VDA ISA2027: the catalog change and the question of when you go in.

On July 1, 2026, the VDA published the successor to VDA ISA 6 — the assessment catalog every TISAX® assessment is based on. It becomes binding for all assessments commissioned on or after January 1, 2027. Anyone commissioning in 2026 is assessed against the familiar catalog as usual. This is not a dramatic transition, but it is a decision attached to a date — and that is better made deliberately.

01.01.2027 commissioning cut-off
~43 revised controls
9,500+ sites with a valid label
4–9 months of preparation
First things first

What counts is the date of commissioning, not the date of the assessment.

This distinction is regularly confused and it decides which catalog applies. What matters is the point at which you commission the assessment — not the date the assessor is on site with you. An assessment still commissioned in December 2026 runs against VDA ISA 6 as usual, even if the assessment itself only takes place in spring 2027.

  • Commissioned by December 31, 2026 — assessed against VDA ISA 6 as usual
  • Commissioned from January 1, 2027 — assessed against VDA ISA2027
  • Existing labels keep their validity until their regular expiry
  • For recertifications, the commissioning date decides as well
Changes

What the new catalog does differently.

No break with the systematics, but noticeable shifts — above all where physical security is concerned.

Area VDA ISA 6 VDA ISA2027
Designation Sequential version (6.0.x) The year it becomes binding
Information Security Familiar scope of controls Around 43 revised controls; some “should” requirements become “must”
Prototype Protection Grown structure Comprehensively restructured — the largest substantive change
Data Protection Separate module Continued, in parts aligned with current practice
Binding for Commissioning up to December 31, 2026 Commissioning from January 1, 2027
Effect on active labels None — valid labels continue unchanged until their expiry date

For most companies the transition is manageable: the structure of the catalog stays familiar, and anyone who knows the old one will find their way around the new. The exception is Prototype Protection — anyone holding labels in this area should lay the new catalog against their own current state early, because structural and organizational measures can be affected here that cannot be retrofitted at short notice.

Decision

Commission in 2026 — or prepare for ISA2027?

There is no universally correct answer. But there are four situations in which the answer is unambiguous.

Commission now

Your ISMS is in place and the label is needed.

If a client is waiting and your evidence is largely in place, commission in 2026. You go in against a catalog whose interpretation has been settled for years — among assessors and consultants alike. Familiar rules are an underrated advantage.

Commission now

Your label expires in 2027.

For a recertification falling in 2027, the expiry date is worth a look: bringing the commissioning forward into 2026 can mean running the cycle once more against the familiar catalog — and making the switch only three years later, with considerably more lead time.

Don't rush

You are still at the beginning.

Without a documented ISMS, commissioning in 2026 is not an advantage but a risk. An assessment that ends in nonconformities costs rework, a second appointment, and time in front of your client. Prepare properly and go in under ISA2027.

Have it checked

Prototype Protection is in play.

Here the detailed comparison pays off. Because this module was restructured and can affect structural measures, the concrete current state decides — not the calendar. That check belongs before the commissioning, not after it.

Process

How we guide you through the change.

1

Work the date backwards

Expiry dates of existing labels, client commitments, and realistic preparation time together produce the commissioning window.

2

Determine the delta

Comparison of your current state against both catalogs — with particular attention to Prototype Protection and the controls upgraded to “must” requirements.

3

Close the gaps

Implementation of the open items, on Apple fleets enforced technically through Mosyle MDM and therefore directly demonstrable in the assessment.

4

Go in

Commissioning within the chosen window, preparation of the evidence, and support through the assessment all the way to the label.

Shortcut

An ISMS under ISO 27001 halves the preparation.

The VDA ISA catalog is closely aligned with ISO/IEC 27001 in substance and extends it with the automotive industry's sector-specific requirements. If you already run a living ISMS, you do not need to rebuild — you translate and extend, and you benefit twice, because the same foundation also carries the bulk of the NIS2 requirements.

  • Risk management, policies, and evidence management are already in place
  • What gets added is Prototype Protection and the VDA-specific maturity logic
  • The same ISMS covers 70 to 80 percent of the requirements under Section 30 BSIG
  • One management system, three forms of evidence — instead of three separate projects
FAQ

Frequently asked questions about VDA ISA2027.

As of August 2026.

Does our existing TISAX® label lose its validity because of the new catalog?

No. A valid label remains in force until its regular expiry — the publication of a new catalog changes nothing about that. Labels are typically valid for three years from issuance. ISA2027 only becomes relevant to you at recertification: if you commission the follow-up assessment on or after January 1, 2027, it will be assessed against the new catalog. That is the reason to look at your recertification date early — not in the last quarter before expiry.

Should we commission the assessment in 2026?

That depends on how far along you are. If you have a functioning ISMS and were going to go through the assessment in the coming months anyway, trigger the commissioning in 2026 and be assessed against VDA ISA 6 — familiar rules, familiar interpretations, predictable effort. If you are still at the beginning and would realistically only be ready in the second half of 2027, do not accelerate artificially: a hastily commissioned assessment under the old catalog that ends in nonconformities costs more than clean preparation for the new one.

What changes most in terms of content?

Prototype Protection. This module has been comprehensively restructured — for companies holding Prototype Protection labels, meaning automotive suppliers, engineering service providers, agencies, and film production companies with access to unreleased vehicle material, this is the biggest shift. In the Information Security module, around 43 controls have been revised, and some former “should” requirements have become “must” requirements. The structure stays familiar: anyone who knows the old catalog will find their way around the new one.

Why is the catalog now called ISA2027 instead of version 6.1?

Because the year says more than a sequential number. From now on, the catalog carries the year from which it becomes binding for newly commissioned TISAX® assessments. What used to be a version number you had to look up becomes a designation from which you can read your own situation directly: ISA2027 applies to everything commissioned on or after January 1, 2027.

How long does preparation for a TISAX® assessment take?

As a rule four to nine months, depending on the starting level and the target assessment level. If you already run an ISMS under ISO/IEC 27001:2022, that shortens considerably, because the basic structure — risk management, policies, evidence — is already in place and essentially needs translating into the VDA systematics. Without a documented security management system, the upper end of the range is realistic, particularly when Prototype Protection with its structural and organizational requirements comes into play.

Does TISAX® also apply to service providers without their own manufacturing?

Yes, and that circle is growing. The obligation does not arise from law but from the client's contractual requirement — and that follows who has access to information worth protecting, not who manufactures. Increasingly affected are therefore pure IT services such as cloud hosting and maintenance, engineering service providers, and creative and marketing agencies working with unreleased OEM material. For this group, TISAX® is not a compliance topic but simply the precondition for being awarded work at all.

Read next

Related