
The automotive industry is facing an increasingly complex information security landscape. With connected supply chains, growing cyber threats and greater reliance on digital systems, protecting sensitive information has become a critical requirement for automotive manufacturers and suppliers.
TISAX® has played an important role in establishing a common approach to information security across the automotive supply chain. Now, the release of VDA ISA2027 introduces the next stage in its development, with changes designed to improve clarity, strengthen supply chain security and keep the assessment framework aligned with current information security practices.
So, what does ISA2027 mean for automotive suppliers and when will the new requirements apply?
The Information Security Assessment (ISA) catalogue provides the assessment criteria used as part of TISAX®. It is published by the German Association of the Automotive Industry (VDA) and maintained by the ENX Working Group ISA.
The current version, ISA 6, was released in 2023 and became applicable to TISAX® assessments ordered from 1 April 2024. VDA ISA2027 was officially published on 1 July 2026 and will apply to TISAX® assessments ordered from 1 January 2027.
The release also introduces a new approach to ISA version numbering. Rather than sequential version numbers, future versions will be named according to the year in which they become effective. ISA2028, for example, is expected to be published in summer 2027 and become effective from January 2028.
This means organisations can now expect a more predictable annual cycle of ISA updates.
The key date for organisations planning a TISAX® assessment is 1 January 2027.
Assessments ordered before this date can still be performed against ISA 6, while assessments ordered from 1 January 2027 onwards will use ISA2027.
The introduction of annual ISA updates does not mean that organisations will need to undergo a TISAX® assessment every year. Existing TISAX® labels remain valid for their full validity period, with labels continuing to have a validity period of up to three years.
For organisations planning an assessment, therefore, the timing of the assessment order may be an important consideration.
The new version introduces a number of changes. While some focus on improving the clarity and consistency of the ISA catalogue, others introduce stronger expectations around information security governance, supply chain security and prototype protection.
Perhaps the most visible change is the move to an annual release cycle.
ISA2027 is the first version to use the new naming convention. Future ISA catalogues will generally be published during the summer and become effective on 1 January of the following year.
For organisations, this should make it easier to understand which ISA version applies when planning a new assessment.
It also allows the requirements to evolve through smaller, more predictable updates rather than relying on larger changes between sequential versions.
Importantly, the annual release cycle does not change the established validity period of TISAX® labels.
ISA2027 includes updated and refined mappings to other recognised information security and cybersecurity frameworks.
These include:
References to ISO/IEC 27001:2013 have also been removed.
This is particularly relevant for organisations that already operate an ISO/IEC 27001-certified Information Security Management System (ISMS).
TISAX® and ISO/IEC 27001 are not the same scheme, but the updated mappings can help organisations understand how their existing information security arrangements relate to the requirements assessed through TISAX®.
ISA2027 places considerable emphasis on making the assessment catalogue clearer and more consistent.
The wording, translations, formatting and structure of requirements have been reviewed, with a number of ambiguities and historical inconsistencies removed.
One notable clarification concerns the phrase "The following aspects are considered."
ISA2027 formally defines what this means. Organisations are expected to consciously consider each listed aspect and be able to explain the rationale behind their implementation decision during an assessment.
For organisations preparing for assessment, this reinforces the importance of being able to demonstrate not just that security controls exist, but that decisions have been considered, documented and implemented appropriately.
ISA2027 also introduces or clarifies definitions, including a broader definition of "Project" and a clearer distinction between events and incidents.
One of the most significant changes is the increased emphasis on the security of suppliers and the wider supply chain.
For organisations with high protection needs, ISA2027 places greater emphasis on:
For organisations handling information with very high protection needs, assurance expectations are strengthened further. Suppliers are expected to demonstrate an appropriate level of information security through a TISAX® label, an equivalent third-party assessment or an appropriate supplier audit.
This reflects a broader trend across cybersecurity: organisations increasingly need to understand and manage risks beyond their own internal systems.
For automotive suppliers, this means that information security management may need to extend further into the supply chain, with greater emphasis on how suppliers are selected, monitored and assured.
ISA2027 also introduces a substantial restructuring of the Prototype Protection module.
The previous five control groups have been consolidated into two overarching areas:
The aim is to create a clearer distinction between baseline organisational requirements and enhanced physical protection requirements.
New controls have also been introduced covering the traceability and lifecycle management of protected vehicles, components and parts.
There are also requirements relating to the appropriate disposal, recycling or return of protected vehicles, components, parts and relevant tools in accordance with customer requirements.
These changes reinforce the importance of protecting sensitive prototype information and physical assets throughout their lifecycle.
For most organisations, ISA2027 should not be viewed as a requirement to completely redesign their information security management system.
Instead, organisations should understand how the updated requirements affect their existing controls and whether any changes are necessary before their next assessment.
This is particularly important for organisations that:
Organisations planning a new assessment should consider the version that will apply based on when the assessment is ordered. The ENX TISAX® documentation confirms that the audit provider uses the ISA version valid when the initial assessment is ordered.
There are several practical steps automotive suppliers can take now.
Start by obtaining and reviewing the official ISA2027 catalogue. Pay particular attention to the areas that have changed rather than assuming that existing controls will automatically meet the updated requirements.
The increased focus on supply chain security makes supplier management an important area to review.
Consider whether you have appropriate processes for identifying information security requirements for suppliers, assessing compliance and retaining appropriate evidence.
If your organisation already operates an ISMS, assess it against the relevant ISA2027 requirements. This can help identify areas where existing processes may need to be updated before an assessment.
If you are planning a TISAX® assessment towards the end of 2026 or beginning of 2027, understand which ISA version will apply to your assessment based on the date it is ordered.
There is no requirement to rush into an assessment simply because ISA2027 has been released. Existing TISAX® labels retain their validity and the new annual release cycle does not increase the frequency of reassessment.
If anything, the changes reinforce the role TISAX® plays within the automotive supply chain.
TISAX® was established to provide a common approach to assessing and exchanging information security assessment results between organisations in the automotive industry. According to ENX, more than 21,000 locations have now been assessed according to TISAX® requirements.
The continued development of the ISA reflects the changing nature of information security and the increasing importance of managing cybersecurity risks across interconnected supply chains.
For automotive suppliers, maintaining effective information security is therefore not simply about preparing for an assessment. It is about demonstrating that information security is embedded within the organisation and its relationships with customers, suppliers and other business partners.
VDA ISA2027 represents an important change in the evolution of TISAX®. The new annual release cycle, updated standards mappings, clearer requirements, stronger supply chain expectations and revised Prototype Protection module all reflect the changing information security landscape.
For organisations with an existing TISAX® framework, ISA2027 provides an opportunity to review and strengthen existing arrangements. For organisations preparing for their first assessment, it is important to understand the new requirements early and build them into the preparation process.
With ISA2027 applying to TISAX® assessments ordered from 1 January 2027, organisations planning their next assessment should start considering the changes now.
Want to find out more about TISAX® and ISA2027? Contact TÜV UK to discuss your requirements and assessment options.
TÜV UK Ltd
AMP House
Suites 27 - 29, Fifth Floor, Dingwall Road
Croydon, CR0 2LX
Tel.: +44 20 8680-7711
Enquiries.UK@tuv-nord.com