Skip to main content
Regulatory Updates

Aviation Cybersecurity: What the TSA Directive Means for Part 135 Operators

Cybersecurity compliance is no longer optional — penalties start at $13,910 per day.

Navlyt Editorial TeamNavlyt Editorial TeamNavlytPublished 2/25/2026Updated 4/7/20268 min read
Share: LinkedIn X
Aviation Cybersecurity: What the TSA Directive Means for Part 135 Operators

What the TSA cybersecurity directive covers

The TSA cybersecurity amendment applies to Part 121, 135, 125, and 129 operators. It requires an approved cybersecurity implementation plan, continuous monitoring and detection procedures, patch management obligations, and incident reporting protocols.

Many Part 135 operators do not realize they fall under this directive. If you hold a Part 135 certificate, you likely have cybersecurity compliance obligations.

Building your cybersecurity implementation plan

Your plan must identify critical systems (operational technology, flight planning systems, communication systems, customer data systems), assess cybersecurity risks, define protective measures, and establish incident response procedures.

For small Part 135 operators, critical systems typically include: your flight scheduling/dispatch software, EFB systems, satellite tracking, crew communication platforms, and customer booking systems.

Continuous monitoring and patch management

The directive requires continuous monitoring of critical systems for cybersecurity threats. This does not necessarily mean enterprise-grade SOC monitoring — but it does require documented procedures for detecting and responding to anomalies.

Patch management means keeping all critical software systems updated with security patches within defined timelines. Document your patch management process and maintain evidence of patch application.

Penalty exposure for non-compliance

TSA cybersecurity violations carry penalties up to $13,910 per day per violation. For an operator without an approved implementation plan, daily exposure can accumulate rapidly.

The TSA conducts compliance reviews and expects operators to demonstrate not just a written plan, but active implementation with evidence of monitoring, patching, and incident response capability.

Compliance warning

Penalties of $13,910 per day per violation can accumulate to six figures within weeks. Do not delay cybersecurity compliance planning.

Navlyt tracks this automatically

Turn recurring compliance work into automated tasks and evidence trails.

Start Free Trial

Key takeaways

  • The TSA cybersecurity directive applies to Part 135 operators.
  • An approved implementation plan covering critical systems is required.
  • Continuous monitoring and patch management must be documented.
  • Penalties start at $13,910 per day per violation.
  • Identify your critical systems and build your plan now.

Author

Navlyt Editorial Team

Navlyt Editorial Team

Navlyt

Written by the Navlyt team. Guides reference the specific regulations they discuss and are general information, not legal or regulatory advice — confirm requirements for your operation with your FSDO or compliance officer.

Was this helpful?

Stay ahead of regulatory changes

Stay ahead of regulatory changes and compliance deadlines.

No spam. Unsubscribe anytime.

Related posts