{"id":29850,"date":"2026-04-23T17:20:32","date_gmt":"2026-04-23T16:20:32","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=29850"},"modified":"2026-04-23T17:20:34","modified_gmt":"2026-04-23T16:20:34","slug":"part-is-in-2026-from-regulatory-framework-to-operational-reality","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/","title":{"rendered":"Part-IS in 2026: from regulatory framework to operational reality"},"content":{"rendered":"\n<p><span data-contrast=\"none\">Following\u00a0an initial\u00a0phase focused\u00a0<\/span><a href=\"https:\/\/www.riskinsight-wavestone.com\/2025\/01\/part-is-un-pilier-de-la-cybersecurite-dans-laviation-europeenne\/\"><span data-contrast=\"none\">on understanding the scope and framework of Part-IS<\/span><\/a><span data-contrast=\"none\">\u00a0and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic \u2014 it has become a matter of operational deployment, with clear expectations from authorities and regulatory adjustments designed to\u00a0facilitate\u00a0its implementation.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>Where does the sector stand?\u00a0<\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-29842 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/friseEN.png\" alt=\"\" width=\"1280\" height=\"324\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/friseEN.png 1280w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/friseEN-437x111.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/friseEN-71x18.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/friseEN-768x194.png 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p><span data-contrast=\"none\">The rise of Part-IS has been gradual. After the progressive entry into force of the texts in 2022 and 2023, 2025 was marked by the preparation of compliance files and the structuring of ISMS<\/span><span data-contrast=\"none\">.<\/span><\/p>\n<p><span data-contrast=\"none\">Since 22 February 2026, the implementing regulation has been fully applicable, meaning that new scopes are now covered \u2014 in particular, maintenance and repair activities through Part-145.\u00a0<\/span><span data-contrast=\"none\">Part-IS now applies across the entire operational chain, from design through to operations and support.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Today, the\u00a0organisations\u00a0concerned by Part-IS have acknowledged the subject and\u00a0submitted\u00a0their ISMS. In this context of broad engagement, EASA has on its side adjusted the framework by clarifying and easing certain modalities through the update of the Part-IS AMC and GM.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">EASA\u00a0provides for\u00a0an 18-month development phase after the applicability date to reach a fully operational implementation. This progression can be read simply in three steps: a system that is first present and suitable (<\/span><i><span data-contrast=\"none\">P+S<\/span><\/i><span data-contrast=\"none\">), then operational (<\/span><i><span data-contrast=\"none\">O<\/span><\/i><span data-contrast=\"none\">), before reaching effective long-term functioning (<\/span><i><span data-contrast=\"none\">E<\/span><\/i><span data-contrast=\"none\">).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-29838 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN.png\" alt=\"\" width=\"736\" height=\"438\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN.png 955w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN-321x191.png 321w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN-66x39.png 66w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN-120x70.png 120w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/LigneEN-768x457.png 768w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/span><\/p>\n<h1>The EASA\u00a0updates:\u00a0what\u00a0changes in\u00a0practice?\u00a0<\/h1>\n<p><span data-contrast=\"none\">In late 2025, EASA updated the AMC and GM relating to Part-IS and\u00a0consolidated\u00a0these changes in\u00a0a new version\u00a0of the associated Easy Access Rules.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559685&quot;:180,&quot;335559739&quot;:180,&quot;335559740&quot;:240,&quot;335559991&quot;:180}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">In\u00a0concrete\u00a0terms,\u00a0these\u00a0changes\u00a0introduce\u00a0several\u00a0significant\u00a0easements:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559685&quot;:180,&quot;335559739&quot;:180,&quot;335559740&quot;:240,&quot;335559991&quot;:180}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"none\">Declared\u00a0organisations\u00a0no longer need prior approval of their ISMS.<\/span>\n<ul>\n<li>As a reminder, approved organisations are subject to a formal approval process by the authority (EASA or national authority). They must obtain approval, have their ISMS manual approved, and submit certain modifications for prior validation \u2014 unlike declared organisations, which are supervised ex post by the authority. The list of declared organisations subject to Part-IS can be found <a style=\"font-size: revert;\" href=\"https:\/\/www.easa.europa.eu\/en\/faq\/142354\"><span data-contrast=\"none\">here<\/span><\/a><span style=\"font-size: revert; color: initial;\" data-contrast=\"none\">.<\/span><span style=\"font-size: revert; color: initial;\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559685&quot;:720,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span data-contrast=\"none\">ISMS modifications, when covered by a defined internal procedure, no longer require formal sign-off from the authority: a notification is sufficient.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\">The role of the authority is refocused on supervision and audit, rather than on a systematic approval logic.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-29834 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/TableEN.png\" alt=\"\" width=\"1280\" height=\"548\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/TableEN.png 1280w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/TableEN-437x187.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/TableEN-71x30.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/TableEN-768x329.png 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p><span data-contrast=\"none\">However, expectations\u00a0remain\u00a0the same: the ISMS (SGSI in the regulatory sense) must be robust, consistent, traceable, and genuinely applied. The relief brought by the AMC and GM update is therefore administrative, not operational.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">On the ground, this resonates with the first OSAC feedback on ISMS:\u00a0governance around the ISMS appears as\u00a0a central point. Authorities are paying increased attention to the cybersecurity dimension that\u00a0identified\u00a0actors must\u00a0demonstrate. Document quality is also\u00a0scrutinised\u00a0\u2014 not only in substance, but also in form (structure, consistency\u2026).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>The five key challenges for scaling Part-IS across the sector\u00a0<\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-29846 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/5EN.png\" alt=\"\" width=\"1280\" height=\"446\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/5EN.png 1280w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/5EN-437x152.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/5EN-71x25.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2026\/04\/5EN-768x268.png 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p><span data-contrast=\"none\">Beyond these initial observations, we have seen during our support engagements that the implementation of Part-IS brings five recurring challenges for most organisations: governance &amp; coordination, inventory validation, completion of risk analyses, training of managers and teams, HR constraints and personnel controls.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The most time-consuming, however, remains the risk analysis \u2014 particularly for large multi-site organisations. This can no longer be purely centralised; it must be broken down locally, integrating the realities of each site, functional chains, and subcontractors. This holistic approach is demanding, but essential to demonstrate consistent application of Part-IS.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>A pragmatic approach to scaling up\u00a0<\/h1>\n<p><span data-contrast=\"none\">Faced with these challenges, the key lies in\u00a0anticipating\u00a0deployment. An effective ISMS relies on a solid common foundation, but also on concrete tools enabling local adaptation: templates, guides, risk analysis methods tailored to operational realities.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The success of Part-IS depends on coordination between cybersecurity teams, business teams, and quality and compliance functions. Part-IS is not an\u00a0additional\u00a0layer: it is a cross-cutting framework that durably structures cyber risk management in the service of aviation safety.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>Conclusion\u00a0<\/h1>\n<p><span data-contrast=\"none\">In 2026, Part-IS enters its implementation phase. The consolidation of the AMC\/GM sets a clear baseline and reduces the administrative burden compared to the first version.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">In addition, the late-2025 updates notably extended the scope of Part-IS.D.OR\u00a0to ground handling service providers via Delegated Regulation (EU) 2025\/22 amending (EU) 2022\/1645, applicable from 27 March 2031. No immediate operational impact in 2026, but a useful signal to\u00a0anticipate\u00a0interface mapping \u2014 with no short-term urgency.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following\u00a0an initial\u00a0phase focused\u00a0on understanding the scope and framework of Part-IS\u00a0and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic \u2014 it has&#8230;<\/p>\n","protected":false},"author":1499,"featured_media":25646,"comment_status":"open","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2777,3922,3274],"tags":[3034],"coauthors":[4410],"class_list":["post-29850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-digital-trust","category-deep-dive-en","category-manufacturing-industry-4-0-en","tag-reglementation-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Part-IS in 2026: from regulatory framework to operational reality - RiskInsight<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Part-IS in 2026: from regulatory framework to operational reality - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"Following\u00a0an initial\u00a0phase focused\u00a0on understanding the scope and framework of Part-IS\u00a0and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic \u2014 it has...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-23T16:20:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-23T16:20:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1670\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Madeline Salles\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Madeline Salles\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\"},\"author\":{\"name\":\"Madeline Salles\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8ff9185abd0574dc00c0e378146212b8\"},\"headline\":\"Part-IS in 2026: from regulatory framework to operational reality\",\"datePublished\":\"2026-04-23T16:20:32+00:00\",\"dateModified\":\"2026-04-23T16:20:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\"},\"wordCount\":718,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg\",\"keywords\":[\"r\u00e8glementation\"],\"articleSection\":[\"Cybersecurity &amp; Digital Trust\",\"Deep-dive\",\"Manufacturing &amp; Industry 4.0\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\",\"name\":\"Part-IS in 2026: from regulatory framework to operational reality - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg\",\"datePublished\":\"2026-04-23T16:20:32+00:00\",\"dateModified\":\"2026-04-23T16:20:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg\",\"width\":2560,\"height\":1670},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Part-IS in 2026: from regulatory framework to operational reality\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8ff9185abd0574dc00c0e378146212b8\",\"name\":\"Madeline Salles\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/madeline-salles\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Part-IS in 2026: from regulatory framework to operational reality - RiskInsight","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/","og_locale":"en_US","og_type":"article","og_title":"Part-IS in 2026: from regulatory framework to operational reality - RiskInsight","og_description":"Following\u00a0an initial\u00a0phase focused\u00a0on understanding the scope and framework of Part-IS\u00a0and on drafting Information Security Management Systems (ISMS), the aviation sector has entered a new phase. In 2026, Part-IS is no longer a theoretical or purely documentary topic \u2014 it has...","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/","og_site_name":"RiskInsight","article_published_time":"2026-04-23T16:20:32+00:00","article_modified_time":"2026-04-23T16:20:34+00:00","og_image":[{"width":2560,"height":1670,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg","type":"image\/jpeg"}],"author":"Madeline Salles","twitter_misc":{"Written by":"Madeline Salles","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/"},"author":{"name":"Madeline Salles","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8ff9185abd0574dc00c0e378146212b8"},"headline":"Part-IS in 2026: from regulatory framework to operational reality","datePublished":"2026-04-23T16:20:32+00:00","dateModified":"2026-04-23T16:20:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/"},"wordCount":718,"commentCount":0,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg","keywords":["r\u00e8glementation"],"articleSection":["Cybersecurity &amp; Digital Trust","Deep-dive","Manufacturing &amp; Industry 4.0"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/","name":"Part-IS in 2026: from regulatory framework to operational reality - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg","datePublished":"2026-04-23T16:20:32+00:00","dateModified":"2026-04-23T16:20:34+00:00","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/03\/nis2-scaled.jpg","width":2560,"height":1670},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2026\/04\/part-is-in-2026-from-regulatory-framework-to-operational-reality\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"Part-IS in 2026: from regulatory framework to operational reality"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/8ff9185abd0574dc00c0e378146212b8","name":"Madeline Salles","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/madeline-salles\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/29850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1499"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=29850"}],"version-history":[{"count":2,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/29850\/revisions"}],"predecessor-version":[{"id":29852,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/29850\/revisions\/29852"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/25646"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=29850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=29850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=29850"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=29850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}