
ISO Consulting Services
TISAX — Trusted Information Security Assessment Exchange
TISAX labelling for automotive suppliers handling sensitive information.
TISAX — Trusted Information Security Assessment Exchange
TISAX® stands for Trusted Information Security Assessment Exchange. TISAX® enables mutual acceptance of information security assessments in the automotive industry and provides a common assessment and exchange mechanism that ensures the secure sharing of sensitive information to partner companies, to inspire trust throughout the automotive supply chain.
TISAX® was established by VDA (the German association of the automotive industry) and is operated by ENX Association, who have assessed and confirmed approved audit providers to perform the assessments.
Developed by automotive industry security experts and based on international information security management system (ISMS) standards like ISO/IEC 27001, TISAX® provides a catalogue of requirements, covering virtual, physical and social aspects of information security, specific to the automotive supply chain. This catalogue is referred to as the Information Security Assessment (ISA) and forms the basis of the assessment conducted by approved TISAX® audit providers.
What you get
- ✓TISAX scope definition
- ✓Information security implementation
- ✓Assessment preparation
- ✓Label maintenance support
Our 6-step methodology
- 01
Gap analysis & scoping
- 02
Risk assessment & treatment
- 03
Documentation framework
- 04
Implementation & training
- 05
Internal audit & review
- 06
Certification & sustenance
Automotive Information Security
What is TISAX®?
Trusted Information Security Assessment Exchange (TISAX®) is the automotive industry's globally recognised information security assessment and exchange mechanism.
Developed by the German Association of the Automotive Industry (VDA) and governed by the ENX Association, TISAX enables organisations to demonstrate that their Information Security Management System (ISMS) meets the strict security expectations of automotive manufacturers and suppliers.
Unlike ISO 27001 certification, TISAX is specifically tailored for the automotive sector. Assessments are performed using the VDA ISA (Information Security Assessment) catalogue, which incorporates industry-specific controls for information security, prototype protection, data protection and secure collaboration across the automotive supply chain.
Organisations successfully completing a TISAX assessment receive a TISAX label that can be securely shared with customers and business partners through the ENX platform, reducing duplicate customer audits and strengthening trust throughout the supply chain.
Overview
KEY FACTS
Assessment Standard
Based on the VDA ISA 6.0 catalogue and recognised by the ENX Association for the automotive industry.
Industry Recognition
Accepted by major automotive manufacturers and Tier-1 suppliers worldwide.
Business Benefit
Eliminates multiple customer security audits through a single recognised assessment process.
Security Focus
Covers information security, prototype protection, privacy requirements and secure collaboration across the automotive supply chain.
VDA ISA 6.0
TISAX 6.0 — The 10 Assessment Objectives
TISAX assessments are performed using the VDA ISA 6.0 catalogue. Depending on your organisation's business activities, one or more assessment objectives become applicable. Each objective evaluates specific security requirements across information security, prototype protection and data protection.
Objectives 1 – 5
Information Security
Confidential
High protection needs — AL 2
Strictly Confidential
Very high protection — AL 3
High Availability
Production-relevant suppliers — AL 2
Very High Availability
JIT / JIS critical suppliers — AL 3
Objectives 6 – 8
Prototype Protection
Data
Processing personal data (Art. 28 GDPR).
Special Data
Special categories (Art. 9 GDPR).
Objectives 9 – 10
Data Protection & Connected Services
Proto Parts
Prototype parts & components.
Proto Vehicles
Complete prototype vehicles
Test Vehicles
Camouflaged road / proving-ground use
Proto Events
Events, film & photo shoots
TISAX Assessment Levels
Same requirements — the level defines audit depth, not difficulty
Self-Assessment
Completion of the VDA ISA self-assessment without external verification.
No recognised TISAX label — internal use only.
Remote Assessment
Plausibility check by an ENX-approved audit provider — document review, evidence sampling and video interviews.
For HIGH protection needs — e.g., "Confidential", "High Availability".
On-Site Assessment
Comprehensive on-site audit — direct system verification, interviews, facility inspection and validation of implemented security controls.
For VERY HIGH protection needs — "Strictly Confidential", prototype protection and critical automotive information.
What Changed with VDA ISA 6.0
In force for all new assessments since 1 April 2024
New Label Structure
'Info High' and 'Info Very High' replaced by four labels — Confidential, Strictly Confidential, High Availability, Very High Availability — separating confidentiality from availability.
IT + OT in Scope
Sharper focus on Operational Technology: production networks, controllers and shop-floor systems now sit squarely inside the assessment.
ISO/IEC 27001:2022 Alignment
Catalogue references updated to the 2022 revision of ISO 27001, plus mapping to NIST CSF — one ISMS serves multiple frameworks.
Maturity-Based Assessment
Each control area is rated on maturity levels 0–5; a consistent Level 3 ('Established') is required across all applicable controls.
Revised Data Protection Module
The catalogue for 'Data' and 'Special Data' objectives was fully rewritten around Art. 28 GDPR processor obligations.
English Master Version
English became the leading catalogue language, with translations issued from the English master.
Prepare Early for VDA ISA 6.0 Requirements
Organisations currently preparing for TISAX should align their Information Security Management System with the latest VDA ISA 6.0 requirements, strengthen supplier security governance, enhance operational technology protection and establish continuous compliance monitoring to ensure successful assessments and long-term customer confidence.
Our TISAX Services
End-to-end support from scoping to label
Scoping & ENX Registration Support
Define assessment scope, locations, objectives and assessment level; guide portal registration.
Gap Assessment (VDA ISA 6.0)
Department-wise maturity evaluation against all applicable controls, with a prioritised remediation roadmap.
ISMS Design & Documentation
Policies, procedures, risk assessments, SoA and evidence packs — audit-ready and tailored to your operations.
Control Implementation Support
Identity & access, endpoint, network segmentation, patching, incident response, supplier and prototype controls.
Training & Awareness
Management briefings, employee awareness and internal auditor training for sustained compliance.
Assessment Readiness & Audit Support
Self-assessment, mock audits, evidence review and support through the AL 2 / AL 3 assessment to label issuance.
Your TISAX Journey with Hawksberg
A proven six-step path to your TISAX label
Scope &
Register
Gap
Assessment
Build ISMS &
Remediate
Self-
Assessment
External Audit
(AL 2 / AL 3)
Label &
Maintain
Scope &
Register
Gap
Assessment
Build ISMS &
Remediate
Self-
Assessment
External Audit
(AL 2 / AL 3)
Label &
Maintain
Typical timeline: 4–9 months from kick-off to label, depending on scope, current maturity and assessment level. Our gap-first approach ensures no surprises at the external assessment.
