With our help, you will implement TISAX
Over 5,000 small, medium, and large companies have trusted us over 25 years:
Discover our unique implementation methodology that guarantees
successful certification.
The TISAX information security assessment standard is intended for all companies in the automotive industry and their business partners. These include:
TISAX (Trusted Information Security Assessment Exchange) is an international standard for information security assessment in the automotive industry. It is based on the VDA ISA questionnaire, which was developed in accordance with the ISO 27001 standard. The TISAX model defines the conditions for maintaining the required level of confidentiality when exchanging information between entities involved in the automotive industry. TISAX guarantees a uniform level of data security.
Companies operating in the automotive sector must not only meet the highest standards of information security, but also need to continually demonstrate the quality of their standards when working with other companies. The basis for their assessment is the requirements developed by the German Association of the Automotive Industry (German: Verband der Automobilindustrie – VDA) and set out in the VDA ISA catalogue. These guidelines have long been the cornerstone of information security in the automotive industry. Until recently, however, VDA ISA audits were carried out at the request of a company interested in collaborating with a given entity. The consequence was that the entity was subjected to frequent inspections, which generated unnecessary time and financial costs. The TISAX standard, introduced by the VDA in 2018, was developed to standardise information security assessment mechanisms. This avoids a situation where each potential partner creates its own checklists. Currently, the TISAX model is used by hundreds of companies operating in the automotive industry across more than 40 countries.
The scope of the TISAX standard covers requirements relating to, amongst other things:
TISAX audits are conducted by bodies accredited by the ENX Association. The audit may take the form of a document-based audit or an on-site audit. It focuses on the assessment of objective evidence whilst taking risk factors into account. Should non-compliance with the VDA ISA standard be detected, the audited entity is obliged to implement corrective measures. A positive TISAX audit result demonstrates that the company maintains a level of security management in its operations that meets the requirements of potential partners. A TISAX audit may be conducted independently or as part of the implementation of an information security management system compliant with ISO 27001.
Currently, all major automotive groups require compliance with the VDA ISA standard. A company that has implemented this standard and undergone a TISAX audit demonstrates its reliability to existing and potential partners, thereby avoiding additional checks before entering into a partnership.
A company that has passed the TISAX audit gains:
See what our clients say about our implementations

