ISMS Copilot
EASA Part-IS

EASA Part-IS Copilot

Specialist AI assistant for EASA Part-IS aviation information security compliance

Part-IS obligations are in force: since 16 October 2025 for design, production, and aerodrome organisations, since 22 February 2026 for maintenance, CAMO, and air operations organisations. Map your gap now.

What the EASA Part-IS Copilot Can Do

Part-IS scope assessment across your approvals, declarations, and organisational interfaces

Information security risk assessment drafts centred on aviation safety impact (IS.OR.205)

ISMM drafting and revision support for the information security manual your authority reviews (IS.OR.250)

Information security event detection, response, and internal and external reporting procedures (IS.OR.220 / IS.OR.215 / IS.OR.230)

Subcontracted information security activity requirements (IS.OR.235) and supplier interface risks treated through the risk assessment (IS.OR.205)

Cross-mapping between an existing ISO 27001 ISMS and the Part-IS aviation-specific provisions

About EASA Part-IS Copilot

EASA Part-IS Copilot helps aviation organisations build and evidence the information security management system that EU aviation rules require, from risk assessment and the security manual to incident reporting and supply-chain interfaces.

Delegated Regulation (EU) 2022/1645, since 16 October 2025

  • Covers organisations in the delegated areas: initial airworthiness (design and production approvals) and aerodromes

  • Organisations in its scope have had to comply since 16 October 2025

  • Scope is risk-driven: a documented risk assessment under IS.OR.205 determines which elements are in

Implementing Regulation (EU) 2023/203, from 22 February 2026

  • Carries the requirements for maintenance organisations (Part-145), CAMOs, and air operators under Part-ORO, plus the authority requirements for competent aviation authorities

  • By the applicability date, organisations were expected to have the fundamental ISMS elements at the Present and Suitable levels of the PSOE implementation ladder

  • Compliance is verified by the competent authority identified in the regulation

Cross-framework mappings

Working across EASA Part-IS and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

What is EASA Part-IS?

Part-IS is the information security part of the EU aviation regulatory framework, introduced by Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203. It obliges aviation organisations to identify and manage information security risks that could affect aviation safety, with the scope driven by a documented risk assessment rather than a fixed asset list. The Delegated Regulation has applied to organisations in its scope since 16 October 2025; the Implementing Regulation, which carries the requirements for maintenance, airworthiness management, and air operations organisations plus the authority requirements, applies from 22 February 2026.

Who has to comply with Part-IS?

Covered organisations include maintenance organisations (Part-145), continuing airworthiness management organisations (CAMO), air operators under Part-ORO, design and production organisations, and declared organisations such as NCC and SPO operators and apron management providers; the full category list lives in the scope articles of the two regulations and EASA's applicability FAQs. Exclusions depend on the organisation category and include organisations dealing only with ELA1 or ELA2 aircraft, Part-ML light work, declared training organisations (DTO), and declared design organisations. A third-country airline's AOC itself is out of scope, but the branches it covers under separate EASA certificates, such as Part-145 maintenance or training approvals, are in.

How does the Copilot help with Part-IS?

It turns the Part-IS requirements into working documentation: scope determination across your approvals, risk assessment drafts centred on safety consequences, ISMM structure, change management, incident reporting procedures, and supplier interface treatment. It also organises the evidence path authorities expect on the Present, Suitable, Operational, Effective (PSOE) implementation ladder.

Is my ISO 27001 certification enough for Part-IS?

No. EASA's published FAQ says the Part-IS management-system requirements largely align with ISO/IEC 27001, but Part-IS adds provisions specific to aviation safety, and aviation safety must sit inside your organisational risk management. An existing ISO 27001 ISMS can be adapted and extended to the Part-IS scope after a gap analysis, which is exactly the mapping work this Copilot supports. Compliance with NIS 2 does not automatically satisfy Part-IS either.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.