Navigate / EASA
GM1 IS.I.OR.230 Information security external reporting scheme

ED Decision 2023/009/R

Organisations are required to report occurrences to their competent authority.

EXAMPLES

Design organisations approved by EASA: EASA is the competent authority.

Air operators certified by the competent authority of a Member State: the competent authority of the Member State is the competent authority.

SPECIAL CASES

In a situation where an organisation has two air operator certificates (AOCs) under two different EU Member States (State A and B), the occurrences involving aircraft operating under the State A AOC have to be reported to the State A competent authority; instead, the occurrences involving aircraft operating under the State B AOC have to be reported to the State B competent authority.

For organisations holding multiple approvals, the reporting will be done to the competent authority of the approved part of the organisation where the incident has occurred, or the vulnerability has been discovered. In case the incident/vulnerability affects multiple approvals, the reporting will be done to all the competent authorities.

For organisations holding an approval but operating outside the EU (e.g. Part-145), EASA is the competent authority and they have to report to the Agency.

Dual-use aircraft — a vulnerability may need to be reported through both the military and civil reporting systems if it affects a dual-use function/system. Information reported through the civil reporting system should be sanitised (i.e. all sensitive information should be properly removed).