Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
ARA.GEN.135A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety
Available versions for ERULES-1963177438-21077
Regulation (EU) 2023/203
found in: Aircrew (1178/2011) Part-FCL Part-MED Part-CC Part-ARA Part-ORA Part-DTO (Aug 2023)
From
Aircrew (1178/2011... (Nov 2025)
Aircrew (1178/2011... (Dec 2024)
Aircrew (1178/2011... (Aug 2023)
From section
To
Aircrew (1178/2011... (Nov 2025)
Aircrew (1178/2011... (Dec 2024)
Aircrew (1178/2011... (Aug 2023)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
ARA.GEN.135A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety Regulation (EU) 2023/203 (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point [ARA.GEN.125(c)](#_DxCrossRefBm1199963893), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
ARA.GEN.135A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety Regulation (EU) 2023/203 (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point [ARA.GEN.125(c)](#_DxCrossRefBm894736038), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
#### ARA.GEN.135A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety *Regulation (EU) 2023/203* (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point [ARA.GEN.125(c)](#_DxCrossRefBm1743303704), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139&qid=1686837400194) and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*