Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TISAX prototype protection explained

TISAX Prototype Protection: 20 ISA2027 Controls Explained (2026)

TISAX prototype protection is the part of the scheme that most information-security teams are least prepared for, because it is not about data. It is about physical things — vehicles, components and parts that a manufacturer classifies as requiring protection before launch — and about the workshops, test tracks, transporters and photo studios they pass through. Four of the twelve TISAX assessment objectives belong to this family, three of them assessed on site at level 3, and the criteria catalogue that governs them was restructured in ISA2027: 22 controls became 20, five subsections became two, and every control number changed meaning. This guide explains what the prototype protection catalogue requires as ISA2027 writes it, which objectives trigger it, what changed from ISA 6 and why the renumbering is a trap, and how to prepare a site for an AL 3 prototype assessment.

TISAX prototype protection: two ISA2027 domains, twenty controls, four objectives
8.1 Organizational requirements (13 controls) and 8.2 Physical and environmental security (7), assessed for Proto parts, Proto vehicles, Test vehicles and Proto events.

Which objectives trigger TISAX prototype protection

Objective Covers Assessment level Typical participant
Proto parts Protection of prototype parts and components AL 3 Component suppliers, tooling, test labs
Proto vehicles Protection of prototype vehicles AL 3 Engineering service providers, body and integration suppliers
Test vehicles Handling of test vehicles, including on public roads AL 2 Test and validation providers, fleets
Proto events Protection of prototypes during events and film or photo shoots AL 2 Event agencies, studios, logistics

The objectives are independent — there is no hierarchy among them as there is for the information-security labels — and each applies the Prototype Protection catalogue with the applicability the ISA’s own columns define. Our guide to TISAX labels and the twelve objectives covers the selection; TISAX assessment levels explains why three of these four are on-site assessments.

The ISA2027 TISAX prototype protection catalogue

ISA2027, published by VDA on 1 July 2026 and applicable to every TISAX assessment ordered from 1 January 2027, organizes prototype protection into two domains. Domain 8.1, Organizational requirements, applies to “all companies that manufacture or receive vehicles, components or parts classified as requiring protection”; domain 8.2, Physical and environmental security, applies to companies that do so “on their own properties”.

8.1 Organizational requirements (13 controls)

Control Question (condensed) What an auditor looks for
8.1.1 Regulations for prototype protection defined and responsibilities established A released policy with goals, specifications and named responsibilities
8.1.2 Order-specific requirements and specifications for handling prototypes regulated For each order, customer requirements agreed, documented and observed — the control that absorbed eight ISA 6 controls
8.1.3 Employees and project members participate in training and awareness At least annual training records; project-specific briefings
8.1.4 Qualification of employees for working in prototype areas ensured Sensitive roles determined; job requirements and vetting defined
8.1.5 Non-disclosure agreements in place under valid contract law NDAs at company level and with all employees and project members
8.1.6 Requirements for commissioning subcontractors known and fulfilled Original customer approval; NDAs and requirements flowed down
8.1.7 Process for granting access to security areas Documented authorization responsibilities; assignment and removal process
8.1.8 Visitor management including registration and escorting Registration; documented NDA before access; escorting rules
8.1.9 Rules for carrying and using mobile video and photography devices in security areas Carrying rules (sealing), use rules, enforcement
8.1.10 Rules for image recording and handling of created image material General prohibition with an approval process; handling of approved images
8.1.11 Incident management requirements regulated Per-order incident procedures agreed with the customer; reporting route
8.1.12 Protected vehicles, components and parts documented and traceable A documentation concept covering the lifecycle from receipt to return
8.1.13 Disposal, recycling and return of protected items and relevant tools ensured A concept for classified items and tools at end of use

8.2 Physical and environmental security (7 controls)

Control Question (condensed) What an auditor looks for
8.2.1 A security concept describing minimum physical and environmental requirements A written concept covering outer skin, view protection, access, monitoring
8.2.2 Perimeter security preventing unauthorized access to protected properties Fencing, gates and measures whose sum prevents unauthorized entry
8.2.3 Outer skin of protected objects and security areas constructed to prevent intrusion Secured windows, doors and other openings
8.2.4 View and sight protection in defined security areas No unauthorized viewing of developments needing high or very high protection
8.2.5 Access control at all points of access to security areas At least one of: mechanical locking with documented key management, electronic access control, or personnel control
8.2.6 Premises monitored for intrusion An intrusion detection system with alarm tracking to a qualified security service or control centre
8.2.7 On-site client segregation Spatial separation of clients’ prototypes by personnel, organizational or technical measures

What changed from ISA 6, and the renumbering trap

ISA 6 had 22 TISAX prototype protection controls across five subsections; ISA2027 has 20 across two domains, and the domains swapped order. The consequence, verified from VDA’s own redline workbook, is that every prototype control number now means something different: ISA 6 control 8.1.1 was the physical security concept, ISA2027 8.1.1 is the prototype-protection regulations. Any document, checklist or customer requirement that cites a prototype control by number without stating the ISA version is now ambiguous, and the old number resolves to the wrong control rather than to nothing.

Nine ISA 6 controls have no direct successor, but only one was dropped. The redline’s “Moved Proto Controls” sheet shows eight were “summed up and included in 8.1.2”: the scenario-by-scenario controls for transports, parking and storage, camouflage, trial grounds, public trial drives, events, film and photo shoots, and security classifications. ISA2027 stops asking for a policy per scenario and asks once whether the organization systematically obtains, documents and observes the customer’s order-specific requirements. That is a simplification in the catalogue and a new obligation in practice: a register of order-specific prototype requirements, per order, is now the evidence for the control that absorbed eight.

Seven controls are new or substantially rewritten: 8.1.1 responsibilities, 8.1.2 order-specific requirements, 8.1.4 employee qualification for prototype areas, 8.1.8 visitor registration and escorting, 8.1.11 prototype incident management, 8.1.12 lifecycle traceability and 8.1.13 disposal, recycling and return including tools. Our guide to VDA ISA2027 covers the changes across all three catalogues.

Preparing a site for an AL 3 prototype assessment

  1. Map the prototype flow. Where protected items arrive, are stored, worked on, moved, photographed and returned. The security areas are the places on that map; 8.2 applies to each.
  2. Build the order-specific requirements register. One entry per customer order: the customer’s prototype requirements, the classification, the agreed incident procedure (8.1.11), the documentation and return rules (8.1.12, 8.1.13). This is the 8.1.2 evidence and the document most sites lack.
  3. Close the physical basics before the concept. Perimeter, outer skin, view protection, access control at every entrance, intrusion detection with alarm tracking. Auditors walk these at AL 3; a security concept that describes measures the walk does not find is a finding.
  4. Segregate clients physically. 8.2.7 expects one customer’s prototypes not to be visible to another’s project staff. Shared halls need partitions, covers and schedules, and evidence they are used.
  5. Control cameras and images. Sealing or surrender of mobile devices at the security-area boundary (8.1.9), a general recording prohibition with an approval route, and handling rules for approved images (8.1.10). Phones are the most common on-site finding.
  6. Train and vet the people. Annual training records for everyone in prototype areas (8.1.3), defined qualification requirements for sensitive roles (8.1.4), NDAs on file for staff and subcontractors (8.1.5, 8.1.6), visitor registration with NDA before entry (8.1.8).
  7. Rehearse the walk. An internal audit that follows the prototype flow with the ISA2027 questions in hand, by someone who does not run the site, finds what the audit provider will.

Our TISAX audit checklist covers the assessment sequence the TISAX prototype protection walk sits inside.

Frequently asked questions

What is TISAX prototype protection?
The ISA criteria catalogue and the four assessment objectives — Proto parts, Proto vehicles, Test vehicles, Proto events — that cover physical vehicles, components and parts a manufacturer classifies as requiring protection before launch, and the sites, transports and events they pass through.

Which objectives are assessed on site?
Proto parts and Proto vehicles are AL 3, with on-site inspection. Test vehicles and Proto events are AL 2, assessed by plausibility check and interview.

How many prototype protection controls are there?
Twenty in ISA2027 — thirteen organizational (8.1) and seven physical and environmental (8.2) — down from 22 in ISA 6. The control numbering changed completely between the two versions.

What is the biggest change in ISA2027?
Eight scenario-specific ISA 6 controls (transports, storage, camouflage, trial grounds, public drives, events, shoots, classifications) were consolidated into 8.1.2, order-specific requirements, which now expects a per-order register of customer prototype requirements.

From when does ISA2027 apply?
Every TISAX assessment ordered from 1 January 2027 is assessed against ISA2027. Labels issued under ISA 6 keep their three-year validity.

Where this leaves you

Treat TISAX prototype protection as a site discipline built on one register: know where protected items flow, record each customer’s order-specific requirements, close the physical controls at every security area, segregate clients, control cameras, train and vet the people, and walk it yourself before the auditor does. And cite every control with its ISA version, because from January 2027 the old numbers point at the wrong questions.

References

More on TISAX

The Prototype Protection Policy, the Photo and Film Policy, the Visitor Management Procedure, the Prototype Handling Register, the Order-Specific Prototype Requirements Register and the Prototype Disposal and Return Procedure are in the TISAX Documentation Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.