TISAX®

TISAX® readiness: implement ISA2027 with confidence

TISAX® assessments commissioned from 2027 are based on ISA2027. The new version clarifies requirements and evidence, strengthens supply-chain security and restructures prototype protection. ACM supports you in assessing relevant changes, adapting existing processes in a targeted way and entering the assessment with confidence.

  • Classify ISA2027 changes with confidence
  • Clarify scope, evidence and assessment objectives
  • Build readiness for the next assessment

Introduction

TISAX® for the automotive value chain

TISAX® is aimed at companies that exchange sensitive information in the automotive value chain or need robust information security evidence for customers. For assessments commissioned from 2027, ISA2027 is the relevant basis.

Target groups

Automotive suppliers and service providers

They process information requiring protection for OEMs or other companies in the supply chain and must provide a required TISAX® label.

Manufacturers and development partners

They work with development data, prototypes or test vehicles and need a traceable protection level across locations and partners.

IT, information security and quality leaders

They manage ISMS structures, evidence, internal audits and preparation for a new or recurring TISAX® assessment.

Overview

TISAX® and ISA2027 at a glance

TISAX® is an assessment and exchange mechanism for information security in the automotive industry. The VDA ISA catalog defines the requirements; assessment results are shared selectively with business partners through TISAX® labels in the ENX portal.

TISAX® is the industry-wide established mechanism for assessing and exchanging information security results in the automotive industry.

ISA2027 is the new VDA ISA requirements catalog and applies to TISAX® assessments commissioned from 2027.

Clearer controls, updated references, stronger requirements for supply-chain security and restructured prototype protection.

Existing TISAX® labels retain their validity period. The annual update of the ISA catalog does not automatically lead to more frequent reassessments.

Quick Check

Is TISAX® relevant for your company?

TISAX® is not a legal obligation. The mechanism usually becomes relevant through requirements from customers and partners and through the protection needs of the information being processed. This quick check provides initial orientation and does not replace an individual definition of scope and assessment objectives.

Do customers or business partners require a specific TISAX® label?
Does your company process confidential or strictly confidential information from the automotive industry?
Do you work with prototypes, test vehicles or particularly sensitive development data?
Are your company locations or services part of an automotive supply chain with defined information security requirements?
Please answer the questions for an initial assessment.

Requirements

What ISA2027 changes in concrete terms

ISA2027 develops the existing requirements catalog further. The focus is on clearer controls, traceable decisions, stronger supply-chain governance and revised prototype protection.

For relevant controls, it must be traceable how individual aspects were considered. Decisions, deviations and evidence must be explainable in the assessment.

Relevant suppliers must be classified based on risk. Security requirements, contractual arrangements, evidence and regular monitoring must fit together; significant changes must be included in the assessment.

Mappings to ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 and ISA/IEC 62443 have been revised and clarified. Existing management systems should be reviewed for overlaps and deviations.

Requirements are structured into organizational as well as physical and environmental areas. Traceability, lifecycle and secure return, recovery or disposal of protected prototypes also become more important.

Challenges

Typical hurdles - and how they become manageable

Many companies already have an ISMS and extensive evidence. The challenge is to classify changes correctly, close gaps in a targeted way and make implementation explainable in the assessment.

Solution

From delta analysis to assessment readiness

ACM combines expert classification of ISA2027 with implementation in the existing management system. The focus is on effective processes and evidence that work in daily operations and are traceable in the assessment.

1

Scope and assessment objectives

We clarify locations, protection needs, customer requirements and the suitable assessment objectives.

Result: a clearly defined scope and a robust preparation plan.

2

ISA2027 delta analysis

We compare the current implementation status with ISA2027 on a control-by-control basis, assess deviations and prioritize measures according to risk and assessment relevance.

Result: a traceable gap and action overview.

3

Implementation and evidence

We support processes, policies, supplier governance and the structured preparation of evidence.

Result: effective rules that can be explained in the assessment instead of isolated documents.

4

Readiness check, internal audits and training

We test effectiveness, simulate typical assessment questions and prepare responsible teams in a targeted way.

Result: robust readiness and more confidence in the assessment.

Top Consultants

Across all consulting topics, ACM convinces with both its service portfolio and many years of expertise. With broad IT know-how, ACM provides professional solutions for individual requirements. In-house or remote - according to customer needs.

Top-Consultant 2022 | ACM Consultants GmbH
Top-Consultant 2023 | ACM Consultants GmbH
Top-Consultant 2024 | ACM Consultants GmbH

Approach

Structured and aligned with your assessment date

Our approach is guided by your protection needs, the existing ISMS and the date of the next assessment.

01

Clarify baseline and scope

We capture assessment objectives, locations, protection needs, customer requirements and the planned assessment date.

02

Analyze and prioritize delta

We compare the existing implementation status with ISA2027 on a control-by-control basis and derive a realistic action plan.

03

Implement measures and evidence

We support the adaptation of processes, policies, supplier governance and evidence and integrate them into the existing ISMS.

04

Review effectiveness and readiness

Using gap analysis, readiness check or internal audit, we review implementation, close gaps and prepare involved teams for the assessment.

Use Cases

Information sheet: TISAX® Update 2027

The compact information sheet summarizes start date, key changes, preparation steps and the benefits of ISA2027.

TISAX® Update 2027: ISA2027 is coming

Automotive industry and supply chain

TISAX® Update 2027: ISA2027 is coming

The information sheet shows at a glance which changes ISA2027 introduces, which areas are particularly affected and how companies can structure their preparation.

Download information sheet

FAQ

Frequently asked questions about TISAX® and ISA2027

Clear answers to the most important questions about TISAX®, ISA2027, assessment objectives and preparation.

TISAX® is an assessment and exchange mechanism for information security in the automotive industry operated by the ENX Association. Companies have defined requirements assessed and can selectively share the resulting TISAX® labels with business partners.

No. TISAX® is not a classic certification. The result of a successful assessment is a set of TISAX® labels that represent the achieved assessment objective and can be shared with selected partners in the ENX portal.

TISAX® is particularly relevant for companies in the automotive value chain that process confidential information, development data, prototypes or personal data. The requirement often results from customer contracts or business partner specifications.

ISA2027 is the new version of the VDA ISA requirements catalog for TISAX® assessments. It clarifies controls and evidence obligations, strengthens supply-chain security, updates references to international standards and restructures prototype protection.

ISA2027 applies to TISAX® assessments commissioned from 2027. The decisive point is the date the assessment is commissioned, not the end of an already existing label validity period.

Important changes concern the traceable consideration of individual control aspects, risk-based supplier governance and monitoring, updated standard mappings and organizational, physical and environmental requirements in prototype protection.

Yes. Existing labels remain valid until the end of their respective validity period. The new annual versioning of the ISA catalog does not shorten the validity period; TISAX® labels can continue to be valid for up to three years.

ACM clarifies scope and assessment objectives, performs a control-based delta analysis, supports measures and evidence and reviews readiness with internal audits or a readiness check. On request, we also support assessment preparation and train involved teams.

Contact

Ready for ISA2027?

We support you in the structured transition to ISA2027 - practical, risk-oriented and aligned with your existing management system. Implement TISAX® effectively, not only on paper. Delta analysis, readiness check, supplier management, internal audits and TISAX® training from one source - aligned with protection needs, existing ISMS and your assessment planning.

Get in touch

Or you would like to call us directly

Patrick Andreas > ACM Consultants GmbH | ACM Consultants GmbH Patrick Andreas Managing Director ACM +49 151 14665555

With us, you take centre stage!
We provide you with comprehensive advice on many different topics, identify the status quo of your company and create customised, target-oriented action plans. We are happy to put these into practice for you, but we also provide support in constellations with other service providers - in exactly the way that best serves your requirements.