Skip to content
ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

ISAREADY Editorial Team

Two organisations facing the same catalogue transition can have completely different experiences of it. For one it is an afternoon updating a mapping table. For the other it is a quarter of rework.

The difference is not preparedness in general. It is one specific structural choice made much earlier.

What this article does not do

It does not tell you what any ISA catalogue version contains, what changes between versions, or when a transition applies. That information comes from the VDA and ENX Association, and preparing against a third-party account of a copyrighted catalogue is preparing against a guess.

What follows is ISAREADY methodology for running a version transition. It applies to any catalogue change, which is rather the point.

First, measure your coupling

Before planning anything, find out how tightly your programme is bound to the current version. Three questions:

  1. Is our evidence named and filed by activity, or by catalogue reference?
  2. Do our internal documents cite control numbers in their body text, or in one mapping table?
  3. Would a renumbering change what we do, or only what we call it?

Answer "by activity", "one table" and "only what we call it", and you have a mapping exercise ahead of you. Answer the other way and you have a project — and the honest response is to fix the coupling first, because you will face this again.

Decouple by anchoring on activities

The structural fix is to make activities, not control references, the primary organising principle.

"Quarterly access review of in-scope production systems" is stable. It will still be that activity under the next catalogue and the one after. A control number will not.

So: evidence folders named after activities. Internal procedures written in terms of activities. One mapping table — activity to current catalogue reference — kept in a single place, owned by one person, updated when the catalogue changes.

This is the single highest-leverage change available, and it costs a renaming exercise.

Build the mapping table before you need it

The mapping table is the transition, compressed into one artefact. One row per activity, with columns for:

  • Current catalogue reference
  • New catalogue reference
  • The record the activity produces
  • Status: unchanged, wording changed, expectation changed, new, or removed

Populate the status column honestly as soon as the official documentation is available. Only three of those five statuses generate work, and knowing which rows they are converts a vague sense of disruption into a finite list.

Protect evidence continuity

The specific risk in any transition is an evidence gap — a period where the old approach stopped, the new one had not started, and nothing was recorded.

The gap usually opens because someone pauses an activity while the paperwork is rewritten. Do not do that. Change the reference, change the template later if you must, but keep running the quarterly review on schedule. A record produced under the old structure still demonstrates that the activity happened.

If you have organised evidence by activity as described above, this holds automatically, which is a further argument for it.

Sequence the transition work

Assuming the official documentation is in hand:

  1. Complete the mapping table and mark the rows that genuinely change.
  2. Run a targeted gap assessment against those rows only. This is not a full re-assessment, and treating it as one is a common overreaction.
  3. Assign owners and target dates to the resulting findings.
  4. Update templates and internal references once, driven from the mapping table, rather than document by document as people notice them.
  5. Run an internal audit against the new structure before anyone external does.
  6. Take the outcome to management review and record the decisions.

Step two is where the effort is concentrated, and its size is determined almost entirely by how honestly step one was completed.

Do not wait to start

"We will begin when the new version is published" sounds prudent and is usually expensive.

The parts of a readiness programme that take longest are stable across versions: defining scope, assigning ownership, establishing a risk method, building the evidence habit, completing a first internal audit cycle. None of that is invalidated by a catalogue change.

And the time-bound work — demonstrating a quarterly cycle, accumulating incident records, completing an awareness cycle — needs elapsed time regardless of which version you are eventually assessed against. Waiting does not reduce the work; it reduces the time available to do it.

Communicating the transition internally

One practical note. Catalogue transitions generate anxiety disproportionate to their actual scope, particularly among people who were not involved in the original preparation.

A short internal note that says what is changing, what is not, and which specific activities are affected is worth writing. In our experience the honest version of that note is mostly reassuring — most activities are unaffected — and it prevents a general slowdown while people wait to be told what to do.

For the full method, see our ISA2027 transition page and ISA 6 overview. Our Professional toolkit includes a change-impact worksheet built around the mapping approach described here.

  • ISA2027
  • ISA 6
  • transition
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

How ready is your organisation?

The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.

Start Free Assessment

Continue reading

ISO/IEC 270014 min read

TISAX vs ISO/IEC 27001: What Actually Transfers

The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.

Read
TISAX Readiness5 min read

How to Prepare for a TISAX Assessment

A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.

Read

From requirements to real readiness

The toolkit turns the guidance in these articles into a working programme: gap assessment, risk treatment, evidence, internal audit and management review as one connected system.