Law / European Union

Commission Delegated Regulation (EU) 2022/1645, External Reporting of Information Security Incidents and Vulnerabilities (IS.D.OR.230)

Commission Delegated Regulation (EU) 2022/1645, IS.D.OR.230

In force since .

A vulnerability and incident reporting rule binding public and private bodies.

Obligation class
Reporting, Security

As of .

What it requires

  • This duty binds the organizations named in Article 2(1) of Commission Delegated Regulation (EU) 2022/1645: a production organization or design organization under Part 21, or an aerodrome operator or apron management service provider under Part-ADR.OR, subject to the exception Article 2(1) lists for organizations solely involved in ELA 2 aircraft. It reaches you if you declare that you are an essential or important entity under Directive (EU) 2022/2555 and you are one of them. The Regulation applies from (Article 8).
  • Report to your competent authority any information security incident or vulnerability that may represent a significant risk to aviation safety; where it affects an aircraft or associated system or component, also report it to the design approval holder, and where it affects a system or constituent you use, to the organization responsible for its design (point IS.D.OR.230(b)).
  • Submit a notification as soon as you know of the condition, and a report as soon as possible and not exceeding 72 hours from the time you know of it unless exceptional circumstances prevent this, in the form your competent authority defines (point IS.D.OR.230(c), points (1) and (2)).
  • Submit a follow-up report on the actions you have taken or intend to take to recover and to prevent similar incidents as soon as those actions are identified (point IS.D.OR.230(c), point (3)).
  • Operate an information security reporting system that complies with Regulation (EU) No 376/2014 and its delegated and implementing acts where that Regulation is applicable to you (point IS.D.OR.230(a)).

Who enforces it

Enforcement body

The authority responsible for certifying and overseeing compliance with the Regulation, which is the competent authority designated under the regulation that governs each class of organization it covers.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Point IS.D.OR.230(b) requires the organization to ensure that any information security incident or vulnerability that may represent a significant risk to aviation safety is reported to its competent authority.

Where the incident or vulnerability affects an aircraft or associated system or component, the organization also reports it to the design approval holder, and where it affects a system or constituent the organization uses, to the organization responsible for the design of that system or constituent.

Point IS.D.OR.230(c) requires a notification as soon as the condition is known, a report as soon as possible and not exceeding 72 hours from the time the condition has been known to the organization, and a follow-up report on the recovery and prevention actions. The report is made in the form the competent authority defines and contains all relevant information about the condition known to the organization.

Point IS.D.OR.230(a) requires an information security reporting system that complies with Regulation (EU) No 376/2014 and its delegated and implementing acts where that Regulation is applicable to the organization.

Article 4(2) treats the cybersecurity requirements in point 1.7 of the Annex to Implementing Regulation (EU) 2015/1998 as equivalent to the requirements of this Regulation for an operator or entity in the national civil aviation security programs, except as regards point IS.D.OR.230, which must be complied with as such. The Regulation applies from .

The authority responsible for certifying and overseeing compliance is, for each class of organization, the competent authority designated under the regulation that governs that class (Article 5(1)). Article 131 of Regulation (EU) 2018/1139 requires Member States to lay down the rules on penalties applicable to infringement of that Regulation and of the delegated and implementing acts adopted on the basis of it.

When LexLint raises it

When your app profile says your app runs an essential service.

Back to the example  ·  Lint your app