PART-IS here

The new EASA Part-IS regulation is taking effect. Are you in the aviation industry? We can help you comply.

Achieving EASA Part-IS compliance

EASA's new Part-IS rules affect the entire aviation industry. From design and production organizations to airlines, aerodromes, maintenance providers, ATM/ANS, training organizations, U-space operators and even authorities, almost all stakeholders are obliged to act.

Information security is now a critical requirement for safety. By October 16, 2025 and February 22, 2026, all aviation Companies must have an Information Security Management System (ISMS ) in place. The challenge is clear: aviation has long focused on security and quality, but Part IS adds a new discipline. Companies must now integrate information security into existing management systems, interpret what the regulation really means for their operations, and do it all within tight deadlines, with compliance and certification at stake.

This is where our PART-IS service comes in. We help you assess your situation, design and implement the ISMS, integrate it into your security management system and prepare your teams for the new requirements.

What is PART-IS and why is it important?

PART-IS (information security) is the European Union's regulatory framework that requires organizations and aviation authorities to identify, manage and mitigate information security risks that may affect aviation safety. It complements existing EASA safety regulations by integrating cybersecurity into the same continuous improvement cycle as flight operations, maintenance and safety management.

Part-IS can be considered as a "Security Management System for information security", a structured approach encompassing policy, risk management, competence, reporting and continuous improvement.

Image in image block

Basic requirements of PART-IS

At its core, PART-IS requires Companies to establish and maintain an ISMS that is:

  • Risk-based and performance-oriented: Identifies assets, assesses threats and manages risks proportionally.
  • Operationally integrated: Aligned with SMS, quality and compliance processes.
  • Competency-oriented: Define roles, train staff and create a culture of security.
  • Incident-ready: Detect, classify, respond and recover effectively.

Companies already aligned to ISO/IEC 27001 can leverage existing frameworks, but still need to address aviation-specific requirements such as security impact analysis and incident reporting, as well as overall alignment with security processes.

Relationship to NIS2

Many aeronautical entities also fall under the scope of NIS2 regulations. However, Part I is not a substitute for NIS2 Compliance. While alignment is possible, Companies should plan for complementary implementation rather than assuming equivalence.

Image in image block

Implementation challenges

Defining the scope of the ISMS across complex interfaces.

Aviation ecosystems involve multiple stakeholders, such as operators, OEMs, ANSPs and suppliers. Use operational service maps, not just organizational charts, to define scope.

Unite IT, OT and security cultures.

Cybersecurity teams focus on confidentiality, integrity and availability (CIA), while security teams prioritize risk controls and barriers. Part-IS requires a unified approach.

Incident Detection and Recovery with Security in Mind

Beyond log collection, Enterprises must detect events that could escalate into security incidents and recover without compromising operational security.

Managing Multi-Regulatory Obligations

Harmonize controls across Part-IS, NIS2 and ISO 27001 to avoid duplication and audit fatigue.

How Bureau Veritas adds value

With decades of aviation experience and a deep understanding of Cybersecurity, Bureau Veritas helps Companies achieve credible, audit-ready compliance while maintaining operational efficiency.

Our services include:

01

Applicability and gap assessment

Identify whether Part-SI applies to your company and where current practices fall short.

02

ISMS design and SMS integration

Develop an information security management system that fits seamlessly with your existing security and quality systems.

03

Competency development and training

Equip your teams with the knowledge and skills needed to meet and maintain Part I requirements.

04

Independent warranty and readiness reviews

Validate your compliance with expert reviews that prepare you for audits and regulatory oversight.

Advantages of multidisciplinary teams

Part-IS requires collaboration between the CISO, security manager, compliance, continuing airworthiness and operations managers. When these teams work together, it is possible to obtain

  • Better hazard identification: cyber threat scenarios become part of your operational hazard register (e.g., corrupted OFP, falsified FMS navigation data, compromised AODB).
  • Smarter change control: Security assessments for IT/OT changes include cyber failure modes, and cyber risk treatments consider operational mitigations (procedures, MEL reliefs, ATC coordination).
  • Faster and more secure Incident Response: Playbooks connect SIEM/SOCs actions with safety reporting and coordination (e.g., NOTAM/ATC, dispatch restrictions, ground handling restrictions), reducing both MTTR and safety.

Examples of incidents

  • Manipulated load sheets: A phishing attack compromises flight planning data, triggering verification and recovery protocols.
  • Aerodrome system disruption: A compromise of the AODB disrupts slot allocation, requiring technical containment and manual safety procedures.
  • Navigation data integrity alert: Anomalous surveillance data prompt procedural separation while cyber teams investigate.

CONTACT ME

Do you want to know more about our PART-IS services? Fill in the form and we will contact you within one working day.

USP

Why choose Bureau Veritas Cybersecurity

Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing.

We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.