lagen.nu
AMC & GM to the Articles of Regulations (EU) 2022/1645 and 2023/203 — Issue 1, Amendment 1

AMC & GM to the Articles of Regulations (EU) 2022/1645 and 2023/203 — Issue 1, Amendment 1

Utgivare
Europeiska unionens byrå för luftfartssäkerhet
Antagen
2025-07-24
Utfärdat genom
ED Decision 2025/013/R
Språk
engelska
Ämnesord
AMC & GM to the Articles of Regulations (EU) 2022/1645 and 2023/203
Källa
www.easa.europa.eu
Endast på engelskaEuropeiska unionens byrå för luftfartssäkerhet har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens byrå för luftfartssäkerhet.

Annex to ED Decision 2025/013/R AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1

This document shows deleted, new or amended text as follows:

— deleted text is struck through;

— new or amended text is highlighted in blue;

— an ellipsis ‘[…]’ indicates that the rest of the text is unchanged.

Amendments to the AMC and GM to the Articles of Commission Implementing Regulation (EU) 2023/203

Pursuant to Article 44 of Directive (EU) 2022/2555 (the NIS 2 Directive), the previous Directive (EU) 2016/1148 (the NIS Directive) was repealed with effect from 18 October 2024. In accordance with the NIS 2 Directive, references to the repealed Directive shall be construed as references to Directive (EU) 2022/2555 and shall be read in accordance with the correlation table set out in its Annex III. In accordance with this table, references to Article 14 of Directive (EU) 2016/1148 shall be now read as references to Article 21 and Article 23 of Directive (EU) 2022/2555. For an exact correlation, please refer to Annex III to Directive (EU) 2022/2555. To ensure legal certainty, the equivalence of any requirements should be assessed by the competent authority against the requirements of the national legislation when Directive (EU) 2022/2555 is transposed. When utilising this equivalence, organisations should consider the following: — The equivalence between Regulation (EU) 2023/203 and Directive (EU) 2022/2555 requirements as assessed by the competent authority. — Possible differences in the perimeter of applicability of the rules, in particular as regards the elements that are within the scope under the two different frameworks. The competent authority will decide whether or not the measures implemented by the organisation under the NIS framework can be considered sufficient for satisfying requirements of similar nature under this rule.

Even though the provisions in Regulation (EU) 2023/203 are equivalent to the cybersecurity requirements in point 1.7 of the Annex to Regulation (EU) 2015/1998, in order to ensure effective management of safety consequences by leveraging the requirements of Regulation (EU) 2015/1998, organisations need to consider the differences in the scope of the rules in terms of which elements are covered under the two different regulatory frameworks.

Taking the example of an airport operator, elements such as body scanners, X-ray machines and anti- RPAS systems fall under the scope of the requirements of point 1.7 of the Annex to Regulation (EU) 2015/1998. Elements such as runway lighting control systems and safety training databases fall under the scope of aviation safety rules. On the other hand, the protection of information and the verification of trustworthiness and identity can be considered elements that overlap between the two frameworks.

Consequently, an organisation that has developed a system in accordance with point 1.7 of the Annex to Regulation (EU) 2015/1998 can use it to address safety issues by extending the scope of the system, where necessary, to ensure that all safety-related elements are included. Moreover, compliance with point IS.I.OR.230 has to be ensured.

The applicability of Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 to competent authorities is specified in Article 4(2) and called for under the authority requirements for a management system in the implementing or delegated acts for each domain. Therefore, the Part-IS.AR requirements apply to the competent authority under Article 6(1) irrespective of the allocation of roles and responsibilities to an independent and autonomous entity designated by the State under Article 6(2). At the same time, this independent and autonomous entity designated by the State is not subject to the Part-IS.AR requirements; this entity has only to fulfil the responsibilities for certifying and overseeing organisations’ compliance with Implementing Regulation (EU) 2023/203. This entity typically holds the role of a national information security body within the Member State and is normally subject to similar requirements to those existing in Part-IS.AR.

Amendments to the AMC and GM to the Articles of Commission Delegated Regulation (EU) 2022/1645

Pursuant to Article 44 of Directive (EU) 2022/2555 (the NIS 2 Directive), the previous Directive (EU) 2016/1148 (the NIS Directive) was repealed with effect from 18 October 2024. In accordance with the NIS2 Directive, references to the repealed Directive shall be construed as references to Directive (EU) 2022/2555 and shall be read in accordance with the correlation table set out in its Annex III. In accordance with this table, references to Article 14 of Directive (EU) 2016/1148 shall be now read as references to Article 21 and Article 23 of Directive (EU) 2022/2555. For an exact correlation, please refer to Annex III to Directive (EU) 2022/2555. To ensure legal certainty, the equivalence of any requirements should be assessed by the competent authority against the requirements of the national legislation when Directive (EU) 2022/2555 is transposed. When utilising this equivalence, organisations should consider the following: — The equivalence between Regulation (EU) 2022/1645 and Directive (EU) 2022/2555 requirements as assessed by the competent authority. — Possible differences in the perimeter of applicability of the rules, in particular as regards the elements that are within the scope under the two different frameworks. The competent authority will decide whether or not the measures implemented by the organisation under the NIS framework can be considered sufficient for satisfying requirements of similar nature under this rule.

Notwithstanding the equivalence between the requirements in Regulation (EU) 2022/1645 and the cybersecurity requirements contained in point 1.7 of the Annex to Regulation (EU) 2015/1998, in order to ensure effective management of safety consequences by leveraging the requirements of Regulation (EU) 2015/1998, organisations need to consider the differences in the scope of the rules in terms of which elements are covered under the two different regulatory frameworks.

Taking the example of an airport operator, elements such as body scanners, X-ray machines and anti- RPAS systems fall under the scope of the requirements of point 1.7 of the Annex to Regulation (EU) 2015/1998. Elements such as runway lighting control systems and safety training databases fall under the scope of aviation safety rules. On the other hand, the protection of information and the verification of trustworthiness and identity can be considered element that overlap between the two frameworks.

Consequently, an organisation that has developed a system in accordance with point 1.7 of the Annex to Regulation (EU) 2015/1998 can use it to address safety issues by extending the scope of the system, where necessary, to ensure that all safety-related elements are included. Moreover, compliance with point IS.D.OR.230 has to be ensured.

The applicability of Annex I (Part-IS.AR) to Implementing Regulation (EU) 2023/203 to competent authorities is specified in its Article 4(2) and called for under the authority requirements for a management system in the implementing or delegated act for each domain. Therefore, the Part-IS.AR requirements apply to the competent authority under Article 5(1) irrespective of the allocation of roles and responsibilities to an independent and autonomous entity designated by the State under Article 5(2). At the same time, this independent and autonomous entity designated by the State is not subject to the Part-IS.AR requirements; this entity has only to fulfil the responsibilities for certifying and overseeing organisations’ compliance with Implementing Regulation (EU) 2023/203. This entity typically holds the role of a national information security body within the Member State and is normally subject to similar requirements to those existing in Part-IS.AR.

Fotnoter

  1. AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1
  2. N o te to t h e r e a d e r
  3. In amended, and in particular in existing (that is, unchanged) text, ‘Agency’ is used interchangeably with ‘EASA’. The interchangeable use of these two terms is more apparent in the consolidated versions. Therefore, please note that both terms refer to the ‘European Union Aviation Safety Agency (EASA)’.
  4. Annex to ED Decision 2025/013/R Page 1 of 5
  5. AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1
  6. Annex to ED Decision 2025/013/R Page 2 of 5
  7. AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1
  8. Annex to ED Decision 2025/013/R Page 3 of 5
  9. AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1
  10. Annex to ED Decision 2025/013/R Page 4 of 5
  11. AMC & GM to the Articles of Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 Issue 1, Amendment 1
  12. Annex to ED Decision 2025/013/R Page 5 of 5