An interview with Robert Brown, Global Head of Automotive, BSI
TISAX® ISA2027 brings a more predictable release cycle, clearer requirements, and a stronger focus on supply chain security. We asked Robert Brown what’s changing, when the new requirements apply, and what you should do now.
Key Facts: The TISAX® Information Security Assessment (ISA) was updated as VDA ISA2027 on 1 July 2026.
- The TISAX® ISA will be updated annually and republished each July and will take effect in the following January
- From 1 January 2027, ISA2027 becomes the default assessment catalogue for new TISAX® assessments
- Existing TISAX® labels will be valid until their stated expiration date
- Reassessments will be performed against the latest version of the ISA
Why does TISAX® matter to automotive organizations?
TISAX® (Trusted Information Security Assessment Exchange) gives automotive manufacturers and suppliers a common way to assess and exchange information about information security. That matters in an industry where very high volumes of sensitive data move through complex, global supply chains.
The scheme has grown quickly since its first assessment in 2016. Increasingly Tier 1 suppliers are now flowing down the TISAX requirement to their suppliers.
ENX Association, the governance organization of TISAX® reports that more than 21,000 locations have been assessed and that those assessments have led to well over 100,000 identified and implemented security improvements. Today, more than ten OEMs mandate TISAX®, using the assessment results to evaluate business partners and protect their supply chains from information security threats.
What exactly is the TISAX® ISA?
ISA stands for Information Security Assessment. It’s the requirements catalogue used as the basis for TISAX® Assessments.
It was originally developed as an automotive adaptation of the information security management standard ISO/IEC 27001. Now, the ISA has evolved into an independent industry standard while remaining aligned with internationally recognized information security frameworks.
Participants use the ISA to prepare for assessment and, if successful, share their TISAX® Assessment Results with selected customers and partners through the ENX Portal.
So, what’s changing to the TISAX® ISA?
The short answer is that ISA2027 makes the catalogue clearer, more consistent, and better aligned with today’s security risks.
Five key changes stand out:
- New year-based versioning. The name now tells you when the catalogue becomes effective. ISA2027 applies to assessments ordered in 2027.
- Updated mappings. ENX has updated the mappings to NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022, clarified mappings to ISA/IEC 62443, and removed references to ISO/IEC 27001:2013.
- Clearer language. ENX reviewed wording, translations, formatting, and requirement structures. It also formally defined the phrase “The following aspects are considered”, so organizations must consciously consider each listed aspect and explain their implementation decision during an assessment.
- Stronger supply chain assurance. Organizations with high protection needs must document, review, and monitor supplier compliance and supporting evidence more closely. For very high protection needs, suppliers are expected to demonstrate adequate information security through a TISAX® label, an equivalent third-party assessment or an appropriate supplier audit.
- Restructured Prototype Protection. The previous five control groups are now two domains: Organizational Requirements, and Physical and Environmental Security. New controls cover traceability and lifecycle tracking, as well as disposal, recycling or return of protected prototypes, parts, and tools.
Note: The Data Protection questionnaire has not changed between ISA 6 and ISA2027, according to the official ENX redline comparison.
When do the changes to the TISAX® ISA take effect?
The ISA will be updated on 1 July each year and take effect from 1 January in the following year. This six-month period allows for approved audit providers and participants to get ready for assessment against the new version.
ISA2027 becomes the default catalogue for TISAX® Assessments contracted from 1 January 2027. However, assessments contracted before that date, or with an initial assessment (Stage 2) scheduled before 1 April 2027, may still be conducted against ISA 6. The scope registration date doesn’t determine which version applies.
Assessments ordered before 1 January 2027 can still be performed against ISA 6. ENX has also stated that March 2027 is the final date to open an initial assessment under ISA 6.
For Simplified Group Assessments and scope extensions, the ISA version used for the initial assessment continues to apply. All locations within a scope must be assessed against the same version.
Does the annual release cycle mean annual assessments?
No. This is an important point. ENX plans to publish future ISA catalogues annually, but TISAX® labels will continue to remain valid for up to three years.
The annual cycle allows the catalogue to evolve in smaller, more predictable steps. It doesn’t create the need for annual reassessment.
In practice, many organizations will move across several ISA versions between full assessments.
What do existing TISAX® participants need to do?
There’s no immediate action required. Your existing TISAX® label remains valid until its expiry date.
However, now is a good time to review when your next assessment is due and identify any ISA2027 requirements that could affect your organization. The ISA version used for your next assessment will depend on when it’s ordered, so some organizations may transition directly to ISA2027, while others may move to a later annual version.
Where should teams focus their preparation?
I’d start with four practical actions:
- Download ISA2027 and the ENX redline comparison from the ENX Portal.
- Map the changes against your existing controls and assessment scope.
- Review supplier assurance and Prototype Protection requirements.
- Update policies, evidence, and internal ownership where needed.
Just as importantly, make sure your teams can explain the rationale behind their approach. ISA2027 places greater emphasis on demonstrating that decisions have been consciously considered and documented.
Does ISA2027 change an ENX Vehicle Cyber Security (VCS) audit?
Not directly. ENX VCS, the vehicle cyber security audit, is a separate audit scheme based on ISO/SAE 21434.
However, ENX says you should have valid TISAX® labels for every location in the VCS audit scope when the VCS audit takes place.
If you’re planning both activities, coordinate the timelines. Make sure the necessary TISAX® labels will remain valid and confirm which ISA version applies to any upcoming TISAX® assessment.
What’s your final advice for TISAX® participants?
Start with your key dates, then focus on the changes that’ll have the biggest impact on your organization. Check your label expiry, expected assessment order date, suppliers, protection needs, and any Prototype Protection activities.
Remember that ISA2027 is an evolution rather than a reason to start again. A focused gap review can help you protect the controls that already work and direct effort into the areas that have changed.
Take the next step
- Download ISA2027 and the ENX redline comparison – Review the official catalogue and identify changes relevant to your scope.
- Explore VDA ISA based on TISAX® training – Build your team’s understanding of the ISA and ISMS requirements.
- Contact BSI – Discuss your assessment timing and readiness priorities with our team.