<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Madeline Salles, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/madeline-salles/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/author/madeline-salles/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 23 Apr 2026 16:20:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Madeline Salles, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/author/madeline-salles/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Part-IS in 2026: from regulatory framework to operational reality</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/04/part-is-in-2026-from-regulatory-framework-to-operational-reality/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/04/part-is-in-2026-from-regulatory-framework-to-operational-reality/#respond</comments>
		
		<dc:creator><![CDATA[Madeline Salles]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 16:20:32 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[règlementation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29850</guid>

					<description><![CDATA[<p>Following an initial phase focused on understanding the scope and framework of Part-IS and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic — it has...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/part-is-in-2026-from-regulatory-framework-to-operational-reality/">Part-IS in 2026: from regulatory framework to operational reality</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="none">Following an initial phase focused </span><a href="https://www.riskinsight-wavestone.com/en/2025/01/part-is-a-pillar-of-cybersecurity-in-european-aviation/"><span data-contrast="none">on understanding the scope and framework of Part-IS</span></a><span data-contrast="none"> and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic — it has become a matter of operational deployment, with clear expectations from authorities and regulatory adjustments designed to facilitate its implementation.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<h1>Where does the sector stand? </h1>
<p><img fetchpriority="high" decoding="async" class="size-full wp-image-29842 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/friseEN.png" alt="" width="1280" height="324" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/friseEN.png 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/friseEN-437x111.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/friseEN-71x18.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/friseEN-768x194.png 768w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p><span data-contrast="none">The rise of Part-IS has been gradual. After the progressive entry into force of the texts in 2022 and 2023, 2025 was marked by the preparation of compliance files and the structuring of ISMS</span><span data-contrast="none">.</span></p>
<p><span data-contrast="none">Since 22 February 2026, the implementing regulation has been fully applicable, meaning that new scopes are now covered — in particular, maintenance and repair activities through Part-145. </span><span data-contrast="none">Part-IS now applies across the entire operational chain, from design through to operations and support.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">Today, the organisations concerned by Part-IS have acknowledged the subject and submitted their ISMS. In this context of broad engagement, EASA has on its side adjusted the framework by clarifying and easing certain modalities through the update of the Part-IS AMC and GM.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">EASA provides for an 18-month development phase after the applicability date to reach a fully operational implementation. This progression can be read simply in three steps: a system that is first present and suitable (</span><i><span data-contrast="none">P+S</span></i><span data-contrast="none">), then operational (</span><i><span data-contrast="none">O</span></i><span data-contrast="none">), before reaching effective long-term functioning (</span><i><span data-contrast="none">E</span></i><span data-contrast="none">).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"><img decoding="async" class=" wp-image-29838 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN.png" alt="" width="736" height="438" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN.png 955w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN-321x191.png 321w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/LigneEN-768x457.png 768w" sizes="(max-width: 736px) 100vw, 736px" /></span></p>
<h1>The EASA updates: what changes in practice? </h1>
<p><span data-contrast="none">In late 2025, EASA updated the AMC and GM relating to Part-IS and consolidated these changes in a new version of the associated Easy Access Rules.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:180,&quot;335559739&quot;:180,&quot;335559740&quot;:240,&quot;335559991&quot;:180}"> </span></p>
<p><span data-contrast="none">In concrete terms, these changes introduce several significant easements:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:180,&quot;335559739&quot;:180,&quot;335559740&quot;:240,&quot;335559991&quot;:180}"> </span></p>
<ul>
<li><span data-contrast="none">Declared organisations no longer need prior approval of their ISMS.</span>
<ul>
<li>As a reminder, approved organisations are subject to a formal approval process by the authority (EASA or national authority). They must obtain approval, have their ISMS manual approved, and submit certain modifications for prior validation — unlike declared organisations, which are supervised ex post by the authority. The list of declared organisations subject to Part-IS can be found <a style="font-size: revert;" href="https://www.easa.europa.eu/en/faq/142354"><span data-contrast="none">here</span></a><span style="font-size: revert; color: initial;" data-contrast="none">.</span><span style="font-size: revert; color: initial;" data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:720,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></li>
</ul>
</li>
<li><span data-contrast="none">ISMS modifications, when covered by a defined internal procedure, no longer require formal sign-off from the authority: a notification is sufficient.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></li>
<li><span data-contrast="none">The role of the authority is refocused on supervision and audit, rather than on a systematic approval logic.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><img decoding="async" class="size-full wp-image-29834 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/TableEN.png" alt="" width="1280" height="548" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/TableEN.png 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/TableEN-437x187.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/TableEN-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/TableEN-768x329.png 768w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p><span data-contrast="none">However, expectations remain the same: the ISMS (SGSI in the regulatory sense) must be robust, consistent, traceable, and genuinely applied. The relief brought by the AMC and GM update is therefore administrative, not operational.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">On the ground, this resonates with the first OSAC feedback on ISMS: governance around the ISMS appears as a central point. Authorities are paying increased attention to the cybersecurity dimension that identified actors must demonstrate. Document quality is also scrutinised — not only in substance, but also in form (structure, consistency…).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<h1>The five key challenges for scaling Part-IS across the sector </h1>
<p><img loading="lazy" decoding="async" class="size-full wp-image-29846 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/5EN.png" alt="" width="1280" height="446" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/5EN.png 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/5EN-437x152.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/5EN-71x25.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/5EN-768x268.png 768w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></p>
<p><span data-contrast="none">Beyond these initial observations, we have seen during our support engagements that the implementation of Part-IS brings five recurring challenges for most organisations: governance &amp; coordination, inventory validation, completion of risk analyses, training of managers and teams, HR constraints and personnel controls.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">The most time-consuming, however, remains the risk analysis — particularly for large multi-site organisations. This can no longer be purely centralised; it must be broken down locally, integrating the realities of each site, functional chains, and subcontractors. This holistic approach is demanding, but essential to demonstrate consistent application of Part-IS.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<h1>A pragmatic approach to scaling up </h1>
<p><span data-contrast="none">Faced with these challenges, the key lies in anticipating deployment. An effective ISMS relies on a solid common foundation, but also on concrete tools enabling local adaptation: templates, guides, risk analysis methods tailored to operational realities.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">The success of Part-IS depends on coordination between cybersecurity teams, business teams, and quality and compliance functions. Part-IS is not an additional layer: it is a cross-cutting framework that durably structures cyber risk management in the service of aviation safety.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<h1>Conclusion </h1>
<p><span data-contrast="none">In 2026, Part-IS enters its implementation phase. The consolidation of the AMC/GM sets a clear baseline and reduces the administrative burden compared to the first version.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="none">In addition, the late-2025 updates notably extended the scope of Part-IS.D.OR to ground handling service providers via Delegated Regulation (EU) 2025/22 amending (EU) 2022/1645, applicable from 27 March 2031. No immediate operational impact in 2026, but a useful signal to anticipate interface mapping — with no short-term urgency.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/part-is-in-2026-from-regulatory-framework-to-operational-reality/">Part-IS in 2026: from regulatory framework to operational reality</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/04/part-is-in-2026-from-regulatory-framework-to-operational-reality/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
