European Sovereignty Monitor

Policy and law

EU aviation cybersecurity rule Part-IS becomes binding across airlines

Commission Implementing Regulation (EU) 2023/203, EASA's Part-IS, became applicable across the EU to airlines, maintenance organisations, training bodies and air navigation providers, requiring a formal information security management system for aviation safety risks.

Verified EUR-Lex, Commission Implementing Regulation (EU) 2023/203, consolidated text applicable from 22 February 2026

What it does not test. Does not certify that any individual organisation has actually met the new requirement.

How this item counts. Towards autonomy: it changes whose law governs. Binding 3 of 3 (in force or operating), scale 3 of 3 (large), Verified counts in full: weight +9 of 36 possible. EU cybersecurity rule now in force EU-wide across airlines and ANSPs. European Sovereignty Index

Previously in Policy and law

Verified ANSSI leads G7 call for urgent shift to post-quantum cryptography Reported EU Commission sends AI Act information requests to over 30 companies Reported EU antitrust officials seek information on Oracle's cloud licensing practices

All Policy and law news →