Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TISAX audit checklist guide for VDA ISA 2027

TISAX Audit Checklist: A Clear Guide to the 7 ISA 2027 Steps

A TISAX audit checklist written against VDA ISA 6 is about to go out of date. ISA 2027 was published on 1 July 2026 and becomes the catalogue for every assessment ordered from 2027 onward, so the checklist you prepare against this year matters less than the catalogue your assessment will actually be run against.

This guide sets out what a TISAX audit checklist has to cover in 2026 and 2027 — which catalogue applies to you, which assessment level you are being asked for, what evidence the audit provider will want, and the renumbering trap that catches organizations reusing an old gap analysis.

TISAX audit checklist: which VDA ISA catalogue applies to an assessment by order date
Which catalogue your assessment is run against depends on when the assessment is ordered, not when it is performed.

Step one on any TISAX audit checklist: which catalogue applies

This is the question that decides everything else, and it turns on the order date rather than the assessment date. ENX states that assessments ordered before 1 January 2027 can still be performed with ISA 6, and that ISA 2027 is the official version for assessments ordered from 2027 onward. The final date to open an initial assessment under ISA 6 is March 2027.

When the assessment is ordered Catalogue used What to prepare against
Before 1 January 2027 VDA ISA 6 (current release 6.0.3, published 25 April 2024) ISA 6.0.3 controls and maturity levels
From 1 January 2027 VDA ISA 2027 (published 1 July 2026) ISA 2027 controls, including the consolidated prototype protection labels
Initial assessment opened after March 2027 ISA 2027 only ISA 6 is closed to new initial assessments

Two practical consequences follow. If your label renews in the first half of 2027, ordering the assessment in late 2026 keeps you on a catalogue you already know. If your renewal is later than that, preparing against ISA 6 is preparing against the wrong document.

What actually changed in ISA 2027

The VDA has moved to year-based naming with an annual publication cycle, so “ISA 2027” is a release year rather than a version number. The information security module keeps the same broad shape but the wording was reworked across most of the catalogue, with a noticeable shift from should to must — requirements that were previously read as good practice are now read as expectations.

The structural change is in prototype protection, which has been consolidated into two hierarchical labels: Prototype Protection Basic at assessment level 2, covering processes and qualified personnel, and Prototype Protection Facilities at assessment level 3, which adds the physical safeguards for facilities. That mirrors how the other TISAX labels already work, and it removes the overlapping-scope confusion that made prototype scoping hard to explain to a customer.

The trap: control numbers moved. A gap analysis built on ISA 6 control identifiers cannot be lifted into ISA 2027 by find-and-replace, because a given number does not necessarily point at the same requirement in both catalogues. ENX publishes a redline document, Changes of ISA2027 to ISA 6.0 (7 August 2026), and reading it against your own control mapping is a faster route than re-deriving everything.

The TISAX audit checklist, step by step

The sequence below is the one that keeps an assessment on schedule. Most of the cost of a TISAX assessment is incurred before the audit provider arrives.

1. Fix the scope and the locations

TISAX is assessed per location and per scope, not per company. Decide which legal entities, sites and services are inside the assessment scope before anything else, because the scope drives the price, the duration and the number of site visits. A scope that quietly includes a warehouse nobody has thought about is the most common reason an assessment slips.

2. Choose the assessment objectives

The assessment objectives are what your customer is actually asking for. Information security with high protection need is the common baseline; strictly confidential, personal data and prototype protection are separate objectives with their own requirements. Ask your customer to name the objectives in writing rather than inferring them, and if prototype protection is in scope, confirm which of the two ISA 2027 labels they need.

3. Confirm the assessment level

The assessment level follows from the objectives, and it changes what the audit provider does:

  • AL1 — a self-assessment, with no verification by an audit provider. Rarely what a customer means when they ask for TISAX.
  • AL2 — a plausibility check of your self-assessment, based on evidence and interviews, usually run by web conference. This is the level behind most “high protection need” requests.
  • AL3 — a comprehensive on-site assessment with document inspection and interviews, used for very high protection needs such as the strictly confidential objective.

4. Complete the self-assessment honestly

This is the step a TISAX audit checklist exists to support, and the one most often rushed.

The VDA ISA self-assessment is scored on maturity levels, and the temptation is to score aspirationally. Do not. At AL2 and AL3 the audit provider is checking whether your claimed maturity is plausible against evidence, and an inflated self-assessment produces findings that a truthful one would not have. Score what you can evidence today, and record the gap where you cannot.

5. Assemble evidence against each control

Evidence means the artifact, not the assertion: the policy with an approval date, the access review with the reviewer’s name on it, the training record, the supplier assessment, the log retention setting. Build the evidence pack in control order so that the interview does not become a search party.

6. Close the gaps you can close before the audit

Anything you can fix in the weeks before the assessment costs less than a finding. Findings become a corrective action plan, and while a corrective action plan is survivable, it delays the label. A temporary label depends on a corrective action plan report with an overall result of “minor non-conform” and expires nine months after the closing meeting of the initial assessment, so the clock does not stop while you fix things.

7. Register, order and share

Registration on the ENX portal is a prerequisite for participating in TISAX at all. Once registered, you order the assessment from a TISAX audit provider, and once you hold a result you share it with the customer who asked for it — TISAX is a closed exchange, and a logo on a website proves nothing. Labels are valid for three years, so put the renewal in the calendar with enough lead time to order under the right catalogue.

What a TISAX audit checklist should not do

Two habits waste time. The first is treating the ISA catalogue as a document set to be produced rather than a set of practices to be evidenced — a folder of policies nobody follows scores badly at AL2, because the interview goes past the policy to the person doing the work. The second is copying an ISO 27001 Statement of Applicability across and calling it a TISAX gap analysis. The two overlap heavily, and an existing ISMS is a genuine head start, but the ISA catalogue asks questions about prototypes, third-party access and physical separation in a way that ISO 27001 does not.

A TISAX audit checklist should therefore track evidence and owners, not document titles. If you are already certified to ISO 27001, the efficient route is to map your existing controls to the ISA 2027 catalogue once, note where the automotive requirements go further, and treat only that delta as new work.

Frequently asked questions

Is TISAX a certification?
No. TISAX produces an assessment result and a label that you share with other participants through the ENX portal. It is an exchange mechanism, not a public certificate, which is why displaying a logo means nothing on its own.

How long is a TISAX label valid?
Three years. Renewal is applied for through the ENX portal, and the catalogue used depends on when the renewal assessment is ordered.

Do we have to redo everything for ISA 2027?
No. The information security requirements were reworked for clarity rather than replaced, so most of an ISA 6 evidence pack still applies. What has to be redone is the mapping, because identifiers moved and some requirements hardened from should to must.

Can we still be assessed against ISA 6?
Only if the assessment is ordered before 1 January 2027, and initial assessments under ISA 6 cannot be opened after March 2027.

What happens if the audit provider raises findings?
You produce a corrective action plan. A result of “minor non-conform” with an accepted plan can support a temporary label, which expires nine months after the closing meeting of the initial assessment.

Where this leaves you

A useful TISAX audit checklist in 2026 has three columns, not one: the requirement, the evidence, and the catalogue it is written against. Fix the scope and the assessment objectives first, confirm the assessment level with the customer who asked, score the self-assessment against what you can actually show, and check the order date against the ISA 2027 cut-over before you spend a single day preparing. Getting the catalogue right is the cheapest decision on the list and the most expensive one to get wrong.

References

More on TISAX

The documentation behind every step above is in the TISAX Documentation Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.