Information SecurityGlobal (Automotive)

TiSAX compliance

Trusted Information Security Assessment Exchange

TiSAX is the automotive industry's mechanism for assessing and sharing information security maturity, based on the VDA ISA catalogue. Pelta helps suppliers manage the TiSAX control set, keep evidence linked, and prepare for assessment with confidence.

Who it's for

Does TiSAX apply to you?

  • Automotive suppliers and partners
  • Organisations exchanging sensitive information with OEMs
  • Suppliers needing to demonstrate information security maturity

TiSAX is a mechanism, not a standard

The underlying requirements come from the VDA ISA (Information Security Assessment) catalogue, which draws heavily on ISO/IEC 27001. TiSAX is the mechanism that lets a supplier be assessed once by an accredited provider and then share the result with multiple partners through an exchange — avoiding a separate audit for every customer.

Assessment objectives and levels

You are assessed against specific objectives — for example handling information with high protection needs, prototype protection, or data protection — at an assessment level that reflects the sensitivity involved.

TiSAX assessment levels (indicative)
LevelApproachTypical use
AL 1Self-assessmentInternal use; not usually accepted for sharing
AL 2Evidence review, largely remote, plus a plausibility checkInformation with high protection needs
AL 3In-depth assessment including an on-site auditVery high protection needs, prototypes
The TiSAX process

Register

ENX portal

Self-assess

Against VDA ISA

Remediate

Close gaps

Assess

Accredited provider

Share labels

Via the exchange

How to prepare efficiently

  • Start from the VDA ISA catalogue and self-assess honestly against your target objectives and level.
  • If you already hold ISO 27001, map those controls across first — the overlap is substantial.
  • Prioritise the areas the catalogue weights most heavily for your objectives, such as prototype protection if in scope.
  • Keep evidence linked to each control so the assessor can trace claims quickly.
Assessment levels, objectives and labels are defined by the current VDA ISA and TiSAX rules. Confirm the exact scope your customer requires before you begin.

Common pitfalls to avoid

  • Running TiSAX and ISO 27001 as two separate programmes instead of one control set mapped to both.
  • Targeting a higher assessment level than the customer actually requires.
  • Leaving prototype-protection controls late when they carry heavy weight for that objective.
How Pelta helps

Run TiSAX on one connected platform

VDA ISA control set

Manage your controls against the TiSAX / VDA ISA catalogue directly.

Assessment-ready evidence

Keep the evidence for each control linked and current ahead of assessment.

Maturity view

See where you stand across the catalogue at a glance.

Reuse with ISO 27001

TiSAX aligns closely with ISO 27001 — reuse controls and evidence across both.

TiSAX FAQs

What is TiSAX?+

TiSAX (Trusted Information Security Assessment Exchange) is the automotive sector's approach to assessing and sharing information security maturity, based on the VDA ISA catalogue.

Is TiSAX the same as ISO 27001?+

No, but they are closely related. The VDA ISA catalogue TiSAX assesses against draws heavily on ISO 27001, so holding ISO 27001 gives you a substantial head start.

What are the TiSAX assessment levels?+

Levels reflect the sensitivity of the information in scope, from self-assessment (AL 1) through remote evidence review (AL 2) to an in-depth on-site audit (AL 3). Your customer's requirements determine the level you need.

How long is a TiSAX label valid?+

TiSAX labels are valid for a defined period (commonly three years) before reassessment. Confirm the current validity and reassessment rules via the official TiSAX process.

Who needs TiSAX?+

Automotive suppliers and partners that exchange sensitive information with OEMs or tier-one suppliers, where the customer requires demonstrated information security maturity.

How does TiSAX relate to ISO 27001?+

TiSAX draws heavily on ISO 27001. Running both in Pelta lets you reuse overlapping controls and evidence rather than duplicating effort.

See TiSAX compliance on Pelta

Prepare for TiSAX on Pelta — manage the VDA ISA control set, map evidence, and demonstrate information security maturity to automotive partners.