What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) was developed in 2017 by the German Association of the Automotive Industry (VDA) and is based on the ISO/IEC 27001 standard. It enables companies to assess their information security and share the results with partners. TISAX specifically focuses on the requirements of the automotive industry.

The goal of TISAX is to ensure standardized and comparable levels of information security among manufacturers, suppliers, and service providers. Companies can have their information security assessed by accredited audit providers and share the results via the central TISAX portal – a significant advantage, especially in complex supply chains with high security requirements.

Assessments are conducted by accredited audit providers and coordinated by the ENX Association, which also operates the TISAX platform. The TISAX process follows a maturity model that evaluates the level of implementation of information security measures – from basic structures to fully established processes.

Steht bei Ihnen ein TISAX-Audit an?

The Questionnaire for the TISAX Assessment

The assessment is based on the VDA ISA (Information Security Assessment) questionnaire, currently in version 6.0. The questions are available via ENX and VDA.

The questionnaire is aligned with ISO/IEC 27001 and extended by automotive-specific requirements, including Prototype Protection, Data Protection in line with GDPR and secure handling of confidential development data.

A successfully completed TISAX assessment has become a prerequisite for many business relationships in the automotive industry. TISAX builds trust, reduces audit effort, and strengthens a company’s position as a reliable partner in global competition.

TISAX Requirements Explained – Simple and Practical

The TISAX requirements form the basis for information security assessment in the automotive industry. They are based on the VDA ISA questionnaire (version 6.0) and define the measures companies must implement to achieve a TISAX label.

Many companies face the challenge of correctly interpreting the TISAX requirements and integrating them into their existing processes.

Structure of TISAX Requirements (VDA ISA 6.0)

TISAX requirements are defined in the VDA ISA catalog and cover all relevant areas of information security:
Information Security Management (ISMS)
Organization and responsibilities

Asset Management

Risk management

Personnel and Awareness

Physical security
IT-Sicherheit und BetriebIT security and operations
Supplier management
Data protection and compliance
The catalog includes around 45 main questions with several hundred detailed requirements.

Understanding Protection Needs and TISAX Labels

A key element of TISAX is defining protection requirements. Companies must determine:

  • which information needs to be protected
  • the required protection level (e.g. Confidential or Strictly Confidential)
  • whether additional requirements apply (e.g. very high availability or prototype protection)
These factors define the scope and depth of the assessment.

What do TISAX requirements mean in practice?

Implementing TISAX requirements typically includes:

  • establishing or improving an ISMS
  • introducing structured processes
  • defining clear responsibilities
  • ensuring continuous improvement (PDCA cycle)
TISAX is therefore not just an IT topic, but a company-wide management system.

TISAX Maturity Model

Evaluation is based on a maturity model ranging from Level 0 to Level 5. For successful certification:

  • target level is at least Level 3 (“Established”)
  • processes must be documented, implemented, and verifiable
  • weaknesses cannot be compensated by stronger areas
  •  

Typical challenges

  • unclear interpretation of requirements
  • missing documentation
  • processes not audit-ready
  • unclear responsibilities
  • lack of evidence
  •  
TISAX verstehen – kompakt erklärt

Conclusion – Successfully implementing TISAX requirements

The key to success lies in a structured, risk-based approach and practical implementation. A structured gap analysis is the fastest way to gain clarity about your current status.

TISAX Audit Preparation – The Path to Certification

Preparing for a TISAX audit is a key step towards successful certification.

The audit evaluates not only documentation, but more importantly how information security is actually implemented in practice.

Process of TISAX audit preparation

Preparation typically follows five phases:

Define scope and audit objectives

• define locations
• select labels
• define protection requirements

Gap-Analyse (Fit-Gap)

• compare current state vs. TISAX requirements
• identify gaps
• prioritize actions

Implementation

• establish ISMS
• introduce policies and processes
• implement technical and organizational measures

Evidence generation

• documentation
• audit evidence
• proven processes

Audit preparation

• internal reviews
• interview preparation
• management briefing

Typical mistakes

Success factors

What is assessed in a
TISAX audit?

The following elements are subject of the Audit:

AL2 assessments are performed remotely, while AL3 includes on-site audits.

TISAX audit preparation with InShield Consulting

With InShield Consulting, you prepare efficiently and in a structured way:

TISAX and ISO/IEC 27001

TISAX is closely aligned with international information security standards such as ISO/IEC 27001. While ISO/IEC 27001 provides a universal framework for Information Security Management Systems (ISMS), TISAX builds on these principles by adding industry-specific requirements for the automotive sector.
Companies that are already certified according to ISO/IEC 27001 benefit from a more efficient implementation and audit process for TISAX, as the two standards are largely compatible in many areas.

Integration of additional international standards

TISAX also incorporates elements from other recognized standards and frameworks to ensure comprehensive coverage of information security requirements:

ISO/IEC 27002: TISAX integrates security controls and measures from this guideline, which supports the implementation of ISO/IEC 27001.

ISO/IEC 27701: For data protection and GDPR compliance, TISAX builds on principles from this standard, which focuses on privacy information management.

NIST Cybersecurity Framework: Some TISAX requirements align with the security categories and controls defined in this framework, which is widely used in the United States.

Global recognition and trust

ISO/IEC 27001: Provides global recognition and is particularly important for organizations operating with international partners.
TISAX: Establishes industry-specific trust within the automotive sector and across its supply chain.
Combined approach: Companies holding both ISO/IEC 27001 and TISAX certifications can address a broader range of requirements and demonstrate their security standards both internally and externally.

Comparison: TISAX vs. ISO/IEC 27001

Aspect

ISO/IEC 27001

TISAX

Target group
All industries

Automotive industry and its supply chain

Focus
Implementation of an ISMS
Assessment of industry-specific information security requirements
Flexibility
Highly flexible, adaptable to organization
Standardized modules for specific requirements
Certification process
ISO audit by accredited certification bodies
TISAX audit by accredited audit providers
Risk management
Core component
Core component, tailored to automotive-specific risks
International scope
Globally recognized
Primarily European, with increasing international relevance

Comparison: TISAX vs. ISO/IEC 27001

ISO/IEC 27001

All industries
Implementation of an ISMS
Highly flexible, adaptable to organization
ISO audit by accredited certification bodies
Core component
Globally recognized

TISAX

Automotive industry and its supply chain
Assessment of industry-specific information security requirements
Standardized modules for specific requirements
TISAX audit by accredited audit providers
Core component, tailored to automotive-specific risks
Primarily European, with increasing international relevance

Are you ready for your TISAX audit?

Answer 12 key questions to assess how well your company is prepared for TISAX certification.

Thema Ihrer Anfrage:

Subject of your inquiry: