Regulation (EU) 2023/203

Introducing Information Security Management System (ISMS) within European Airports in Compliance with EASA Requirements

read more
Information Security Management System blog image

June 18, 2025

Steven Bentley

Sofema Aviation Services (SAS) Considers Aerodrome Information Security Management System (ISMS) obligations to be observed by Feb 2026 Introduction In today’s increasingly interconnected aviation landscape, the risk to information systems is growing rapidly. With the proliferation of digital infrastructure supporting critical airport functions—from airside operations to baggage handling—the need for a robust Information Security Management…

Information & Cybersecurity within an EASA Part CAMO Organisation – Introduction

read more
EASA Part CAMO Organisation blog image

May 30, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the key issues to be faced by the EASA Part CAMO Organisation when implementing PART IS & Regulation (EU) 2023/203 regulatory requirements Introduction The European aviation landscape is undergoing a pivotal transformation in response to the rapidly evolving threat environment posed by cyber and information security risks. Effective Feb 2026…

The Potential for Information Security / Cyber Exposure in Aircraft Maintenance Management (Part CAMO)

read more
Cyber Exposure blog image

May 27, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the key issues to be faced by the Part CAMO Organisation when implementing PART IS & Regulation (EU) 2023/203 regulatory requirements Introduction The potential for information security and cyber exposure within an EASA-compliant Part CAMO (Continuing Airworthiness Management Organisation) is significant and growing, particularly as digital transformation, remote access, and…

Identifying ISMS Compliance Gaps within Organisational Business Areas

read more
ISMS Compliance blog image

April 28, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers areas of key exposure related to the implementation of ISMS As well as demonstrating compliance with Regulation (EU) 2023/203, Operators should focus on reducing exposure to cyber risks and operational disruptions, by improving business resilience and safety in line with EASA requirements. Finally, Operators should aim to strengthen stakeholder confidence…