TiSAX — the Trusted Information Security Assessment Exchange — is how the automotive industry assesses and shares information security maturity. If an OEM or tier-one supplier has asked you for TiSAX, this guide explains what it involves and how to prepare without over-engineering it.
TiSAX is a mechanism, not a standard
The underlying requirements come from the VDA ISA (Information Security Assessment) catalogue, which draws heavily on ISO/IEC 27001. TiSAX is the mechanism that lets a supplier be assessed once by an accredited provider and then share the result with multiple partners through an exchange — avoiding a separate audit for every customer.
Assessment objectives and levels
You are assessed against specific objectives — for example handling of information with high protection needs, or prototype protection, or data protection — at an assessment level that reflects the sensitivity involved.
| Level | Approach | Typical use |
|---|---|---|
| AL 1 | Self-assessment | Internal use; not usually accepted for sharing |
| AL 2 | Evidence review, largely remote, plus a plausibility check | Information with high protection needs |
| AL 3 | In-depth assessment including an on-site audit | Information with very high protection needs, prototypes |
Register
On the ENX portal
Self-assess
Against VDA ISA
Remediate
Close gaps
Assess
Accredited provider
Labels
Shared via exchange
How to prepare efficiently
- Start from the VDA ISA catalogue and do an honest self-assessment against your target objectives and level.
- If you already hold ISO 27001, map those controls across first — the overlap is substantial.
- Prioritise the areas the catalogue weights most heavily for your objectives, such as prototype protection if in scope.
- Keep evidence linked to each control so the assessor can trace claims quickly.
Reuse, don't rebuild
Because TiSAX and ISO 27001 share so much, the worst outcome is running them as two separate programmes. Managing one control set with a single, connected evidence trail — and mapping it to both — is what keeps TiSAX from becoming a parallel workload. That shared-mapping model is how Pelta approaches overlapping information-security frameworks.
ISO 27001
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding TiSAX
~75% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
Frequently asked questions
What is TiSAX?+
TiSAX (Trusted Information Security Assessment Exchange) is the automotive industry's mechanism for assessing information security maturity against the VDA ISA catalogue and sharing the result with partners through an exchange.
Is TiSAX the same as ISO 27001?+
No, but they are closely related. The VDA ISA catalogue that TiSAX assesses against draws heavily on ISO 27001, so holding ISO 27001 gives you a substantial head start.
What are the TiSAX assessment levels?+
There are assessment levels reflecting the sensitivity of the information in scope, ranging from self-assessment through remote evidence review to an in-depth on-site audit. Your customer's requirements determine the level you need.
How long is a TiSAX label valid?+
TiSAX labels are valid for a defined period (commonly three years) before reassessment. Confirm the current validity and reassessment rules via the official TiSAX process.
Who needs TiSAX?+
Automotive suppliers and partners that exchange sensitive information with OEMs or tier-one suppliers, where the customer requires demonstrated information security maturity.