Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
ARA.GEN.330A Changes to the information security management system
Available versions for ERULES-1963177438-21079
Regulation (EU) 2023/203
found in: Aircrew (1178/2011) Part-FCL Part-MED Part-CC Part-ARA Part-ORA Part-DTO (Aug 2023)
From
Aircrew (1178/2011... (Nov 2025)
Aircrew (1178/2011... (Dec 2024)
Aircrew (1178/2011... (Aug 2023)
From section
To
Aircrew (1178/2011... (Nov 2025)
Aircrew (1178/2011... (Dec 2024)
Aircrew (1178/2011... (Aug 2023)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
ARA.GEN.330A Changes to the information security management system Regulation (EU) 2023/203 (a) With regard to changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280), the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point [ARA.GEN.300](#_DxCrossRefBm1199963922). If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point [ARA.GEN.350](#_DxCrossRefBm1199963924). (b) With regard to other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280): (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
ARA.GEN.330A Changes to the information security management system Regulation (EU) 2023/203 (a) With regard to changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280), the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point [ARA.GEN.300](#_DxCrossRefBm894736067). If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point [ARA.GEN.350](#_DxCrossRefBm894736069). (b) With regard to other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280): (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*
#### ARA.GEN.330A Changes to the information security management system *Regulation (EU) 2023/203* (a) With regard to changes managed and notified to the competent authority in accordance with the procedure set out in point IS.I.OR.255(a) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280), the competent authority shall include the review of such changes in its continuing oversight in accordance with the principles laid down in point [ARA.GEN.300](#_DxCrossRefBm1743303733). If any non-compliance is found, the competent authority shall notify the organisation thereof, request further changes and act in accordance with point [ARA.GEN.350](#_DxCrossRefBm1743303735). (b) With regard to other changes requiring an application for approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to [Implementing Regulation (EU) 2023/203](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0203&qid=1686898139280): (1) upon receiving the application for the change, the competent authority shall check the organisation’s compliance with the applicable requirements before issuing the approval; (2) the competent authority shall establish the conditions under which the organisation may operate during the implementation of the change; (3) if it is satisfied that the organisation complies with the applicable requirements, the competent authority shall approve the change. *[applicable from 22 February 2026 — Implementing Regulation (EU) 2023/203]*