Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
IS.D.OR.255 Changes to the information security management system
Available versions for ERULES-1963177438-19920
Regulation (EU) 2022/1645
found in: Information Security (2023/203 and 2022/1645) Part-IS (Jun 2024)
Regulation (EU) 2025/22
found in: Information Security (2023/203 and 2022/1645) Part-IS (Dec 2025)
From
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
From section
To
Information Securi... (Dec 2025)
Information Securi... (Jun 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
IS.D.OR.255 Changes to the information security management system Regulation (EU) 2022/1645 (a) Changes to the ISMS may be managed and notified to the competent authority in a procedure developed by the organisation. This procedure shall be approved by the competent authority. (b) With regard to changes to the ISMS not covered by the procedure referred to in point (a), the organisation shall apply for and obtain an approval issued by the competent authority. With regard to these changes: (1) the application shall be submitted before any such change takes place, in order to enable the competent authority to determine continued compliance with this Regulation and to amend, if necessary, the organisation certificate and related terms of approval attached to it; (2) the organisation shall make available to the competent authority any information it requests to evaluate the change; (3) the change shall be implemented only upon receipt of a formal approval by the competent authority; (4) the organisation shall operate under the conditions prescribed by the competent authority during the implementation of such changes.
#### IS.D.OR.255 Changes to the information security management system *Regulation (EU) 2025/22* (a) Changes to the ISMS may be managed and notified to the competent authority in a procedure developed by the organisation. This procedure shall be approved by the competent authority, except for declaring organisations. (b) With regard to changes to the ISMS not covered by the procedure referred to in point (a), the organisation shall apply for and obtain an approval issued by the competent authority, except for declaring organisations, for which an approval is not required. With regard to these changes: (1) the application shall be submitted before any such change takes place, in order to enable the competent authority to determine continued compliance with this Regulation and to amend, if necessary, the organisation certificate and related terms of approval attached to it; (2) the organisation shall make available to the competent authority any information it requests to evaluate the change; (3) the change shall be implemented only upon receipt of a formal approval by the competent authority, except for declaring organisations, which may implement the change immediately; (4) the organisation shall operate under the conditions prescribed by the competent authority during the implementation of such changes.