If your organisation is inside the scope of Part-IS, the two headline dates are already behind you. That is precisely why this is the moment to pay attention. The applicability date was never the finish line — it was the starting gun for an assessment process that your competent authority is running right now, on a calendar that is not fully in your control.
This article sets out what the competent authority is actually looking for, where you sit on their assessment ladder, and — the part most organisations underestimate — which dates are still ahead of you.
The dates that have already passed
Two regulations create Part-IS, and they carry different dates:
| Regulation | Part | Applies from | Who it Catches |
| Commission Delegated Regulation (EU) 2022/1645 | Part-IS.D.OR | 16 October 2025 | Part-21 design and production organisations (excluding those working only with ELA2 aircraft), aerodrome operators and apron management service providers |
| Commission Implementing Regulation (EU) 2023/203 | Part-IS.I.OR (organisations) and Part-IS.AR (authorities) | 22 February 2026 | Part-145 maintenance organisations, Part-CAMO, air operators, ATOs, aero-medical centres, FSTD operators, ATCO training organisations, ATM/ANS providers, U-space and CIS providers, and organisations designing or producing ATM/ANS systems — subject to the exclusions in Article 2(1) |
Both regulations carry exclusions, and they matter. Under Regulation (EU) 2022/1645, organisations solely involved in the design or production of ELA2 aircraft are out. Under Regulation (EU) 2023/203, Article 2(1) excludes — among others — Part-145 organisations solely maintaining aircraft covered by Part-ML; CAMOs solely managing Part-ML aircraft; approved training organisations providing solely theoretical training or training solely on ELA2 aircraft; FSTD operators solely operating ELA2 FSTDs; air navigation service providers holding a limited certificate under ATM/ANS.OR.A.010; and flight information service providers declaring under ATM/ANS.OR.A.015. Read Article 2(1) against your own approval before assuming you are in scope — or out of it.
Note the split carefully, because it is frequently reported the wrong way round. Continuing airworthiness organisations — Part-145 and Part-CAMO — sit under the Implementing Regulation, with the 22 February 2026 date. Design and production organisations and aerodromes sat under the Delegated Regulation and were caught four months earlier.
Being past the date is not the same as being compliant
This is the single most important idea in the EASA guidance, and it is the one that catches Accountable Managers off guard.
Compliance with Part-IS is not something you achieve by hitting a date. It is a verdict your competent authority issues about you, after it has completed a sequence of assessments. The Part-IS Implementation Task Force guidelines on the oversight approach — Part-IS TF G-03, revision 1, adopted 26 August 2025 — state it plainly: the organisation will only be deemed to have reached Part-IS compliance once the authority has completed all the phases leading it to conclude that the organisation has reached the “Present”, “Suitable” and “Operating” implementation levels. The same document adds that this assessment process “is not expected to be completed until well after the applicability date”.
So if you are sitting on an internal report that says “Part-IS: compliant”, it is describing your own opinion, not your regulatory status.
The PSOE Ladder
The guidance standardises four implementation levels, known as PSOE:
- Present and Suitable — the foundation is built. Scope defined, policy written and communicated, ISMS structure appointed, risk methodology established, initial risk assessment done, reporting routes in place, contracts settled, staff assessed for competence and trustworthiness.
- Operating — the ISMS is actually running and producing results. This is the level at which you are considered Part-IS compliant.
- Effective — continuous improvement under IS.I/D.OR.260. No specific maturity level is required by the rule; organisations may use the maturity models in GM1 IS.I/D.OR.260(a) and choose to go further voluntarily. The guidance notes that higher maturity may, in the longer term, increase authority confidence and influence the level of oversight applied to you.
A useful nuance from the guidance: requirements do not all matter equally at all times. Scope definition, the ISMS itself, risk assessment and treatment, contracting, personnel, the manual and the change procedure carry high relevance during the foundation stage and then move to the background. Internal reporting, incident detection/response/recovery, response to authority findings, external reporting, record-keeping and continuous improvement are background during foundation and become high relevance once you are operating. If your ISMS effort is still concentrated where it was eighteen months ago, it is pointed at the wrong requirements.
What the authority does - and what you must have handed over
The guidance sets a two-phase approach.
Phase 1 — document review and approval. The competent authority reviews and approves your Information Security Management Manual (ISMM) and your IS.I/D.OR.255 change procedure. This is a documentary review, but it is not only a desktop exercise: the guidance expressly contemplates discussions and clarifications with the organisation. Ideally this was completed before the applicability date.
Four things had to be made available to the authority, “sufficiently in advance” of that date:
- The first version of the ISMM (which may be integrated into an existing manual or exposition already held by the organisation; the guidance gives the POE for production organisations and the MOE for maintenance organisations as examples).
- The IS.I/D.OR.255 procedure for changes to the ISMS.
- An initial risk assessment identifying your activities, facilities and resources; the services you operate, provide, receive or maintain; the equipment, systems, data and information supporting them; your interfaces with other organisations; and the major risks and threat scenarios, both internal and at the interfaces.
- Evidence that internal compliance monitoring has taken place — a report describing your level of compliance against every criterion in the guidance’s assessment table, identifying anything not yet at “Present and Suitable” level, with a corrective action plan for those gaps.
Point 4 is the one Compliance Monitoring Managers should read twice. Part-IS puts compliance monitoring inside the rule itself, at IS.I/D.OR.200(a)(12): the organisation must monitor its own compliance and provide feedback on findings to the Accountable Manager. The guidance then makes your compliance monitoring output a submission item — and tells the authority to use it to judge how well you understand the regulation.
Phase 2 — the audit. The authority then audits you against the “Audit” column of the same table: not whether the procedure exists, but whether it is real. Have staff actually been assessed for trustworthiness and competence? Is the policy genuinely available to all staff and contracted parties, and was it properly communicated? Are the assets actually in the inventory, or only the template for one? Are the people who process internal and external reports identified, trained and authorised? Are the Competent Authority’s access rights to your contracted parties written into the contracts?
This audit may be performed after the applicability date, may combine on-site and remote elements, and may take the form of assessments and inspections. Critically, the guidance encourages authorities to integrate it into ongoing oversight — including combining it with audits already planned for other management systems such as SMS, the NIS Directive or AVSEC.
If you were late: the three cases
The guidance sets out three scenarios, and the third has teeth:
- Case 1 — documentation arrived early enough for approval by the applicability date.
- Case 2 — documentation arrived before the date but too late to approve. You may continue operating normally while the assessment runs, unless findings already identified justify limitations.
- Case 3 — documentation did not arrive by the applicability date. The competent authority is expected to raise a Level 2 finding for failure to provide any proof of compliance with ISMS requirements. Depending on how quickly you respond and what a preliminary review shows, the authority may allow normal operation or may impose limitations while that finding is open.
The forward calendar: dates still ahead of you
Here is what is actually still in front of you.
Your next oversight audit — the live deadline. Because the Part-IS audit is folded into your existing oversight programme, its timing is set by your domain’s oversight-programme rule rather than by Part-IS. In air operations, ARO.GEN.305 applies an oversight planning cycle not exceeding 24 months, extendable to 36 months and then to a maximum of 48 months where defined conditions are met, and reducible if safety performance declines. Equivalent oversight-programme provisions exist in the other domains. Practical consequence: if you sit on a standard 24-month cycle, your Part-IS Phase 2 audit should fall within roughly two years of the applicability date — which for Implementing Regulation organisations points to early 2028 at the outside, and for many considerably sooner. Treat that as an estimate rather than a published deadline: oversight cycles run from your authority’s own programme, not from the Part-IS date, and an extended 36- or 48-month cycle pushes it further out. Ask your authority for your scheduled date rather than waiting to be told.
The 18-month development phase — if EASA is your competent authority. Where EASA itself acts as competent authority, it has published a policy allowing organisations under its responsibility an 18-month development phase for full implementation of Part-IS — that is, to move from “Present and Suitable” to a full operational level — with oversight teams verifying the various implementation stages through existing planned oversight activities. Read against the applicability dates, that points to roughly April 2027 for Delegated Regulation organisations and August 2027 for Implementing Regulation organisations. EASA’s published FAQ does not state the start point explicitly, so if EASA is your authority, ask them to confirm the date they are applying to you. If a national authority oversees you, this policy does not automatically apply — national timelines govern.
Rolling deadlines that never stop. Three obligations run permanently once you are operating:
- 72 hours. Under IS.I/D.OR.230, an information security incident or vulnerability that may represent a significant risk to aviation safety must be notified as soon as the condition is known to the organisation, with the report submitted as soon as possible and not exceeding 72 hours from the time the condition became known, unless exceptional circumstances prevent it. A follow-up report on actions taken and intended follows as soon as those actions are identified. If your incident procedure does not have a 72-hour clock built into it, it is not finished.
- 5 years. Under IS.I/D.OR.245, records of key processes, identified risks and their treatment measures, and reported incidents and vulnerabilities are kept for at least five years; a derogation approval under IS.I/D.OR.200(e) and its associated risk assessment for at least five years after that approval loses validity; contracts for at least five years after amendment or termination.
- 3 years. Personnel qualification and experience records are retained for as long as the person works for the organisation and at least three years after they leave.
7–8 October 2026 — the Part-IS Implementation Workshop. EASA is holding the Part-IS Implementation Workshop 2026 at its premises on 7–8 October 2026, in hybrid format. The oversight approach guidelines themselves were first announced at the Part-IS workshop in November 2024 and published on 10 March 2025, so this is a reasonable place to expect the next tranche of thinking.
27 March 2031 — ground handling. Commission Delegated Regulation (EU) 2025/22 of 19 December 2024 extended Part-IS to ground handling organisations subject to Delegated Regulation (EU) 2025/20. Article 1 of that amendment applies from 27 March 2031. That is a long runway, but if you depend on ground handling data feeds, your interface risk assessment cannot assume a Part-IS-regulated counterparty before then. The same amendment, applicable from 16 October 2025, also confirmed that declaring organisations do not need approval of the ISMM or of the change procedure.
Guidance still to come. Sections 2.1.2, 2.1.3 and 2.1.4 of the oversight guidelines — assessment at “Operating” level, assessment at “Effective” level, and oversight of integrated ISMS and SMS — are all marked reserved for future developments. Everything published so far concerns the foundation. The criteria against which your operating ISMS will be judged are not yet written. Build for defensible substance, not for a checklist that does not exist yet.
| Date | What | Status |
|---|---|---|
| 16 October 2025 | Delegated Regulation (EU) 2022/1645 applies — Part-21 DOA/POA, aerodromes, apron management | Passed |
| 1 January 2026 | Regulation (EU) 2023/203 applies to the EGNOS air navigation service provider | Passed |
| 22 February 2026 | Implementing Regulation (EU) 2023/203 applies — Part-145, CAMO, air operators, ATOs, ATM/ANS and others | Passed |
| June 2026 | EASA publishes Part-IS proportional implementation guidelines for competent authorities | Published |
| 7–8 October 2026 | Part-IS Implementation Workshop 2026, EASA premises, hybrid | Upcoming |
| April 2027 / August 2027 | End of EASA’s 18-month development phase, where EASA is the competent authority (confirm with EASA) | Upcoming |
| early 2028 (estimate) | Phase 2 Part-IS audit for organisations on a standard 24-month oversight planning cycle; later if the cycle is extended | Upcoming — estimate, not a published deadline |
| 27 March 2031 | Article 1 of Delegated Regulation (EU) 2025/22 applies — Part-IS extends to ground handling organisations | Upcoming |
| Rolling | 72-hour external reporting; 5-year records; 3-year personnel records after departure | Continuous |
Proportionality is available - but you have to earn it
The guidance is explicit that there is no clean split between complex and non-complex organisations. Instead the authority weighs three indicators separately: your position in the functional chain and the number and safety relevance of your interfaces; the complexity of your structure, hierarchies and processes; and the complexity of your ICT systems, data and external connections.
For simpler organisations, the guidance expressly accepts a streamlined risk assessment prioritised by safety impact, cost-effective controls leveraging existing processes, concise documentation built from templates, focused training, outsourcing to managed security providers, information sharing through channels such as ECCSA, and internal audits scaled to size. Where an organisation uses standard commercial off-the-shelf ICT, using ISO/IEC 27001 Annex A controls as a checklist is accepted — with the caveat that the Part-IS versus ISO/IEC 27001 comparison guide must be referenced so that Part-IS specifics are correctly addressed.
For complex organisations, the expectation moves the other way: governance committees with senior management, IT, legal and business representation; KPI reporting to the board; harmonised policies across business units; risk aggregation and correlation across departments, locations and platforms; role-based training and continuous awareness campaigns; supply chain risk management with third-party audits; a dedicated SOC; SIEM, DLP and EDR tooling; and crisis simulation exercises.
EASA published a further Task Force document, Part-IS proportional implementation — Guidelines for Competent Authorities, in June 2026, aimed specifically at organisations that qualify as simple from an information security perspective, with appendices covering ISMS scope and risk registers and internal reporting templates. If you consider yourself a simple organisation, that document is now the reference your inspector is likely to be holding.
What this means for each of you
Accountable Manager. IS.I/D.OR.240 puts three duties on you personally: ensure the resources exist, establish and promote the information security policy, and demonstrate a basic understanding of the regulation. That third duty is written into the rule as an obligation on you personally, not on your Information Security Manager. You also sign the ISMM statement — and if you are not the CEO, the CEO countersigns it. Your practical question this quarter is simple: when is our Part-IS audit, and what would it find today?
Information Security Manager. Your centre of gravity should have shifted from building to running. Detection, response and recovery; internal reporting throughput; external reporting inside 72 hours; records; measured continuous improvement. Under IS.I/D.OR.260 the effectiveness and maturity assessment runs on a calendar basis you define yourself or following an incident — so define it, write the date down, and evidence it.
Compliance Monitoring Manager. You own the item the authority uses to calibrate its opinion of the whole organisation. The compliance monitoring report against the assessment criteria is not an internal document; it is a submission. Gaps disclosed with a credible corrective action plan read as maturity. Gaps found by the inspector that your own report missed read as a compliance monitoring function that does not work — and that is a finding about your management system, not just about information security.
One last point worth settling in writing: EASA’s published position is that Part-IS does not operate as lex specialis under Article 4 of the NIS 2 Directive (EU) 2022/2555, because its scope is narrower. If both apply to you, both apply — independently.
Sources:
- Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022 — Article 8 (application from 16 October 2025).
- Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 — Article 16 (application from 22 February 2026; 1 January 2026 for the EGNOS air navigation service provider); points IS.I.OR.200, 225, 230, 240, 245, 250, 255, 260.
- Commission Delegated Regulation (EU) 2025/22 of 19 December 2024 — Article 3 (Article 1 applies from 27 March 2031; Article 2 from 16 October 2025).
- Part-IS Implementation Task Force, “Part-IS oversight approach — Guidelines for Competent Authorities”, Part-IS TF G-03 rev. 1, August 2025.
- Part-IS Implementation Task Force, “Part-IS proportional implementation — Guidelines for Competent Authorities”, June 2026.
- EASA, Easy Access Rules for Information Security (Regulations (EU) 2023/203 and 2022/1645), revision from December 2025.
- EASA FAQ, “Information Security (Part-IS) — Applicability” and “Oversight approach” (18-month development phase), last updated 26 September 2025; EASA FAQ on the NIS 2 Directive and Part-IS.
- Regulation (EU) No 965/2012, Annex II, ARO.GEN.305 — oversight planning cycle.
- EASA, Part-IS Implementation Workshop 2026, 7–8 October 2026, hybrid.
Disclaimer
This article is provided for information and educational purposes only. It is a summary and interpretation of publicly available European Union regulations and EASA guidance material as at the date of writing, and it is not legal, regulatory, technical or professional advice. It does not create or alter any obligation, and it is not a substitute for the official texts of Commission Delegated Regulation (EU) 2022/1645, Commission Implementing Regulation (EU) 2023/203 and their amendments, the associated AMC and GM, or the guidance published by EASA and the Part-IS Implementation Task Force. Regulations, guidance and dates change. Always verify the current position against the official published sources and consult your competent authority for any determination that affects your organisation’s approval, certificate or declaration. No liability is accepted for any action taken or not taken on the basis of this article.