Contact

What are you looking for?

VDA Publishes ISA2027 Catalog for TISAX® Assessments

Sep 16, 2026

The VDA has published its latest Information Security Assessment (ISA) catalog for the Trusted Information Security Assessment Exchange (TISAX). TISAX will transition from ISA 6.0.3 to ISA2027, which takes effect for all orders from January 1, 2027.

This new edition has a year-based naming system, replacing the numerical system. Changes are gradual, but signal where TISAX and the automotive industry’s approach to information security is going.

We outline how this annually published ISA catalog applies to TISAX customers when they renew their TISAX label on the usual three-year cycle.

Annual publication cycle

The switch from numbered versions to year-based titling suggests that the ISA catalog will be released annually going forward. This approach would allow requirements to be updated more regularly in response to evolving cybersecurity risks and industry needs.

New editions are expected to be published mid-year, with each new ISA catalog becoming mandatory from the start of the following year. This gives organizations gearing up to renew their TISAX label about six months to review the changes and pinpoint and implement the required measures before assessment.

Prototype Protection module simplification

The Prototype Protection module previously involved several assessment objectives with different scopes, which could make selection of the appropriate scope more complex. This often resulted in adjustments and requests for scope extension.

ISA2027 addresses this with a simpler structure – just two labels:

  • Prototype Protection Basic (AL2)
  • Prototype Protection Facilities (AL3)

The Facilities label covers all the Basic requirements – the same hierarchical model used for other TISAX labels, where Strictly Confidential includes all requirements of Confidential, Very High Availability includes all requirements of High Availability, and Special Categories of Personal Data covers all requirements of Standard Categories of Personal Data.

Prototype Protection Basic indicates that an organization has established appropriate processes and qualified personnel for securely handling prototypes, including components and vehicles. Prototype Protection Facilities goes one step further, demonstrating that an organization’s sites and facilities have physical safeguards to store and protect prototypes locally.

This simplicity and harmonization make the Prototype Protection module easy to understand and reduce the risk of organizations choosing an incomplete set of labels.

Information Security module minor amendments

This module has small adjustments. It has 43 revised controls, mostly aimed at improving interpretation between organizations and auditors. Some requirements also shift emphasis from “should” to “must”.

Conclusion

For organizations already compliant with ISA 6.0.3, transitioning to ISA2027 is unlikely to cause many issues.

The simple Prototype Protection module has been welcomed, while the Information Security module changes are only minor and understandable. Transitioning to ISA2027 should be easier than the transition to ISA 6.0.

If you need to renew your TISAX labels and are planning an assessment under ISA2027, you should begin reviewing the revised requirements as soon as possible. This is a perfect opportunity to review your information security management system (ISMS) against ISA2027 to identify gaps and implement improvements before your assessment.

To note:

  • Currently valid labels are unaffected – ISA2027 becomes relevant at your next assessment
  • Check your policy documentation against the requirements that have moved from “should” to “must”
  • Review your suppliers and service providers concerning the broader IT Service Provider scope, with a focus on sharing responsibilities clearly

Why choose SGS for your TISAX assessment?

With years of worldwide experience in information security and the automotive industry, we are perfectly placed to provide TISAX alongside helping organizations manage their supply chain, providing safe and reliable vehicles, improving quality, efficiency and safety, and reducing environmental impact.

Discover our established TISAX offering today.

For further information, please contact:

Serene Chan

Serene

Chan

Head of Digital Trust Assessments
Global Product Manager – TISAX

About SGS

SGS is the world’s leading Testing, Inspection and Certification company. We operate a network of over 2,500 laboratories and business facilities across 115 countries, supported by a team of over 100,000 dedicated professionals. With more than 145 years of service excellence, we combine the precision and accuracy that define Swiss companies to help organizations achieve the highest standards of quality, compliance and sustainability.

Our brand promise – when you need to be sure – underscores our commitment to trust, integrity and reliability, enabling businesses to thrive with confidence. We proudly deliver our expert services through the SGS name and a portfolio of trusted specialized brands, including Applied Technical Services, Brightsight, Bluesign and Nutrasource.

SGS is publicly traded on the SIX Swiss Exchange under the ticker symbol SGSN (ISIN CH1256740924, Reuters SGSN.S, Bloomberg SGSN SW).

News & Insights

  • SGS - Mauritius - Phoenix

SGS House,

Valentina, 73553,

Phoenix,

Mauritius