TiSAX is a mechanism, not a standard
The underlying requirements come from the VDA ISA (Information Security Assessment) catalogue, which draws heavily on ISO/IEC 27001. TiSAX is the mechanism that lets a supplier be assessed once by an accredited provider and then share the result with multiple partners through an exchange, avoiding a separate audit for every customer.
Assessment objectives and levels
You are assessed against specific objectives (for example handling information with high protection needs, prototype protection, or data protection) at an assessment level that reflects the sensitivity involved.
| Level | Approach | Typical use |
|---|---|---|
| AL 1 | Self-assessment | Internal use; not usually accepted for sharing |
| AL 2 | Evidence review, largely remote, plus a plausibility check | Information with high protection needs |
| AL 3 | In-depth assessment including an on-site audit | Very high protection needs, prototypes |
Register
ENX portal
Self-assess
Against VDA ISA
Remediate
Close gaps
Assess
Accredited provider
Share labels
Via the exchange
How to prepare efficiently
- Start from the VDA ISA catalogue and self-assess honestly against your target objectives and level.
- If you already hold ISO 27001, map those controls across first, the overlap is substantial.
- Prioritise the areas the catalogue weights most heavily for your objectives, such as prototype protection if in scope.
- Keep evidence linked to each control so the assessor can trace claims quickly.
Common pitfalls to avoid
- Running TiSAX and ISO 27001 as two separate programmes instead of one control set mapped to both.
- Targeting a higher assessment level than the customer actually requires.
- Leaving prototype-protection controls late when they carry heavy weight for that objective.