Aviation Cybersecurity: What the TSA Directive Means for Part 135 Operators
Cybersecurity compliance is no longer optional — penalties start at $13,910 per day.
What the TSA cybersecurity directive covers
The TSA cybersecurity amendment applies to Part 121, 135, 125, and 129 operators. It requires an approved cybersecurity implementation plan, continuous monitoring and detection procedures, patch management obligations, and incident reporting protocols.
Many Part 135 operators do not realize they fall under this directive. If you hold a Part 135 certificate, you likely have cybersecurity compliance obligations.
Building your cybersecurity implementation plan
Your plan must identify critical systems (operational technology, flight planning systems, communication systems, customer data systems), assess cybersecurity risks, define protective measures, and establish incident response procedures.
For small Part 135 operators, critical systems typically include: your flight scheduling/dispatch software, EFB systems, satellite tracking, crew communication platforms, and customer booking systems.
Continuous monitoring and patch management
The directive requires continuous monitoring of critical systems for cybersecurity threats. This does not necessarily mean enterprise-grade SOC monitoring — but it does require documented procedures for detecting and responding to anomalies.
Patch management means keeping all critical software systems updated with security patches within defined timelines. Document your patch management process and maintain evidence of patch application.
Penalty exposure for non-compliance
TSA cybersecurity violations carry penalties up to $13,910 per day per violation. For an operator without an approved implementation plan, daily exposure can accumulate rapidly.
The TSA conducts compliance reviews and expects operators to demonstrate not just a written plan, but active implementation with evidence of monitoring, patching, and incident response capability.
Compliance warning
Penalties of $13,910 per day per violation can accumulate to six figures within weeks. Do not delay cybersecurity compliance planning.
Navlyt tracks this automatically
Turn recurring compliance work into automated tasks and evidence trails.
Start Free TrialKey takeaways
- The TSA cybersecurity directive applies to Part 135 operators.
- An approved implementation plan covering critical systems is required.
- Continuous monitoring and patch management must be documented.
- Penalties start at $13,910 per day per violation.
- Identify your critical systems and build your plan now.
Author
Navlyt Editorial Team
Navlyt
Written by the Navlyt team. Guides reference the specific regulations they discuss and are general information, not legal or regulatory advice — confirm requirements for your operation with your FSDO or compliance officer.
Was this helpful?
Stay ahead of regulatory changes
Stay ahead of regulatory changes and compliance deadlines.
Related posts
The Complete Part 135 Compliance Checklist for Charter Operators (2026)
A complete checklist of FAA Part 135 compliance requirements for on-demand charter operators covering training, documentation, aircraft, and crew currency.
How to Prepare for an FSDO Audit: A Step-by-Step Guide for Part 135 Operators
Step-by-step guide to preparing your Part 135 operation for an FAA FSDO audit including what inspectors look for, common findings, and readiness controls.
FAA SMS Mandate for Part 135: Your Implementation Timeline and Compliance Roadmap
A practical roadmap for Part 135 operators facing the FAA SMS mandate — covering the four pillars, phased timeline, documentation, and how to build SMS without enterprise resources.