My bookmarksSign up free
Source

Commission Implementing Regulation (EU) 2019/1583 of 25 September 2019 amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures (Text with EEA relevance.)

Commission Implementing Regulation (EU) 2019/1583 of 25 September 2019 amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures (Text with EEA relevance.)

Implementing Regulation (EU) 2019/1583 · Regulation · 3 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Article 1

Open ↗

The Annex to Implementing Regulation (EU) 2015/1998 is amended in accordance with the Annex to this Regulation.

Supplementary provisions

ANNEXSupplementary provisions

Open ↗

ANNEX The Annex to Implementing Regulation (EU) 2015/1998 is amended as follows: (1) The following point 1.0.6 is added: ‘1.0.6. The appropriate authority shall establish and implement procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other national authorities and agencies, airport operators, air carriers and other entities concerned, to conduct effective security risk assessments relating to their operations.’; (2) The following point 1.7 is added: ‘1.7   IDENTIFICATION AND PROTECTION OF CIVIL AVIATION CRITICAL INFORMATION AND COMMUNICATION TECHNOLOGY SYSTEMS AND DATA FROM CYBER THREATS 1.7.1. The appropriate authority shall ensure that airport operators, air carriers and entities as defined in the national civil aviation security programme identify and protect their critical information and communications technology systems and data from cyber-attacks which could affect the security of civil aviation. 1.7.2. Airport operators, air carriers and entities shall identify in their security programme, or any relevant document cross-referenced in the security programme, the critical information and communications technology systems and data described in 1.7.1. The security programme, or any relevant document cross-referenced in the security programme shall detail the measures to ensure the protection from, detection of, response to and recovery from cyber-attacks, as described in 1.7.1. 1.7.3. The detailed measures to protect such systems and data from unlawful interference shall be identified, developed and implemented in accordance with a risk assessment carried out by the airport operator, air carrier or entity as appropriate. 1.7.4. Where a specific authority or agency is competent for measures related to cyber threats within a single Member State, this authority or agency may be designated as competent for the coordination and/or monitoring of the cyber-related provisions in this Regulation. 1.7.5. Where airport operators, air carriers and entities as defined in the national civil aviation security programme are subjected to separate cybersecurity requirements arising from other EU or national legislation, the appropriate authority may replace compliance with the requirements of this regulation by compliance with the elements contained in the other EU or national legislation. The appropriate authority shall coordinate with any other relevant competent authorities to ensure coordinated or compatible oversight regimes.’; (3) Point 11.1.2 is replaced by the following: ‘11.1.2. The following personnel shall have successfully completed an enhanced or a standard background check: a) Persons being recruited to implement, or to be responsible for the implementation of, screening, access control or other security controls elsewhere than a security restricted area; b) Persons having unescorted access to air cargo and mail, air carrier mail and air carrier material, in-flight supplies and airport supplies to which the required security controls have been applied; c) Persons having administrator rights or unsupervised and unlimited access to critical information and communications technology systems and data used for civil aviation security purposes as described in 1.7.1 in accordance with the national aviation security programme, or having been otherwise identified in the risk assessment in accordance with 1.7.3. Unless otherwise specified in this Regulation, whether an enhanced or a standard background check has to be completed shall be determined by the appropriate authority in accordance with applicable national rules.’; (4) The following point 11.2.8 is added: ‘11.2.8.   Training of persons with roles and responsibility related to cyber threats 11.2.8.1. Persons implementing the measures as laid down in point 1.7.2 shall have the skills and aptitudes required to carry out their designated tasks effectively. They shall be made aware of relevant cyber risks on a need-to-know basis. 11.2.8.2. Persons having access to data or systems shall receive appropriate and specific job related training commensurate with their role and responsibilities, including being made aware of relevant risks where their job function requires this. The appropriate authority, or the authority or agency as laid down in point 1.7.4 shall specify or approve the content of the course.’.

Other acts of the same type
Commission Implementing Regulation (EU) 2026/355 of 18 February 2026 renewing the approval of the active substance pyrimethanil in accordance with Regulation (EC) No 1107/2009 of the European Parliament and of the Council and amending Commission Implementing Regulation (EU) No 540/2011Commission Implementing Regulation (EU) 2026/356 of 18 February 2026 concerning the authorisation of a preparation of endo-1,4-beta-xylanase produced with Bacillus subtilis LMG S-15136 as a feed additive for gestating sows (holder of authorisation: Puratos NV)Commission Implementing Regulation (EU) 2026/357 of 18 February 2026 amending Implementing Regulation (EU) 2023/2200 as regards administrative changes to the Union authorisation of the biocidal product family HCl Disinfecting Toilet Bowl CleanerCommission Implementing Regulation (EU) 2026/398 of 18 February 2026 amending Implementing Regulation (EU) No 686/2012 as regards the allocation to Member States, for the purposes of the renewal procedure, of the evaluation of metconazole and quinolin-8-olCommission Implementing Regulation (EU) 2026/400 of 18 February 2026 granting a Union authorisation for the biocidal product family CHLOROCRESOL BASED PRODUCTS-CID Lines NV in accordance with Regulation (EU) No 528/2012 of the European Parliament and of the CouncilCommission Implementing Regulation (EU) 2026/347 of 17 February 2026 imposing a definitive anti-dumping duty on imports of sweetcorn originating in the Kingdom of Thailand, following an expiry review pursuant to Article 11(2) of Regulation (EU) 2016/1036 of the European Parliament and of the CouncilCommission Implementing Regulation (EU) 2026/348 of 17 February 2026 concerning the authorisation of a preparation of Lacticaseibacillus huelsenbergensis DSM 115424 as a feed additive for all animal speciesCommission Implementing Regulation (EU) 2026/349 of 17 February 2026 laying down technical information for the calculation of technical provisions and basic own funds for reporting with reference dates from 31 December 2025 until 30 March 2026 in accordance with Directive 2009/138/EC of the European Parliament and of the Council on the taking-up and pursuit of the business of Insurance and ReinsuranceCommission Implementing Regulation (EU) 2026/362 of 17 February 2026 making imports of benzyl alcohol originating in the People’s Republic of China subject to registration with a view to allowing the levy of anti-dumping duties on the imports subject to registrationCouncil Regulation (EU) 2026/384 of 17 February 2026 amending Regulation (EC) No 314/2004 concerning restrictive measures in view of the situation in ZimbabweCommission Regulation (EU) 2026/340 of 16 February 2026 correcting certain language versions of Regulation (EU) No 231/2012 laying down specifications for food additives listed in Annexes II and III to Regulation (EC) No 1333/2008 of the European Parliament and of the CouncilCommission Implementing Regulation (EU) 2026/329 of 13 February 2026 amending Implementing Regulation (EU) 2015/2447 as regards adding the Republic of Moldova and Montenegro to the list of countries in the guarantor’s undertakings for transit

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

Contents

What to look at next