To mark TISAX’s tenth anniversary, the ENX Association published the new assessment catalog VDA ISA2027 on July 1, 2026. It applies as binding for all TISAX assessments ordered from January 1, 2027. For automotive suppliers – and there are especially many of them in NRW, with its tooling, plastics, and locking-technology regions – this raises a very concrete question: when do I order my next assessment, and against which catalog do I prepare?
The short answer up front: there is no reason to rush, but good reasons for a deliberate timing decision still this year.
Briefly framed: what TISAX requires – and what it does not
TISAX is the automotive industry’s assessment and exchange mechanism for information security. Its basis is the VDA ISA catalog, which is oriented in substance toward ISO/IEC 27001. Two distinctions are important:
- A TISAX label is not an ISO 27001 certificate – and conversely, an ISO certificate does not replace a TISAX label.
- TISAX is not a legal obligation. The requirement comes contractually from the OEMs and large Tier 1 customers, who require a valid label from their suppliers.
The procedure is standardized: registration with the ENX Association, self-assessment against the ISA catalog, assessment by an ENX-approved audit service provider, and subsequently exchange of the result via the ENX platform. For registration, a one-time ENX fee of EUR 405 net per site and assessment scope applies, with discounts for companies with many sites. The costs of the actual assessment come on top and depend on the assessment scope.
On assessment levels: Assessment Level AL2 (remote assessment) covers protection needs such as “high” or “confidential” and high availability, AL3 (on-site assessment) the levels “very high” or “strictly confidential.” A pure self-assessment (AL1) does not lead to a label.
The new version logic: year number instead of version number
With ISA2027, ENX switches to year-based versioning with annual releases. The transition rule is cleanly drawn:
- Assessments ordered up to December 31, 2026 continue to run under VDA ISA 6 (currently in revision 6.0.3) – the catalog binding for all assessments ordered since April 1, 2024.
- Assessments ordered from January 1, 2027 run under ISA2027.
- Follow-up assessments and scope extensions remain on the version of the original assessment.
Important for planning certainty: a TISAX result remains valid for three years, and the annual catalog releases change nothing about this – no one has to go to assessment more often in future just because a new catalog appears annually. The new version takes effect only at the next regularly ordered assessment.
What changes in substance with ISA2027
Three blocks of changes stand out:
- Supply chain: the requirements for managing your own sub-suppliers are strengthened. The expectation is to document and monitor the information-security compliance of suppliers – among other things through proof via TISAX labels. Anyone who so far has only a confidentiality clause in the purchasing contract will have to do additional work here.
- Prototype protection: the thematic block is restructured and split into two domains.
- Mappings: ISA2027 brings mappings to NIST CSF 2.0 and ISO/IEC 27001:2022 – helpful for everyone who maintains TISAX and an ISO certification in parallel and wants to avoid duplicate work.
The proven maturity-level model is retained in this. Anyone solidly positioned on ISA 6 today therefore does not begin from zero – but must in particular hold the supplier-management block honestly up against the new expectations.
The timing question: order in 2026 or prepare for 2027?
For suppliers whose label expires in 2027 or whose OEM customer requires a label for the first time, two sensible strategies emerge:
Option A: Order the assessment still in 2026
Anyone who orders their assessment by the end of 2026 is assessed under ISA 6.0.3 – familiar terrain, a well-rehearsed self-assessment, a calculable result. The subsequent result is valid for three years. This option is a good fit when the label has to be renewed in the foreseeable future anyway and the organization is well prepared on the current catalog.
Option B: Prepare deliberately for ISA2027
Anyone who has their assessment done later, or has to close gaps anyway, should run the gap analysis directly against ISA2027 – with a focus on supplier management: which sub-suppliers process information worth protecting? How is their compliance documented and monitored? Do TISAX labels of the relevant partners exist? These questions need lead time, because the answers depend on third parties.
In both cases: begin with the gap analysis before the OEM customer’s letter setting a deadline arrives. A TISAX project under a customer’s time pressure is more costly in nerves than the same project on a self-chosen schedule.
Side note: TISAX and NIS-2
For suppliers who additionally fall under NIS-2, it is worth looking at the ENX paper “Fulfillment of NIS2 through TISAX” of June 29, 2025. It describes how TISAX evidence and NIS-2 requirements relate to one another – a useful starting point for bundling both topics in a common security strategy instead of running two separate compliance projects.
Conclusion
ISA2027 is not a break but a plannable evolution with a clear cutoff date: what is decisive is the order date of the assessment, not the assessment date. The actual work for most suppliers lies in the new weight of supplier management. Anyone who makes the timing decision – ISA 6 still in 2026 or deliberate preparation for ISA2027 – consciously now turns a customer requirement into an orderly project on their own schedule.
How sector7 supports you
As an owner-led firm, we accompany suppliers in NRW from the gap analysis through the self-assessment to assessment preparation – with compliance consulting on TISAX, ISO 27001, NIS-2, and DORA from a single source. The technical measures behind it we implement ourselves: from certified network and security engineering (Juniper, Cisco, HPE, F5, Fortinet, Palo Alto Networks), through 24/7 NOC monitoring, to lived Veeam backup practice. On request at plannable flat monthly rates, so the TISAX preparation stays budgetable.
This article is a professional assessment and does not replace legal advice in individual cases.