Pilot Hub News

New Part-IS requirements: Information security becomes a mandatory task for small aviation companies

Last updated on 22 February 2026
With the introduction of Part-IS, the European aviation regulator is tightening the requirements for information security in civil aviation. While large airlines and organisations already have established management systems in place, small flight schools, commercial flight operations and maintenance companies in particular face considerable organisational and administrative challenges. Industry associations therefore advocate pragmatic solutions and provide concrete assistance to enable implementation on time and with reasonable effort.

Information security as a new key regulatory issue

With Part-IS (Information Security), the European Union Aviation Safety Agency is expanding its regulatory framework to include binding specifications on information security. The aim is to systematically protect civil aviation against cyber threats, data manipulation, IT failures and unauthorised access.

The increasing digitalisation of operational processes - from electronic flight preparation tools and digital maintenance documentation to networked flight operation systems - also makes smaller organisations potential targets for attack. At the same time, many processes are now dependent on a stable IT infrastructure. A successful cyberattack can therefore not only cause economic damage, but also have a direct impact on flight safety.

Part-IS therefore establishes binding requirements for:

  • Risk assessment and protection needs analysis
  • Organisational responsibilities for information security
  • Reporting processes for security incidents
  • Training and sensitisation
  • Documentation and continuous monitoring

The requirements apply not only to major airlines, but also to other airlines:

  • Flight schools (ATO/DTO)
  • Commercial CAT flight operations
  • NCC operator (Non-Commercial Complex)
  • Maintenance organisations according to Part-145
  • CAMO organisations

It is precisely here that a tension arises between regulatory requirements and practical feasibility.

Small businesses under considerable pressure to implement

While larger organisations often already have compliance and IT security departments, many smaller aviation companies work with very lean structures. One person often takes on several functions - from safety manager to administrative manager.

The introduction of a comprehensive information security management system can quickly seem disproportionate in such structures. Documentation obligations, risk analyses, training certificates and reporting processes generate administrative costs that can hardly be covered in terms of personnel and finances.

Against this backdrop, industry representatives are lobbying the European Union Aviation Safety Agency and the Federal Ministry for Digital and Transport for practicable and proportionate solutions. The aim is to ensure that small companies can achieve a high level of protection without being forced to implement oversized management systems that are disproportionate to the size of the company.

Sample instructions as a pragmatic interim solution

In order to provide concrete support to affected companies, a sample guide has been developed that translates the key requirements of Part-IS into a lean, practical structure.

The approach behind it is clear:

  • Concentration on material risks
  • Simple, comprehensible documentation
  • Clear responsibilities
  • Realistic action plans

The sample documents enable small companies to submit an application on time and thus formally fulfil regulatory requirements. Even if such a sample application cannot, of course, cover every individual case completely, it provides a reliable basis for dialogue with the competent authority.

Compliance with the deadlines is essential. After the application has been submitted, the authority can provide targeted feedback and request adjustments. This iterative approach is also in line with official practice when introducing new regulations.

Implementation by the authorities still under development

Another aspect that is causing discussion in the industry is the implementation status on the part of the authorities. According to current information, the national authorities are still in the process of fully establishing the internal structures required as part of the Part-IS Authority Requirements.

This means that the supervisory authority is also in a transition phase. Against this background, it is expected that a sense of proportion will be exercised in the case of slightly delayed or incomplete applications - especially if it is recognisable that a company is seriously addressing the issue.

Cyber risks in general aviation are increasing

The introduction of Part-IS is no coincidence. The number of reported cyber incidents in critical infrastructures is continuously increasing worldwide. Aviation is not immune to this.

Typical areas of risk in general aviation include

  • Ransomware attacks on maintenance companies
  • Manipulation or failure of flight planning software
  • Compromised e-mail systems
  • Inadequately secured cloud services
  • Lack of access controls to digital documentation

Smaller organisations in particular are often considered „easy targets“ as they invest less in IT security. Part-IS aims to establish minimum standards that apply uniformly across Europe.

Conclusion: Balance between safety and proportionality

With Part-IS, information security will finally become an integral part of safety management in aviation. For small flight schools, CAT and NCC operators and maintenance companies, this means a considerable need for organisational adaptation.

It will be crucial to find the right balance: On the one hand, cyber risks must be taken seriously and addressed systematically. On the other hand, regulatory requirements must not structurally overburden small companies.

Pragmatic model solutions, a constructive dialogue with the authorities and a proportionate application of the requirements can help to ensure that information security in general aviation does not become an administrative burden, but a genuine safety gain.


Source references:
AOPA

Not a member yet? Register now: