TISAX (Trusted Information Security Assessment Exchange)
TISAX is the German automotive industry's information security assessment scheme, based on the VDA ISA questionnaire. Results are shared through the ENX portal. Common for suppliers to VW, BMW, Mercedes-Benz, Bosch, Continental and others.
Who it applies to
Any organisation processing information for the automotive industry — OEMs, tier-1 to tier-n suppliers, engineering services.
How ISO-STANDARD.app helps with TISAX
10 in-depth articles
TISAX assessment levels (AL1, AL2, AL3) explained
The assessment level maps to the risk profile of the information you handle. Getting it right saves months of rework.
AL1: self-assessment only
Rare in practice. Used only for low-risk information categories at the buyer's discretion.
AL2: plausibility check
Remote assessment with document review and interviews. The most common level for standard prototype data or ordinary personal data.
AL3: full on-site audit
Deep on-site or intensive remote assessment. Required for high-protection prototypes, high-volume personal data, or connected-vehicle data.
Choosing correctly
The customer specifies the required assessment objectives. Confirm with them before starting — starting at AL2 when you need AL3 wastes a full cycle.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
The VDA ISA questionnaire structure
ISA is the assessment content. Understand the seven catalogues and the assessment logic behind them.
Seven catalogues
Information Security, Prototype Protection, Data Protection, plus specialised modules. Not every organisation answers all — objectives determine scope.
Maturity model
Each control is scored on a 0–5 maturity scale. Level 3 (established) is typically the target; higher for critical processes.
Target maturity per objective
Different assessment objectives set different target maturities. Prototype protection targets are higher than standard information security.
Evidence per control
Every control needs specific evidence — policies alone are not enough. Screenshots, logs, test records are expected.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX prototype protection: the special regime
Prototype protection is where TISAX earns its reputation. Physical controls, digital controls, and process controls interlock.
Physical security
Access controls, video surveillance, room construction, key management. Data-centre-grade requirements applied to workshops and test tracks.
Vehicle handling
Camouflage, transport regime, test track access, disposal. Every touchpoint has controls.
Sub-supplier controls
You flow the same controls to sub-suppliers who touch the prototype. Contract terms are expected.
Incident response
Leaks (photos, specifications, physical intrusions) trigger specific notification obligations to the OEM.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX vs ISO 27001: the practical difference
Both are information security frameworks. TISAX is a supply-chain assessment scheme with automotive-specific controls layered on.
Common ground
TISAX ISA is heavily aligned with ISO 27001 and ISO 27002. An ISO 27001-certified organisation has done most of the work.
Automotive extras
Prototype protection, connection-to-third-parties controls, and data protection module specifics. These are TISAX-only.
Assessment mechanics
ISO 27001 is a certification against a standard. TISAX is a shared assessment with a defined result exchanged via the ENX portal.
Buyer expectations
OEMs increasingly accept ISO 27001 for baseline suppliers and require TISAX for those touching prototype or connected-vehicle data.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX labels and assessment objectives explained
The labels you receive are what buyers actually see on the ENX portal. Choose them deliberately.
Objective categories
Information Security, Prototype Protection (with sub-objectives), Data Protection. Each maps to a label.
Sharing scope
You choose who can see your results on the ENX portal — specific OEMs or broadly. Sharing scope changes commercial value.
Label duration
Labels are valid for three years, with an interim check often required. Plan the recertification runway.
Multiple labels
Most suppliers hold multiple labels because different customers ask for different objectives. Consolidate where possible to reduce assessment load.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
Starting a TISAX programme from ISO 27001
If you have ISO 27001, budget 3–6 months. If you don't, budget 9–12.
Baseline your ISO 27001 coverage
Map your existing controls to the ISA catalogue. Identify gaps.
Automotive-specific gaps
Prototype protection is usually the biggest new work area. Physical security, sub-supplier flow-down, and workshop controls dominate.
Choose an audit provider
TISAX assessments are done by ENX-approved providers. Book early — capacity is limited, especially at year-end.
Register on ENX
Registration, scope definition, provider selection all happen on the ENX portal. Get familiar with it before crunch time.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX audit preparation: a two-week countdown
The audit is intense. Prepare the ground so you're demonstrating, not creating.
Two weeks out
Confirm sample sites and interviewees. Ensure all evidence is filed and named consistently.
One week out
Full dry-run interview per interviewee. Verify physical controls are in place; don't discover a gap on audit day.
Audit week
Assessor-led. Have a runner to fetch evidence quickly. Take notes on findings and clarifications requested.
After the audit
Address any non-conformities within the specified window. Move quickly — the assessment result is held until closed.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
The TISAX data protection module
The DP module maps closely to GDPR but adds automotive-specific expectations.
GDPR baseline
The module assumes GDPR compliance. If your ROPA and DPIA process is weak, DP module scores will be weak.
Automotive extras
Handling of connected-vehicle data, telematics, driver behaviour data. Special category considerations for on-board footage.
Controller/processor clarity
OEM/supplier arrangements can be complex. The audit expects clear allocation of roles for every processing activity.
Cross-border
Global automotive data flows are the norm. Transfer mechanisms must be documented for every jurisdiction pair.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX for connected-vehicle and telematics data
Connected vehicles generate high-volume, high-sensitivity data. TISAX has raised the bar accordingly.
Data classification
Vehicle-generated data (location, behaviour, sensor) has specific classifications with high protection expectations.
Backend security
The backend platforms that receive vehicle data must meet stringent controls — including for development and test environments.
Third parties
Analytics providers, cloud hyperscalers, insurance partners — all inherit the scope through contract flow-down.
Emerging expectations
OEMs are adding vehicle-cybersecurity (ISO 21434) alignment to TISAX conversations. Expect this to formalise.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
TISAX recertification and staying assessment-ready
Every three years feels far away until it isn't. Continuous evidence is cheaper than assessment-crunch mode.
The three-year cycle
Full recertification every three years. Interim self-assessment often required by some OEMs, especially for high-risk labels.
Between assessments
Quarterly review of the ISA catalogue against your reality. Change control feeds the register; don't let drift accumulate.
Buyer questionnaires
Publishing your TISAX label in a Trust Center removes friction. Some buyers still send questionnaires — a shared library helps.
Continuous improvement
TISAX findings are gold. Track them as corrective actions with root cause analysis, not just closure tickets.
How ISO-STANDARD.app helps with TISAX
Inside the workspace, this topic maps to concrete artefacts: pre-loaded TISAX controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the TISAX shape.
Ready to evidence TISAX?
Load the pre-mapped controls, capture evidence continuously, and publish your TISAX posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.