Skip to content

Transition planning

ISA2027 transition: plan the change instead of absorbing it late

ENX Association published VDA ISA2027 on 1 July 2026, applying to TISAX assessments ordered from 1 January 2027. This page sets out what ENX has announced — with sources — and then how to run the transition without restarting your readiness programme. What it does not do is restate the catalogue’s control text: that is copyrighted VDA material, and preparing against a third-party paraphrase of it is preparing against a guess.

Last updated 8 September 2026 · ISAREADY Editorial Team

What ENX has published

Official framework information The following is publicly announced by ENX Association. It is a summary with attribution, not a reproduction: the catalogue itself is copyrighted VDA material and we do not restate its control text.

  • Published 1 July 2026. VDA ISA2027 is the successor to ISA 6.
  • Applies to TISAX assessments ordered from 1 January 2027.Assessments ordered before that date can still be performed against ISA 6.
  • March 2027 is given as the final date to open an initial assessment under ISA 6, per the ENX Download Center.
  • An annual release cycle begins, with year-based naming replacing sequential version numbers.
  • Existing label validity is not shortened by the move to annual releases.
  • Mappings updated to NIST CSF 2.0 and ISO/IEC 27001:2022, with references to ISO/IEC 27001:2013 removed.
  • Stronger emphasis on supply-chain security, consistent with the governance and supply-chain focus of CSF 2.0.
  • Prototype protection is restructured.

Two honest caveats. First, dates and transition conditions are exactly the sort of detail that gets adjusted — verify against ENX before committing to an assessment date. Second, knowing that a module was restructured is not the same as knowing what it now requires; that comes from the catalogue.

What it means for a readiness programme

ISAREADY recommendation This section is our reading, not an official statement.

The date that matters is when you order the assessment, not when you start preparing. That makes the decision concrete: if an assessment will be ordered in 2027, prepare against ISA2027; if it is ordered in 2026 and opened before the ISA 6 cut-off, ISA 6 still governs it.

The annual cycle is the more consequential change, and it is easy to under-react to. A programme that treats a catalogue version as a one-off project will now face that project every year. One that maps activities to references — and keeps evidence named after activities — faces an annual mapping review instead. That structural choice is worth making before the next release rather than after it.

If prototype protection is in your scope, treat the restructuring as a reason for a targeted gap assessment of that module specifically, rather than assuming your existing arrangements map across unchanged.

Step one: an honest impact assessment

Before planning anything, establish how coupled your programme is to the current version. Three questions:

  • Is our evidence named and filed by activity, or by catalogue reference?
  • Do our internal documents cite specific control numbers in their body text, or in one mapping table?
  • Would a renumbering change what we do, or only what we call it?

Organisations that answer “by activity”, “one table” and “only what we call it” have a mapping exercise ahead of them. Organisations that answer the other way have a project.

Step two: build the mapping before you need it

The mapping table is the whole transition, compressed. One row per activity, with columns for the current reference, the new reference, the record it produces, and a status.

Build it as soon as the official documentation is available, and populate the status column honestly: unchanged, wording changed, expectation changed, new, or removed. Only the middle three need work.

Industry good practice Maintaining a requirement-to-activity mapping is ordinary management system practice. It is what makes any standard revision, in any framework, a manageable event.

Step three: protect evidence continuity

The risk in any transition is an evidence gap: a period where the old approach stopped and the new one had not started, and nothing was recorded.

Avoid it by never stopping the activity. Change the reference, change the template if you must, but do not pause the quarterly access review while you rewrite the paperwork. A record produced under the old structure is still a record that the activity happened.

See evidence management for how to structure the archive so this holds automatically.

Step four: sequence the transition

A workable order, assuming the official documentation is in hand:

  1. Complete the mapping table and mark the rows that genuinely change.
  2. Assess the changed rows against current practice — this is a targeted gap assessment, not a full one.
  3. Assign owners and target dates to the resulting findings.
  4. Update templates and internal references once, from the mapping table, rather than document by document.
  5. Run an internal audit against the new structure before anyone external does.
  6. Take the outcome to management review and record the decisions.

Our Professional toolkit includes a transition worksheet built around exactly this sequence.

Do not wait for the new version to start

The parts of a readiness programme that take longest are the ones that are stable across versions: defining scope, assigning ownership, establishing a risk method, building the evidence habit, running a first internal audit cycle.

None of that is wasted by a catalogue change. Waiting, on the other hand, costs you the one thing you cannot buy back — the elapsed time over which evidence accumulates.

Frequently asked questions

When does ISA2027 apply?
ENX Association published VDA ISA2027 on 1 July 2026, and it applies to TISAX assessments ordered from 1 January 2027 onwards. Assessments ordered before that date can still be performed against ISA 6. ENX gives March 2027 as the final date to open an initial assessment under ISA 6. Confirm the current position on the ENX portal before you commit to a date — this is the kind of detail that gets adjusted.
Does the annual release cycle shorten our existing label?
No. ENX has stated that moving to an annual ISA release model does not shorten the validity of labels already held. A new catalogue version governs assessments ordered from its applicability date; it does not retroactively expire work already completed.
What does ISAREADY not tell you about the catalogue?
The control text. ISA is copyrighted material published by the VDA, and we neither reproduce nor closely paraphrase it. What we summarise here is the publicly announced scope of the change; what a specific control requires comes from the catalogue itself.
Should we wait for the new catalogue before starting preparation?
Almost never. The management system foundations — scope, ownership, risk method, evidence discipline, internal audit, management review — are stable across catalogue versions. Waiting means starting later with the same amount of work ahead of you, and with less time to accumulate evidence.
How do we keep evidence continuity across a transition?
Name evidence after the activity that produced it rather than after a catalogue reference, and keep the activity-to-reference mapping in a single table. Then a transition updates the mapping, not the evidence archive.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.