Explanatory Note To Ed Decision 2020-006-r
Explanatory Note To Ed Decision 2020-006-r
Explanatory Note To Ed Decision 2020-006-r
Aircraft cybersecurity
CS-25 Amendment 25 — CS-27 Amendment 7 — CS-29 Amendment 8
CS-APU Amendment 1 — CS-E Amendment 6 — CS-ETSO Amendment 15
CS-P Amendment 2— AMC-20 Amendment 18 — AMC and/GM to CS-23
AMC/GM to Part 21
RELATED NPA/CRD: 2019-01 — RMT.0648
EXECUTIVE SUMMARY
The objective of this Decision is to mitigate the potential effects of cybersecurity threats on safety. Such threats
could be the consequences of intentional unauthorised acts of interaction with the aircraft on-board electronic
networks and systems.
This Decision issues amendments to CS-25, CS-27, CS-29, CS-APU, CS-E, CS-ETSO, CS-P, and to the related
acceptable means of compliance (AMC) and/or guidance material (GM), together with AMC-20, AMC/GM to
CS-23 and AMC/GM to Part 21. The aim of the amendments is to introduce cybersecurity provisions into the
relevant certification specifications (CSs), taking into account:
— the existing special conditions (SCs), and
— the recommendations of the Aircraft Systems Information Security/Protection (ASISP) Working Group of the
Aviation Rulemaking Advisory Committee (ARAC)
by following a proportional approach.
The amendments are expected to contribute to the update of the European Union Aviation Safety Agency
(EASA) CSs and AMC and GM to reflect the state of the art of the protection of products and equipment against
cybersecurity threats. They are also expected to improve harmonisation with the Federal Aviation
Administration (FAA) regulations. Overall, they would improve safety, would have neither social nor
environmental impact, and would have a negative-to-neutral economic impact.
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 1 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
Table of contents
Table of contents
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 2 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
1. About this Decision
1 Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of
civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005,
(EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European
Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European
Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1) (https://eur-
lex.europa.eu/legal-content/EN/TXT/?qid=1535612134845&uri=CELEX:32018R1139).
2 EASA is bound to follow a structured rulemaking process as required by Article 115(1) of Regulation (EU) 2018/1139.
Such a process has been adopted by the EASA Management Board (MB) and is referred to as the ‘Rulemaking Procedure’.
See MB Decision No 18-2015 of 15 December 2015 replacing Decision 01/2012 concerning the procedure to be applied
by EASA for the issuing of opinions, certification specifications and guidance material (http://www.easa.europa.eu/the-
agency/management-board/decisions/easa-mb-decision-18-2015-rulemaking-procedure).
3 https://www.easa.europa.eu/document-library/general-publications?publication_type%5B%5D=2467
4 https://www.easa.europa.eu/document-library/terms-of-reference-and-group-compositions/tor-rmt0648
5 In accordance with Article 115 of Regulation (EU) 2018/1139, and Articles 6(3) and 7 of the Rulemaking Procedure.
6 https://www.easa.europa.eu/document-library/notices-of-proposed-amendment/npa-2019-01
7 https://www.easa.europa.eu/document-library/comment-response-documents
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 3 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
2. In summary — why and what
8 Commission Regulation (EU) No 748/2012 of 3 August 2012 laying down implementing rules for the airworthiness and
environmental certification of aircraft and related products, parts and appliances, as well as for the certification of design
and production organisations (OJ L 224, 21.8.2012, p. 1) (https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1579001172632&uri=CELEX:32012R0748).
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 4 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
2. In summary — why and what
The specific objective of this Decision is to take into account the interdependencies between aviation
safety and security in order to mitigate the safety effects caused by potential cybersecurity threats.
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 5 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
3. How we monitor and evaluate the rules
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 6 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
4. References
4. References
4.1. Related regulations
n/a
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 7 of 8
An agency of the European Union
European Union Aviation Safety Agency Explanatory Note to Decision 2020/006/R
4. References
TE.RPRO.00058-008 © European Union Aviation Safety Agency. All rights reserved. ISO 9001 certified.
Proprietary document. Copies are not controlled. Confirm revision status through the EASA intranet/internet. Page 8 of 8
An agency of the European Union