Skip to content

Framework information

ISA 6 and what a catalogue version means for your preparation

The ISA catalogue is the assessment catalogue published by the VDA and used in TISAX assessments. This page explains how we think about catalogue versions in readiness work — and is deliberately careful about what it does not do: it does not reproduce the catalogue, summarise its requirements, or tell you what a specific control expects. For that, use the official source.

Last updated 8 August 2026 · ISAREADY Editorial Team

What the ISA catalogue is

ISA stands for Information Security Assessment. It is the catalogue published by the VDA that is used as the basis for TISAX assessments, covering information security and, where applicable, additional scopes such as prototype protection and data protection.

Official framework information The existence, ownership and role of the ISA catalogue are publicly documented by the VDA and ENX Association. The specific content of any version — its controls, its structure, its maturity expectations — is available only from those sources, and this page does not restate it.

We take that restriction seriously. A supplier who prepares against a third-party summary of a catalogue is preparing against a guess.

ISA 6 is superseded by ISA2027, published on 1 July 2026 and applying to assessments ordered from 1 January 2027. ENX gives March 2027 as the final date to open an initial assessment under ISA 6 — see the ISA2027 page for what changed and how to plan the move.

Why catalogue versions matter — and why they should matter less

A new catalogue version can change structure, emphasis, wording or numbering. For a team that has organised its entire programme around question numbers, that is disruptive: every reference, every evidence folder name, every internal mapping has to be revisited.

For a team that organised around themes and activities, it is a mapping exercise. The access review still happens. The record still exists. What changes is which reference it is presented under.

ISAREADY recommendation Our recommendation is therefore structural: name your evidence after the activity, not after a catalogue reference, and keep the mapping in one place you can update in an afternoon.

Preparing in a version-resilient way

  • Anchor on activities. “Quarterly access review” is stable. A control number is not.
  • Keep one mapping table. Activity → current catalogue reference. When the catalogue changes, you update one table.
  • Keep the evidence map separate. Activity → record → owner → location. This should survive several catalogue versions untouched.
  • Read the official change information. When a version changes, the publisher is the only reliable account of what changed.

A note on maturity expectations

Assessments against the ISA catalogue involve maturity judgements. We deliberately do not state what level is expected for any scope or control, because that is defined by the official documentation and can change between versions.

What we can say is what makes any maturity judgement easier to defend: the practice is defined, applied consistently across the whole scope, and evidenced by records you did not have to reconstruct. Our maturity assessment guidance describes how to grade that consistently in your own reviews.

Frequently asked questions

Where can I get the ISA catalogue?
From the VDA, which publishes it, and through ENX Association’s participant documentation. Always work from the current official version. We do not reproduce the catalogue or its questions, and no third-party summary — including ours — is a substitute for it.
Does ISAREADY provide the ISA questions?
No. The catalogue is copyrighted material published by the VDA. Our tools are original content structured around information security management themes; they do not reproduce, paraphrase or renumber the official questions.
Do we need to restructure our programme for a new catalogue version?
Usually not, if the programme is built around themes and evidence rather than around question numbers. That is the practical argument for organising your evidence by activity rather than by catalogue reference: a renumbering then costs you a mapping exercise instead of a rebuild.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.