FramewiseCOMPLIANCE
Practice

TISAX

The automotive industry assessment required by European OEMs and their tier-one suppliers.

What it is

TISAX is the automotive sector assessment and exchange mechanism built on the VDA ISA catalogue, governed by ENX. Assessments are performed by ENX-approved audit providers at assessment levels 2 or 3, against objectives covering information security, prototype protection, and data protection. Results are shared through the ENX portal rather than published, and labels are valid for three years.

Who typically needs it

  • Suppliers to European automotive OEMs and tier-one manufacturers
  • Engineering services and software firms handling OEM prototype or design data
  • Companies whose OEM customer has issued a TISAX label requirement with a deadline
  • ISO 27001 certified organizations who now need the automotive-specific assessment
  • Defense suppliers with automotive-adjacent product lines carrying both CMMC and TISAX

What the engagement looks like

Baseline. We assess against the VDA ISA catalogue at the assessment level and objectives your customer specified, and confirm the label scope. The wrong assessment objective is a costly error to discover during fieldwork.

Build. We implement against the maturity model the catalogue uses, which scores each control from incomplete through optimizing. Where you hold ISO 27001, much of the underlying work is already done and the effort is in the automotive-specific objectives.

Build, continued. Prototype protection carries physical and personnel requirements that software-oriented programs routinely miss — access zones, visitor handling, media control, and photography restrictions.

Audit Sprint. We mock the assessment against the ISA catalogue, close maturity gaps, and support the ENX-approved provider engagement through to label issuance.

Steady State. Labels run three years. We maintain the maturity evidence, keep the ENX portal registration current, and prepare the reassessment ahead of expiry.

Common failure modes

  • Assessment level or objectives chosen without confirming them against the OEM requirement
  • Prototype protection treated as an IT control set rather than a physical security program
  • ISO 27001 evidence reused without mapping it to the VDA ISA maturity scoring
  • Label scope drawn around the wrong legal entity or site

Price range

Programs typically run between $30,000 and $70,000 for the Build phase, lower where an ISO 27001 certification is already in place.

Related frameworks

Talk to us about your TISAX.

Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.

Book a consultation