ISA2027 is the new version of the VDA Information Security Assessment catalogue,
the standard behind every TISAX assessment. The VDA published it on 1 July 2026, and
it becomes binding for every TISAX assessment ordered from 1 January 2027. If you are
planning an assessment for next year, you are planning it against ISA2027, not ISA 6.
This guide covers what actually changed — verified against the published catalogues rather
than the summaries — and what it means for the documentation you will be assessed on.
ISA2027 dates: when your TISAX assessment switches over
Two dates matter, and they refer to different things. Getting them the wrong way round is the most
common planning mistake.
| Date | What happens |
|---|---|
| 1 July 2026 | The VDA published ISA2027. Available free from ENX. |
| 31 December 2026 | Last day an assessment can be ordered under ISA 6. |
| 1 January 2027 | Every TISAX assessment ordered from this date is assessed against ISA2027. The date you registered your scope is irrelevant. |
| March 2027 | Last date to open an initial assessment under ISA 6. The date of your kick-off meeting is irrelevant. |
Two further rules are worth knowing. Simplified Group Assessments and scope extensions use the ISA
version of the initial assessment, and all locations in a scope are assessed against the same
version — you cannot mix. And TISAX labels remain valid for three years, unchanged.
ISA2027 introduces year-based versioning
The name is not a typo for a version number. ISA2027 abandons sequential versions in favour of
naming each release after the year it becomes effective, published each summer and effective on
1 January following. ISA2028 will publish in summer 2027 and apply to assessments ordered in 2028.
This does not mean annual reassessment. Labels still last three years, so in practice most
organisations will skip several ISA generations between assessments. The annual cycle simply lets the
catalogue evolve in smaller steps.
What actually changed in ISA2027
The headline is narrower than most coverage suggests. Counting the controls in the published
catalogues:
| Module | ISA 6 | ISA2027 | Verdict |
|---|---|---|---|
| Information Security | 46 controls | 46 controls | No control added or removed. One moved: 1.2.4 became 6.1.3. The changes are in the requirement text. |
| Data Protection | 12 controls | 12 controls | The control set is unchanged. |
| Prototype Protection | 22 controls | 20 controls | Substantially rewritten. |
So if your information security documentation is in good shape for ISA 6, ISA2027 is not a rebuild.
The work concentrates in two places: prototype protection, and supplier management.
ISA2027 rewrites Prototype Protection
This is the largest revision the Prototype Protection module has had since it was introduced. Five
subsections collapse into two domains:
- 8.1 Organizational requirements — 13 controls
- 8.2 Physical and Environmental Security — 7 controls
Every prototype control number now means something different
The two domains swapped position. In ISA 6, physical security was 8.1 and organisational
requirements were 8.2. In ISA2027 it is the other way round. The practical consequence is worth
stating plainly: old control numbers still look valid but point at the wrong control.
ISA 6’s 8.1.1 is the physical security concept; ISA2027’s 8.1.1 is prototype protection regulations
and responsibilities.
Anything that cites prototype control numbers — a cross-mapping matrix, a Statement of
Applicability, an internal audit checklist — needs renumbering rather than reviewing. This is
the kind of staleness that does not announce itself.
Eight ISA 6 controls became one
Nine ISA 6 prototype controls have no direct successor, but only one was genuinely dropped. The
redline document ENX publishes alongside the catalogue shows that eight of them were
“summed up and included in” a single new control, 8.1.2:
- 8.2.4 security classifications of the project
- 8.3.1 transports of protected vehicles, components or parts
- 8.3.2 parking and storage
- 8.4.1 camouflage regulations
- 8.4.2 protection of test and trial grounds
- 8.4.3 test and trial drives in public
- 8.5.1 presentations and events
- 8.5.2 film and photo shootings
The ninth, documented visitor management, is superseded by a broader replacement.
Read that list carefully, because the shift it represents is the real story of ISA2027. The
catalogue has stopped asking whether you hold a separate policy for each prototype scenario. It asks
once, under 8.1.2, whether you systematically obtain, document and observe the
customer-specific and order-specific requirements that apply across all of them. The
scenario content still matters. What changes is how you are expected to evidence it — per
customer and per order, rather than as a shelf of standalone policies.
Six genuinely new prototype controls in ISA2027
| Control | What it requires |
|---|---|
| 8.1.1 | Prototype protection regulations defined and responsibilities established. |
| 8.1.2 | Order-specific requirements and specifications for handling prototypes — the control that absorbed the eight above. |
| 8.1.4 | Qualification and suitability of employees working in prototype areas. |
| 8.1.8 | Visitor management including registration, escorting and traceable documentation. |
| 8.1.11 | Incident management requirements, specific to prototypes. |
| 8.1.12 | Traceability — the location and currently responsible department of protected vehicles, components and parts documented and trackable across the entire processing period. |
| 8.1.13 | Disposal, recycling or return of protected vehicles, components, parts and relevant tools once no longer needed, in line with the client’s specifications. |
The last two are new obligations rather than restatements. Lifecycle traceability and end-of-life
disposal were not controls in ISA 6 at all, and most existing prototype documentation has nothing that
answers them.
ISA2027 raises the bar on supply chain security
The Information Security control set did not change, but the requirement text did — and the
largest change is control 6.1.1, information security among contractors and
cooperation partners.
At high protection needs, ISA 6 asked only that proof of an adequate security level
be provided. ISA2027 widens the acceptable evidence to include a checked questionnaire or
self-assessment, an attestation, a certificate or a supplier audit — and then adds a
requirement that was not there before: the supplier’s level of compliance, both with the required
evidence and with contractual agreements, must be documented, regularly reviewed and
monitored, and reviewed again on change. Changes of requirements, a change in supplier
status, or a change in supply chain structure all trigger a fresh review.
At very high protection needs, ISA 6 had no additional requirements at all. ISA2027
fills that gap. An adequate security level should be demonstrated by a third-party audit — an
adequate TISAX label or equivalent — or by a supplier audit covering the agreed customer
requirements. And if no audit is conducted, management must take a risk-based decision to
continue doing business with that supplier, and a record of that decision must exist.
Contractual obligations to customers on supply chain risk transparency must also be met.
In practice this turns a supplier register from a list into a monitored control. If yours records
who your suppliers are but not what evidence you hold, when you last reviewed it and what would
trigger the next review, that is the gap ISA2027 will find. The same direction of travel runs through
NIS2 and wider
supply chain security practice.
Built to ISA2027, not retro-fitted to it.
The TISAX Toolkit carries all 78 ISA2027 controls in its Statement of Applicability, with documents for the controls this edition introduced — order-specific prototype requirements, prototype incident management, lifecycle traceability, and end-of-life disposal and return — plus cross-mapping to ISO/IEC 27001:2022, ISA/IEC 62443-2-1 and NIST CSF 2.0.
ISA2027 updates the mappings to other standards
The reference mappings were reviewed throughout the catalogue. Counting the references in each
version shows exactly what moved:
| Reference | ISA 6 | ISA2027 |
|---|---|---|
| ISO/IEC 27001:2013 | 38 references | 0 — removed entirely |
| ISO/IEC 27001:2022 | 40 references | 40 references |
| NIST CSF 1.1 | 33 references | 0 |
| NIST CSF 2.0 | none | 32 references |
| ISA/IEC 62443 | 25 references | 27 references |
If your documentation still maps to ISO/IEC 27001:2013, ISA2027 has removed the bridge you were
relying on. Mapping to the 2022 Annex A controls is now the
only supported route. The growing set of ISA/IEC 62443 references also reflects ISA2027’s greater
attention to operational technology.
One smaller structural change: ISA2027 removes the “usual person responsible for process
implementation” column that ISA 6 carried.
ISA2027 defines what “the following aspects are considered” means
This sounds like housekeeping and is not. The phrase appears throughout the catalogue, and
organisations and assessors have interpreted it differently for years. ISA2027 now defines it: each
listed aspect must be consciously considered, and the rationale behind the
implementation decision must be explainable during the assessment.
That is a documentation change. It is no longer enough for a policy to cover the listed aspects
implicitly — you need to be able to say why you implemented each one the way you did. Adding a
short justification against each decision is cheap to do in advance and awkward to reconstruct in an
assessment room.
ISA2027 also broadens the definition of a project, separates events from incidents more clearly,
and names managers and organisational leaders as an explicit target group for security awareness and
training.
How to prepare for ISA2027
If your assessment will be ordered in 2027, work through this in order:
- Download the redline. ENX publishes an ISA 6 to ISA2027 comparison document
alongside the catalogue, both free. It is the fastest route to the detail. - Renumber every prototype reference in your cross-mapping matrix, Statement of
Applicability and audit checklists. Do this first — the old numbers are wrong in a way that
looks right. - Build the order-specific requirements evidence for 8.1.2. One register capturing
customer requirements for transport, storage, camouflage, trial grounds, public drives, events and
shootings replaces the eight controls that were consolidated. - Close 8.1.12 and 8.1.13 — prototype traceability across the processing
period, and disposal, recycling or return including tools. - Rebuild the supplier register as a monitored control for 6.1.1, with evidence
held, compliance level, review dates and change triggers — plus a management risk-acceptance
record for the very-high case where no audit exists. - Re-map to ISO/IEC 27001:2022 and NIST CSF 2.0 if you are still on 2013 or CSF 1.1.
- Add rationale against the aspects your policies consider.
If your assessment is ordered before the end of 2026 and opened by March 2027, you are assessed
against ISA 6 and none of this is urgent — but your next assessment will be against ISA2028 or
later, and the prototype restructure carries forward.
ISA2027 frequently asked questions
Does ISA2027 invalidate my current TISAX label?
No. TISAX labels remain valid for their full period, which is up to three years, regardless of
which ISA version they were assessed against. ISA2027 does not shorten, revoke or otherwise affect a
label you already hold. You will be assessed against whatever version is current when you order your
next assessment.
Does the new annual release cycle mean annual reassessment?
No, and this is the most common misreading of the change. The catalogue now publishes every summer,
but assessment frequency is unchanged. Because labels last three years, most organisations will skip
two or more ISA generations between assessments. The annual cycle exists so the catalogue can evolve
in small, predictable steps instead of large jumps.
Which ISA version will my next assessment use?
It depends solely on when the assessment is ordered. Ordered on or before
31 December 2026, you are assessed against ISA 6, provided the assessment is opened by March 2027.
Ordered from 1 January 2027, you are assessed against ISA2027. The date you registered your scope and
the date of your kick-off meeting have no bearing on which version applies — a distinction that
catches people out when a project slips across the year boundary.
Where can I download the ISA2027 catalogue?
ENX publishes it free. The catalogue, the ISA 6 to ISA2027 redline comparison and the participant
handbook are all available from the TISAX downloads page linked in the references below. Translations
are being added over time; where versions differ, the English one is authoritative.
Does ISA2027 change the TISAX assessment objectives or labels?
No. The three assessment objectives — information security, prototype protection and data
protection — are unchanged, and so is the label structure. What changed is the content of the
controls behind them, most substantially in prototype protection.
Is ISA2027 harder to pass than ISA 6?
For information security at normal protection needs, broadly no — the control set is
identical and much of the change is clarification. It is more demanding in three specific places: the
new prototype controls covering traceability and disposal, supplier evidence monitoring at high
protection needs, and the very high protection tier of control 6.1.1, which previously had no
additional requirements at all. Organisations handling information at very high protection needs will
feel ISA2027 most.
What if we only handle information security, not prototypes?
Then ISA2027 is a light touch for you. The Information Security module has the same 46 controls it
had in ISA 6, with one renumbering and revised wording. Your priorities are the supplier changes in
6.1.1 and re-mapping anything still tied to ISO/IEC 27001:2013 or NIST CSF 1.1.
References
- VDA ISA2027 released (ENX Association) — the official release announcement of 1 July 2026, including the new versioning model.
- ISA2027 webinar series and redline document — ENX’s summary of the changes and the assessment timeline.
- VDA ISA2027 catalogue (XLSX) — the catalogue itself, published free by ENX. The English version is authoritative.
- TISAX downloads — the ISA2027 catalogue, the ISA6 to ISA2027 redline, and the participant handbook.