Without a valid TISAX label, automotive OEMs and tier suppliers won't put you on the contract. The assessment is based on the VDA ISA catalogue and run by the ENX Association. We get you assessment-ready so you pass first time and sustain that security afterwards.
One assessment, recognised across the industry. Verify exact requirements against the current VDA ISA catalogue and the ENX portal.
TISAX (Trusted Information Security Assessment Exchange) is operated by the ENX Association; criteria derive from the VDA ISA catalogue of the German automotive association.
Suppliers, developers and service providers in the automotive supply chain that handle sensitive information from OEMs and their partners.
AL1 to AL3. AL1 is self-assessment only (not used in the exchange), AL2 (high protection need) is typically remote and document-based, AL3 (very high protection need) involves an on-site assessment.
Most commonly information security, prototype protection and data protection; the outcome is the corresponding TISAX labels.
The result isn't public. You share it selectively with partners via the ENX portal. Validity is typically 3 years.
TISAX isn't a classic certification but a shared result of an assessment performed by an approved TISAX audit provider.
From a gap analysis against VDA ISA to implementing controls and preparing for the assessment.
Design of an information-security management system and the physical/logical controls for prototype protection.
Implementing VDA ISA controls: segmentation, identity management, logging and detection-as-code.
Penetration tests that prove the controls actually work, useful as evidence for the assessment.
24/7 monitoring and response that keep the security level between assessments, not just on audit day.
TISAX builds on the same foundations as ISO 27001 and NIS2. We cover them together.
Straight answers to what clients ask us most.
TISAX is the automotive industry's information-security assessment mechanism, operated by the ENX Association based on the VDA ISA catalogue. Suppliers and service providers handling sensitive information from carmakers and their partners need it.
Both rest on information-security management, but TISAX is automotive-specific, uses the VDA ISA catalogue, and its result is shared via the ENX portal. An ISO 27001 ISMS is a strong starting point for a TISAX assessment.
It depends on the target level (AL2/AL3) and your starting point. After a gap analysis against VDA ISA it's typically weeks to months of implementing controls; we set the schedule around your customer's deadline.
Yes. Prototype protection is a separate assessment objective with its own physical and logical security requirements. We design and implement the controls and prepare the evidence for the assessment.
We run a gap analysis against the VDA ISA catalogue, implement the missing controls and prepare you for the assessment at your target level.