Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 laying down rules for the application of Regulation (EU) 2018/1139 of the European Parliament and of the Council, as regards requirements for the management of information security risks with a potential impact on aviation safety for organisations covered by Commission Regulations (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU) 2015/340, Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664, and for competent authorities covered by Commission Regulations (EU) No 748/2012, (EU) No 1321/2014, (EU) No 965/2012, (EU) No 1178/2011, (EU) 2015/340 and (EU) No 139/2014, Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664 and amending Commission Regulations (EU) No 1178/2011, (EU) No 748/2012, (EU) No 965/2012, (EU) No 139/2014, (EU) No 1321/2014, (EU) 2015/340, and Commission Implementing Regulations (EU) 2017/373 and (EU) 2021/664

Type Implementing Regulation
Publication 2022-10-27
Last updated 2026-02-22
State In force
Department European Commission, MOVE
Source EUR-Lex
articles 16
Reform history JSON API

(3) Annex Vc (Part-CAMO) is amended as follows: (a) the Table of Contents is amended as follows: (i) the following heading is inserted after heading CAMO.A.200: ‘CAMO.A.200AInformation security management system’; (ii) the following heading is inserted after heading CAMO.B.135: ‘CAMO.B.135AImmediate reaction to an information security incident or vulnerability with an impact on aviation safety’; (iii) the heading of point CAMO.B.205 is replaced by the following: ‘CAMO.B.205Allocation of tasks’; (iv) the following heading is inserted after heading CAMO.B.330: ‘CAMO.B.330AChanges to the information security management system’; (b) the following point CAMO.A.200A is inserted after point CAMO.A.200: Information security management system In addition to the management system referred to in point CAMO.A.200, the organisation shall establish, implement and maintain an information security management system in accordance with Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’; (c) in point CAMO.B.125, the following point (c) is added: ‘(c) The competent authority of the Member State shall provide the Agency as soon as possible with safety-significant information stemming from the information security reports it has received pursuant to point IS.I.OR.230 of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203.’; (d) the following point CAMO.B.135A is inserted after CAMO.B.135: Immediate reaction to an information security incident or vulnerability with an impact on aviation safety (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point CAMO.B.125(c), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to Regulation (EU) 2018/1139 and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned.’; (e) in point CAMO.B.200, the following point (e) is added: ‘(e) In addition to the requirements contained in point (a), the management system established and maintained by the competent authority shall comply with Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’; (f) point CAMO.B.205 is amended as follows: (i) the heading is replaced by the following: Allocation of tasks’; (ii) the following point (c) is added: ‘(c) With regard to the certification and oversight of the organisation’s compliance with point CAMO.A.200A, the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point CAMO.B.200(e) covers all the certification and continuing oversight tasks performed on its behalf.’; (g) in point CAMO.B.300, the following point (g) is added: ‘(g) With regard to the certification and oversight of the organisation’s compliance with point CAMO.A.200A, in addition to complying with points (a) to (f), the competent authority shall review any approval granted under point IS.I.OR.200(e) of this Regulation or point IS.D.OR.200(e) of Delegated Regulation (EU) 2022/1645 following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.’ (h) the following point CAMO.B.330A is inserted after point CAMO.B.330: Changes to the information security management system (a) For changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203, the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point CAMO.B.300. If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point CAMO.B.350. (b) For other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203: (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change.’.

ANNEX VIII

Annexes II (Part ATCO.AR) and III (Part ATCO.OR) to Regulation (EU) 2015/340 are amended as follows:

(1) Annex II (Part ATCO.AR) is amended as follows: (a) in point ATCO.AR.A.020, the following point (c) is added: ‘(c) The competent authority of the Member State shall provide the Agency as soon as possible with safety-significant information stemming from the information security reports it has received pursuant to point IS.I.OR.230 of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203.’; (b) the following point ATCO.AR.A.025A is inserted after point ATCO.AR.A.025: Immediate reaction to an information security incident or vulnerability with an impact on aviation safety (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point ATCO.AR.A.020, and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to Regulation (EU) 2018/1139 and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned.’; (c) in point ATCO.AR.B.001, the following point (e) is added: ‘(e) In addition to the requirements contained in point (a), the management system established and maintained by the competent authority shall comply with Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’; (d) point ATCO.AR.B.005 is amended as follows: (i) the heading is replaced by the following: Allocation of tasks’; (ii) the following point (c) is added: ‘(c) With regard to the certification and oversight of the organisation’s compliance with point ATCO.OR.C.001A, the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point ATCO.AR.B.001(e) covers all the certification and continuing oversight tasks performed on its behalf.’; (e) in point ATCO.AR.C.001, the following point (f) is added: ‘(f) With regard to the certification and oversight of the organisation’s compliance with point ATCO.OR.C.001A, in addition to complying with points (a) to (e), the competent authority shall review any approval granted under point IS.I.OR.200(e) of this Regulation or point IS.D.OR.200(e) of Delegated Regulation (EU) 2022/1645 following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.’ (f) the following point ATCO.AR.E.010A is inserted after point ATCO.AR.E.010: Changes to the information security management system (a) With regard to changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203, the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point ATCO.AR.C.001. If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point ATCO.AR.C.010. (b) With regard to other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203: (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change.’;

(2) Annex III (Part ATCO.OR) is amended as follows: The following point ATCO.OR.C.001A is inserted after point ATCO.OR.C.001: Information security management system In addition to the management system referred to in point ATCO.OR.C.001, the training organisation shall establish, implement and maintain an information security management system in accordance with Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’.

ANNEX IX

Annexes II (Part-ATM/ANS.AR) and III (Part-ATM/ANS.OR) to Implementing Regulation (EU) 2017/373 are amended as follows:

(1) Annex II (Part-ATM/ANS.AR) is amended as follows: (a) in point ATM/ANS.AR.A.020, the following point (c) is added: ‘(c) The competent authority of the Member State shall provide the Agency as soon as possible with safety-significant information stemming from the information security reports it has received pursuant to point IS.I.OR.230 of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203.’; (b) the following point ATM/ANS.AR.A.025A is inserted after point ATM/ANS.AR.A.025: ‘ ATM/ANS.AR.A.025A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point ATM/ANS.AR.A.020(c), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to Regulation (EU) 2018/1139 and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under Regulation (EU) 2018/1139 and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned.’; (c) in point ATM/ANS.AR.B.001, the following point (e) is added: ‘(e) In addition to the requirements contained in point (a), the management system established and maintained by the competent authority shall comply with Annex I (Part-IS.AR) of Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’; (d) point ATM/ANS.AR.B.005 is amended as follows: (i) the heading is replaced by the following: ‘ ATM/ANS.AR.B.005 Allocation of tasks ’; (ii) The following point (c) is added: ‘(c) With regard to the certification and oversight of the organisation’s compliance with point ATM/ANS.OR.B.005A, the competent authority may allocate tasks to qualified entities in accordance with point (a), or to any relevant authority responsible for information security or cybersecurity within the Member State. When allocating tasks, the competent authority shall ensure that: (1) all aspects related to aviation safety are coordinated and taken into account by the qualified entity or relevant authority; (2) the results of the certification and oversight activities performed by the qualified entity or relevant authority are integrated in the overall certification and oversight files of the organisation; (3) its own information security management system established in accordance with point ATM/ANS.AR.B.001(e) covers all the certification and continuing oversight tasks performed on its behalf.’; (e) in point ATM/ANS.AR.C.010, the following point (d) is added: ‘(d) With regard to the certification and oversight of the organisation’s compliance with point ATM/ANS.OR.B.005A, in addition to complying with points (a) to (c), the competent authority shall review any approval granted under point IS.I.OR.200(e) of this Regulation or point IS.D.OR.200(e) of Delegated Regulation (EU) 2022/1645 following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.’ (f) the following point ATM/ANS.AR.C.025A is inserted after point ATM/ANS.AR.C.025: ‘ ATM/ANS.AR.C.025A Changes to the information security management system (a) For changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203, the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point ATM/ANS.AR.C.010. If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point ATM/ANS.AR.C.050. (b) With regard to other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203: (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change.’;

(2) Annex III (Part-ATM/ANS.OR) is amended as follows: (a) the following point ATM/ANS.OR.B.005A is inserted after point ATM/ANS.OR.B.005: ‘ ATM/ANS.OR.B.005A Information security management system In addition to the management system referred to in point ATM/ANS.OR.B.005, the service provider shall establish, implement and maintain an information security management system in accordance with Implementing Regulation (EU) 2023/203 in order to ensure the proper management of information security risks which may have an impact on aviation safety.’; (b) point ATM/ANS.OR.D.010 is replaced by the following: ‘ ATM/ANS.OR.D.010 Security management (a) Air navigation services and air traffic flow management providers and the Network Manager shall, as an integral part of their management system as required in point ATM/ANS.OR.B.005, establish a security management system to ensure: (1) the security of their facilities and personnel so as to prevent unlawful interference with the provision of services; (2) the security of operational data they receive, or produce, or otherwise employ, so that access to it is restricted only to those authorised. (b) The security management system shall define: (1) the process and procedures relating to security risk assessment and mitigation, security monitoring and improvement, security reviews and lesson dissemination; (2) the means designed to identify, monitor and detect security breaches and to alert personnel with appropriate security warnings; (3) the means to control the effects of security breaches and to identify recovery action and mitigation procedures to prevent re-occurrence. (c) Air navigation services and air traffic flow management providers and the Network Manager shall ensure the security clearance of their personnel, if appropriate, and coordinate with the relevant civil and military authorities to ensure the security of their facilities, personnel and data. (d) The aspects related to information security shall be managed in accordance with point ATM/ANS.OR.B.005A.’.

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.