Who should read this: a company that machines parts, writes software, supplies equipment or provides services to airlines, maintenance organisations, airports, air navigation providers or aerospace manufacturers, and has started receiving information security questionnaires it did not receive two years ago.
There is a reason those questionnaires arrived. Your customers came into scope of a new regulation, and the regulation tells them to think about you.
The two dates
Part-IS is the information security regime for civil aviation. It arrived in two pieces.
Delegated Regulation (EU) 2022/1645, applicable since 16 October 2025. This caught aerodrome operators, apron management service providers, and Part 21 design and production organisations. If you supply parts, materials or engineering into aircraft production, your customer has been in scope for almost a year.
Implementing Regulation (EU) 2023/203, applicable since 22 February 2026. This is the larger one. Part 145 maintenance organisations, continuing airworthiness management organisations, commercial and non-commercial air operators, approved training organisations, flight simulation training device operators, air navigation service providers, air traffic controller training centres, and the competent authorities themselves.
That second date is why supplier assessments started landing on aviation software vendors, ground equipment suppliers and MRO subcontractors this year rather than last. Airlines, MROs and ANSPs only came into scope in February.
What it asks of your customer
An approved organisation has to establish, implement and maintain an information security management system proportionate to its size, nature and complexity, and to the risk its activities carry. The distinguishing feature against a general-purpose standard is that Part-IS is a safety regulation. The risks that matter are the ones with a potential impact on aviation safety, not on commercial confidentiality.
In outline it requires them to identify and assess information security risks with a safety impact, treat them, define accountability and roles, detect and respond to incidents, report incidents and vulnerabilities to their authority, and integrate all of it with the safety management system they already run.
For most of them, the ISMS discipline is new and the management-system discipline is not. They have run a safety management system for years. Part-IS lands as a second management system on the same rails.
The part everyone overstates, and what EASA actually says
Here is where a lot of supplier-facing commentary goes wrong, and it is worth getting right because it changes what you should agree to.
There is a widespread claim that Part-IS flows down to every supplier. It does not, and EASA has answered this directly. The rule on contracted activities, IS.I.OR.235, applies to suppliers and subcontractors that perform tasks pertinent to information security management activities. Suppliers and subcontractors that do not fall under the general provision at IS.I.OR.205 instead.
So the regulation draws a line. If you are running part of your customer’s information security management, you are inside a specific rule. If you are supplying them a component, a service or a system, you are handled as part of their own risk management rather than by direct flow-down.
Two practical consequences.
You are still assessed. Your customer has to consider information security risks arising from their interfaces with you, because those risks could reach aviation safety. That assessment is real and it lands on you as questionnaires, contract clauses and sometimes audits.
But the obligation is theirs, not yours. You are not legally required to hold a Part-IS ISMS unless you are an approved organisation yourself. What you are commercially required to do is satisfy your customer’s assessment. That distinction matters when someone sends you a contract amendment asserting that you must be “Part-IS compliant”. The honest answer is usually that you must be able to evidence appropriate information security for the interfaces you touch, which is a different and more manageable commitment.
Which suppliers get the hardest questions
From the shape of the regulation, the pressure is not evenly distributed. It concentrates where an information security failure at the supplier could plausibly reach a safety outcome.
- Software that touches operations. Flight operations, crew scheduling, maintenance records, load and balance, cargo systems, airport operational databases. A corrupted or unavailable maintenance record is a safety question, not an IT question.
- Anything with a data interface into the approved organisation. System integrations, remote access, hosted services, engineering data exchange.
- Design and production data. Technical data under configuration control, where integrity failure has an airworthiness consequence.
- Ground and test equipment with software in it, particularly where it is connected.
Whereas a supplier of raw material, fasteners or consumables with no data interface tends to see a lighter version of the same questionnaire.
If your product is software or a connected device, note also that a second and entirely separate obligation may apply to you directly rather than by contract: the Cyber Resilience Act, whose reporting duties start on 11 September 2026 and which is described in the Cyber Resilience Act reporting duty.
What to build, and what not to
The efficient answer for a supplier in the 20 to 250 employee range is not a Part-IS ISMS. It is an ISO 27001 aligned management system, scoped to the interfaces your aviation customers care about, with the aviation-specific additions bolted on.
That works because your customer’s assessment is asking for evidence of governance, risk management, access control, supplier management, incident handling and recovery. An ISMS produces all of that as a matter of course, and it answers the questionnaires from your non-aviation customers at the same time. The practical route through it without a security team is set out in ISO 27001 for a company without a security team.
The three aviation-specific additions worth making explicitly:
- Assess risk against safety impact, not just business impact. This is the mental shift. Your customer’s risk register asks what could hurt someone. Yours should be able to answer in the same terms for the interfaces you own.
- Know your interfaces and treat them as the scope boundary. Which systems connect, what data crosses, who has remote access, what your recovery time is for each. That is what will be asked about.
- Be able to report. Your customer has incident and vulnerability reporting obligations to their authority. If the incident starts in your systems and touches theirs, the clock is running on them. Agree the notification path before you need it, not during.
If you also supply defence or space customers, or hold contracts touching several jurisdictions, the mapping problem gets worse rather than better, which is the argument in doing ISO 27001 and NIS2 once instead of twice. Build one control set and map the frameworks onto it.
An independent security audit is the cheapest way to find out how far your current position is from what your customers are about to ask for, before the next questionnaire arrives.
The technical reality: what an interface assessment leaves open
Part-IS, like every management system regulation, asks for a process and an assessment. It does not test whether your controls work.
Your customer’s supplier assessment will ask whether you have access control, logging, vulnerability management and backup. Documented answers to all four satisfy it. The same four answers are compatible with an environment where nobody has queried a log, a critical vulnerability has been open since spring, and no restore has ever been timed.
The gap matters more here than in most sectors, because the thing on the other side of your interface is an organisation whose regulator judges it on safety outcomes. If an integrity failure in your data reaches their operation, the question asked afterwards will not be whether you had a policy. It will be how long the problem was there before anyone noticed.
Which means the useful investment is not a thicker questionnaire response. It is detection and exposure management running continuously on the systems that touch your customer’s, with findings that carry an owner and a deadline, and evidence that accumulates as it happens rather than being assembled the week the audit is announced. That argument in full is in evidence that assembles itself.