Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FAA has proposed cybersecurity airworthiness requirements for transport-category airplanes, engines and propellers, but a final rule and effective date are not confirmed. The proposal, RIN 2120-AL94, was published on August 21, 2024; a March 2026 target in the federal rulemaking agenda was a projected milestone, not proof that the rule took effect.

When will the FAA aircraft cybersecurity rule take effect?

There is no confirmed effective date. The FAA published its “Equipment, Systems, and Network Information Security Protection” notice of proposed rulemaking (NPRM) on August 21, 2024. The Unified Agenda later listed March 2026 as a target for a final rule, but that schedule entry did not establish that a rule was issued. As of the FAA rulemaking index update of September 15, 2026, and a targeted Federal Register search, no final rule for RIN 2120-AL94 had been located. Check the Federal Register notice and FAA rulemaking records for an authoritative update before treating the proposal as in force.

The NPRM’s comment period ended October 21, 2024. That date marked the close of comments, not the start of compliance obligations.

Which aircraft products would the proposal cover?

The proposal would establish cybersecurity requirements for transport-category airplanes and for engine-control and propeller-control systems. It would affect new products and changed products undergoing certification; it is not framed as a general cybersecurity rule for every aircraft already in service.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Proposed regulation Product or system
14 CFR §25.1319 Airplane equipment, systems and networks
14 CFR §33.28(n) Engine-control systems
14 CFR §35.23(f) Propeller-control systems

The FAA describes the intended scope and regulatory amendments in the NPRM. The proposal addresses certification of these product categories, rather than operational cybersecurity requirements for airlines or a universal mandate to retrofit the existing fleet.

What cybersecurity evidence would manufacturers need to provide?

Applicants would need to identify and assess risks from intentional unauthorized electronic interactions (IUEI), then mitigate risks as necessary to protect safety, functionality and continued airworthiness. In practical terms, the proposed certification showing would connect the product’s architecture and electronic interfaces to plausible threat conditions and the protections chosen to address them.

  • Analyze the architecture and interfaces: consider equipment, systems and networks separately and in relation to one another, including internal and external interfaces.
  • Evaluate relevant threats: assess possible IUEI conditions, their potential severity and the likelihood of exploitation.
  • Apply protections: use technical protections, layered defenses or process controls as needed to address identified risks.
  • Address continued airworthiness: provide procedures and instructions that preserve security protections after certification.

The proposed §25.1319 states that airplane equipment, systems and networks “must be protected from intentional unauthorized electronic interactions that may result in adverse effects on the safety of the airplane.” That is a proposed standard, not a currently effective requirement. The NPRM discusses corresponding provisions for engine and propeller control systems.

What counts as an intentional unauthorized electronic interaction?

The proposal focuses on intentional electronic activity without authorization that could adversely affect aircraft safety. The NPRM’s description encompasses unauthorized access, use, disclosure, denial, disruption, modification or destruction involving information or aircraft-system interfaces. It distinguishes these interactions from physical attacks and electromagnetic jamming.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This focus means the applicant’s assessment is not simply a checklist of internet-facing equipment. The proposed analysis includes internal as well as external interfaces and considers how systems interact, because an electronic pathway can matter even if it does not connect directly to a public network.

Why is the FAA proposing standardized requirements?

The FAA says increasingly networked aircraft architectures create vulnerabilities with potential airworthiness consequences. In the absence of a common set of codified criteria, the agency has relied on project-specific special conditions. The FAA argues that repeated, project-by-project requirements can vary across certification programs and authorities, making compliance more complex, costly and time-consuming.

The proposal would put recurring criteria into regulations, implement recommendations from the Aviation Rulemaking Advisory Committee’s Aircraft Systems Information Security/Protection (ASISP) working group, and bring FAA certification requirements closer to the corresponding European standards. The U.S. proposal is intended to standardize criteria while maintaining the safety level provided by existing special conditions, according to the DOT/FAA Unified Agenda entry.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does the proposal relate to EASA requirements?

EASA finalized related cybersecurity amendments on July 1, 2020, covering CS-25 Amendment 25, CS-E Amendment 6 and CS-P Amendment 2. The FAA says its proposal is intended to harmonize with these certification specifications. That is an alignment goal; it does not mean the U.S. NPRM itself is an EASA rule or that the two authorities’ certification processes are identical. The FAA describes the EASA amendments and harmonization objective in its proposal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.