Skip to content

TISAX

TISAX as a managed assessment, not a one-off project

Map VDA ISA criteria, scope the relevant assessment level and connect prototype-data controls with owners and evidence. The next OEM assessment reuses the approved work as far as the scope allows.

Validity of every TISAX label
3 years
AL1 self-assessment, AL2 remote, AL3 on-site
3 levels
ENX-ready evidence package per assessment
1 package

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • TISAXRequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

Full VDA ISA catalog coverage

KaitoSec ships with the complete VDA ISA (Information Security Assessment) catalog structured as assignable criteria. Every criterion, including the additional requirements for high and very high protection needs, is linked to implementation guidance, so your team knows what is required and which evidence to collect.

02

Scope the right assessment level

TISAX defines three assessment levels: AL1 as self-assessment, AL2 with remote audit, AL3 with on-site audit for prototype data. KaitoSec helps determine which level your OEM customers require and limits the implementation work to that level, so no effort goes into a level nobody requires.

03

ENX portal readiness

The ENX Association portal is where TISAX results are registered and shared with OEM customers. KaitoSec prepares your evidence package in the format ENX-accredited audit providers expect and tracks submission status through the assessment.

The workflow

01

Track maturity per ISA criterion

For each ISA criterion, KaitoSec tracks the current maturity level against the target maturity of 3 that the TISAX methodology sets for all criteria. Ahead of the assessment date you see which criteria are furthest from target.

02

Prototype and Development Data Controls

TISAX AL3 includes specific requirements for handling prototype data and development secrets. KaitoSec provides dedicated control sets for physical security, need-to-know access and securing R&D environments.

03

Manage sharing with OEM customers

Once your TISAX label is active on the ENX portal, KaitoSec keeps track of which OEM customers you have shared results with and which scope each release covers. You stay in control of who sees what.

FAQ

What is TISAX and who needs it?

TISAX (Trusted Information Security Assessment Exchange) is an automotive industry information security assessment standard based on the VDA ISA catalog. It is required by most major German OEMs and is increasingly demanded by Tier 1 suppliers. Any company in the automotive supply chain that handles sensitive OEM data, prototype information, or critical development assets is likely to need a TISAX label.

How does TISAX differ from ISO 27001?

TISAX is specifically designed for the automotive supply chain and focuses on protection of vehicle data, prototype data, and supplier relationships. ISO 27001 is a general ISMS standard applicable to any sector. TISAX builds on ISO 27001 concepts but has sector-specific requirements. Results are shared exclusively through the ENX portal; there is no public certificate as with ISO 27001. See the TISAX glossary entry for the assessment-level structure and ENX portal role.

Which assessment level do we need?

Assessment level depends on the sensitivity of the data you handle for OEM customers. AL1 covers normal information protection and is self-assessment only. AL2 is required for high protection needs and involves remote audit by an ENX-accredited audit provider. AL3 covers very high protection needs, such as prototype data, and requires on-site audit. Your OEM customer will specify the required level in the contract.

How long is a TISAX label valid?

TISAX labels are valid for three years from the date of the assessment. KaitoSec tracks your label expiry and sends reminders well in advance, so reassessment preparation starts early enough and no gap opens in your supplier qualification.

Can KaitoSec map TISAX controls to ISO 27001?

Yes. KaitoSec maintains a cross-mapping between VDA ISA criteria and ISO 27001:2022 Annex A controls. If your organisation pursues a TISAX label and an ISO 27001 certificate, evidence and implementations are reused across both frameworks. That saves duplicate work.

Related frameworks