Automotive suppliers and service providers
They process information requiring protection for OEMs or other companies in the supply chain and must provide a required TISAX® label.
TISAX®
TISAX® assessments commissioned from 2027 are based on ISA2027. The new version clarifies requirements and evidence, strengthens supply-chain security and restructures prototype protection. ACM supports you in assessing relevant changes, adapting existing processes in a targeted way and entering the assessment with confidence.
Introduction
TISAX® is aimed at companies that exchange sensitive information in the automotive value chain or need robust information security evidence for customers. For assessments commissioned from 2027, ISA2027 is the relevant basis.
They process information requiring protection for OEMs or other companies in the supply chain and must provide a required TISAX® label.
They work with development data, prototypes or test vehicles and need a traceable protection level across locations and partners.
They manage ISMS structures, evidence, internal audits and preparation for a new or recurring TISAX® assessment.
Overview
TISAX® is an assessment and exchange mechanism for information security in the automotive industry. The VDA ISA catalog defines the requirements; assessment results are shared selectively with business partners through TISAX® labels in the ENX portal.
TISAX® is the industry-wide established mechanism for assessing and exchanging information security results in the automotive industry.
ISA2027 is the new VDA ISA requirements catalog and applies to TISAX® assessments commissioned from 2027.
Clearer controls, updated references, stronger requirements for supply-chain security and restructured prototype protection.
Existing TISAX® labels retain their validity period. The annual update of the ISA catalog does not automatically lead to more frequent reassessments.
Quick Check
TISAX® is not a legal obligation. The mechanism usually becomes relevant through requirements from customers and partners and through the protection needs of the information being processed. This quick check provides initial orientation and does not replace an individual definition of scope and assessment objectives.
Requirements
ISA2027 develops the existing requirements catalog further. The focus is on clearer controls, traceable decisions, stronger supply-chain governance and revised prototype protection.
For relevant controls, it must be traceable how individual aspects were considered. Decisions, deviations and evidence must be explainable in the assessment.
Relevant suppliers must be classified based on risk. Security requirements, contractual arrangements, evidence and regular monitoring must fit together; significant changes must be included in the assessment.
Mappings to ISO/IEC 27001:2022, NIST Cybersecurity Framework 2.0 and ISA/IEC 62443 have been revised and clarified. Existing management systems should be reviewed for overlaps and deviations.
Requirements are structured into organizational as well as physical and environmental areas. Traceability, lifecycle and secure return, recovery or disposal of protected prototypes also become more important.
Challenges
Many companies already have an ISMS and extensive evidence. The challenge is to classify changes correctly, close gaps in a targeted way and make implementation explainable in the assessment.
Solution
ACM combines expert classification of ISA2027 with implementation in the existing management system. The focus is on effective processes and evidence that work in daily operations and are traceable in the assessment.
We clarify locations, protection needs, customer requirements and the suitable assessment objectives.
Result: a clearly defined scope and a robust preparation plan.
We compare the current implementation status with ISA2027 on a control-by-control basis, assess deviations and prioritize measures according to risk and assessment relevance.
Result: a traceable gap and action overview.
We support processes, policies, supplier governance and the structured preparation of evidence.
Result: effective rules that can be explained in the assessment instead of isolated documents.
We test effectiveness, simulate typical assessment questions and prepare responsible teams in a targeted way.
Result: robust readiness and more confidence in the assessment.
Across all consulting topics, ACM convinces with both its service portfolio and many years of expertise. With broad IT know-how, ACM provides professional solutions for individual requirements. In-house or remote - according to customer needs.
Approach
Our approach is guided by your protection needs, the existing ISMS and the date of the next assessment.
We capture assessment objectives, locations, protection needs, customer requirements and the planned assessment date.
We compare the existing implementation status with ISA2027 on a control-by-control basis and derive a realistic action plan.
We support the adaptation of processes, policies, supplier governance and evidence and integrate them into the existing ISMS.
Using gap analysis, readiness check or internal audit, we review implementation, close gaps and prepare involved teams for the assessment.
Use Cases
The compact information sheet summarizes start date, key changes, preparation steps and the benefits of ISA2027.
Automotive industry and supply chain
The information sheet shows at a glance which changes ISA2027 introduces, which areas are particularly affected and how companies can structure their preparation.
FAQ
Clear answers to the most important questions about TISAX®, ISA2027, assessment objectives and preparation.
TISAX® is an assessment and exchange mechanism for information security in the automotive industry operated by the ENX Association. Companies have defined requirements assessed and can selectively share the resulting TISAX® labels with business partners.
No. TISAX® is not a classic certification. The result of a successful assessment is a set of TISAX® labels that represent the achieved assessment objective and can be shared with selected partners in the ENX portal.
TISAX® is particularly relevant for companies in the automotive value chain that process confidential information, development data, prototypes or personal data. The requirement often results from customer contracts or business partner specifications.
ISA2027 is the new version of the VDA ISA requirements catalog for TISAX® assessments. It clarifies controls and evidence obligations, strengthens supply-chain security, updates references to international standards and restructures prototype protection.
ISA2027 applies to TISAX® assessments commissioned from 2027. The decisive point is the date the assessment is commissioned, not the end of an already existing label validity period.
Important changes concern the traceable consideration of individual control aspects, risk-based supplier governance and monitoring, updated standard mappings and organizational, physical and environmental requirements in prototype protection.
Yes. Existing labels remain valid until the end of their respective validity period. The new annual versioning of the ISA catalog does not shorten the validity period; TISAX® labels can continue to be valid for up to three years.
ACM clarifies scope and assessment objectives, performs a control-based delta analysis, supports measures and evidence and reviews readiness with internal audits or a readiness check. On request, we also support assessment preparation and train involved teams.
Contact
We support you in the structured transition to ISA2027 - practical, risk-oriented and aligned with your existing management system. Implement TISAX® effectively, not only on paper. Delta analysis, readiness check, supplier management, internal audits and TISAX® training from one source - aligned with protection needs, existing ISMS and your assessment planning.
With us, you take centre stage!
We provide you with comprehensive advice on many different topics, identify the status quo of your company and create customised, target-oriented action plans. We are happy to put these into practice for you, but we also provide support in constellations with other service providers - in exactly the way that best serves your requirements.