Part-IS Compliance: Why Your Biggest Audit Risk Isn’t Cybersecurity

Yuval Sive

August 25, 2026

Part-IS findings won't be about firewalls

Estimated reading time: 5 minutes

Most of what’s been written about Part-IS was published to help organizations prepare for the new information security rules. Almost nothing has been written about what actually happens once the audits begin.  

Since 22 February 2026, Part-145 organizations have had to manage information security risks that could affect aviation safety, under point 145.A.200A. National authorities are now conducting their first round of specialized cyber audits, in which organizations must demonstrate that they have identified their critical information assets. That window is open right now and closes in February 2027. 

This timing is important. Twelve months sounds generous until you consider what a typical audit cycle actually involves: notification, scheduling, the audit itself, the findings, corrective action plans, and follow-up verification.  

For a mid-sized MRO, that’s not twelve months of runway. It is closer to two or three, once you account for the queue of organizations ahead of you and the time needed to fix anything an auditor flags. The organizations that wait for their audit date to start making changes will be doing their information asset identification under a corrective action deadline, not on their own schedule. 

Cyber was never the exposure

Part-IS protects confidentiality, integrity and availability. The industry translated this as a cybersecurity problem and bought a SIEM (a security monitoring tool for detecting network intrusions). But for a Part-145 shop, the real risk isn’t a hacker: it’s that nobody can prove who last changed a work instruction. 

If your technical documentation lives on a shared drive with inherited permissions and no change history, you cannot demonstrate integrity of maintenance data to an auditor. That isn’t an IT finding. It’s a document control finding wearing a cyber costume, and it lands on the Account Manager. Could you tell an auditor who approved the last change to a work instruction, and when? If not, that’s the finding waiting to happen, not a hacker. 

Paper doesn’t get you out of scope 

The sharpest line in this: paper is not a Part-IS exemption. Only organizations working solely on Part-ML aircraft (EASA’s simplified category for very light aircraft) sit outside scope. Being low-tech doesn’t get you out; it just means your critical information assets are undocumented rather than merely unprotected. 

What Auditors Are Actually Looking For 

Ask yourself: do you actually know what your critical information assets are, or would it take a week to find out if an auditor asked tomorrow? 

They want evidence that you know what your critical information assets are, who can touch them, and whether you’d notice if something changed without authorization. In practice, that means: 

  • A documented, defensible list of the information assets that support airworthiness (work instructions, maintenance records, task cards, software configurations, EO/AD tracking, i.e. engineering orders and airworthiness directives) 
  • Clear ownership and access control for each of them 
  • A change history that shows who changed what, when, and why 
  • A way of showing this to an auditor without scrambling to reconstruct it after the fact 

Take the shared-drive example above. An auditor doesn’t need to understand your network architecture to raise a finding. They only need to establish who approved the last revision to a given work instruction, and when. If that can’t be answered, because the folder has been open to the whole department since 2019 with no record of who changed what, that’s a finding. It doesn’t matter that the drive sits behind a firewall and a login screen.  

Confidentiality was never the question. Integrity was. 

None of this requires new hardware, and it doesn’t require a cybersecurity specialist on staff. It requires the same discipline Part-145 already demands of a safety management system. To identify the hazard, evaluate it, control it, provide evidence that you’ve done so, then apply that same discipline to information rather than physical processes. Organizations that already run a mature SMS have most of the muscle memory they need; they just haven’t pointed it at their documentation yet. 

Where Organizations Fall Short 

Meeting that checklist on paper is one thing. Keeping it true day to day is another, and that’s where most organizations lose ground. In practice, the gap tends to show up in one of three places. 

  • Ownership: someone assumes IT “has” information security covered, when IT controls the infrastructure, but nobody has been assigned to own the aviation-safety risk sitting on top of it. 
  • Scope: organizations map their obvious digital systems, the maintenance software, the EFB (electronic flight bag), and stop there, missing the shared drives, printed work packs, and personal laptops that also hold critical information. 
  • Evidence: the controls might genuinely exist, but nobody has written them down in a form an auditor can follow. 

Any one of these is enough to generate a finding in your first specialized cyber-audit. All three together is how a “low-tech, low-risk” organization ends up with the longest corrective action plan in the hangar. 

The Cost of Waiting 

Organizations that treat this as a one-off ‘get ready’ exercise are the ones likely to walk into a finding over the next twelve months. The ones that treat it as an ongoing management system requirement, reviewed and evidenced the same way a safety hazard log already is, will sail through the first oversight cycle instead of becoming a cautionary example of it. 

The reality is that most of the “get ready for Part-IS” content published before February told organizations what the regulation said. A small portion of it told them what an auditor would actually be looking for when they walked through the door twelve months later. That’s the gap we are trying to close. 

Ask yourself one question: could you hand an auditor your critical information asset register today? If the answer is no, that’s this year’s priority. 

WORKING TOGETHER TO POWER

Peak Operational Performance, Proactive Safety Management and Modern Training Management