ED Decision 2025/013/R
Notwithstanding the equivalence between the requirements in Regulation (EU) 2022/1645 and the cybersecurity requirements contained in point 1.7 of the Annex to Regulation (EU) 2015/1998, in order to ensure effective management of safety consequences by leveraging the requirements of Regulation (EU) 2015/1998, organisations need to consider the differences in the scope of the rules in terms of which elements are covered under the two different regulatory frameworks.
Taking the example of an airport operator, elements such as body
scanners, X-ray machines and anti-RPAS systems fall under the scope
of the requirements of point 1.7 of the Annex to Regulation
(EU)
2015/1998. Elements such as runway lighting control systems and
safety training databases fall under the scope of aviation safety
rules. On the other hand, the protection of information and the
verification of trustworthiness and identity can be considered
element that overlap between the two frameworks.
Consequently, an organisation that has developed a system in accordance with point 1.7 of the Annex to Regulation (EU) 2015/1998 can use it to address safety issues by extending the scope of the system, where necessary, to ensure that all safety-related elements are included. Moreover, compliance with point IS.D.OR.230 has to be ensured.
Guidance clarifies how organisations can use Regulation (EU) 2015/1998 systems to manage safety consequences, considering scope differences and ensuring compliance with IS.D.OR.230.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...