MarketplaceCritical InfrastructureEU Regulation 2022/1645
Critical InfrastructureRegulation

EU Regulation 2022/1645

Commission Delegated Regulation (EU) 2022/1645

EU Regulation 2022/1645 establishes mandatory cybersecurity management requirements for Part 21 Design Organisations (DOs) and Production Organisations (POs) in the aviation sector. It introduces the implementation of an Information Security Management System (ISMS) to protect critical systems, data, and processes from cyber threats.

Overview

Commission Delegated Regulation (EU) 2022/1645 is an amendment to Regulation (EU) No 748/2012, introducing cybersecurity management requirements in Subparts J and G of Part 21 for Design Organisations (DOs) and Production Organisations (POs). These entities are required to implement and maintain an Information Security Management System (ISMS) to identify and manage security risks impacting aviation safety, establish incident reporting mechanisms, and ensure continuous improvement in cybersecurity. Key challenges include integrating ISMS with existing safety systems, managing compliance with evolving regulations, and addressing supply chain and cultural resistance issues. The regulation aligns with EASA cybersecurity rulemaking and addresses risks like legacy system vulnerabilities, remote work security, and insider threats.

Related in Critical Infrastructure

Critical InfrastructureLaw

SOCIA 2018 — Security of Critical Infrastructure Act 2018

The Security of Critical Infrastructure Act 2018 (SOCIA) establishes a regulatory framework for managing national security risks to Australia’s critical infrastructure sectors. It introduces statutory obligations, reporting requirements, and oversight mechanisms for critical assets.

Australian Department of Home Affairs • Australia • vNo. 29, 2018

View details
Critical InfrastructureLaw

Clean Energy Act 2011

The Clean Energy Act 2011 establishes the framework for implementing a carbon pricing mechanism in Australia. It includes provisions for covered entities, emission obligations, and limits on emissions units.

Parliament of Australia • Australia

View details
Critical InfrastructureLaw

Renewable Energy (Electricity) Act 2000

The Renewable Energy (Electricity) Act 2000 establishes a legal framework to encourage the generation of electricity from renewable energy sources in Australia. It creates a system for renewable energy certificates and mandates a Renewable Power Percentage to ensure participation by electricity retailers.

Australian Government • Australia

View details
Critical InfrastructureLaw

Ozone Protection and Synthetic Greenhouse Gas Management Act 1989

The Ozone Protection and Synthetic Greenhouse Gas Management Act 1989 is Australian legislation designed to manage the use, import, and export of ozone-depleting substances (ODS) and synthetic greenhouse gases (SGGs). It aligns with Australia's obligations under the Montreal Protocol, emphasizing environmental protection through licensing, quotas, and controls on substances and equipment.

Australian Government • Australia • v7, 1989

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call