ISA 6 to ISA2027: Preparing for the Transition
A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.
Practical TISAX and ISO/IEC 27001 readiness tools for automotive suppliers and information security teams. Structured gap assessment, risk treatment, evidence management and internal verification — as one connected system rather than a folder of documents.
Around 10 minutes. No account needed to start, and your answers stay in your browser until you ask for the report.
What is expected of your organisation. Necessary, and the easiest part to obtain — a requirement list is not a programme.
How the requirement is actually met in daily operation: who does it, when, and what happens when it is not done.
The dated, attributable record that the process ran. Decided in advance, produced as you go, retrievable on request.
Organisations that prepare well do not simply write more documents. They build the structure that connects the three: processes that implement the requirement, and evidence produced as a by-product of the work rather than assembled retroactively in the four weeks before an assessment.
Establish scope and an honest baseline. What is actually in place, not what the documents claim.
Convert the baseline into findings with an owner, a priority and a target date.
Do the work: processes, controls and the decisions that make them stick in daily operation.
Produce the record as the activity happens. Decided in advance, not reconstructed later.
Check yourself against your own rules through internal audit before anyone else does.
Close findings at root cause and feed the outcome back into risk, controls and awareness.
Compare where you are against where you need to be, and turn the difference into owned, dated actions.
A repeatable method, risks with owners, treatment plans, and residual risk accepted by someone with the authority to accept it.
Define the record before the activity happens, so nothing has to be reconstructed under time pressure.
A planned programme that checks you against your own rules and tracks findings to closure at root cause.
Know which third parties touch information in scope, agree requirements in writing, and follow findings through.
Defined scope, assigned responsibilities, management objectives and the resources to meet them.
Judge how consistently a practice operates, not just whether a document exists describing it.
Management review, corrective action and measurement, so readiness is maintained rather than rebuilt.
What you receive
ISAREADY Readiness Indicator
An overall percentage plus a band — Strong, Developing, Attention Required or Priority Action.
Category breakdown
A score per theme, so effort goes where the gap actually is rather than where it feels productive.
Evidence readiness view
A separate score for whether you could produce the records, which is usually the weakest part.
Prioritised next steps
Concrete actions in sequence, and a downloadable PDF you can circulate internally.
Prepare
The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.
Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.
Assess & Implement
Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.
Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.
Govern & Scale
Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.
Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.
A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.
The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.
A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.
Every substantive statement in our guidance is labelled as official framework information, industry good practice, or an ISAREADY recommendation. You should always verify official requirements against the current source documentation.
No toolkit, ours included, guarantees a TISAX label, an ISO certification or a specific assessment result. What preparation changes is whether you can demonstrate what you do — which is the part you control.
The structure in the toolkit is the structure we would apply to run a readiness programme: scope, gap assessment, risk treatment, implementation, evidence, internal audit, management review.
Questions about scope, tiers or an enterprise rollout? Talk to us.
Begin with an indicative view of where you stand. Ten minutes, no account, and a report you can share with management.
Your answers stay in your browser until you request the report.
We use essential cookies to run this site. With your permission we also use analytics cookies to understand which guidance is useful. Nothing non-essential loads until you choose. Cookie details