Industry Guide Updated: August 2026

Does the Cyber Resilience Act Apply to Aviation Systems?

Learn if the EU CRA applies to Aviation Systems, what the core compliance requirements are, and how to start preparing your engineering teams automatically.

Core Definition

It Depends. Typically exempt if governed by EASA regulations. Cockpit avionics under EASA rules are typically CRA-exempt, but airline booking or ground-crew scheduling software is ordinary CRA-scoped software. If you do not fall into an explicit exemption, your Aviation Systems will be subjected to the CRA's strict requirements.

Key Compliance Steps for Aviation Systems

  1. Determine Classification: Check if your Aviation Systems falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
  2. Perform Risk Assessment: Map out the attack surface for your software and document the mitigations for the "secure by design" requirement.
  3. Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
  4. Generate an SBOM: Ensure all dependencies used in your Aviation Systems are documented in a machine-readable Software Bill of Materials.
  5. Avoid the Common Pitfall: Applying the EASA exemption too broadly to non-flight-critical systems that share the same corporate codebase.

How This Plays Out in Practice

Cockpit avionics under EASA rules are typically CRA-exempt, but airline booking or ground-crew scheduling software is ordinary CRA-scoped software.

What to Watch For

Applying the EASA exemption too broadly to non-flight-critical systems that share the same corporate codebase.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Aviation Systems.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.