Acts Online
GT Shield

Civil Aviation Act, 2009 (Act No. 13 of 2009)

Regulations

Civil Aviation Regulations, 2011

Part 111 : Aviation Security

111.01.19 Measures relating to cyber threats

 

(1) A designated airport, air carrier, air traffic and navigation service provider, catering store, and supplies service provider shall—
(a) identify and secure its critical information, communication technology systems and data used for aviation purposes to ensure cybersecurity, privacy, and resilience as prescribed in Document SA-CATS 111;
(b) ensure that its cybersecurity measures are in accordance with a risk assessment and threat levels;
(c) implement cybersecurity measures as prescribed in Document SA-CATS 111; and
(d) report cybersecurity incidents as prescribed in Document SA-CATS 111 to the Director within 48 hours of becoming aware of an incident.

[Regulation 111.01.19(1) substituted by section 18(a) of the Thirty-Third Amendment of the Civil Aviation Regulations, 2026, Notice No. 7844, GG55226, dated 21 August 2026 and shall come into operation upon Publication in the Government Gazette, save for Part 92, which shall come into operation upon the Proclamation by the President of the Civil Aviation Amendment Act, 2021 (Act No. 22 of 2021]

 

(2) A designated air port, air carrier of a scheduled service, air traffic and navigation service provider and catering stores and catering supplies service provider shall develop procedures for—
(a) testing of cyber-security;
(b) cyber-security response;
(c) cyber-security incident analysis; and
(d) cyber-security incident reporting.

 

(3) A cyber-security incident shall be reported to the Director within 48  hours of occurrence.

 

[Regulation 111.01.19 inserted by regulation 29(d) of Notice No. R. 1503, GG45491, dated 15 November 2021 (Twenty-First Amendment of the Civil Aviation Regulations, 2021)]