With the publication of the VDA ISA 2027, the automotive industry sets another important milestone for information security and supply chain security. The new questionnaire will form the basis for all TISAX® assessments commissioned from January 1, 2027 onward.
What’s New?
The most significant change is the new year-based versioning model. Instead of sequential version numbers, the catalog will now use the year in which it becomes mandatory. New versions are therefore expected to follow the ISA 2027 annually, giving companies better predictability and transparency. At the same time, the validity of TISAX® labels remains unchanged at up to three years.
Focus on Supply Chain Security
A key focus of the ISA 2027 is securing the supply chain. Companies with an elevated need for protection will need to provide stronger evidence that their suppliers meet defined security requirements. This includes documented evidence, regular reviews, and the assessment of significant changes within the supply chain. For particularly critical information, additional evidence is required, for example through TISAX® labels, comparable audits, or supplier audits.
Improved Clarity and Updated Standards
The catalog has been comprehensively revised to make requirements clearer, more consistent, and easier to interpret. In addition, references to international standards have been updated, including the NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and ISA/IEC 62443. Outdated references to ISO/IEC 27001:2013 have been removed.
New Developments in Prototype Protection
The Prototype Protection (PTS) section has also been fundamentally revised. The previous structure has been simplified and merged into the areas of “Organizational Requirements” and “Physical and Environmental Security.” In addition, new requirements have been introduced for the traceability, management, and proper disposal of prototypes, components, and tools.
What Does This Mean for Companies?
Companies should familiarize themselves with the changes introduced by the ISA 2027 at an early stage. In particular, the increased requirements for supplier management, the stronger governance orientation, and the more precise documentation obligations will make it necessary to adapt existing information security and compliance processes.
Conclusion
The VDA ISA 2027 strengthens information security across the entire automotive value chain and addresses the growing demands on cybersecurity, compliance, and resilience. For companies, the new version offers an opportunity to further develop their own security organization and sustainably strengthen trustworthiness with customers, business partners, and manufacturers.
COMPLIONS Advisory GmbH supports companies in preparing for TISAX® assessments, implementing information security requirements, and building sustainable governance, risk, and compliance structures.




