VDA ISA 2027 – The Most Important Changes in the TISAX® Catalogue

On 1 July 2026, the German Association of the Automotive Industry (VDA) published the successor to VDA ISA 6 – the questionnaire behind every TISAX® assessment. Many expected it to be called „ISA 7.0“; officially it is named ISA 2027, because the VDA has switched to year-based version names. The structure largely stays the same – but the requirements become more binding, the supply chain moves into sharper focus, and prototype protection has been rebuilt from the ground up.

The key facts in numbers

  • Year-based naming: „2027“ instead of „7.0“ – an annual publication cycle from now on, for better planning.
  • Information security: 46 controls – the same as ISA 6. No control explosion, but 44 of the 46 controls were edited; in 25 controls, requirements change, are removed, or move.
  • Prototype protection: from 22 to 20 controls – the module has been completely restructured.
  • Data protection: unchanged – all 12 controls in chapter 9 are identical to ISA 6.
  • New framework mapping: ISA 2027 maps to NIST CSF 2.0 and ISO/IEC 27001:2022; the old references to ISO 27001:2013 are gone.

From recommendation to obligation

The most consequential change is a quiet one: requirements move from the should level (recommendation) to the must level (obligation). Two examples:

  • Control 1.1.1: making security policies available to employees and informing them about relevant changes used to be a should-requirement – in ISA 2027 it is mandatory.
  • Control 4.1.2: passwords according to the state of the art move from a side note into the regular requirements.

If your ISMS was built only to clear the must-threshold of ISA 6, this is exactly where the first new gaps will appear.

Chapter overview

ChapterWhat changesRating
1 – IS PoliciesNew crisis management (1.6.3), policy duties now mandatory (1.1.1)Major change
2 – Human ResourcesTeleworking rewritten with concrete must-requirements (2.1.4)Major change
3 – Physical SecurityA few clarificationsMinor change
4 – Access ManagementPassword and login rules tightenedMinor change
5 – IT SecurityMany small edits, additions for high protection needsMinor change
6 – SuppliersSupplier verification duties tightened, 1.2.4 becomes 6.1.3Major change
7 – ComplianceRewording onlyMinor change
8 – Prototype ProtectionFully restructured, 22 → 20 controlsMajor change
9 – Data ProtectionNo changesUnchanged

The supply chain moves into focus

Control 1.2.4 (external IT service providers) moves into the supplier chapter as the new control 6.1.3 – labelled a „Supplier Statement of Applicability“ (Supplier SoA) for the first time. The real tightening is in 6.1.1: for high protection needs, supplier security evidence must now be documented and reviewed regularly and on changes; for very high protection needs, a third-party audit or an adequate TISAX® label of the supplier is expected. Supplier management thus becomes one of the areas where the preparation effort will grow noticeably.

Prototype protection: rebuilt, not extended

Prototype protection is the biggest structural change: the five sections of ISA 6 (8.1 to 8.5) are merged into two (8.1 organisational8.2 physical and environmental security), controls are combined and outdated content is removed – from 22 down to 20 controls. If your assessment scope includes prototype protection, your documentation structure will need remapping even where the underlying measures stay the same.

What stays the same: data protection

Chapter 9 (data protection) is untouched – all 12 controls are word-for-word identical to ISA 6. If your scope includes the data protection module, nothing changes there.

When does VDA ISA 2027 apply?

The catalogue itself contains no transition date – the binding switchover date for TISAX® assessments is set by ENX. For the predecessor ISA 6, roughly six months passed between publication and mandatory use for new assessments. Until ENX announces the date, current assessments continue to run on ISA 6, and existing TISAX® labels do not automatically lose their validity.

What you should do now

  1. No panic migration: ISA 6 remains the assessed catalogue until ENX sets the date.
  2. Review the substantial chapters first: 1, 2, 6 and 8 – crisis management, teleworking, supplier management and prototype protection.
  3. Check the should-to-must promotions: requirements you previously treated as optional may now be mandatory.
  4. GAP analysis against the changed controls instead of reworking the whole catalogue.

How 360 Digital Transformation supports you

We guide you through the move to VDA ISA 2027 – from the GAP analysis through implementing the tightened controls and remapping prototype protection to preparing for the assessment. Foundations: the overview of TISAX® requirements and the TISAX® assessment. Still on ISA 6? You will find all the details in our article VDA ISA 6 – the most important changes. Happy to help as part of our consultancy for TISAX®.

Source: VDA – Information Security

About the Author

VDA ISA 2027

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 lead auditor. He has been working in IT project management for more than 11 years. His passion is information security for small and medium-sized businesses, and he helps these companies overcome their information security challenges with a practical consulting approach.

TISAX® is a registered trademark of the ENX Association. 360 Digitale Transformation has no business relationship with ENX. The mention of the TISAX® trademark does not constitute any statement by the trademark owner regarding the suitability of the services advertised here. TISAX® assessments for obtaining labels are carried out only by the audit providers listed on the ENX website.

360 Digital Transformation
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.