Light
Dark
System
Log In
Loading...
Compare / EASA/
Incorporated Amendments
/
Compare & Highlight Differences
21.B.20A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety
Available versions for ERULES-1963177438-21951
Regulation (EU) 2023/203
found in: Initial Airworthiness and Environmental Protection (748/2012) Part-21 Part-21L (Jul 2024)
Regulation (EU) 2024/1110
found in: Initial Airworthiness and Environmental Protection (748/2012) (Nov 2025)
From
Initial Airworthin... (Nov 2025)
Initial Airworthin... (Jul 2024)
From section
To
Initial Airworthin... (Nov 2025)
Initial Airworthin... (Jul 2024)
To section
No visible text changes
0 removals
0 additions
View
Rich
Plain
Sync scrolling
Share
From
Show details
Hide details
To
Show details
Hide details
Version
Show side by side
21.B.20A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety Regulation (EU) 2023/203 (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point [21.B.15](#_DxCrossRefBm1649097504)(c), and without undue delay provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, non-installed equipment, persons or organisations subject to [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139) and its delegated and implementing acts. (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139) and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. [applicable from 22 February 2026 – Regulation (EU) 2023/203]
#### 21.B.20A Immediate reaction to an information security incident or vulnerability with an impact on aviation safety *Regulation (EU) 2024/1110* (a) The competent authority shall implement a system to appropriately collect, analyse, and disseminate information related to information security incidents and vulnerabilities with a potential impact on aviation safety that are reported by organisations. This shall be done in coordination with any other relevant authorities responsible for information security or cybersecurity within the Member State to increase the coordination and compatibility of reporting schemes. [applicable from 22 February 2026 – Regulation (EU) 2023/203] (b) The Agency shall implement a system to appropriately analyse any relevant safety-significant information received in accordance with point [21.B.15](#_DxCrossRefBm485230997)(c) and, without undue delay, provide the Member States and the Commission with any information, including recommendations or corrective actions to be taken, that is necessary for them to react in a timely manner to an information security incident or vulnerability with a potential impact on aviation safety involving products, parts, control and monitoring units (CMUs), CMU components, non-installed equipment, and persons or organisations that are subject to [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139) and its delegated and implementing acts. [applicable from 22 February 2026 – Regulation (EU) 2024/1110] (c) Upon receiving the information referred to in points (a) and (b), the competent authority shall take adequate measures to address the potential impact on aviation safety of the information security incident or vulnerability. [applicable from 22 February 2026 – Regulation (EU) 2023/203] (d) Measures taken in accordance with point (c) shall immediately be notified to all persons or organisations that shall comply with them under [Regulation (EU) 2018/1139](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018R1139) and its delegated and implementing acts. The competent authority of the Member State shall also notify those measures to the Agency and, when combined action is required, the competent authorities of the other Member States concerned. [applicable from 22 February 2026 – Regulation (EU) 2023/203]