Complision

TISAX: What It Is and What an Automotive Manufacturer Will Ask

If your customer is a vehicle manufacturer or a Tier 1 supplier, this explains where the requirement comes from.

TISAX (Trusted Information Security Assessment Exchange) is the information security assessment scheme specific to the European automotive industry, based on the VDA ISA catalogue and operated via the ENX platform, where results are shared between manufacturers and suppliers.

You engage an ENX-authorized audit provider, who assesses you at one of three assessment levels — AL1 (self-assessment), AL2 (remote review), AL3 (on-site audit) — depending on the protection level your customer requires. Optional modules cover prototype protection and personal data handling.

Who does this apply to?

Any automotive-industry supplier handling manufacturer or other suppliers’ information: parts, prototypes, engineering, embedded software, IT services, logistics.

Typical questions

  • Do you have a documented information security policy?

    VDA ISA

  • How do you protect prototype information before public release?

    prototype protection module

Evidence you’d need

  • Documented security policy
  • Prototype protection procedure, if applicable

Asked for TISAX or a VDA ISA-based questionnaire?

Upload it — we classify it by control, whether or not you know your assessment level yet.

Analyze my questionnaire for free

FAQ

Is TISAX the same as ISO 27001?

No, though they overlap heavily. TISAX is automotive-specific and works as a result exchange on the ENX platform, not a standalone certification.

Other frameworks

TISAX Questionnaire From Your Customer | Complision