Before a TISAX assessment, the existence of a supplier policy is not enough. What matters is the specific control evidence: how the company set requirements for a particular supplier, assessed assurance, detected change and decided what to do about a deviation.
Note: General professional guidance; not legal advice or a certification or audit guarantee.
That is where ISA2027 sharpens the focus. ENX announced the new version on 1 July 2026, and the official English ISA2027 workbook is available. ISA2027 applies to TISAX assessments ordered from 1 January 2027, making the order date the decisive lever for catalogue version planning. According to ENX, the new annual publication cycle does not change the validity of existing labels or automatically increase reassessment frequency. Existing labels retain their validity period; labels can still remain valid for up to three years.
This is not an annual certification machine. It is a more frequent catalogue cycle with an unchanged label lifecycle. The pressure on management and the ISMS therefore comes not from a manufactured annual alarm, but from stronger expectations for supply-chain evidence.
Prototype Protection is also being simplified structurally: the previous five groups are consolidated into two domains. The official English ISA2027 workbook contains 78 numbered control questions in total: 46 in Information Security, 20 in Prototype Protection and 12 in Data Protection. This is not a universal audit volume; the applicable modules and questions depend on the assessment objectives. The restructuring, module coverage and stronger supplier-security emphasis should be handled as separate parts of the version delta. Claims about requirements moving from “should” to “must” still require a defensible version comparison.
The supplier problem is not the contract; it is the closed evidence chain
Many organisations have security clauses, supplier lists and questionnaires. Yet they cannot show which requirements apply to a particular protection need, who evaluates the submitted evidence, or what happens after a material change.
A typical break looks like this. Procurement requires “appropriate information security”. The supplier points to a certificate or label. A business team adopts a new cloud component. The ISMS learns about it during the next scheduled review. Each activity looks plausible in isolation; together they do not form a defensible control chain.
Consider a hypothetical operating case. An engineering provider is allowed to access a segregated project repository. At initial approval, its assurance evidence matches the agreed service and location. Six months later, part of the work is moved to a subcontractor. The contract contains a general security clause, but neither Procurement nor the business has defined which changes require notification or who assesses their effect. The problem is not a missing document. What is missing is the transition from a new fact to a new decision.
A closed evidence chain must therefore do more than store files. It connects the actual service scope with protection need and requirements, tests accepted evidence against its real scope, and records who owns the remaining risk. If one link changes, the entire relationship need not stop automatically. Nor should the old approval continue by inertia. That decision logic is what turns supplier administration into defensible governance.
In the scenario, the provider announces the subcontracting arrangement on a Tuesday. Procurement forwards the message to the business but initially treats it as an operational contract matter. The business sees no reason to escalate because the formal access permissions have not changed. Information Security learns about it a week later. By then it is unclear whether the existing assurance covers the new part of the service, location and access path. Nobody has necessarily acted unreasonably; each role has simply decided within its own field of view. That local plausibility creates the system-level gap.
A workable process therefore turns the notification into an identifiable review case. The service owner describes what is actually changing. Procurement links the contract, subcontractor terms and outstanding commitments. Information Security assesses protection need, assurance scope and additional risk; Privacy and other functions join where their subject matter is affected. The authorised role then decides whether to continue, restrict the service or request further evidence. The original onboarding remains available as the decision made at that time, but is visibly supplemented for the changed scope.
This gives management a different view of supplier risk. A list of expired documents reveals administrative work, but not necessarily the most urgent decisions. More relevant are relationships where protection need, current service and accepted assurance no longer align, or where a material change remains open without an owner. Management can prioritise resources, require interim controls or consciously address commercial dependency.
According to ENX’s explanation, ISA2027 places greater emphasis—particularly for high protection needs—on documenting, reviewing and monitoring supplier compliance and the associated evidence. Reviews should also take material changes affecting suppliers or supply-chain structures into account. For very high protection needs, assurance expectations are stronger: suppliers are expected to demonstrate an adequate information-security level through a TISAX label, equivalent third-party assessment or appropriate supplier audit.
Static documents demonstrate a point in time and a defined scope. They do not replace scope validation or ongoing change signals.
Turn requirements into a control model
The practical answer is not a larger questionnaire library. It is a risk-based supplier governance model that connects requirements, evidence and decisions.
1. Start with protection need and dependency
Do not segment suppliers only by spend or contract value. Consider information assets, access paths, operational dependency, subcontractors, substitutability and the impact of outage or disclosure. A small specialist provider may be more security-critical than a large office supplier.
Segmentation must lead to testable consequences. Each segment defines applicable requirements, accepted evidence, review frequency and authority for approving exceptions.
Each segment needs a minimum decision path if segmentation is to remain more than a one-off spreadsheet exercise. Lower protection needs may be handled through standardised evidence and periodic review. Higher protection needs call for tighter scope validation, specialist approval and change signals. The number of categories is not the point; their effect is. Two supplier classes that trigger identical requirements, evidence and escalation are usually classification without control value.
2. Cascade requirements precisely
A clause saying that a supplier maintains “appropriate security measures” leaves substantial room for interpretation. A traceable mapping from protection need to minimum requirements, evidence forms, notification times, subcontractor rules and change notifications is more useful.
Cascading does not mean sending the full catalogue to every small vendor. It means passing relevant requirements along the actual service chain and verifying their implementation in a proportionate way.
3. Test the evidential value
A label, certificate or audit report is not a universal pass. Check its scope, location, covered services, protection need, validity and visible limitations. Document why the evidence is sufficient for the specific relationship—or which additional assurance is needed.
For very high protection needs, the accepted form of assurance should be explicitly reasoned and approved. “Document present” is not an assessment conclusion.
Suppose, hypothetically, that a provider’s label covers a German location and one named managed service. The commissioned team now also uses a service delivered from another location. The evidence may remain authentic, valid and professionally strong while no longer covering the relevant service in full. The operational decision cannot be reduced to “certificate: yes or no”. It must identify the supported part of the relationship, the remaining gap and a proportionate additional review or restriction.
This distinction avoids two equally unhelpful reactions. One accepts every document without testing scope. The other dismisses any assurance that does not exactly match an internal preferred format. Sound governance uses the evidence available, states its reach, and adds assurance only where protection need and unresolved questions justify it. Besides reducing unnecessary review effort, that makes the reasoning intelligible to management and an assessor later.
4. Make changes trigger review
ISA2027 emphasises significant changes. The organisation therefore needs defined signals: new subcontractors, site changes, ownership changes, major incidents, platform migrations, changed data flows, new remote access or material scope expansion.
These signals should initiate a proportionate review. An annual supplier meeting alone cannot reliably capture changes between scheduled reviews.
Signal routes must match the real sources of information. A location change may reach Procurement, new technical access the business team, an incident the SOC, and a subcontractor Contract Management. Requiring every function to perform the same security assessment would be inefficient. They do, however, need to recognise a defined signal and pass it with minimum information into the shared review process. The central control is therefore not an omniscient supplier register, but a reliable handover from distributed observations.
A review trigger does not have to launch a full reassessment. A change of registered address may require only an administrative check. New privileged remote access may require a substantive scope review, additional technical restrictions and renewed approval. A graduated process prevents every change from starting the same machinery while ensuring that consequential changes do not evaporate in a shared mailbox.
In a hypothetical Thursday-evening case, a key supplier reports a major incident and a temporary relocation of service at the same time. An organisation with only an annual review cycle now improvises under pressure. A prepared model first identifies the affected services and data flows, then checks available evidence and interim controls, and finally routes continuation, restriction or suspension to the authorised decision-maker. A message becomes a controlled sequence of finding, assessment and approval.
5. Make deviations decision-ready
Not every supplier can immediately provide the requested evidence. A controlled organisation has alternatives: additional controls, restricted scope, technical isolation, a time-limited exception, audit rights, an exit plan or supplier replacement. The decision, expiry date and accountable owner are recorded.
“Accepted by Procurement” is not a risk-treatment category. The mechanism is the separation between commercial approval and risk acceptance. The same people may coordinate both decisions, but the decisions must not be confused by accident.
That separation also changes management reporting. Instead of describing a supplier broadly as “non-compliant”, the decision brief should identify the missing requirement or assurance, the service affected and the available options. Management can then weigh value, dependency, interim controls and duration without recreating the specialist assessment. The result may be further assurance, but it may equally be a technical restriction or a prepared exit. Governance does not require every exception to be prohibited; it requires every exception to be decidable and finite.
The decision brief should be short enough to receive a decision and precise enough not to become a record of mood. It states the evidence gap, affected scope, potential consequence, interim controls, proposed duration and next verifiable step. Expiry date, accountable owner and escalation threshold must be set together.
Hypothetically, a difficult-to-replace specialist supplier may be unable to provide the requested independent assurance for another four months. Management could continue the service for a limited period if access and scope are reduced, additional logging is enabled, and an exit scenario is prepared. The point is not that every gap disappears immediately. It is that the organisation consciously decides which residual risk it carries, for how long, and which event reopens the decision early.
The annual cycle requires version capability, not annual panic
ISA2027 introduces a yearly model: catalogues are generally expected to be published in summer and become effective on 1 January of the following year for newly ordered assessments. Organisations may therefore continue to skip catalogue generations between regular reassessments.
The right response is a version-delta process. When a new ISA appears, the ISMS identifies changed requirements, affected supplier segments and missing evidence. It determines which contracts and review forms need adjustment and separates actions for the next ordered assessment from those worth taking regardless because the underlying risk is real.
This turns a catalogue transition into a planned change. It enters the existing control system as prioritised work rather than becoming a complete remediation project shortly before an assessment.
A workable 60-day plan
During the first two weeks, consolidate the supplier population, protection needs and existing assurance evidence. Keep gaps and conflicting classifications visible.
By day 30, define accepted evidence forms, evaluation criteria and change signals for the most important segments. At least the most critical suppliers receive a documented scope-and-evidence review.
By day 45, clarify responsibilities across Procurement, the business, Information Security, Privacy and management. Establish decision thresholds and expiry dates for deviations.
By day 60, test the mechanism on three real suppliers: one with adequate evidence, one with a scope gap and one with a significant change. The test is not whether the form is complete. It is whether the process produces a reasoned decision.
Management checklist
- Suppliers are segmented by information value, access, dependency and protection need; segments drive different requirements and review cycles.
- Labels, certificates and audits are checked against the specific scope.
- Subcontractors and requirement cascading are included.
- Material changes trigger reassessment outside the calendar review.
- Evidence gaps have an owner, due date and interim control.
- Commercial approval remains distinguishable from risk acceptance.
- A documented ISA version-delta process accounts for order date, annual cycle, label validity and reassessment frequency.
Conclusion: the A-R-C impulse
ISA2027 does not make supplier governance more demanding merely by asking for more documents. The difference is the traceable connection between protection need, requirement, evidence, change and decision.
The A-R-C impulse: select three security-critical suppliers and map the evidence chain for each on one page. If scope, evaluation, change signal or exception decision is missing, you have identified the next priority. That is how supply-chain information security becomes controllable, auditable and management-ready.
Scope and limitations
This article offers a professional governance perspective. It is not legal advice or a binding interpretation of the ISA catalogue. It does not replace review of the official ISA2027 workbook or coordination with ENX, customers or an approved audit provider. No TISAX label or assessment outcome is guaranteed.
Sources
- ENX Association, “10 Years of TISAX – VDA ISA2027 Released”, 1 July 2026, accessed 2 August 2026: https://enx.com/en-US/news/isa2027/
- ENX Association, official English ISA2027 workbook (authoritative in case of discrepancies), accessed 2 August 2026: https://www.enx.com/isa2027-en.xlsx
About the author
Andreas Rühl supports organizations as an interim CISO and ISMS/GRC advisor. His focus is making information security manageable, auditable and fit for management decisions.