TISAX (Trusted Information Security Assessment Exchange)

TISAX is the German automotive industry's information security assessment scheme, based on the VDA ISA questionnaire. Results are shared through the ENX portal. Common for suppliers to VW, BMW, Mercedes-Benz, Bosch, Continental and others.

Who it applies to

Any organisation processing information for the automotive industry — OEMs, tier-1 to tier-n suppliers, engineering services.

How ISO-STANDARD.app helps with TISAX

Pre-loaded TISAX control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current TISAX posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to TISAX clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

TISAX assessment levels (AL1, AL2, AL3) explained

The assessment level maps to the risk profile of the information you handle. Getting it right saves months of rework.

AL1: self-assessment only

Rare in practice. Used only for low-risk information categories at the buyer's discretion.

AL2: plausibility check

Remote assessment with document review and interviews. The most common level for standard prototype data or ordinary personal data.

AL3: full on-site audit

Deep on-site or intensive remote assessment. Required for high-protection prototypes, high-volume personal data, or connected-vehicle data.

Choosing correctly

The customer specifies the required assessment objectives. Confirm with them before starting — starting at AL2 when you need AL3 wastes a full cycle.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

The VDA ISA questionnaire structure

ISA is the assessment content. Understand the seven catalogues and the assessment logic behind them.

Seven catalogues

Information Security, Prototype Protection, Data Protection, plus specialised modules. Not every organisation answers all — objectives determine scope.

Maturity model

Each control is scored on a 0–5 maturity scale. Level 3 (established) is typically the target; higher for critical processes.

Target maturity per objective

Different assessment objectives set different target maturities. Prototype protection targets are higher than standard information security.

Evidence per control

Every control needs specific evidence — policies alone are not enough. Screenshots, logs, test records are expected.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX prototype protection: the special regime

Prototype protection is where TISAX earns its reputation. Physical controls, digital controls, and process controls interlock.

Physical security

Access controls, video surveillance, room construction, key management. Data-centre-grade requirements applied to workshops and test tracks.

Vehicle handling

Camouflage, transport regime, test track access, disposal. Every touchpoint has controls.

Sub-supplier controls

You flow the same controls to sub-suppliers who touch the prototype. Contract terms are expected.

Incident response

Leaks (photos, specifications, physical intrusions) trigger specific notification obligations to the OEM.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX vs ISO 27001: the practical difference

Both are information security frameworks. TISAX is a supply-chain assessment scheme with automotive-specific controls layered on.

Common ground

TISAX ISA is heavily aligned with ISO 27001 and ISO 27002. An ISO 27001-certified organisation has done most of the work.

Automotive extras

Prototype protection, connection-to-third-parties controls, and data protection module specifics. These are TISAX-only.

Assessment mechanics

ISO 27001 is a certification against a standard. TISAX is a shared assessment with a defined result exchanged via the ENX portal.

Buyer expectations

OEMs increasingly accept ISO 27001 for baseline suppliers and require TISAX for those touching prototype or connected-vehicle data.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX labels and assessment objectives explained

The labels you receive are what buyers actually see on the ENX portal. Choose them deliberately.

Objective categories

Information Security, Prototype Protection (with sub-objectives), Data Protection. Each maps to a label.

Sharing scope

You choose who can see your results on the ENX portal — specific OEMs or broadly. Sharing scope changes commercial value.

Label duration

Labels are valid for three years, with an interim check often required. Plan the recertification runway.

Multiple labels

Most suppliers hold multiple labels because different customers ask for different objectives. Consolidate where possible to reduce assessment load.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

Starting a TISAX programme from ISO 27001

If you have ISO 27001, budget 3–6 months. If you don't, budget 9–12.

Baseline your ISO 27001 coverage

Map your existing controls to the ISA catalogue. Identify gaps.

Automotive-specific gaps

Prototype protection is usually the biggest new work area. Physical security, sub-supplier flow-down, and workshop controls dominate.

Choose an audit provider

TISAX assessments are done by ENX-approved providers. Book early — capacity is limited, especially at year-end.

Register on ENX

Registration, scope definition, provider selection all happen on the ENX portal. Get familiar with it before crunch time.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX audit preparation: a two-week countdown

The audit is intense. Prepare the ground so you're demonstrating, not creating.

Two weeks out

Confirm sample sites and interviewees. Ensure all evidence is filed and named consistently.

One week out

Full dry-run interview per interviewee. Verify physical controls are in place; don't discover a gap on audit day.

Audit week

Assessor-led. Have a runner to fetch evidence quickly. Take notes on findings and clarifications requested.

After the audit

Address any non-conformities within the specified window. Move quickly — the assessment result is held until closed.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

The TISAX data protection module

The DP module maps closely to GDPR but adds automotive-specific expectations.

GDPR baseline

The module assumes GDPR compliance. If your ROPA and DPIA process is weak, DP module scores will be weak.

Automotive extras

Handling of connected-vehicle data, telematics, driver behaviour data. Special category considerations for on-board footage.

Controller/processor clarity

OEM/supplier arrangements can be complex. The audit expects clear allocation of roles for every processing activity.

Cross-border

Global automotive data flows are the norm. Transfer mechanisms must be documented for every jurisdiction pair.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX for connected-vehicle and telematics data

Connected vehicles generate high-volume, high-sensitivity data. TISAX has raised the bar accordingly.

Data classification

Vehicle-generated data (location, behaviour, sensor) has specific classifications with high protection expectations.

Backend security

The backend platforms that receive vehicle data must meet stringent controls — including for development and test environments.

Third parties

Analytics providers, cloud hyperscalers, insurance partners — all inherit the scope through contract flow-down.

Emerging expectations

OEMs are adding vehicle-cybersecurity (ISO 21434) alignment to TISAX conversations. Expect this to formalise.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

TISAX recertification and staying assessment-ready

Every three years feels far away until it isn't. Continuous evidence is cheaper than assessment-crunch mode.

The three-year cycle

Full recertification every three years. Interim self-assessment often required by some OEMs, especially for high-risk labels.

Between assessments

Quarterly review of the ISA catalogue against your reality. Change control feeds the register; don't let drift accumulate.

Buyer questionnaires

Publishing your TISAX label in a Trust Center removes friction. Some buyers still send questionnaires — a shared library helps.

Continuous improvement

TISAX findings are gold. Track them as corrective actions with root cause analysis, not just closure tickets.

How ISO-STANDARD.app helps with TISAX

Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.

Ready to evidence TISAX?

Load the pre-mapped controls, capture evidence continuously, and publish your TISAX posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.