EU drone FOD reporting is now mandatory under European Union law for the first time. Drone operators must report foreign object debris and poor surface conditions on takeoff and landing surfaces as mandatory aviation occurrences. The expanded framework — published in late July — places UAS operators on equal footing with airlines and airports.
Commission Implementing Regulation (EU) 2026/1821 was adopted July 27 and published in the EU Official Journal on July 28, 2026. It amends the classified-occurrence list in Implementing Regulation (EU) 2015/1018. The regulation enters into force 20 days after publication. It applies directly across all EU member states without national transposition.
EU Drone FOD Reporting: What’s New
The regulation adds a dedicated Annex VI covering unmanned aircraft systems (UAS). This marks the first time drones have received their own mandatory reporting category in the EU’s occurrence framework.
Under the new rules, a UAS operator must file a mandatory report when “Foreign Object Damage/Debris (FOD) or poor surface conditions on the take-off and landing surface” is encountered. That obligation covers all phases of UAS operation where the aircraft interacts with prepared surfaces — at aerodromes or vertiports.
Notably, FOD appears under two separate UAS reporting categories: operations from aerodromes or vertiports, and environmental or external-environment occurrences. Both entries carry mandatory reporting status.
That mirrors existing requirements for manned aircraft and ground handlers. The new annex extends the same obligation to UAS operators with no exemption for commercial operations at certified aerodromes.
U-Space Airspace Coverage
The regulation also introduces a new category of U-space occurrences. U-space refers to EU-designated airspace volumes where drone operations may only be conducted with support from U-Space Service Providers (USSPs).
Reportable U-space events include loss of situational awareness and encounters between manned and unmanned aircraft. Failure to comply with flight authorisations also triggers mandatory reporting. So do service disruptions from USSPs that endanger any aircraft or person.
Regulators are treating U-space incidents with the same safety-data priority historically reserved for controlled airspace. That shift reflects Europe’s push to integrate commercial drone operations safely into managed airspace as corridors proliferate across cities and logistics networks.
Cybersecurity Incidents Now Mandatory
One of the more consequential changes extends beyond drones. Cybersecurity incidents that cause “abnormal behaviour of a system” are now explicitly mandatory across several aviation domains.
The regulation specifically names malware infections and Distributed Denial-of-Service (DDoS) attacks as triggering events. Compromised information or data also qualifies — but only when these incidents result in actual system anomalies.
That classification reflects a regulatory shift: information security failures are now treated as safety failures, not merely IT incidents.
What the Framework Change Means for Operators
The underlying architecture dates to 2014. Regulation (EU) No 376/2014 established the harmonized EU-wide occurrence-reporting system. Implementing Regulation (EU) 2015/1018 defined the classified list of what must be reported. Regulation 2026/1821 is the first substantial expansion of that list to cover unmanned systems.
The scope is limited to higher-risk UAS operations requiring a design certificate or declaration. Recreational flights below certification thresholds are not affected.
According to the regulation’s recitals, mandatory reporting obligations now extend to UAS operators, remote pilots, manufacturers, maintenance organisations, air navigation service providers, aerodromes, and ground handlers.
All affected organisations should review internal reporting procedures, safety management system taxonomies, and staff training before the regulation takes effect.
Security Reporting Transitional Period
The regulation also reorganizes certain aviation security occurrences. Bomb threats, hijacking incidents, and selected aerodrome or passenger-related events will transition toward a dedicated EU security-reporting framework.
A transitional period runs until December 31, 2027. During that window, those events remain subject to mandatory reporting under the current structure.
The 2025 Leipzig/Halle Airport incident illustrated the reporting gap regulators are now closing. An explosive drone was found on an apron as a cargo aircraft struck an unidentified tarmac object. FODNews covered that incident in detail.
What Airport and Drone Operators Should Do Now
The regulation enters into force 20 days after its July 28, 2026 publication date. Compliance windows are short. EASA’s occurrence reporting page will reflect the 2026/1821 amendments as they take effect.
Operators should audit SMS documentation for UAS-specific occurrence categories and update reporting forms to include new UAS, U-space, and cybersecurity fields. Remote pilots at certified aerodromes — especially those conducting scheduled drone deliveries or inspections — should be briefed on the FOD reporting obligation.
The full text of Implementing Regulation (EU) 2026/1821 is available on EUR-Lex.
Sources
- EUR-Lex — Commission Implementing Regulation (EU) 2026/1821 (July 28, 2026)
- EASA — Occurrence Reporting regulatory framework
- EASA — Regulation (EU) No 376/2014 on occurrence reporting in civil aviation
- Unmanned Airspace — “European Union updates incident mandatory reporting mechanism, extending drones and U-space coverage” (August 2, 2026)