If you work in automotive supply chains, July 1st, 2026 quietly changed your compliance
roadmap: the VDA published ISA2027, the successor to the ISA 6.0.3 catalog that
underpins every TISAX assessment — and killed sequential version numbers while at it.
The versioning change is the real headline
There will never be an "ISA 7". Catalogs are now named for the year they take effect:
ISA2027 becomes binding for assessments commissioned from January 1st, 2027;
ISA2028 will be published in summer 2027, and so on — a fixed yearly rhythm.
Why does that matter more than the content changes? Because gap analysis between catalog
versions used to be a once-every-three-years exercise. Under a yearly cadence it becomes
a recurring discipline — exactly the kind of structured, evidence-heavy work you want to
prepare programmatically instead of rediscovering it in a panic each cycle.
What actually changed in ISA2027
From the ENX announcement (primary source):
- Prototype protection was completely restructured — several control areas merged, plus a new requirement for traceable tracking of vehicles, components and parts across their lifecycle. If you're an AL 3 candidate handling pre-series data, this is your biggest construction site.
- Reference framework refresh: alignment with NIST CSF 2.0 and ISO/IEC 27001:2022 — and complete removal of all ISO 27001:2013 references. (Reminder: 2013-era ISO certificates have been void since October 31st, 2025, regardless of the printed date.)
- Sharper definitions for "project", "event" and "incident", and leadership is now an explicit target group for awareness training.
- Extended supply-chain monitoring requirements for high protection needs.
Consultant blogs are already circulating detail counts ("43 updated controls", should-to-must
upgrades). Treat those as unverified until you've checked the official ISA2027 workbook in
the ENX download area — the workbook is the source of truth, not blog summaries.
What does NOT change
Existing TISAX labels keep their full validity (up to three years). The new catalog does
not force early re-assessment; commissioning date decides which catalog applies. If you
commission in 2026, you're still assessed against 6.0.3.
The German-market wrinkle: NIS2 stacking
For DACH suppliers there's a second regulatory layer: Germany's NIS2 implementation act
has been in force since December 2025 with no transition period, catching most companies
above 50 employees. The good news is evidence reuse — a TISAX-grade ISMS covers most
technical-organisational NIS2 requirements. What TISAX does not cover: BSI registration,
national incident-reporting duties, and management liability. We wrote up the overlap in
detail (German): NIS2 compliance reality check.
Preparing without drowning
The expensive part of TISAX prep isn't understanding controls — it's evidence mapping:
finding, for each of ~45 controls, the right documents across SharePoint, Confluence,
ticket systems and mailboxes, then keeping that mapping alive across catalog years.
That workflow is where document intelligence genuinely helps (retrieval, gap analysis,
consistency checks) — and where it doesn't (maturity judgment, the auditor conversation).
Our full German write-up on the 2026/27 audit reality, including the ISA2027 changes and
an honest look at AI tooling claims: TISAX-Audit 2026/27 — was sich mit ISA2027 ändert.
Sources: ENX "10 Jahre TISAX – VDA ISA2027 veröffentlicht" (2026-07-01), ENX download
portal, LRQA/SGS on the ISO 27001:2013 sunset. Facts checked against primary sources
2026-07-17.
Top comments (0)