Glossary · simply explained

TISAX

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry standard for proving information security: manufacturers and suppliers are assessed against the VDA ISA catalogue and share results via a common platform — one assessment recognised by all participants instead of individual audits per customer.

Anyone working for automotive manufacturers or processing their confidential information can hardly avoid TISAX: many OEMs require a valid label as a condition for collaboration.

How TISAX works

The basis is the VDA ISA catalogue, closely aligned with ISO 27001 and extended by modules for prototype protection and data protection. Depending on the protection needs of the information processed, assessment levels apply: from self-assessment with plausibility checks to on-site audits by an approved audit provider. The result are labels valid for three years, shared via the ENX platform.

The path leads through a lived ISMS: risk management, policies, access control, physical security, supplier governance — plus the automotive-specific requirements, such as handling prototypes and camouflaged vehicle material. Maturity levels count: processes must not only exist but demonstrably work.

TISAX in practice

  • One assessment for many customers: result sharing replaces audit series.
  • Three assessment levels depending on protection needs — up to on-site audits.
  • Network security pays in directly: segmentation, access control, monitoring.
  • Plan preparation realistically: from ISMS build-up to label often takes months.

Frequently asked questions about TISAX

Who needs a TISAX label?

Companies exchanging confidential information with automotive manufacturers or their supply chain — development service providers, suppliers, agencies, IT providers. Whether and which level is required usually follows from the client’s demands.

What is the difference between TISAX and ISO 27001?

ISO 27001 is the generic ISMS standard with a certificate; TISAX uses a catalogue aligned with it, adds automotive-specific modules and replaces the certificate with shared assessment results. An ISO 27001 basis eases TISAX considerably but does not replace it.

Which assessment levels exist?

Three: level 1 as self-assessment without external checks, level 2 with plausibility checks by an audit provider (usually remote), level 3 with a comprehensive on-site audit — for very high protection needs such as prototype information. The required level is set by the information protection needs.

How long does the path to a TISAX label take?

Depending on the starting point: with a lived ISMS a few months are realistic; starting from zero, plan six to twelve months for build-up, evidence and assessment. The bottleneck is rarely tooling but lived processes including documentation.

Does network security pay into TISAX?

Directly: the ISA catalogue requires network segmentation, controlled remote access, access control and event logging, among other things. Running segmentation, ZTNA and monitoring cleanly demonstrably covers audit-relevant requirements.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.