Service · For EASA-approved organizations

EASA Part-IS gap check

Since 22 February 2026, EASA’s information security rules (Part-IS) apply to the maintenance organizations and operators it approves, including Part-145 organizations outside the EU. If your next audit will ask about your information security management system and you are not sure what it needs to contain, this is the short, fixed-scope way to find out.

Is this for you?

  • You hold an EASA approval, such as a foreign Part-145 certificate, and Part-IS now applies to you.
  • You have between five and two hundred people, and nobody whose full-time job is information security.
  • Your quality or compliance team has read Part-IS and wants an outside view of what is missing before the authority looks.
  • You want a list of what to write and what to do, not a 300-page report.

What you get

  • Gap list. Your current processes and documents against the Part-IS requirements: information security risk management, incident detection and response, the roles Part-IS asks for, the management system itself, and reporting to the authority. Each gap is rated by how much it will matter at the next audit.
  • The manual sections to write. Which parts of your exposition, or of a separate information security management manual, need new or changed text, with an outline for each.
  • 90-day plan. The ten or so actions that close the most important gaps, in order, sized for your own team.
  • Working session. An hour with you to go through the findings and adjust the plan to what is realistic.

How it runs

  • Day 0Readiness call45 minutes on your approvals, your organization and what the authority has said so far. A fixed quote follows.
  • Days 1–2Documents and interviewsI read your exposition, procedures and any security documents you have, and hold three or four 45-minute interviews: quality, IT, maintenance or operations, and the accountable manager if possible.
  • Days 3–4Gap analysisThe gap list, the manual outline and the plan.
  • Day 5Working sessionThe results walked through with you, and priorities adjusted.

What I need from you

One internal contact, your exposition and procedures, and three or four people for 45-minute interviews. About five working days of my time, spread over two weeks, all of it remote.

Questions I get asked

Our organization is outside the EU. Does Part-IS apply to us?

If EASA approves you directly, as it does foreign Part-145 organizations, yes: EASA’s user guide for foreign Part-145 approvals makes Part-IS part of the exposition from 22 February 2026. If you hold only Canadian approvals, it does not, and the readiness assessment against NIST CSF 2.0 or ISO/IEC 27001 is the better fit. We confirm your case on the call.

How is this different from the readiness assessment?

The gap check covers Part-IS only and takes about five days. The readiness assessment takes two to three weeks, covers your whole security program and ends with a risk register. Many organizations start with the gap check and decide afterwards whether they need more.

Do you write the manual for us?

Not in the gap check: you get an outline of each section. Writing the sections, or acting as your part-time security lead while the system matures, can follow as a separate fixed-scope engagement.

Is this an audit?

No. I do not certify and I am not the authority. The gap check prepares you for the authority’s review.

Start with a 45-minute readiness call

Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.

Ask about a Part-IS gap check
Eugene Pik

Eugene Pik

Founder of Mevocopter Aerospace. M.Sc. in Aviation and Aerospace Sustainability with a specialization in Aviation Cybersecurity from Embry-Riddle; Ph.D. researcher in Data Science at the University of Essex; earlier career in computer support and network security.