Is this for you?
- You hold an EASA approval, such as a foreign Part-145 certificate, and Part-IS now applies to you.
- You have between five and two hundred people, and nobody whose full-time job is information security.
- Your quality or compliance team has read Part-IS and wants an outside view of what is missing before the authority looks.
- You want a list of what to write and what to do, not a 300-page report.
What you get
- Gap list. Your current processes and documents against the Part-IS requirements: information security risk management, incident detection and response, the roles Part-IS asks for, the management system itself, and reporting to the authority. Each gap is rated by how much it will matter at the next audit.
- The manual sections to write. Which parts of your exposition, or of a separate information security management manual, need new or changed text, with an outline for each.
- 90-day plan. The ten or so actions that close the most important gaps, in order, sized for your own team.
- Working session. An hour with you to go through the findings and adjust the plan to what is realistic.
How it runs
- Day 0Readiness call45 minutes on your approvals, your organization and what the authority has said so far. A fixed quote follows.
- Days 1–2Documents and interviewsI read your exposition, procedures and any security documents you have, and hold three or four 45-minute interviews: quality, IT, maintenance or operations, and the accountable manager if possible.
- Days 3–4Gap analysisThe gap list, the manual outline and the plan.
- Day 5Working sessionThe results walked through with you, and priorities adjusted.
What I need from you
One internal contact, your exposition and procedures, and three or four people for 45-minute interviews. About five working days of my time, spread over two weeks, all of it remote.
Questions I get asked
Our organization is outside the EU. Does Part-IS apply to us?
If EASA approves you directly, as it does foreign Part-145 organizations, yes: EASA’s user guide for foreign Part-145 approvals makes Part-IS part of the exposition from 22 February 2026. If you hold only Canadian approvals, it does not, and the readiness assessment against NIST CSF 2.0 or ISO/IEC 27001 is the better fit. We confirm your case on the call.
How is this different from the readiness assessment?
The gap check covers Part-IS only and takes about five days. The readiness assessment takes two to three weeks, covers your whole security program and ends with a risk register. Many organizations start with the gap check and decide afterwards whether they need more.
Do you write the manual for us?
Not in the gap check: you get an outline of each section. Writing the sections, or acting as your part-time security lead while the system matures, can follow as a separate fixed-scope engagement.
Is this an audit?
No. I do not certify and I am not the authority. The gap check prepares you for the authority’s review.
Start with a 45-minute readiness call
Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.
Ask about a Part-IS gap check