FAA Cybersecurity Framework for Aviation
What is FAA Cybersecurity Framework for Aviation?
The 'FAA Cybersecurity Framework for Aviation' is not a single FAA-published document but a DISTRIBUTED U.S. aviation cybersecurity policy stack maintained by the Federal Aviation Administration (FAA) covering: (a) AIRCRAFT cybersecurity airworthiness under 14 CFR Part 25 + Part 23/27/29 (Special Conditions historically + Notice of Proposed Rulemaking 2024 NPRM to codify cybersecurity as a standing airworthiness requirement); (b) ADVISORY CIRCULARS AC 119-1 (Cybersecurity for Operators), AC 25-21 (Aircraft Network Security Architecture), AC 23-XX series (general aviation), AC 27-XX series (rotorcraft); (c) RTCA / EUROCAE INDUSTRY STANDARDS DO-326A / ED-202A (Airworthiness Security Process Specification), DO-356A / ED-203A (Airworthiness Security Methods + Considerations), DO-355A / ED-204A (Information Security Guidance for Continuing Airworthiness), ARINC 811 (Aircraft Network Security Architecture); (d) AIR TRAFFIC MANAGEMENT cybersecurity through the FAA Cybersecurity Strategy + the National Airspace System (NAS) cybersecurity program; (e) AIRPORT cybersecurity coordinated with TSA + DOT cybersecurity initiatives; (f) UAS / DRONE cybersecurity under 14 CFR Part 107 + Remote ID rule + UAS Traffic Management (UTM); (g) SUPPLY CHAIN cybersecurity for aviation including alignment with CISA Cyber Performance Goals (CPGs) + NIST SSDF + Executive Order 14028; (h) FAA INTERNAL information security via FAA Order 1370.123A; (i) INDUSTRY COLLABORATION via the Aviation Cybersecurity Working Group (ACWG) + the Aviation Cyber Initiative (ACI) led by FAA + DOT + DHS / CISA + DOD. It comprises 15 controls organised across 7 domains, and applies in the United States (FAA).
How FAA Cybersecurity Framework for Aviation maps to other frameworks
All 15 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains FAA Cybersecurity Framework for Aviation groups its controls into
Where FAA Cybersecurity Framework for Aviation overlaps with the standards you already hold
Where to get trained on FAA Cybersecurity Framework for Aviation
2 courses in the catalogue cover FAA Cybersecurity Framework for Aviation directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What FAA Cybersecurity Framework for Aviation means in your sector
What FAA Cybersecurity Framework for Aviation means for your job
Questions people ask about FAA Cybersecurity Framework for Aviation
What is FAA Cybersecurity Framework for Aviation?
How many controls does FAA Cybersecurity Framework for Aviation have?
Where does FAA Cybersecurity Framework for Aviation apply?
What frameworks does FAA Cybersecurity Framework for Aviation map to?
How do I get started with FAA Cybersecurity Framework for Aviation compliance?
Query FAA Cybersecurity Framework for Aviation programmatically
FAA Cybersecurity Framework for Aviation, its 15 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FAA Cybersecurity Framework for Aviation API reference and MCP config →What FAA Cybersecurity Framework for Aviation requires, control by control
Each page carries the requirement text for one FAA Cybersecurity Framework for Aviation control and what an assessor expects to see as evidence.
- FAA-CSA-AC119-1 Cybersecurity for Operators (FAA AC 119-1)
- FAA-CSA-GOVERNANCE FAA Cybersecurity Strategy, Governance and Order 1370.123A
- FAA-CSA-INTERNATIONAL Coordination with EASA Part-IS, ICAO AVSEC and International Cybersecurity Frameworks
- FAA-CSA-NAS National Airspace System (NAS) and Air Traffic Management Cybersecurity
- FAA-CSA-OPERATOR-CYBER-IR Aviation Cyber Incident Response and Reporting to FAA and NTSB
- FAA-CSA-SUPPLYCHAIN Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment)
How ready are you for FAA Cybersecurity Framework for Aviation?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.