The most significant expansion of cybersecurity obligations in Irish aviation is confirmed by the IAA 2025 Annual Report, published June 2026. EU Part-IS information security regulations became applicable to most Irish aviation entities in Q4 2025 and Q1 2026. The NIS2 Directive will extend obligations to more entities, and the Critical Entities Resilience Directive will apply to some — a step-change in cybersecurity obligations for airports, airlines, aircraft maintenance organisations, and ATM providers.

These new obligations warrant an urgent reading from aviation executives. Cybersecurity is identified in the IAA 2025 Annual Report as one of three principal risks, alongside regulatory failure and geopolitical disruption. The case for treating this as a board-level input rests on the scale of digital integration across the Irish aviation industry: from passenger ticketing and airline finance to the specialised ATM and aircraft maintenance engineering platforms on which safe operations depend.

Part-IS is the most actionable framework. It applies across flight operations, airworthiness, aerodromes, and air traffic services. The IAA has already implemented European cybersecurity requirements across its Aerodromes Division. The IAA is actively assisting regulated entities in adopting the new rules. Appropriate resilience measures must be demonstrably in place — this standard of operational excellence in information security is now a regulatory baseline, not a best practice aspiration.

The NIS2 Directive and Critical Entities Resilience Directive extend the cybersecurity perimeter beyond NIS1. When transposed into Irish law, they will require a broader cohort of aviation entities to demonstrate cybersecurity resilience, incident reporting, and supply chain security governance. The EASA Management Board Advisory Body discussed cybersecurity at all three 2025 meetings, confirming EU aviation regulators regard the threat as systemic and escalating. For Irish aviation operations management, cybersecurity investment is no longer optional.

The IAA's digital transformation illustrates the dual character of aviation digitisation. The IAA's project, completed in 2025, processes €5.3 million in online payments, has issued 57,000 digital licences and certificates, and handled 874,000 user messages, including certificates for aircraft maintenance aircraft maintenance licences, drone operator registrations, and pilot certifications. Every transaction is a potential target. Airport management and aviation technology operations are fundamentally digital — and system security is inseparable from aviation safety.

Three priorities follow. First, every Irish aviation entity in scope of Part-IS should have completed a gap analysis and be executing a remediation plan. Second, NIS2 transposition timelines should be tracked, as the extended scope will require some organisations to build cybersecurity governance functions they currently lack. Third, workforce development in aviation cybersecurity should be treated as a pipeline priority alongside the more widely discussed shortages in pilots and aircraft maintenance engineering.

The IAA 2025 Annual Report is direct: digitisation brings simplified processes, access to new markets, and improved competitiveness — but also creates new and escalating cybersecurity risks. For those leading the Irish aviation industry — across airlines, airports, MRO providers, lessors, and the wider aviation technology ecosystem — Part-IS, NIS2, and the Critical Entities Resilience Directive are the regulatory architecture of aviation excellence in a connected digital world.