Skip to main content
Aviatize — Flight School Management Software
Compliance11 min read

EASA Part-IS Is Here for ATOs: What Flight Schools Actually Need to Do

Dominiek De RooJuly 16, 2026

A New Rule That Caught a Lot of Schools Off Guard

Most Approved Training Organisations spent 2025 focused on the training rules they know — syllabi, examiner standardisation, the compliance monitoring function. Comparatively few noticed that a new, cross-cutting obligation was arriving alongside them. As of 22 February 2026, EASA's information-security regulation — universally shortened to Part-IS — applies to ATOs, and it applies whether the school is a large integrated academy or a modest club-based operation with one classroom and three aeroplanes.

Part-IS was introduced by two linked pieces of European law: Delegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203 — and it is the latter, 2023/203, that brings Approved Training Organisations into scope, from 22 February 2026. Its logic is straightforward and, once you see it, hard to argue with. Aviation safety now depends on information systems — scheduling, records, flight data, maintenance tracking, examiner and student data — and an information-security failure in those systems can have safety consequences. Part-IS obliges affected organisations to manage that risk deliberately, the same way they already manage operational and airworthiness risk.

The reason it caught schools off guard is that "cybersecurity" sounds like an IT-department problem, or an airline-scale problem, not something a training organisation needs a formal system for. That framing is wrong, and acting on it is a compliance risk. Part-IS is a safety regulation that happens to be about information, it names ATOs explicitly, and the applicability date has arrived. This is what it requires and how to meet it proportionately.

What Part-IS Actually Requires

At its core, Part-IS requires each affected organisation to establish, implement, and maintain an information-security management system (ISMS) — a structured, documented way of identifying information-security risks that could affect aviation safety, treating them, and keeping the whole thing under review.

If that sounds like an existing management-system discipline applied to a new domain, that is exactly what it is. The requirements are in large part consistent with the widely used ISO/IEC 27001 information-security standard, but Part-IS adds provisions specific to the context of aviation safety — the point is not protecting information for its own sake, but protecting the information and systems whose compromise could put flights, students, or crews at risk.

In practical terms, an ISMS under Part-IS means the organisation has to do a defined set of things and be able to show it: identify the information assets and systems that matter to safety; assess the security risks to them; put proportionate controls in place to reduce those risks; detect and respond to information-security incidents; report certain incidents to the competent authority; and monitor and improve the system over time. It is a cycle — assess, treat, monitor, improve — not a one-off document you write and file. The deliverable is not a policy PDF; it is a living function inside the organisation.

Yes, Your ATO Is In Scope

The single most common misconception is that Part-IS is an airline rule. It is not. From 22 February 2026 it applies across a broad slice of the European aviation system: air carriers, maintenance organisations, continuing-airworthiness management organisations, Approved Training Organisations, aeromedical centres, operators of flight-simulation training devices, air-traffic-controller training organisations, air navigation service providers, and the oversight authorities themselves.

ATOs are on that list by name. If your school holds an ATO approval under the EASA framework, Part-IS applies to you. It does not matter that you are small, that you do not think of yourself as running critical infrastructure, or that your "IT" is a scheduling platform and a shared drive. The obligation is triggered by your approval status, not by your size or your self-image.

There is an important distinction worth drawing for schools that operate declared training under a lighter regime rather than a full ATO approval — the precise scope of who is caught turns on your specific approval, and your national competent authority is the definitive source for your situation. But for any organisation holding a full ATO approval, the answer is unambiguous: you are in scope, and the date has passed. If you have not started, the right move is to start now and demonstrate genuine, good-faith progress rather than to assume the rule is for someone else.

It Bolts Onto Your Management System, Not Beside It

The good news — and the key to doing this without creating a parallel bureaucracy — is that Part-IS is designed to integrate with the management system your ATO already runs. You are not being asked to build a second, standalone organisation. You are being asked to extend the management-system disciplines you already have into the information-security domain.

Your ATO already operates a compliance monitoring function under the organisation requirements, with a nominated postholder responsible for it. You very likely already run, or are building, a safety management system — the systematic, organisation-wide approach to identifying and managing safety risk through policy, risk assessment, assurance, and promotion. Part-IS's information-security risk management is meant to sit inside that same management-system architecture: the same governance, the same risk-assessment habits, the same monitoring-and-improvement loop, now covering information-security risk alongside operational and airworthiness risk.

That integration is not just administratively convenient; it is the intended design. An ISMS that lives off to the side, owned by an outside IT contractor and disconnected from the accountable manager and the safety function, is both harder to maintain and weaker in practice. The organisations that will find Part-IS least painful are the ones with a mature, genuinely functioning management system already — because for them, Part-IS is a new input into an existing machine rather than a machine they have to build from scratch.

The Concrete Deliverables: Risk, Incidents, Reporting

Stripped to its working parts, Part-IS asks an ATO to be able to demonstrate four things.

An information-security risk assessment. You identify the systems and information that matter to safety — the scheduling and operational platform, training and licensing records, examiner data, maintenance tracking, anything whose loss, corruption, or unauthorised change could affect safe training operations — and you assess the threats to them and how bad the consequences would be. This is the foundation everything else rests on.

Proportionate controls. For the risks that matter, you put reasonable measures in place: access control so only the right people reach sensitive systems and data, backups and recovery so a failure or attack does not erase your records, sensible account and password practices, and vendor due diligence on the systems you depend on. "Proportionate" is the operative word — more on that below.

Incident detection and response. You have a way to notice when something has gone wrong — a breach, a data loss, a compromised account — and a defined way to respond, contain it, and recover.

Reporting. Certain information-security occurrences have to be reported to your competent authority, in the same spirit as the mandatory occurrence reporting your organisation already does for safety events. Part-IS extends the reporting reflex your ATO already has into the information-security domain. Knowing in advance what triggers a report — and having the process ready — is part of being compliant, not something to improvise during an actual incident.

Proportionality: A Three-Aircraft ATO Is Not an Airline

The fear that Part-IS means airline-scale cybersecurity spending for a small training organisation is understandable, and it is misplaced. Part-IS explicitly requires an ISMS proportionate to the organisation's size, nature, and complexity, and to the risks inherent in its activities. A small ATO is expected to have a small, sensible ISMS — not a security operations centre.

In practice this means a modest school's obligations are real but bounded. The risk assessment is smaller because there are fewer systems. The controls are the sensible baseline any well-run organisation should have anyway — controlled access, reliable backups, decent account hygiene, awareness among staff, and knowing which outside services hold your data and whether they are trustworthy. The documentation is proportionate to the operation. What Part-IS does not tolerate is the absence of the discipline altogether: having simply never thought about information-security risk, having no backups, having no idea who can access student and examiner data, and having no plan for a breach.

The honest reading is that Part-IS formalises what a competently run school should already be doing, and asks it to be documented and reviewed rather than left to chance. For an organisation that has been casual about information security, that is real work. For one that already takes it seriously, Part-IS is mostly about writing down and systematising the good practice that is already there.

What 'Ready' Means — and a Practical Path There

EASA and national authorities recognise that building an ISMS is a journey, not a switch you flip. The maturity framework often referenced is PSOE — Present, Suitable, Operational, Effective. The expectation around the applicability date is that organisations can demonstrate at least the earlier stages: that the ISMS is present and suitable for the organisation, with operation and demonstrated effectiveness following as it beds in. In other words, you are expected to have genuinely started and to have a sound system in place — not to have years of proven track record on day one.

A practical path for an ATO that is behind: first, formally assign ownership — the accountable manager owns Part-IS, integrated with the existing management system, not delegated away to an unaccountable contractor. Second, inventory the information and systems that matter to safe operations and run a first risk assessment. Third, close the obvious gaps — backups, access control, incident response basics. Fourth, document the ISMS proportionately and fold its monitoring into your existing compliance-monitoring and safety-review cycle. Fifth, talk to your competent authority; they are administering this across many small organisations and would far rather see credible progress than silence.

One overlooked piece of the risk assessment is the operational software the school runs on. Your scheduling, records, and billing platform holds exactly the safety-relevant data Part-IS is concerned with, so the security posture of that system — how it controls access, protects data, and handles authentication — is legitimately part of your information-security scope. It is fair to expect your platform vendor to take security seriously and to be able to answer for how they protect your data; at Aviatize, that backend security discipline is built into the product rather than bolted on. Choosing operational systems you can actually stand behind in a risk assessment is one of the quieter ways to make Part-IS compliance easier on yourself.

Part-IS is not the end of the world, and it is not just for airlines. It is a proportionate, management-system-based obligation that a competently run ATO can meet — provided it stops treating the rule as somebody else's problem and starts treating information security as part of how it manages safety. For the wider regulatory backdrop these obligations sit within, see our comparison of EASA and FAA compliance.

Frequently asked questions

Does EASA Part-IS apply to flight schools and ATOs?
Yes. From 22 February 2026, Part-IS applies to Approved Training Organisations along with air carriers, maintenance organisations, CAMOs, FSTD operators, ATCO training organisations, air navigation service providers, and others. ATOs are named explicitly, and the obligation is triggered by your approval status, not your size — a small club-based ATO is in scope just as an airline is. The precise scope for any organisation operating under a lighter or declared regime should be confirmed with the national competent authority.
When did EASA Part-IS come into force?
The applicability date for the relevant requirements is 22 February 2026. Part-IS was introduced through Delegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203. Organisations that have not started should begin now and be able to demonstrate genuine, good-faith progress toward a working information-security management system rather than assume the rule does not apply to them.
What is an ISMS under Part-IS?
An information-security management system is a structured, documented way of identifying information-security risks that could affect aviation safety, treating them with proportionate controls, detecting and responding to incidents, reporting certain occurrences to the authority, and monitoring and improving over time. The requirements are largely consistent with ISO/IEC 27001 but add provisions specific to aviation safety. It is a living function, not a one-off policy document.
Does a small ATO have to do as much as an airline under Part-IS?
No. Part-IS explicitly requires an ISMS proportionate to the organisation's size, nature, complexity, and inherent risks. A small ATO is expected to have a small, sensible ISMS — controlled access, reliable backups, good account hygiene, staff awareness, vendor due diligence, and an incident plan — not an airline-scale security operation. What is not acceptable is having no information-security discipline at all.
How does Part-IS relate to an ATO's safety management system?
Part-IS is designed to integrate with the management system an ATO already runs rather than sit beside it. Its information-security risk management uses the same governance, risk-assessment habits, and monitoring-and-improvement loop as your existing safety management system and compliance monitoring function — now extended to cover information-security risk. Organisations with a mature, genuinely functioning management system will find Part-IS far easier because it becomes a new input to an existing machine.

Stay in the Loop

Get monthly updates on new features and industry insights for flight schools.

We respect your privacy. Unsubscribe at any time.

Ready to Modernize Your Flight School?

Book a demo and see Aviatize in action. No commitment required.