Blogs & Insights
Nagase Europe Successfully Completes TISAX® Assessment
Nagase (Europa) GmbH has successfully completed its TISAX® Assessment, demonstrating its commitment to Information Security and the Cybersecurity requirements of the automotive supply chain.
To meet the increasing security expectations of customers and business partners, Nagase Europe implemented a TISAX-compliant Information Security Management System (ISMS). The project included a structured gap assessment, implementation of the required security processes, documentation, risk management, employee awareness measures, a Trial Assessment, and preparation for the official TISAX Assessment.
Despite an ambitious project schedule and a lean project team, the assessment was completed successfully through close collaboration between Nagase Europe and InShield Consulting. A pragmatic, risk-based approach helped ensure an efficient implementation while maintaining full alignment with the TISAX requirements.

The successful assessment confirms that Nagase Europe has established an effective framework for protecting confidential information and managing information security risks. This achievement further strengthens the company’s position as a trusted partner within the global automotive supply chain.
InShield Consulting supported the project from the initial readiness assessment through implementation, audit preparation, and assessment support. We congratulate the entire Nagase Europe team on this important milestone and thank everyone involved for the excellent cooperation throughout the project.
TISAX® is a registered trademark of the ENX Association. TISAX results are not intended for the general public.
New Handelsblatt Article: TISAX Consulting for Automotive Suppliers
TISAX has become a key requirement for many companies in the automotive supply chain. However, organizations often underestimate the effort required to achieve a successful assessment.
In a recently published Handelsblatt article, I discuss why TISAX should not be viewed solely as an IT project, which challenges suppliers typically face, and how a structured approach can help reduce complexity, effort, and audit risks.



The article is based on practical experience from numerous international TISAX projects and provides guidance for suppliers, engineering service providers, software companies, logistics providers, and other organizations working with automotive customers.
Read the article in Handelsblatt:
TISAX Consulting for Automotive Suppliers
Why TISAX often starts in Sales – and how organizations can manage it
In many automotive suppliers, TISAX does not start with IT or security.
It starts with Sales. And that makes perfect sense.



From the customer’s perspective, TISAX is part of supplier readiness.
From Sales’ perspective, the priority is clear: relationships, deals, delivery. Cybersecurity frameworks? Not exactly in front of mind.
So what happens?
The request is noted. Maybe mentioned. Then parked.
Until it comes back — months later — this time at management level, with deadlines attached and pressure rising.
A familiar pattern.
But this isn’t a failure of Sales. It’s a structural gap between commercial processes and security governance.
Organizations that handle TISAX well do not leave Sales alone with it.
They create:
- Clear escalation paths.
- Shared awareness.
- Defined ownership.
So when TISAX comes up, it does not get delayed — it gets directed.
Because in the end, it is not just about compliance. It’s about enabling Sales to respond with confidence and protecting the customer relationship before pressure builds.
Why OEMs request TISAX – and what it means for Suppliers
When OEMs ask their suppliers for TISAX, it is rarely just a formal compliance checkbox.
In most cases, it is a signal that cybersecurity has become a business-critical expectation – not only an IT topic.



From many years of working with OEMs and suppliers in TISAX contexts, one pattern is very clear: the request usually comes when sensitive information, development data, or operational continuity are seen as essential to the partnership.
TISAX is therefore less about “having a certificate” and much more about demonstrating reliability, structure, and risk awareness in daily operations.
For suppliers, this often means a shift in mindset:
From reactive compliance → to proactive trust building.
Understanding this perspective early makes a significant difference in how efficiently and calmly the TISAX journey can be managed.
The 6 most frequent critical findings in TISAX audits
When preparing for a TISAX audit, many organizations focus heavily on policies and documentation.
Yet in practice, the most critical findings are rarely about missing documents – they are about gaps between intention and reality.



Across many audits in the automotive supply chain, the same patterns appear again and again:
– insufficient physical security (buildings, access zones, separation of areas)
– unclear responsibilities for information security
– risk assessments that exist on paper but not in decision-making
– access rights that are not consistently reviewed
– supplier security that is assumed, not verified
– and incident handling that is defined, but not practiced
These findings are not about complexity. They are about structure, ownership, and consistency.
Addressing them early makes audits more predictable – and organizations more resilient.