Guide · For builders and operators

Aviation cybersecurity frameworks compared: which one fits a small company?

NIST, ISO, CIS, RTCA, EUROCAE, EASA, ICAO: the acronyms multiply faster than a ten-person company can read them. This guide sorts the frameworks that actually matter for a small aviation business by what they cover, whether anyone certifies you, how much work they are, and who will ask you for them.

Key takeaways

  • There are two different jobs: securing the company (its network, people and data) and securing the product (the aircraft and its systems). Enterprise frameworks do the first; DO-326A and its family do the second. You will probably need one of each.
  • For a company of 10 to 50 people, NIST CSF 2.0 gives you the structure and the CIS Controls give you the first 56 things to actually do. Neither certifies you; both are free.
  • ISO/IEC 27001 is the one customers and OEM partners ask for by name. Get it when a contract depends on it, not before.
  • If you hold or plan an EASA organization approval, EASA Part-IS is not optional: it requires an information security management system with safety-focused risk assessment and incident reporting.
  • Pick the framework that answers the question your next regulator, customer or investor will ask. Everything else is a reading list.

Two jobs, two families of frameworks

Most confusion about aviation cybersecurity frameworks comes from mixing up two problems that need different tools.

The first is organizational security: protecting your company's laptops, cloud accounts, design files, email and maintenance records from the everyday threats every business faces, such as phishing, ransomware and stolen credentials. The frameworks for this are generic. They come from NIST, ISO and the Center for Internet Security, and they apply to a drone start-up in the same way they apply to a dental practice.

The second is product security, or airworthiness security: making sure the aircraft you design, build or maintain cannot be made unsafe by a deliberate attack on its systems. The frameworks here are aviation-specific, written by RTCA and EUROCAE and recognized by the FAA and EASA, and they live inside the certification process.

An operator or MRO mostly needs the first family plus the aviation regulator's own requirements. A developer needs both. Knowing which job a framework does prevents the two classic mistakes: certifying the office to ISO 27001 while the aircraft's update path is unauthenticated, or writing a beautiful DO-326A threat model while the engineering team's cloud account has no multi-factor authentication.

Enterprise frameworks

NIST Cybersecurity Framework 2.0

Released in February 2024, CSF 2.0 organizes cybersecurity into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. (The original had five; Govern was added to make leadership and risk management explicit. If a document you are reading still says five, it is out of date.) Each Function breaks down into Categories and Subcategories that describe outcomes, not specific controls, which is why it works for organizations of any size. You describe your current state as a Profile, your desired state as a Target Profile, and the gap becomes your plan. NIST publishes free quick-start guides, including one for small businesses. Nobody certifies you against CSF; you self-assess. It is the framework I use to structure a readiness assessment because it maps cleanly onto everything else.

ISO/IEC 27001:2022

The international standard for an information security management system (ISMS). It specifies management-system requirements (leadership, risk assessment, treatment, monitoring, improvement) and a list of 93 reference controls in Annex A, grouped into organizational, people, physical and technological themes. It is certifiable: an accredited body audits you and issues a certificate that procurement departments recognize. That recognition is its value and its cost. Building and certifying an ISMS in a company of 20 people is realistically a six-to-twelve-month effort with real management time, followed by annual surveillance audits. Do it when a customer, partner or investor makes it a condition; before that, use its control list as a checklist without the audit.

CIS Critical Security Controls v8.1

The most practical document on this list. The CIS Controls are a prioritized list of specific safeguards, and Implementation Group 1 (IG1) selects the 56 that every organization should do first regardless of size: inventory your devices and software, manage accounts and access, patch, back up, secure configurations, train people, and so on. If you have no security program today, IG1 is the first 90 days. It is free, and it maps to CSF and ISO 27001 so nothing is wasted later.

NIST SP 800-30 and SP 800-53

SP 800-30 is a method for conducting risk assessments; it is useful when you need a defensible way to rank risks, and its structure (threat sources, threat events, vulnerabilities, likelihood, impact) is what most risk registers are quietly based on. SP 800-53 is the catalogue of controls used by US federal systems. It is comprehensive and heavy; a small company should borrow from it rather than adopt it.

ISO 31000, COSO ERM and COBIT

These are not cybersecurity frameworks. ISO 31000 is a general risk-management standard, COSO ERM is an enterprise risk-management model used by boards and auditors, and COBIT is an IT governance framework. They matter if your board, investors or auditors already use them, because your cyber risk reporting should fit their vocabulary. They do not tell you how to secure anything.

Aviation-specific frameworks and rules

DO-326A/ED-202A and its family (product security)

The Airworthiness Security Process Specification and its companions define how a developer shows a certification authority that an aircraft's systems resist deliberate attack: DO-326A/ED-202A for the process, DO-356A/ED-203A for methods and assurance levels, DO-355A/ED-204A for continuing airworthiness, and DO-392/ED-206 for security event management. EASA accepts them through AMC 20-42; the FAA has applied them through special conditions and moved to codify the requirements in 2024. If you design aircraft or aircraft systems, this family is not a choice but the shape of your certification evidence. I cover it in detail in the airworthiness security guide.

EASA Part-IS (organizational security for approved organizations)

Part-IS is the European Union's information security regulation for aviation organizations: Delegated Regulation (EU) 2022/1645 and Implementing Regulation (EU) 2023/203, applicable from late 2025 and early 2026 depending on the type of organization. It applies to holders of EASA approvals, including design and production organizations, maintenance organizations, continuing-airworthiness management organizations, air operators, training organizations, ATM/ANS providers and aerodromes. It requires an information security management system focused on risks with a potential impact on aviation safety, incident detection and reporting, and integration with the existing safety management system. In practice it is an ISO 27001-shaped obligation with an aviation-safety lens; an organization that already holds ISO 27001 can extend it, and one that does not can build Part-IS compliance on a CSF or ISO structure.

ICAO

ICAO sets the global frame. Annex 17 requires States to ensure that operators and other entities identify and protect critical information and communications technology systems from unlawful interference, and ICAO's Aviation Cybersecurity Strategy and Action Plan drive national programs. Annex 19 brings safety management systems, into which cyber risk increasingly has to be folded. ICAO material rarely lands on a small company directly; it arrives through the national authority's rules and through customers' expectations.

FAA and TSA

For operators of aircraft with connected systems, FAA Advisory Circular 119-1 describes the Aircraft Network Security Program an operator is expected to run. In the United States the Transportation Security Administration has since 2023 imposed cybersecurity requirements on regulated airport and aircraft operators through security directives and emergency amendments; smaller operators are usually outside that net but often inside the supply chain of someone who is not.

Canada

Transport Canada currently addresses cybersecurity mainly through existing airworthiness, operational and safety-management requirements rather than a stand-alone cyber regulation. Federal legislation to protect critical cyber systems in federally regulated sectors, including transportation, has been proposed (most recently as Bill C-8); its status should be checked at the time of reading. Canadian companies selling into the US or EU are, in practice, governed by their customers' regimes.

Side by side

FrameworkSecuresCertificationEffort for a 10–50 person companyWho will ask for it
NIST CSF 2.0The companyNone (self-assessed)Low to medium; a structure, not a control listUS customers, investors, boards; a natural basis for a readiness assessment
CIS Controls v8.1, IG1The companyNoneLow; 56 concrete safeguardsNobody by name, but it is what auditors check for in practice
ISO/IEC 27001:2022The companyYes, by accredited bodiesHigh; 6–12 months to first certificate, then annual auditsAirlines, OEMs, European partners, some investors and insurers
NIST SP 800-30 / 800-53Risk method / control catalogueNoneBorrow, don't adoptUS government-adjacent customers
DO-326A / ED-202A familyThe productThrough type certificationSignificant, scaled by assurance levelFAA, EASA, Transport Canada during certification; OEM partners
EASA Part-ISThe organization (safety-related information security)Regulatory compliance, overseen by the authorityMedium to high; an ISMS with aviation-safety scopeEASA and national authorities, for approved organizations
ICAO Annex 17 / StrategyStates and their regulated entitiesState oversightIndirectArrives through national rules and customer expectations
ISO 31000, COSO, COBITGovernance and risk vocabularyNone (COBIT has training certifications)Low; use their language for reportingBoards, auditors, enterprise customers

Recommended paths

If you develop eVTOL, UAS or avionics

  1. Company: start with CIS IG1 to close the obvious gaps, and describe your program in NIST CSF 2.0 terms so that investor and partner questionnaires have ready answers.
  2. Product: adopt the DO-326A/ED-202A process from the concept phase and agree a Plan for Security Aspects of Certification with the authority early.
  3. Later: pursue ISO 27001 when an OEM partnership or a customer contract requires it; add Part-IS if you hold or seek an EASA design or production organization approval.

If you operate aircraft or run an MRO

  1. Company: CIS IG1 plus a CSF 2.0 profile, with particular attention to backups and maintenance-record integrity, which are what ransomware actually threatens in your business.
  2. Regulatory: if you hold an EASA approval, Part-IS applies; build it on the same structure rather than as a separate paper exercise. If you operate connected aircraft under FAA rules, look at AC 119-1.
  3. Later: ISO 27001 when a lessor, airline customer or insurer asks for it.

Three mistakes I see most often

  • Choosing by prestige rather than by question. A start-up that certifies to ISO 27001 because it sounds serious, before any customer has asked, spends a year of management attention it needed elsewhere.
  • Treating a framework as the program. A CSF profile with nothing behind it is a document. The program is the backups that were tested, the accounts that were reviewed, the patch that was applied.
  • Ignoring the product side. For a developer, a perfect organizational program does not answer the authority's question about the aircraft. The two have to be planned together.

Questions I get asked

Which cybersecurity framework should a small aviation company start with?

NIST CSF 2.0 for the structure and the CIS Controls for the first concrete steps; both are free and neither requires certification. Add ISO/IEC 27001 when a customer or OEM contract demands it.

Do I need DO-326A or ISO 27001?

They do different jobs. DO-326A/ED-202A secures the product, the aircraft and its systems, and is what a certification authority looks for; ISO 27001 secures the company and is what customers and partners ask for. Many aircraft developers eventually need one of each.

Is EASA Part-IS mandatory?

For organizations holding an EASA approval within its scope, yes: it requires an information security management system with safety-focused risk assessment and incident reporting. Outside EASA's jurisdiction it is still a useful model.

How much effort does a framework take?

For a company of 10 to 50 people, NIST CSF 2.0 with the CIS Controls takes a few weeks to set up and a few hours a month to run. ISO 27001 certification is typically six to twelve months of work plus an external audit.

How I can help

My security program and readiness assessment reviews your systems, people and obligations against the framework that fits you (NIST CSF 2.0, ISO/IEC 27001 or EASA Part-IS) in two to three weeks. You get a prioritized risk register and a 90-day roadmap your own team can run.

Ask about a readiness assessment
Eugene Pik

Eugene Pik

Founder of Mevocopter Aerospace. M.Sc. in Aviation and Aerospace Sustainability with a specialization in Aviation Cybersecurity from Embry-Riddle; before aviation, he prepared Health Canada and FDA regulatory submissions for medical-device makers. Publications · ORCID

References

  1. NIST (2024). The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29.
  2. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements.
  3. Center for Internet Security. CIS Critical Security Controls, version 8.1.
  4. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments; NIST SP 800-53 Rev. 5, Security and Privacy Controls.
  5. RTCA DO-326A / EUROCAE ED-202A; DO-356A / ED-203A; DO-355A / ED-204A; DO-392 / ED-206. EASA AMC 20-42.
  6. Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 (EASA Part-IS).
  7. ICAO Annex 17, Security; ICAO Aviation Cybersecurity Strategy and Cybersecurity Action Plan; ICAO Annex 19, Safety Management.
  8. FAA Advisory Circular 119-1, Airworthiness and Operational Authorization of Aircraft Network Security Program (ANSP).