What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) was developed in 2017 by the German Association of the Automotive Industry (VDA) and is based on the ISO/IEC 27001 standard. It enables companies to assess their information security and share the results with partners. TISAX specifically focuses on the requirements of the automotive industry.
The goal of TISAX is to ensure standardized and comparable levels of information security among manufacturers, suppliers, and service providers. Companies can have their information security assessed by accredited audit providers and share the results via the central TISAX portal – a significant advantage, especially in complex supply chains with high security requirements.
Assessments are conducted by accredited audit providers and coordinated by the ENX Association, which also operates the TISAX platform. The TISAX process follows a maturity model that evaluates the level of implementation of information security measures – from basic structures to fully established processes.

The Questionnaire for the TISAX Assessment
The questionnaire is aligned with ISO/IEC 27001 and extended by automotive-specific requirements, including Prototype Protection, Data Protection in line with GDPR and secure handling of confidential development data.
TISAX Requirements Explained – Simple and Practical
The TISAX requirements form the basis for information security assessment in the automotive industry. They are based on the VDA ISA questionnaire (version 6.0) and define the measures companies must implement to achieve a TISAX label.
Many companies face the challenge of correctly interpreting the TISAX requirements and integrating them into their existing processes.
Structure of TISAX Requirements (VDA ISA 6.0)
Asset Management
Personnel and Awareness

Understanding Protection Needs and TISAX Labels
A key element of TISAX is defining protection requirements. Companies must determine:
- which information needs to be protected
- the required protection level (e.g. Confidential or Strictly Confidential)
- whether additional requirements apply (e.g. very high availability or prototype protection)
What do TISAX requirements mean in practice?
Implementing TISAX requirements typically includes:
- establishing or improving an ISMS
- introducing structured processes
- defining clear responsibilities
- ensuring continuous improvement (PDCA cycle)
TISAX Maturity Model
Evaluation is based on a maturity model ranging from Level 0 to Level 5. For successful certification:
- target level is at least Level 3 (“Established”)
- processes must be documented, implemented, and verifiable
- weaknesses cannot be compensated by stronger areas
Typical challenges
- unclear interpretation of requirements
- missing documentation
- processes not audit-ready
- unclear responsibilities
- lack of evidence

Conclusion – Successfully implementing TISAX requirements
- A structured gap analysis is the fastest way to gain clarity on your current status.
TISAX Audit Preparation – The Path to Certification
Preparing for a TISAX audit is a key step towards successful certification.
The audit evaluates not only documentation, but more importantly how information security is actually implemented in practice.
Process of TISAX audit preparation
Define scope and audit objectives
• define locations
• select labels
• define protection requirements
Gap-Analyse (Fit-Gap)
• compare current state vs. TISAX requirements
• identify gaps
• prioritize actions
Implementation
• establish ISMS
• introduce policies and processes
• implement technical and organizational measures
Evidence generation
• documentation
• audit evidence
• proven processes
Audit preparation
• internal reviews
• interview preparation
• management briefing
Typical mistakes
- focusing only on documentation
- missing evidence
- starting too late
- lack of management involvement
Success factors
- early project start
- clear structure
- realistic planning
- practical implementation
- practical implementation
What is assessed in a
TISAX audit?
- policies and processes
- real implementation in daily operations
- documentation and evidence
- employee awareness
- consistency of implementation
AL2 assessments are performed remotely, while AL3 includes on-site audits.
TISAX audit preparation with InShield Consulting
- Fit-Gap Workshops
- ISMS implementation and optimization
- support with documentation and evidence
- interview preparation
- support until the audit
TISAX and ISO/IEC 27001
TISAX is closely aligned with international information security standards such as ISO/IEC 27001. While ISO/IEC 27001 provides a universal framework for Information Security Management Systems (ISMS), TISAX builds on these principles by adding industry-specific requirements for the automotive sector.
Companies that are already certified according to ISO/IEC 27001 benefit from a more efficient implementation and audit process for TISAX, as the two standards are largely compatible in many areas.
Integration of additional international standards
ISO/IEC 27002: TISAX integrates security controls and measures from this guideline, which supports the implementation of ISO/IEC 27001.
ISO/IEC 27701: For data protection and GDPR compliance, TISAX builds on principles from this standard, which focuses on privacy information management.

Global recognition and trust

Comparison: TISAX vs. ISO/IEC 27001
Aspect
ISO/IEC 27001
TISAX
Automotive industry and its supply chain
Comparison: TISAX vs. ISO/IEC 27001
ISO/IEC 27001
TISAX
Are you ready for your TISAX audit?
Answer 12 key questions to assess how well your company is prepared for TISAX certification.