TiSAX is a mechanism, not a standard
The underlying requirements come from the VDA ISA (Information Security Assessment) catalogue, which draws heavily on ISO/IEC 27001. TiSAX is the mechanism that lets a supplier be assessed once by an accredited provider and then share the result with multiple partners through an exchange — avoiding a separate audit for every customer.
Assessment objectives and levels
You are assessed against specific objectives — for example handling information with high protection needs, prototype protection, or data protection — at an assessment level that reflects the sensitivity involved.
| Level | Approach | Typical use |
|---|---|---|
| AL 1 | Self-assessment | Internal use; not usually accepted for sharing |
| AL 2 | Evidence review, largely remote, plus a plausibility check | Information with high protection needs |
| AL 3 | In-depth assessment including an on-site audit | Very high protection needs, prototypes |
Register
ENX portal
Self-assess
Against VDA ISA
Remediate
Close gaps
Assess
Accredited provider
Share labels
Via the exchange
How to prepare efficiently
- Start from the VDA ISA catalogue and self-assess honestly against your target objectives and level.
- If you already hold ISO 27001, map those controls across first — the overlap is substantial.
- Prioritise the areas the catalogue weights most heavily for your objectives, such as prototype protection if in scope.
- Keep evidence linked to each control so the assessor can trace claims quickly.
Common pitfalls to avoid
- Running TiSAX and ISO 27001 as two separate programmes instead of one control set mapped to both.
- Targeting a higher assessment level than the customer actually requires.
- Leaving prototype-protection controls late when they carry heavy weight for that objective.