IS compliance once the authority has completed all the phases leading it to conclude that the organisation has reached the “Present”, “Suitable” and “Operating” implementation levels. The same document adds that this assessment process “is not expected to be completed until well after the applicability date”.

So if you are sitting on an internal report that says “Part-IS: compliant”, it is describing your own opinion, not your regulatory status.

 

The PSOE Ladder

The guidance standardises four implementation levels, known as PSOE:

  • Present and Suitable — the foundation is built. Scope defined, policy written and communicated, ISMS structure appointed, risk methodology established, initial risk assessment done, reporting routes in place, contracts settled, staff assessed for competence and trustworthiness.
  • Operating — the ISMS is actually running and producing results. This is the level at which you are considered Part-IS compliant.
  • Effective — continuous improvement under IS.I/D.OR.260. No specific maturity level is required by the rule; organisations may use the maturity models in GM1 IS.I/D.OR.260(a) and choose to go further voluntarily. The guidance notes that higher maturity may, in the longer term, increase authority confidence and influence the level of oversight applied to you.

A useful nuance from the guidance: requirements do not all matter equally at all times. Scope definition, the ISMS itself, risk assessment and treatment, contracting, personnel, the manual and the change procedure carry high relevance during the foundation stage and then move to the background. Internal reporting, incident detection/response/recovery, response to authority findings, external reporting, record-keeping and continuous improvement are background during foundation and become high relevance once you are operating. If your ISMS effort is still concentrated where it was eighteen months ago, it is pointed at the wrong requirements.

 

What the authority does - and what you must have handed over

The guidance sets a two-phase approach.

Phase 1 — document review and approval. The competent authority reviews and approves your Information Security Management Manual (ISMM) and your IS.I/D.OR.255 change procedure. This is a documentary review, but it is not only a desktop exercise: the guidance expressly contemplates discussions and clarifications with the organisation. Ideally this was completed before the applicability date.

Four things had to be made available to the authority, “sufficiently in advance” of that date:

  1. The first version of the ISMM (which may be integrated into an existing manual or exposition already held by the organisation; the guidance gives the POE for production organisations and the MOE for maintenance organisations as examples).
  2. The IS.I/D.OR.255 procedure for changes to the ISMS.
  3. An initial risk assessment identifying your activities, facilities and resources; the services you operate, provide, receive or maintain; the equipment, systems, data and information supporting them; your interfaces with other organisations; and the major risks and threat scenarios, both internal and at the interfaces.
  4. Evidence that internal compliance monitoring has taken place — a report describing your level of compliance against every criterion in the guidance’s assessment table, identifying anything not yet at “Present and Suitable” level, with a corrective action plan for those gaps.

Point 4 is the one Compliance Monitoring Managers should read twice. Part-IS puts compliance monitoring inside the rule itself, at IS.I/D.OR.200(a)(12): the organisation must monitor its own compliance and provide feedback on findings to the Accountable Manager. The guidance then makes your compliance monitoring output a submission item — and tells the authority to use it to judge how well you understand the regulation.

Phase 2 — the audit. The authority then audits you against the “Audit” column of the same table: not whether the procedure exists, but whether it is real. Have staff actually been assessed for trustworthiness and competence? Is the policy genuinely available to all staff and contracted parties, and was it properly communicated? Are the assets actually in the inventory, or only the template for one? Are the people who process internal and external reports identified, trained and authorised? Are the Competent Authority’s access rights to your contracted parties written into the contracts?

This audit may be performed after the applicability date, may combine on-site and remote elements, and may take the form of assessments and inspections. Critically, the guidance encourages authorities to integrate it into ongoing oversight — including combining it with audits already planned for other management systems such as SMS, the NIS Directive or AVSEC.

 

If you were late: the three cases

The guidance sets out three scenarios, and the third has teeth:

  • Case 1 — documentation arrived early enough for approval by the applicability date.
  • Case 2 — documentation arrived before the date but too late to approve. You may continue operating normally while the assessment runs, unless findings already identified justify limitations.
  • Case 3 — documentation did not arrive by the applicability date. The competent authority is expected to raise a Level 2 finding for failure to provide any proof of compliance with ISMS requirements. Depending on how quickly you respond and what a preliminary review shows, the authority may allow normal operation or may impose limitations while that finding is open.

The forward calendar: dates still ahead of you

Here is what is actually still in front of you.

Your next oversight audit — the live deadline. Because the Part-IS audit is folded into your existing oversight programme, its timing is set by your domain’s oversight-programme rule rather than by Part-IS. In air operations, ARO.GEN.305 applies an oversight planning cycle not exceeding 24 months, extendable to 36 months and then to a maximum of 48 months where defined conditions are met, and reducible if safety performance declines. Equivalent oversight-programme provisions exist in the other domains. Practical consequence: if you sit on a standard 24-month cycle, your Part-IS Phase 2 audit should fall within roughly two years of the applicability date — which for Implementing Regulation organisations points to early 2028 at the outside, and for many considerably sooner. Treat that as an estimate rather than a published deadline: oversight cycles run from your authority’s own programme, not from the Part-IS date, and an extended 36- or 48-month cycle pushes it further out. Ask your authority for your scheduled date rather than waiting to be told.

The 18-month development phase — if EASA is your competent authority. Where EASA itself acts as competent authority, it has published a policy allowing organisations under its responsibility an 18-month development phase for full implementation of Part-IS — that is, to move from “Present and Suitable” to a full operational level — with oversight teams verifying the various implementation stages through existing planned oversight activities. Read against the applicability dates, that points to roughly April 2027 for Delegated Regulation organisations and August 2027 for Implementing Regulation organisations. EASA’s published FAQ does not state the start point explicitly, so if EASA is your authority, ask them to confirm the date they are applying to you. If a national authority oversees you, this policy does not automatically apply — national timelines govern.

Rolling deadlines that never stop. Three obligations run permanently once you are operating:

  • 72 hours. Under IS.I/D.OR.230, an information security incident or vulnerability that may represent a significant risk to aviation safety must be notified as soon as the condition is known to the organisation, with the report submitted as soon as possible and not exceeding 72 hours from the time the condition became known, unless exceptional circumstances prevent it. A follow-up report on actions taken and intended follows as soon as those actions are identified. If your incident procedure does not have a 72-hour clock built into it, it is not finished.
  • 5 years. Under IS.I/D.OR.245, records of key processes, identified risks and their treatment measures, and reported incidents and vulnerabilities are kept for at least five years; a derogation approval under IS.I/D.OR.200(e) and its associated risk assessment for at least five years after that approval loses validity; contracts for at least five years after amendment or termination.
  • 3 years. Personnel qualification and experience records are retained for as long as the person works for the organisation and at least three years after they leave.

7–8 October 2026 — the Part-IS Implementation Workshop. EASA is holding the Part-IS Implementation Workshop 2026 at its premises on 7–8 October 2026, in hybrid format. The oversight approach guidelines themselves were first announced at the Part-IS workshop in November 2024 and published on 10 March 2025, so this is a reasonable place to expect the next tranche of thinking.

27 March 2031 — ground handling. Commission Delegated Regulation (EU) 2025/22 of 19 December 2024 extended Part-IS to ground handling organisations subject to Delegated Regulation (EU) 2025/20. Article 1 of that amendment applies from 27 March 2031. That is a long runway, but if you depend on ground handling data feeds, your interface risk assessment cannot assume a Part-IS-regulated counterparty before then. The same amendment, applicable from 16 October 2025, also confirmed that declaring organisations do not need approval of the ISMM or of the change procedure.

Guidance still to come. Sections 2.1.2, 2.1.3 and 2.1.4 of the oversight guidelines — assessment at “Operating” level, assessment at “Effective” level, and oversight of integrated ISMS and SMS — are all marked reserved for future developments. Everything published so far concerns the foundation. The criteria against which your operating ISMS will be judged are not yet written. Build for defensible substance, not for a checklist that does not exist yet.

 

DateWhatStatus
16 October 2025Delegated Regulation (EU) 2022/1645 applies — Part-21 DOA/POA, aerodromes, apron managementPassed
1 January 2026Regulation (EU) 2023/203 applies to the EGNOS air navigation service providerPassed
22 February 2026Implementing Regulation (EU) 2023/203 applies — Part-145, CAMO, air operators, ATOs, ATM/ANS and othersPassed
June 2026EASA publishes Part-IS proportional implementation guidelines for competent authoritiesPublished
7–8 October 2026Part-IS Implementation Workshop 2026, EASA premises, hybridUpcoming
April 2027 / August 2027End of EASA’s 18-month development phase, where EASA is the competent authority (confirm with EASA)Upcoming
early 2028 (estimate)Phase 2 Part-IS audit for organisations on a standard 24-month oversight planning cycle; later if the cycle is extendedUpcoming — estimate, not a published deadline
27 March 2031Article 1 of Delegated Regulation (EU) 2025/22 applies — Part-IS extends to ground handling organisationsUpcoming
Rolling72-hour external reporting; 5-year records; 3-year personnel records after departureContinuous

 

Proportionality is available - but you have to earn it

The guidance is explicit that there is no clean split between complex and non-complex organisations. Instead the authority weighs three indicators separately: your position in the functional chain and the number and safety relevance of your interfaces; the complexity of your structure, hierarchies and processes; and the complexity of your ICT systems, data and external connections.

For simpler organisations, the guidance expressly accepts a streamlined risk assessment prioritised by safety impact, cost-effective controls leveraging existing processes, concise documentation built from templates, focused training, outsourcing to managed security providers, information sharing through channels such as ECCSA, and internal audits scaled to size. Where an organisation uses standard commercial off-the-shelf ICT, using ISO/IEC 27001 Annex A controls as a checklist is accepted — with the caveat that the Part-IS versus ISO/IEC 27001 comparison guide must be referenced so that Part-IS specifics are correctly addressed.

For complex organisations, the expectation moves the other way: governance committees with senior management, IT, legal and business representation; KPI reporting to the board; harmonised policies across business units; risk aggregation and correlation across departments, locations and platforms; role-based training and continuous awareness campaigns; supply chain risk management with third-party audits; a dedicated SOC; SIEM, DLP and EDR tooling; and crisis simulation exercises.

EASA published a further Task Force document, Part-IS proportional implementation — Guidelines for Competent Authorities, in June 2026, aimed specifically at organisations that qualify as simple from an information security perspective, with appendices covering ISMS scope and risk registers and internal reporting templates. If you consider yourself a simple organisation, that document is now the reference your inspector is likely to be holding.

 

What this means for each of you

Accountable Manager. IS.I/D.OR.240 puts three duties on you personally: ensure the resources exist, establish and promote the information security policy, and demonstrate a basic understanding of the regulation. That third duty is written into the rule as an obligation on you personally, not on your Information Security Manager. You also sign the ISMM statement — and if you are not the CEO, the CEO countersigns it. Your practical question this quarter is simple: when is our Part-IS audit, and what would it find today?

Information Security Manager. Your centre of gravity should have shifted from building to running. Detection, response and recovery; internal reporting throughput; external reporting inside 72 hours; records; measured continuous improvement. Under IS.I/D.OR.260 the effectiveness and maturity assessment runs on a calendar basis you define yourself or following an incident — so define it, write the date down, and evidence it.

Compliance Monitoring Manager. You own the item the authority uses to calibrate its opinion of the whole organisation. The compliance monitoring report against the assessment criteria is not an internal document; it is a submission. Gaps disclosed with a credible corrective action plan read as maturity. Gaps found by the inspector that your own report missed read as a compliance monitoring function that does not work — and that is a finding about your management system, not just about information security.

One last point worth settling in writing: EASA’s published position is that Part-IS does not operate as lex specialis under Article 4 of the NIS 2 Directive (EU) 2022/2555, because its scope is narrower. If both apply to you, both apply — independently.

 

Sources:

 

  • Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022 — Article 8 (application from 16 October 2025).
  • Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 — Article 16 (application from 22 February 2026; 1 January 2026 for the EGNOS air navigation service provider); points IS.I.OR.200, 225, 230, 240, 245, 250, 255, 260.
  • Commission Delegated Regulation (EU) 2025/22 of 19 December 2024 — Article 3 (Article 1 applies from 27 March 2031; Article 2 from 16 October 2025).
  • Part-IS Implementation Task Force, “Part-IS oversight approach — Guidelines for Competent Authorities”, Part-IS TF G-03 rev. 1, August 2025.
  • Part-IS Implementation Task Force, “Part-IS proportional implementation — Guidelines for Competent Authorities”, June 2026.
  • EASA, Easy Access Rules for Information Security (Regulations (EU) 2023/203 and 2022/1645), revision from December 2025.
  • EASA FAQ, “Information Security (Part-IS) — Applicability” and “Oversight approach” (18-month development phase), last updated 26 September 2025; EASA FAQ on the NIS 2 Directive and Part-IS.
  • Regulation (EU) No 965/2012, Annex II, ARO.GEN.305 — oversight planning cycle.
  • EASA, Part-IS Implementation Workshop 2026, 7–8 October 2026, hybrid.

 

Disclaimer

This article is provided for information and educational purposes only. It is a summary and interpretation of publicly available European Union regulations and EASA guidance material as at the date of writing, and it is not legal, regulatory, technical or professional advice. It does not create or alter any obligation, and it is not a substitute for the official texts of Commission Delegated Regulation (EU) 2022/1645, Commission Implementing Regulation (EU) 2023/203 and their amendments, the associated AMC and GM, or the guidance published by EASA and the Part-IS Implementation Task Force. Regulations, guidance and dates change. Always verify the current position against the official published sources and consult your competent authority for any determination that affects your organisation’s approval, certificate or declaration. No liability is accepted for any action taken or not taken on the basis of this article.

Frequently asked questions

What is EASA Part-IS?

Part-IS is the set of EU rules requiring aviation organisations and competent authorities to manage information security risks that could have an impact on aviation safety. It is contained in Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203, and it requires organisations in scope to implement an Information Security Management System (ISMS).

When did EASA Part-IS become applicable?

Commission Delegated Regulation (EU) 2022/1645 applies from 16 October 2025. Commission Implementing Regulation (EU) 2023/203 applies from 22 February 2026, except for the EGNOS air navigation service provider subject to Implementing Regulation (EU) 2017/373, for which it applied from 1 January 2026.

Which organisations fall under Regulation (EU) 2022/1645 and which under Regulation (EU) 2023/203?

Regulation (EU) 2022/1645 covers Part-21 design and production organisations (excluding those working only with ELA2 aircraft), aerodrome operators and apron management service providers. Regulation (EU) 2023/203 covers Part-145 maintenance organisations, Part-CAMO continuing airworthiness management organisations, air operators, approved training organisations, aero-medical centres, FSTD operators, ATCO training organisations, ATM/ANS service providers, U-space and common information service providers, and organisations designing or producing ATM/ANS systems. Article 2(1) of Regulation (EU) 2023/203 sets out exclusions, including Part-145 organisations solely maintaining Part-ML aircraft, CAMOs solely managing Part-ML aircraft, approved training organisations providing solely theoretical training or training solely on ELA2 aircraft, FSTD operators solely operating ELA2 FSTDs, air navigation service providers holding a limited certificate, and flight information service providers that declare their activity. Organisations should check Article 2(1) against their own approval.

Does Part-IS apply to Part-145 and CAMO organisations?

Yes. Part-145 maintenance organisations and Part-CAMO continuing airworthiness management organisations fall under Commission Implementing Regulation (EU) 2023/203, which applies from 22 February 2026. Article 2(1) of that Regulation excludes Part-145 organisations that solely maintain aircraft covered by Part-ML and continuing airworthiness management organisations that solely manage aircraft covered by Part-ML.

What do the Part-IS PSOE implementation levels mean?

PSOE stands for Present, Suitable, Operating and Effective. Present and Suitable cover the foundation of the ISMS. Operating means the ISMS is running and producing results, and this is the level at which an organisation is considered Part-IS compliant. Effective covers the continuous improvement pursued after compliance is achieved, under point IS.I/D.OR.260.

Is my organisation Part-IS compliant once the applicability date has passed?

No. According to the Part-IS Implementation Task Force oversight approach guidelines, an organisation is only deemed to have reached Part-IS compliance once the competent authority has completed all phases and concluded that the organisation has reached the Present, Suitable and Operating levels. The guidance states this is not expected to be completed until well after the applicability date.

What does the competent authority review first under Part-IS?

The competent authority follows a two-phase approach. Phase 1 is the review and approval of the Information Security Management Manual (ISMM) and the change procedure required by point IS.I/D.OR.255. Phase 2 is an audit of the organisation, which may be performed after the applicability date and integrated into ongoing oversight activities.

What must an organisation submit to its competent authority for Part-IS?

Four items: the first version of the Information Security Management Manual, the IS.I/D.OR.255 procedure for changes to the ISMS, an initial risk assessment covering activities, resources, systems, data and interfaces with other organisations, and evidence that internal compliance monitoring has taken place, including a corrective action plan for any gaps.

Does the ISMM have to be a separate manual?

No. The oversight approach guidelines state that the elements of the ISMM may be integrated into an existing manual or exposition already held by the organisation, such as a Maintenance Organisation Exposition or a Production Organisation Exposition, and that approval may then be granted by approving the revision of that manual. Organisations holding multiple approvals may integrate the ISMM elements into a single manual.

What happens if an organisation did not submit its Part-IS documentation on time?

The oversight approach guidelines describe three cases. If documentation was not made available to the competent authority by the applicability date, the authority is expected to raise a Level 2 finding indicating that the organisation has not provided any proof of compliance with ISMS requirements, and may then, depending on how quickly the organisation responds and on a preliminary review of the documents, allow the organisation to continue operating normally or impose limitations while that finding remains open.

What is the Part-IS 72 hour reporting deadline?

Under point IS.I/D.OR.230, an information security incident or vulnerability that may represent a significant risk to aviation safety must be notified to the competent authority as soon as the condition is known to the organisation, with the report submitted as soon as possible and not exceeding 72 hours from the time the condition became known, unless exceptional circumstances prevent this. A follow-up report on actions taken and intended follows as soon as those actions have been identified.

How long must Part-IS records be kept?

Under point IS.I/D.OR.245, records of key processes, identified risks and their treatment measures, and reported incidents and vulnerabilities are kept for at least five years. A derogation approval granted under point IS.I/D.OR.200(e) and its associated information security risk assessment are kept for at least five years after that approval loses validity, and contracts for at least five years after amendment or termination. Personnel qualification and experience records are kept for as long as the person works for the organisation and for at least three years after they leave.

When will my Part-IS audit take place?

The Part-IS audit is integrated into the organisation's existing oversight programme, so the timing follows the applicable oversight-programme rule rather than Part-IS itself. In air operations, ARO.GEN.305 applies an oversight planning cycle not exceeding 24 months, extendable to 36 and then to a maximum of 48 months where defined conditions are met. Organisations should ask their competent authority for their scheduled date.

What is the EASA 18 month development phase for Part-IS?

Where EASA acts as the competent authority, it has published a policy allowing organisations under its responsibility an 18 month development phase for the full implementation of Part-IS, moving from a present and suitable level to a full operational level, with compliance verification integrated into existing planned oversight activities. Organisations overseen by a national competent authority should confirm the timeline applied to them.

Can an organisation be exempted from Part-IS?

Points IS.I.OR.200(e) and IS.D.OR.200(e) allow a competent authority to approve an organisation not implementing the ISMS requirements where the organisation demonstrates, through a documented risk assessment, that its activities do not pose information security risks with a potential impact on aviation safety. The Part-IS Implementation Task Force has published dedicated implementation guidelines for this derogation.

Do declaring organisations need approval of the ISMM?

No. Commission Delegated Regulation (EU) 2025/22 amended Delegated Regulation (EU) 2022/1645 to confirm that an approval of the Information Security Management Manual is not required for declaring organisations, and that the procedure for changes to the ISMS does not require approval for declaring organisations.

When does Part-IS apply to ground handling organisations?

Commission Delegated Regulation (EU) 2025/22 of 19 December 2024 extended Part-IS to ground handling organisations subject to Delegated Regulation (EU) 2025/20. Article 1 of that amending Regulation applies from 27 March 2031.

If my organisation complies with the NIS 2 Directive, is it covered for Part-IS?

No. EASA's published position is that Part-IS does not fall under the category of lex specialis under Article 4 of Directive (EU) 2022/2555, because its scope is narrower than that of the NIS 2 Directive. Organisations subject to both must comply with both.

Can Part-IS implementation be proportionate to the size of the organisation?

Yes. The oversight approach guidelines direct competent authorities to assess three indicators separately: the organisation's position in the functional chain and the number and safety relevance of its interfaces, the complexity of its structure and processes, and the complexity of its ICT systems and data. Simpler organisations may use streamlined risk assessments, concise documentation, templates, outsourcing and scaled internal audits. EASA published dedicated proportional implementation guidelines for competent authorities in June 2026.

Can ISO/IEC 27001 be used to show compliance with Part-IS?

It can support compliance but does not replace it. The oversight approach guidelines accept the use of ISO/IEC 27001 Annex A controls as a checklist for organisations using standard commercial off-the-shelf ICT, provided the Part-IS versus ISO/IEC 27001 comparison guide is referenced so that Part-IS specifics are correctly addressed. The Part-IS Implementation Task Force published dedicated guidelines for ISO/IEC 27001:2022 conforming organisations in July 2024.

What are the Accountable Manager's personal duties under Part-IS?

Point IS.I/D.OR.240 places three duties on the Accountable Manager: ensure that all necessary resources are available to comply with the regulation, establish and promote the information security policy, and demonstrate a basic understanding of the regulation. Separately, under point IS.I/D.OR.250 the Accountable Manager signs the statement in the Information Security Management Manual confirming that the organisation will at all times work in accordance with the Annex and with the ISMM, and where the Accountable Manager is not the chief executive officer, the CEO countersigns that statement.


Our Services