What this answers, and who it’s for

You have a job you want a drone to do. Inspect a roof, survey a solar farm, photograph a construction site, map a field, film in a town centre. Somewhere between the idea and the first flight, someone tells you that you might need permission — and the moment you look it up you meet a wall of words written for people who already work in aviation.

This guide is the version we wish existed when we went through it ourselves. It answers four questions, in the order they actually come up:

  • Do the rules apply to what I want to do? Not every operation needs an authorisation. Some are allowed under simpler rules, and finding that out early saves you the rest of this page.
  • If they do, which route am I on? There is more than one way through, and they differ enormously in effort. Picking the wrong one is the most expensive mistake available at this stage.
  • What will I actually have to produce? Documents, mostly — describing how you operate, what could go wrong, and what you do about it.
  • How long does it take, and what makes it take longer?

It is written for someone with no aviation background, which means every term gets explained the first time it appears. Where the rules have a precise name for something, we use it — you will meet it again on the authority’s forms — but we say it in plain language first.

What it does not do

It cannot tell you that your application will be approved. That decision belongs to the aviation authority of the country you apply in, and nobody outside it can promise you the answer. What this guide can do is tell you what they are going to ask, so that what you send them is complete the first time.

It is also not legal advice, and it is not a substitute for reading the rules that apply to you. Every regulatory statement here names the instrument and the provision it comes from, so you can check any of it against the source.

One thing to know before you start

The framework is European and common across the EU: the term Specific category comes from the UAS Regulation — Regulation (EU) 2019/947 — where it is defined in Article 3(b). The same three categories, the same definitions, and broadly the same routes apply whether you are flying in Ireland, Estonia or Portugal.

Your national authority still adds to it. Countries publish their own conditions and their own alternative ways of meeting a requirement, and those do not automatically carry across borders. We come back to that near the end, once the common part makes sense — but it is worth knowing from the start that “what the EU rules say” and “what you will be asked for” are related, not identical.

What is on this page

The three categories, in plain language

European drone rules sort every flight into one of three buckets. Article 3 of the UAS Regulation names them, and Articles 4, 5 and 6 define them. They are not about how professional you are or what you charge. They are about how much harm the flight could do.

Open is the low-risk bucket. You need no permission before you fly: Article 3(a) says an Open operation is not subject to any prior operational authorisation, nor to a declaration by the operator before the operation takes place. That does not mean there are no rules — there are plenty, and they are the next section. It means nobody has to approve your operation before it happens.

Specific is the middle bucket, and it is where the rest of this guide lives. Article 3(b) says a Specific operation requires an operational authorisation issued by the competent authority — the aviation authority of the country you are registered in — or, in certain defined cases, a declaration the operator makes under Article 5(5). Most of the commercial work we are asked about lands here. Being in this bucket does not mean your operation is dangerous. It means the authority wants the case written down before you start.

Certified is the high-consequence bucket, and it is almost certainly not yours. It is built for aircraft-scale operations carrying people. Article 3(c) requires the aircraft itself to be certified under Delegated Regulation (EU) 2019/945, the operator to be certified, and, where applicable, the remote pilot to be licensed — the same machinery that sits behind a passenger aircraft. Article 6(1)(b) puts an operation here when it is conducted over assemblies of people, involves the transport of people, or involves carrying dangerous goods that may pose a high risk to others in an accident. Guidance to Article 6 is blunt about the second of those: the transport of people is always in the Certified category.

One nuance is worth having, because it is the single place the Certified boundary touches ordinary commercial work. Flying over a crowd does not automatically mean Certified. Guidance to Article 6 says that flying over assemblies of people with a system whose characteristic dimension is less than 3 metres may sit in the Specific category, unless the risk assessment concludes it belongs in Certified. At 3 metres or more, guidance to Article 3 treats it as always Certified.

What pushes an operation out of Open

The mechanism is simpler than it looks, and guidance to Article 3 states it directly: an operation does not belong to the Open category when at least one of the general criteria in Article 4 is not met — its own example is flying beyond visual line of sight — or when the detailed criteria for a subcategory are not met. Its second example is operating a 10 kg aircraft close to people when the relevant subcategory is limited to 4 kg.

So there is no scoring system and no borderline. One failed criterion moves you. These are the six general ones, from Article 4(1):

  • Class marking. The system belongs to one of the classes set out in Delegated Regulation (EU) 2019/945 — the C0 to C6 labels you find on the box — or is privately built, or meets the conditions in Article 20. A drone bought before class marking took effect is the common case, and Article 20 is what decides it.
  • Weight. Maximum take-off mass of less than 25 kg.
  • Distance from people. The remote pilot keeps the aircraft a safe distance from people, and it is not flown over assemblies of people. That term is defined, and the definition is not what most people assume: Article 2(3) says an assembly of people means gatherings where persons are unable to move away due to the density of the people present. It is not a headcount. A busy market where nobody could step aside counts; twenty people spread across a field does not.
  • Visual line of sight. The remote pilot keeps the aircraft in sight at all times, with narrow exceptions for follow-me mode and for using an observer.
  • Height. The aircraft stays within 120 metres of the closest point of the surface of the earth. That last phrase matters when your ground is not flat: UAS.OPEN.010(2) says the measurement adapts to the terrain, so the 120 metres is measured from the hillside beneath the aircraft, not from where you are standing.
  • Nothing dropped, nothing dangerous. The aircraft carries no dangerous goods and does not drop any material. This one catches people out — see the agricultural example below.

If all six hold, you are in Open, and a second layer then applies. Article 4(2) divides Open into three subcategories — A1, A2 and A3 — and each sets its own limits on how close you may fly to people who are not part of your operation. The rules call them uninvolved persons, and the distinction does real work: your own briefed staff who are part of the operation are involved, while a member of the public crossing the car park is not.

A2 is the subcategory most commercial jobs bump into. UAS.OPEN.030(1) requires that the aircraft does not overfly uninvolved persons and that the operation takes place at a safe horizontal distance of at least 30 metres from them — reducible to a minimum of 5 metres when the aircraft has an active low-speed mode, after you have evaluated the weather, the aircraft’s performance and how well the overflown area is segregated. UAS.OPEN.030 also requires a class C2 aircraft and a remote-pilot certificate of competency obtained through a further theoretical examination.

A3 is the keep-well-away subcategory. UAS.OPEN.040 requires an area where the remote pilot reasonably expects that no uninvolved person will be endangered for the whole time of the operation, and a safe horizontal distance of at least 150 metres from residential, commercial, industrial or recreational areas.

One more trap before the examples. Even a flight that satisfies every criterion above can still be restricted, because Member States may define UAS geographical zones under Article 15 — areas where flying is limited, excluded or conditional regardless of which category you are in. National additions get their own section later.

Five worked examples

These are the shapes of job we are asked about most often. For each: where it usually lands, the one criterion that actually decides it, and what would flip it. They turn on EU-level rules, so they are country-neutral — but read the national section before acting on any of them.

“We want to photograph our own roofs twice a year”

A small industrial unit or warehouse. Your building, your yard, your schedule.

Usually Open, usually A2. The building sits in a commercial or industrial area, so A3’s 150-metre standoff is unavailable — there is nowhere to stand that far away. That leaves A2: a class C2 aircraft, the additional pilot certificate, and 30 metres from anyone not involved in the flight.

What flips it to Specific: not being able to control who is underneath. A shared car park, a public pavement along the fence, or a neighbouring unit whose staff come and go during the flight all break the 30-metre requirement. And if your aircraft predates class marking and Article 20 does not cover it, that alone is enough on its own.

“We want to survey a 40-hectare solar farm”

Panel-by-panel imagery across a large rural site, flown to a grid.

Usually Specific, and visual line of sight is what decides it. A site that size takes the aircraft further than you can genuinely see it, and Article 4(1)(d) makes no allowance for knowing roughly where it is. Doing it properly inside Open means repositioning repeatedly and flying many short missions instead of one.

What keeps it in Open: a small enough array, or accepting the repositioning. What settles it as Specific: needing to fly beyond visual line of sight as a matter of course. That is the exact example the guidance to Article 3 reaches for.

“We want monthly progress shots of a construction site”

A part-built structure, workers on site, usually in or near a town.

Usually Specific, because two criteria bite at once. The site is in a built-up area, so A3 is out. And a construction site has people on it who are not part of your flight — subcontractors, delivery drivers, inspectors — which makes A2’s 30 metres very hard to hold for the length of a flight over the structure.

What keeps it in Open: a site you can genuinely clear and control, briefed staff only, and a flight path that stays 30 metres from everyone else. Achievable on a quiet site, unrealistic on a busy one.

“We want to map our fields each spring”

Aerial mapping of farmland for crop health, drainage or yield planning.

Often Open, in A3 — the most likely of these five to stay there. Farmland is usually more than 150 metres from residential, commercial, industrial or recreational areas, and there are usually no uninvolved persons within range.

What flips it instantly: spraying. Article 4(1)(f) says the aircraft must not drop any material, so the moment the job means applying something to the crop rather than photographing it, the operation is out of Open however empty the field is. Field size can flip it too, through the same visual-line-of-sight limit as the solar farm.

“We want to film in the town centre for a client”

Street-level and elevated shots in a public place, with people around.

Specific, in practice. In a town centre you cannot reliably keep 30 metres from uninvolved people, and you certainly cannot undertake not to overfly them. Article 4(1)(c) rules out flying over assemblies of people in Open at all.

Where it gets more serious: if the shot genuinely requires flying over a crowd, you are at the Certified boundary described earlier — under 3 metres of characteristic dimension it may remain Specific subject to the risk assessment, and at 3 metres or more it is Certified, which is a different undertaking entirely.

The pattern across all five: what decides your category is almost never the aircraft, and almost never the purpose. It is where the people are, whether you can see the aircraft, and whether anything leaves it.

The four things every Specific operator needs

Whatever route you end up on, the same four things sit underneath it. None is optional, and the order matters — each one feeds the next.

Registration as a UAS operator. You register once, in one Member State, and that state’s authority is the one that authorises you: Article 5(1) says the authorisation comes from the competent authority in the Member State where the operator is registered. It is not a formality you can leave until later, because your operator registration number is one of the things the application itself has to carry (UAS.SPEC.030(3)(a)). Article 14 sets out who registers and how.

Remote pilot competency. Article 8(2) does something unusual here: rather than naming one qualification, it says the competencies are those set out in your operational authorisation, or in the standard scenario you declared under, or as defined by your operator certificate. In other words the requirement is specific to your operation, and you find out what it is as part of getting approved.

An operations manual — sometimes. UAS.SPEC.030(3)(e) requires one “when required by the risk and complexity of the operation”, not automatically. Its own section below covers what tips that.

An authorisation, or a declaration in its place. UAS.SPEC.030(1) is the default: before starting a Specific operation you obtain an operational authorisation from the national competent authority of your Member State of registration. There are exactly two exceptions — the declaration route below, and holding a light UAS operator certificate (LUC) with the appropriate privileges.

One more thing rides along: the application must confirm that appropriate insurance cover will be in place, where Union or national law requires it (UAS.SPEC.030(3)(f)).

The three routes, and how to tell which one you are on

This is where the effort differs by an order of magnitude, so it is worth getting right before you start writing anything.

Guidance to AMC1 Article 11 states the structure plainly: for some Specific operations, alternatives to carrying out a full risk assessment are offered. There are two of them, and everything else is the full assessment.

Route 1 — declare under a standard scenario (STS). A standard scenario is a predefined type of Specific operation for which the mitigating measures have already been worked out, so the authority can be satisfied with a declaration that you will apply them (Article 2(6)). Two are published, in Appendix 1 to the Annex:

  • STS-01 — a C5-marked aircraft, up to 3 m and 25 kg, flown within visual line of sight over a controlled ground area that may be in a populated area, up to 120 m.
  • STS-02 — a C6-marked aircraft, same size limits, flown beyond visual line of sight over a controlled ground area entirely inside a sparsely populated area, up to 2 km from the pilot with an airspace observer or 1 km without, up to 120 m.

A controlled ground area is the term for ground you can guarantee holds only people involved in your operation (Article 2(21)) — a closed site, not a cordon of optimism.

The practical prize is speed. Under UAS.SPEC.020 you submit the declaration, the authority verifies it is complete and confirms receipt without undue delay, and you are then entitled to start — there is no assessment to wait through. The catch is the class marking: STS-01 and STS-02 need a C5 or C6 aircraft, and if yours is not marked as one, this route is closed however well your operation otherwise fits.

Route 2 — apply against a predefined risk assessment (PDRA). A PDRA is a risk assessment somebody has already done for a shape of operation, which you adopt rather than repeat. Five are published as AMC to Article 11: PDRA-S01 and PDRA-S02, derived from the two STSs, and the more generic PDRA-G01, G02 and G03. The S-derived ones exist for a specific and useful reason — they let you fly an STS-shaped operation with an aircraft that lacks the class label the STS demands, a privately built machine being the obvious case.

Unlike a declaration, a PDRA is still an application for an authorisation. And the boundary is hard: if your operation does not fit completely within the PDRA’s limits, you are required to carry out a full risk assessment instead.

Route 3 — the full risk assessment. Everything that does not fit the first two. This is where the SORA comes in, and where the next two sections go.

How to tell which one you are on: work down the list, not up. Does the aircraft carry a C5 or C6 mark and does the operation fit an STS exactly? Declare. If not, does it fit inside a PDRA’s envelope completely? Apply on that. If neither, you are doing a full assessment — and knowing that on day one is worth a great deal, because the three routes ask for very different amounts of work.

Which SORA applies to you

This is the part most likely to be wrong wherever else you read it, so here is the verifiable version.

The risk assessment Article 11 demands can be done using the methodology in AMC1 Article 11 — which guidance describes as, essentially, the Specific Operations Risk Assessment developed by JARUS. But there are two acceptable means of compliance sitting side by side in the current rules, and both are live:

Carries Edition In the June 2026 EAR
AMC1 Article 11 JARUS SORA v2.5 September 2025 page 44
AMC1bis Article 11 JARUS SORA v2.0 December 2020 page 204

Both are carried by the same instrument — ED Decision 2025/018/R, AMC & GM to the UAS Regulation, Issue 1 Amendment 4, applicable 30 September 2025.

SORA 2.0 has not been withdrawn. It is retained in parallel, as AMC1bis, in the same consolidated rules that introduce 2.5. That single fact is the one most often reported wrongly — you will find guidance stating that 2.0 is the SORA, and guidance stating that everyone must now move to 2.5. On the current rules, neither is true: they are two acceptable means of complying with the same, unchanged Article 11. Guidance to AMC1 Article 11 goes further still and notes that other methodologies may be used as alternative means of compliance altogether — the SORA is an acceptable means, not the only conceivable one.

What actually differs, at the level that affects how much work you do:

  • The number of safety objectives. Under 2.5 you show compliance with 17 operational safety objectives, at a level of robustness set by your SAIL. Under 2.0 they run to #24.
  • How the ground risk is derived. In 2.5 the intrinsic ground risk class is scaled 1 to 10 from the aircraft’s maximum characteristic dimension and maximum speed, together with the population density at risk in the operational volume and ground risk buffer. A final ground risk class above 7 is outside the SORA’s scope altogether and belongs in the Certified category.

Who can stay where. If you already hold an authorisation, it was granted against whatever your authority accepted at the time, and the retention of AMC1bis is precisely what means an operation built on 2.0 still has a current acceptable means behind it. You are not left holding a method that no longer exists.

When migrating is worth it. The honest answer is that it usually is not worth doing on its own — it is worth doing when you were going to open the file anyway. UAS.SPEC.030(2) requires an application for an updated authorisation whenever there are significant changes to the operation or to its mitigation measures, and that is the moment the work is being done regardless. For a genuinely new application there is a practical argument for 2.5, as the current edition and the one the rules list first — but the authority you will apply to is the one to confirm that with, and it costs nothing to ask before you start writing.

What the risk assessment asks of you

The shape, not the arithmetic. Article 11 sets out what an operational risk assessment must actually contain, and it is more readable than its reputation.

It has to describe the operation, propose safety objectives, identify the risks on the ground and in the air, identify possible mitigations, and determine how robust those mitigations need to be (Article 11(1)).

The description is not a paragraph. Article 11(2) requires at least the nature of the activities; the operational environment and geographical area — including the population you would overfly, the terrain, the airspace types and volumes, and any geographical zone requirements; the complexity of the operation, including who plans and executes it and what competencies and technical means that takes; the technical features of the aircraft; and the competence of your personnel, including their roles, responsibilities, training and recent experience.

The risks get split in two. Article 11(4) asks for the unmitigated ground risk — whether you are flying within or beyond visual line of sight, the population density of the areas overflown, whether you would fly over an assembly of people, and the aircraft’s dimensions — and the unmitigated air risk, which turns on the airspace volume plus the volume your contingency procedures need, the class of that airspace, and the altitude, the controlled-or-not, aerodrome-or-not and urban-or-rural character of it.

Then Article 11(5) lists the kinds of mitigation available to you: containment measures for people on the ground, strategic limits on where and when you fly, the structure of the airspace itself, the ability to cope with adverse conditions, your own operational and maintenance procedures, the competence of your people, the risk of human error, and design features of the aircraft such as systems that limit the energy at impact.

The single most useful idea in the whole method is robustness, and it is worth understanding before you write a word. Robustness combines integrity — the safety gain a mitigation actually provides — with assurance, the proof that you achieved it. Each runs low, medium or high. And the rule that catches people is this: the robustness is always the lower of the two. Claim a high-integrity mitigation with only a declaration behind it and you have a low assurance, so you have a low robustness. A strong measure you cannot evidence buys you the level of your evidence, not the level of your claim.

Finally, a note on how the process actually runs. In the ten-step SORA, the competent authority gives a preliminary agreement on steps 2 to 9 before you compile the final safety portfolio. It is a conversation with checkpoints, not a document you post and hope for.

The operations manual

Two things about it are commonly got wrong, and they pull in opposite directions.

The first: it is not always required. UAS.SPEC.030(3)(e) asks for an operations manual “when required by the risk and complexity of the operation”. A simple operation on a well-understood route may not need one at all. What tips it is the same thing that drives everything else here — how much could go wrong, and how much of your answer depends on people doing the right thing consistently.

The second: when it is required, it is the document most likely to come back. Not because authorities are difficult, but because of what it has to do. Your risk assessment describes an operation and claims a set of mitigations. The manual is where those claims become procedures somebody follows on a Tuesday in poor light. If the two disagree — if the assessment credits a pre-flight check the manual does not contain, or the manual describes a crew of two where the assessment assumed three — that is visible, and it is the kind of gap that generates questions.

There is also a consequence people underestimate: you are held to your manual. A manual describing an operation you do not actually run is worse than no manual at all, because it becomes the standard you are measured against.

The manual does not travel alone. Alongside it, UAS.SPEC.030(3) requires your operator registration number, the name of your accountable manager, the risk assessment itself, the list of mitigation measures with enough detail for the authority to judge whether they are adequate, and confirmation of insurance where it is required. The application goes in on EASA Form 208; the authorisation, when it comes, arrives as EASA Form 209.

One genuine surprise, worth knowing before you over-prepare. Guidance to Article 12(2)(a) says that where the risk assessment classifies the robustness of your safety objectives and mitigations as low, the authority may issue the authorisation on your declaration of compliance — and that for a visual-line-of- sight operation classified up to SAIL II, it may validate only your compliance matrix and authorise the operation without receiving the evidence at all, including the operations manual.

Read that carefully, because the second half is the half that matters: the same guidance says the applicant remains responsible for complying with every requirement, for producing or obtaining the evidence, and for keeping it updated for the whole validity of the authorisation. Not being asked for the manual is not the same as not needing one.

Your country adds its own rules

Everything above is the common European layer. It is genuinely common — the categories, the criteria, the routes and the risk assessment are the same instrument everywhere in the EU. What differs is the layer your national authority puts on top, and there are three kinds of it.

Geographical zones. Article 15 lets Member States set UAS geographical zones, and Article 2(4) defines one as a portion of airspace established by the competent authority that facilitates, restricts or excludes UAS operations — to address risks relating to safety, privacy, protection of personal data, security or the environment. Note the first verb: a zone can also permit something, not only forbid it. These are national, they change, and they sit on top of whatever category you are in. A perfectly compliant Open flight can still be illegal in a zone.

Alternative means of compliance. National authorities publish their own alternative ways of satisfying a requirement, for particular problems. They are worth hunting for, because an alternative aimed squarely at your situation can be considerably cheaper than the general route.

The Netherlands’ aviation authority, for example, published an alternative means addressing the triggers for enhanced containment, written to align those triggers with SORA 2.5 at a time when the AMC in force still carried 2.0. Amendment 4 now carries 2.5 directly, which raises an obvious question about whether that alternative is still needed in its original form — a question we cannot answer from the consolidated rules, and are not going to guess at.

Ordinary national law. Article 12(2)(c) makes this explicit rather than implied: before granting an authorisation the competent authority requires a statement from you confirming that the intended operation complies with applicable Union and national rules — in particular on privacy, data protection, liability, insurance, security and environmental protection. None of that is aviation law, and none of it is in this guide. It is still a condition of your approval.

None of it carries across a border automatically. If you hold an authorisation and want to fly in another Member State, Article 13 requires you to apply to that state’s authority with a copy of your authorisation and the locations — plus updated mitigation measures where the local airspace, terrain, population or climate demand them. That state assesses without undue delay and confirms; only on that confirmation may you start. Guidance to Article 13 is blunt about what the work involves: identify the local conditions, adapt your operational procedures to them, and submit the relevant chapters of your operations manual amended accordingly. EASA maintains links to the national authorities’ own sites, which is the place to find local conditions, because each Member State publishes its own.

How long it takes, and what drives it

The regulation sets no deadline for deciding an authorisation. That is worth saying plainly, because it is the first thing people want and the honest answer is that no fixed period exists in the rules. What the rules do put a clock on is narrower, and revealing:

  • A declaration under a standard scenario: the authority verifies it is complete and confirms receipt without undue delay, and you may then start (Article 12(5)).
  • A cross-border confirmation: the other Member State assesses without undue delay and confirms, and you may then start (Article 13(2)).

So the single biggest driver of your timeline is not the authority’s workload. It is which of the three routes you are on, and that is decided before you write anything. A declaration has no assessment to wait through. An authorisation does.

After that, four things move the needle, all of them within your control:

  1. Completeness. Article 12(1) has the authority evaluate the risk assessment and the robustness of your mitigations. An assessment that does not let them do that comes back as questions, and questions are the time.
  2. How high your SAIL is. A high SAIL means evidence, and evidence takes far longer to produce than it does to assess — where the low-robustness route described at the end of the previous section may need none submitted at all.
  3. Whether you use the checkpoint. SORA 2.5 has the authority give a preliminary agreement on steps 2 to 9 before you compile the full safety portfolio. Using that checkpoint is how you avoid writing a portfolio against assumptions the authority does not share.
  4. Whether the non-safety statement is ready. Article 12(2)(c)’s confirmation about privacy, data protection, liability, insurance, security and environment is not aviation work, so it tends to be started last and then holds everything else up.

Five reasons applications come back

These are the gaps we see most often. Each is tied to a specific requirement, so you can check your own submission against them rather than take our word for it.

1. The manual and the risk assessment describe different operations. The assessment claims a mitigation; the manual does not contain the procedure that delivers it, or describes a different crew, or a different sequence. Article 12(2)(a)(ii) has the authority evaluate the combination of operational conditions, personnel competence and technical features — so an inconsistency between two of your own documents is exactly what that evaluation surfaces.

2. Mitigations are claimed but not evidenced. This is the robustness rule biting. Robustness is integrity together with assurance, and it is always the lower of the two — so a strong measure with nothing behind it is a weak measure. Article 11(6) requires robustness commensurate with the objectives and risks, and “we will always do X” with no procedure, training record or test behind it does not clear it.

3. The people are described thinly. Article 11(2) asks for the complexity of the operation including personnel competencies, experience and composition, and separately for the competence of personnel including their roles, responsibilities, training and recent experience. Applications routinely describe the aircraft in detail and the crew in a sentence. The regulation asks for the opposite balance more than people expect.

4. The non-safety confirmation is missing. Article 12(2)(c) again. And note that a PDRA does not rescue you here: guidance to AMC1 Article 11 says PDRAs address safety risks only, so security, privacy and the rest still need addressing separately.

5. The operation does not actually fit the route claimed. If your operation does not fit completely within a PDRA’s limits, guidance to AMC1 Article 11 requires a full risk assessment instead. Discovering that after submitting is the most expensive version of this mistake, because the work you did was the wrong work rather than incomplete work.

After approval

An operational authorisation is not a licence to fly generally. Article 12(4) says it details the scope, the specific conditions — operational limitations, the competency required of you and your remote pilots, the technical features of the aircraft — and the information behind it, including the locations where the operation is authorised. Outside those limits you are not authorised, and that is a narrower boundary than most people carry in their heads.

Three obligations then run continuously.

Keep the mitigations adequate. UAS.SPEC.010 requires the operator to regularly evaluate the adequacy of the mitigation measures taken and update them where necessary. It is a standing duty, not a thing you did once.

Re-apply when the operation changes. UAS.SPEC.030(2) requires an application for an updated authorisation whenever there are significant changes to the operation or to the mitigation measures in it. New site, new aircraft, new crew structure, new procedure — the test is significance, and it is worth asking rather than assuming.

Keep the evidence current. Even where the authority authorised you without asking to see the manual, guidance to Article 12(2)(a) puts the obligation to produce, obtain and keep that evidence updated on you, for the whole validity of the authorisation.

Two more things belong on the list. Your authorisation names the documents and records you must keep and the event types you must report, in addition to those already required under the EU occurrence-reporting regulation (Article 12(4)(c)(vi)). And if you want to fly in another Member State, that is Article 13’s process, every time.

Doing it yourself, or getting help

The honest version, including the part that is against our interest.

Do it yourself when the route is bounded. If your aircraft carries a C5 or C6 class mark and your operation fits STS-01 or STS-02 exactly, the declaration route hands you the mitigations and asks you to commit to applying them. That is real work, but it is defined work with a defined end, and you are entitled to start once the authority confirms your declaration is complete. The same argument applies, slightly weaker, to an operation that fits a PDRA completely: someone has already done the risk assessment and you are adopting it.

A simple visual-line-of-sight operation at a low SAIL is a reasonable self-build for the same reason: the evidence burden is at its lightest exactly where the operation is simplest.

The work is worth buying when the expensive decisions come early. The costly mistakes here are not writing mistakes, they are routing mistakes: building a full SORA case for an operation that fitted a PDRA, or building a PDRA application for an operation that did not fit and needed a full assessment. Both are discovered late and cost the whole effort rather than part of it. If you are not confident which of the three routes you are on, answering that properly is the cheapest hour in the project.

The other case is the consistency problem — reason 1 above. Keeping an assessment and a manual describing the same operation, in matching detail, as the operation changes, is not difficult so much as unforgiving.

What nobody can sell you is the outcome. The authority evaluates and decides. Anyone who tells you otherwise is telling you something they cannot know.

Glossary

  • AMC — acceptable means of compliance. One recognised way to satisfy a requirement; not the only permissible way.
  • AMC1bis — the parallel acceptable means to Article 11 carrying SORA 2.0, alongside AMC1 which carries 2.5. Both current.
  • Assemblies of people — gatherings where persons are unable to move away due to the density of the people present (Article 2(3)). Not a headcount.
  • ARC — air risk class. How likely an encounter with manned aircraft is in the airspace you plan to use.
  • BVLOS — beyond visual line of sight; any operation not flown in VLOS (Article 2(8)).
  • ConOps — concept of operations. The description of what you actually intend to do, and the foundation the rest of the assessment is built on.
  • Controlled ground area — ground where the operator can ensure that only involved persons are present (Article 2(21)).
  • GRC — ground risk class. How much harm a loss of control could do to people on the ground.
  • LUC — light UAS operator certificate. An operator-level approval that can carry the privilege to authorise your own operations (Article 2(9)).
  • MTOM — maximum take-off mass, including payload and fuel (Article 2(22)).
  • OSO — operational safety objective. Something your operation must achieve, at a level of robustness set by your SAIL. 2.5 works with 17; 2.0’s run to #24.
  • PDRA — predefined risk assessment. A risk assessment already done for a shape of operation, which you adopt rather than repeat.
  • Robustness — integrity (the safety gain) combined with assurance (the proof you achieved it). Always the lower of the two.
  • SAIL — specific assurance and integrity level, I to VI. The output of the ground and air risk assessment, and what sets how much you must demonstrate.
  • SORA — specific operations risk assessment. The methodology named as the acceptable means of complying with Article 11.
  • STS — standard scenario. A predefined Specific operation whose mitigations are already set, so a declaration replaces an authorisation (Article 2(6)).
  • UAS — unmanned aircraft system: the aircraft plus its control and monitoring unit (Article 2(1)). The regulation’s word for what you would call the drone.
  • Uninvolved persons — people not participating in the operation, or who are not aware of the instructions and safety precautions given by the operator (Article 2(18)). Being nearby and unbriefed is enough.
  • VLOS — visual line of sight: the pilot maintains continuous unaided visual contact with the aircraft, sufficient to control its flight path and avoid collisions (Article 2(7)).

The authority decides

One thing to carry away, because it changes how you plan rather than how you write.

If the authority refuses, Article 12(3) requires it to inform you and to give its reasons — which is genuinely useful, because a refusal arrives as a diagnosis rather than a closed door. What no rule does is oblige it to agree with you.

The practical consequence is about commitments, not paperwork: do not sign a client to a date that assumes an approval you do not yet hold. Plan the engagement so that the approval is a milestone rather than an assumption, quote the work rather than the result, and use the preliminary-agreement checkpoint so that if the authority disagrees with you it does so early and cheaply.

That is also the honest limit of this guide. It can tell you what will be asked and what a complete answer looks like. It cannot tell you what the answer will be.