Framework information
ISA 6 and what a catalogue version means for your preparation
The ISA catalogue is the assessment catalogue published by the VDA and used in TISAX assessments. This page explains how we think about catalogue versions in readiness work — and is deliberately careful about what it does not do: it does not reproduce the catalogue, summarise its requirements, or tell you what a specific control expects. For that, use the official source.
Last updated 8 August 2026 · ISAREADY Editorial Team
What the ISA catalogue is
ISA stands for Information Security Assessment. It is the catalogue published by the VDA that is used as the basis for TISAX assessments, covering information security and, where applicable, additional scopes such as prototype protection and data protection.
Official framework information The existence, ownership and role of the ISA catalogue are publicly documented by the VDA and ENX Association. The specific content of any version — its controls, its structure, its maturity expectations — is available only from those sources, and this page does not restate it.
We take that restriction seriously. A supplier who prepares against a third-party summary of a catalogue is preparing against a guess.
ISA 6 is superseded by ISA2027, published on 1 July 2026 and applying to assessments ordered from 1 January 2027. ENX gives March 2027 as the final date to open an initial assessment under ISA 6 — see the ISA2027 page for what changed and how to plan the move.
Why catalogue versions matter — and why they should matter less
A new catalogue version can change structure, emphasis, wording or numbering. For a team that has organised its entire programme around question numbers, that is disruptive: every reference, every evidence folder name, every internal mapping has to be revisited.
For a team that organised around themes and activities, it is a mapping exercise. The access review still happens. The record still exists. What changes is which reference it is presented under.
ISAREADY recommendation Our recommendation is therefore structural: name your evidence after the activity, not after a catalogue reference, and keep the mapping in one place you can update in an afternoon.
Preparing in a version-resilient way
- Anchor on activities. “Quarterly access review” is stable. A control number is not.
- Keep one mapping table. Activity → current catalogue reference. When the catalogue changes, you update one table.
- Keep the evidence map separate. Activity → record → owner → location. This should survive several catalogue versions untouched.
- Read the official change information. When a version changes, the publisher is the only reliable account of what changed.
A note on maturity expectations
Assessments against the ISA catalogue involve maturity judgements. We deliberately do not state what level is expected for any scope or control, because that is defined by the official documentation and can change between versions.
What we can say is what makes any maturity judgement easier to defend: the practice is defined, applied consistently across the whole scope, and evidenced by records you did not have to reconstruct. Our maturity assessment guidance describes how to grade that consistently in your own reviews.