What Part-IS requires
Maor Compliance helps airlines build, implement and demonstrate an ISMS that stands up to regulatory scrutiny.
Present
Security policies, ISMS documented, cyber security accountability assigned.
Suitable
Risk assessment criteria match the scale of your operation.
Operating
Actively in use and fully deployed across daily operations.
Effective
Tracks metrics and benchmarks performance against the maturity model.
A dual-scope approach: one ISMS built to satisfy your national aviation authority and an ISO 27001 certification body at the same time. Maor bring the information security engineering; we bring the aviation context - how it interlinks with your SMS, compliance monitoring and exposition.
- Part-IS gap analysis
- Part-IS implementation
- ISO 27001 certification support
- ISO 27701 privacy management
- Security risk assessments
- Policy & procedure development
- Internal auditing
- Executive awareness training
Across the regulated
aviation population
The obligations differ by approval. The problem is the same one: proving the system works, not just that it exists.
| Sector | Approval | Part-IS from |
|---|---|---|
| Airlines & operators | AOC / Part-ORO | 22 Feb 2026 |
| Maintenance organisations | Part-145 / AMO | 22 Feb 2026 |
| Continuing airworthiness | Part-CAMO | 22 Feb 2026 |
| Training organisations | Part-ORA / FSTD | 22 Feb 2026 |
| Business aviation | Commercial & private | 22 Feb 2026 |
| Design & production | Part-21 DOA / POA | 16 Oct 2025 |
| Airports & ground handling | Aerodrome / apron | 16 Oct 2025 |
| Lessors & investors | - | Due diligence |
Air navigation service providers fall under either regulation depending on the service. Aviation technology suppliers are increasingly caught through their customers' contracts.
Questions we get asked
What is EASA Part-IS, and who must comply?
Part-IS is the EASA framework mandating cyber security controls to safeguard flight safety - digital vulnerabilities are treated as critical airworthiness risks. It became applicable on 16 October 2025 for aerodrome operators and design and production organisations, and on 22 February 2026 for airlines, Part-145 maintenance organisations, CAMOs and approved training organisations.
We already have an IT security provider. Why do we need you?
Standard IT providers understand data security but not flight safety. A generic checklist doesn't account for continuing airworthiness management systems, flight planning tools or EASA reporting requirements. Our partnership with Maor Compliance merges EASA and IOSA auditing background with information security engineering, so the controls protect the operation rather than just the network.
How does ISO 27001 tie into Part-IS?
Part-IS requires you to build an ISMS. ISO 27001 is the leading international standard for exactly that, so aligning the two gives you a globally recognised framework for work you have to do anyway. We use a dual-scope approach to build one ISMS that satisfies both your national aviation authority and an ISO 27001 certification body.
Can we outsource Part-IS implementation and compliance monitoring?
Yes. Under EASA guidelines these functions can be contracted to external specialists. Ultimate accountability remains with your Accountable Manager, but the joint Dalton Aero and Maor team can handle the gap analysis, design the security manual, manage risk assessments and conduct the internal audits.
What happens if we fail a Part-IS audit?
Non-compliance can affect your operational approvals. Your authority may issue formal findings, mandate corrective actions, or restrict approvals where a system lacks active risk management, monitoring or staff training. The work is in producing audit-ready evidence before the inspection, not after it.
How long does compliance take?
Typically three to nine months, depending on your existing IT infrastructure and the size of the organisation - a small CAMO moves faster than a large maintenance group. Aviation-specific risk templates and delivery frameworks shorten it considerably.
Where do you stand
on Part-IS?
Tell us your approval type and what you already have in place. We will tell you honestly what is missing and what a sensible first step looks like.
- Telephone
- +353 85 714 3791
- anna@daltonaero.com
- Head office
- Dalton Aero Limited
Old Quay Terrace, Sutton Strand
Sutton, Dublin 13, D13 TX43
- Registered
- Ireland, No. 647505
- Coverage
- Ireland, UK, EU and beyond. On site or remote.