ED Decision 2023/009/R
Organisations are required to report occurrences to their competent authority.
EXAMPLES
Design organisations approved by EASA: EASA is the competent authority.
Air operators certified by the competent authority of a Member State: the competent authority of the Member State is the competent authority.
SPECIAL CASES
In a situation where an organisation has two air operator certificates (AOCs) under two different EU Member States (State A and B), the occurrences involving aircraft operating under the State A AOC have to be reported to the State A competent authority; instead, the occurrences involving aircraft operating under the State B AOC have to be reported to the State B competent authority.
For organisations holding multiple approvals, the reporting will be done to the competent authority of the approved part of the organisation where the incident has occurred, or the vulnerability has been discovered. In case the incident/vulnerability affects multiple approvals, the reporting will be done to all the competent authorities.
For organisations holding an approval but operating outside the EU (e.g. Part-145), EASA is the competent authority and they have to report to the Agency.
Dual-use aircraft — a vulnerability may need to be reported through both the military and civil reporting systems if it affects a dual-use function/system. Information reported through the civil reporting system should be sanitised (i.e. all sensitive information should be properly removed).
EASA guidance clarifies reporting of information security occurrences to competent authorities, covering design organisations, air operators, multiple approvals, non-EU operations, and dual-use aircraft sanitisation.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...