Visual element used in the Header & Footer/Header component

Solutions

TISAX White Paper

Manage TISAX readiness through the controls you already operate. Identify gaps, organize evidence, track remediation, and prepare for assessment.

Beth Ball

Director, Risk & Compliance Services

10 min

Table of contents

Prepare for TISAX Assessment Without Starting Another Compliance Program

TISAX readiness requires more than completing the ISA self-assessment. You need to identify applicable requirements, define the assessment scope and objectives, evaluate current practices, address gaps, organize supporting evidence, and prepare for the assessment. If you already manage ISO/IEC 27001 or other security frameworks, some of your existing controls, documentation, and evidence may already support TISAX. The key is determining what can be reused and what must be updated.

Cyturus enables you to manage TISAX using your existing controls, allowing your team to focus on addressing gaps rather than duplicating previous efforts.

What Is TISAX?

TISAX stands for Trusted Information Security Assessment Exchange. It is an assessment and exchange mechanism for information security used across the automotive industry. TISAX assessments are based on the VDA Information Security Assessment (ISA). The ENX Association governs the TISAX program, approves TISAX audit providers, and operates the mechanism through which participants can exchange assessment results.

Organizations register their assessment scope, select an approved audit provider, undergo the applicable assessment, and can then share their assessment results with authorized business partners through TISAX. The objective is straightforward: enable organizations in the automotive value chain to rely on standardized information security assessments rather than requiring the same suppliers and partners to undergo repeated, separate assessments.

Who Needs TISAX?

TISAX is particularly relevant to organizations that process sensitive information for automotive manufacturers, suppliers, and other companies in the automotive value chain. That can include organizations involved in:

  • Automotive manufacturing

  • Engineering and product development

  • Research and development

  • Prototype development and testing

  • Technology and IT services

  • Software development

  • Data processing

  • Automotive supply-chain services

Your business partner may specify the required TISAX assessment objective based on the type and sensitivity of information you manage.

What Does TISAX Readiness Require?

Preparing for TISAX starts before the formal assessment. Your organization should define the assessment scope and objectives, understand applicable ISA requirements, evaluate current maturity, identify and remediate deficiencies, and be prepared to demonstrate effective information security practices.

Define Your TISAX Assessment Scope

The TISAX assessment scope defines what is covered by the assessment. For most organizations, the standard TISAX scope is appropriate. It includes processes, procedures, resources, and locations under your organization’s responsibility that are relevant to the selected assessment objectives.

TISAX scoping is different from ISO/IEC 27001 scoping. Your TISAX assessment scope can be smaller than the scope of your ISMS, but it must sit within your ISMS scope. For organizations with multiple locations, accurately defining the scope is critical, as included locations and objectives directly impact the assessment.

Determine Your TISAX Assessment Objectives

Assessment objectives define what your information security management system is expected to protect based on the information you handle for a business partner. TISAX currently offers 10 assessment objectives. You must select at least one, and multiple objectives may apply to a single assessment scope.

The selected objectives determine assessment requirements and the required assessment level, so this decision should be made early in the readiness process. In many cases, the business partner requiring TISAX will tell you which assessment objective or TISAX label it expects.

Understand Your Assessment Level

TISAX uses three assessment levels:

  • Assessment Level 1 (AL1) is a self-assessment. An auditor verifies completion but does not review the content or request additional evidence. AL1 provides low assurance and is not used for TISAX assessment results.

  • Assessment Level 2 (AL2) includes a plausibility check by an approved audit provider, who reviews evidence and interviews the information security lead. Interviews are typically remote, but on-site inspections may occur if needed.

  • Assessment Level 3 (AL3) requires comprehensive verification, including additional assessment activities and on-site components.

The required assessment level is determined by your assessment objectives and protection needs, not by organizational preference.

Complete Your ISA Self-Assessment and Gap Analysis

The ISA self-assessment establishes your current position against the applicable information security requirements. However, completing the questionnaire is only the first step. A useful TISAX readiness assessment should tell you:

  • Which requirements are already satisfied

  • Which requirements are partially satisfied

  • Which controls need improvement

  • Where policies or procedures are missing

  • Where supporting evidence is insufficient

  • Who owns each deficiency

  • What needs to be remediated before assessment

The outcome should be an actionable readiness plan, not just a static compliance checklist.

Address TISAX Gaps Before Assessment

Once a gap is identified, it must be assigned to an owner. Remediation may involve strengthening a technical or administrative control, updating a policy or procedure, implementing a missing process, collecting evidence, or addressing an underlying risk.

Managing deficiencies alongside their related controls clarifies what remains open, who is responsible, and whether remediation is improving readiness. A spreadsheet does not make you more prepared for TISAX. The work behind it does.

Organize TISAX Documentation and Evidence

Your assessment requires you to demonstrate how applicable information security requirements are implemented. Supporting information may include:

  • Policies

  • Procedures

  • Risk assessments

  • Incident response documentation

  • Technical evidence

  • Records demonstrating implementation

  • Other documentation supporting your security practices

The goal isn't to build another evidence repository. Evidence should be connected to the control or security practice it supports. That makes it easier to see what you already have, what is missing, and where the same evidence supports multiple requirements.

TISAX Usually Isn't Your Only Requirement

Most established automotive organizations do not manage TISAX in isolation. You may already maintain an ISMS, manage ISO/IEC 27001, respond to customer security requirements, operate under privacy requirements, or maintain other cybersecurity and compliance frameworks.

This shifts the focus. Instead of asking “How do we build another TISAX compliance program?” ask “Which TISAX requirements are already supported by the controls we operate, and where are the actual gaps?” Treating each new requirement as a separate compliance project can duplicate controls, documentation, evidence, assessments, and remediation already present in the organization. Cyturus addresses this challenge at the control level.

Manage TISAX Through the Controls You Already Operate

Start With Your Existing Control Environment

Cyturus uses a control-based governance architecture. Your organization's applicable controls are maintained in a Living Control Set, eliminating the need to recreate them for each framework. When TISAX is added to the environment, you can evaluate its requirements against the controls you already have in place. Start by identifying what you already satisfy, what you can reuse, and what is actually missing.

Identify the Gaps That Matter

Not every TISAX requirement necessarily represents new work. Existing controls may already address requirements introduced through TISAX. Other requirements may reveal a genuine deficiency. Cyturus helps distinguish between these cases, allowing your team to focus remediation efforts where they are truly needed rather than treating every requirement as a new task.

Connect Evidence to the Control

Evidence demonstrates that a control or security practice is functioning. It should not be confined solely to an assessment folder. Cyturus allows supporting evidence to be managed in relation to the controls it demonstrates. When a control supports multiple requirements, the underlying evidence can be managed centrally within the control environment, reducing redundant collection and maintenance across compliance workstreams.

Assign and Track Remediation

Identifying a gap is valuable only if it results in corrective action. Cyturus helps teams manage deficiencies, assign responsibility, track remediation, and maintain visibility into outstanding work. Security, compliance, and business stakeholders can see what is open, who owns it, and where the program stands without having to reconstruct the answer from spreadsheets, documents, and status meetings.

Track Progress Over Time

TISAX readiness is not a single snapshot. As controls improve, evidence evolves, deficiencies are remediated, and requirements change, your organization must understand how its security posture is developing. Cyturus maintains assessment iterations, enabling teams to track progress over time, identify ongoing deficiencies, and report the current program status.

Already Managing ISO 27001 or Other Requirements?

Existing ISO/IEC 27001 controls, documentation, and evidence may already support parts of TISAX, but ISO/IEC 27001 certification does not automatically mean you are TISAX-ready.

The opportunity is to determine which existing controls, policies, processes, and evidence already support the applicable TISAX requirements. Instead of duplicating controls for each framework, you can manage the underlying control once and identify all the requirements it supports. When that control changes, you can see where the change has an impact.

Preparing for ISA2027

TISAX requirements are changing. ISA2027 is the next version of the VDA Information Security Assessment catalog and will be the basis for TISAX assessments ordered in 2027. Assessments ordered before January 1, 2027 can still be performed using ISA6. The final date to open an initial assessment under ISA6 is March 2027. ISA2027 also introduces a year-based versioning model for the ISA, making the applicable version easier to identify and creating a more predictable approach to future releases.

For organizations that manage TISAX over time, effective requirements change management becomes increasingly important. When the ISA changes, your team needs to determine:

  • What changed between versions?

  • Which existing controls are affected?

  • Are new controls or practices required?

  • Does existing documentation still support the requirement?

  • Does supporting evidence need to change?

  • Do the changes create new gaps?

  • Do affected controls also support other frameworks?

The goal should not be to initiate a new compliance project with each ISA update. Instead, focus on understanding how changes affect your existing control environment.

A Practical TISAX Readiness Process

  1. Scope: Determine the applicable locations, protection needs, assessment objectives, and assessment scope.

  2. Assess: Complete the applicable ISA self-assessment and establish your current maturity.

  3. Identify Gaps: Determine which requirements are satisfied, partially satisfied, or require remediation.

  4. Remediate: Assign owners and address control, process, documentation, and evidence deficiencies.

  5. Prepare Evidence: Organize the documentation and evidence needed to demonstrate implementation.

  6. Assess and Maintain: Complete the applicable assessment with your chosen TISAX audit provider, address findings where necessary, and maintain the underlying control environment after the assessment.

TISAX Does Not End When the Assessment Is Complete

TISAX assessment results are generally valid for three years, but information security requirements and environments continue to evolve during that period. Controls, systems, evidence, business relationships, and requirements may all change over time. Your team should be able to answer:

  • What is our current TISAX posture?

  • Which deficiencies remain open?

  • Who owns them?

  • What evidence supports our controls?

  • What changed since our previous assessment?

  • Has a change to a control affected another requirement?

  • What happens when the ISA changes?

  • Where do the same controls support other frameworks?

Managing the control environment gives you continuity between assessments. Cyturus helps keep TISAX connected to the broader governance program instead of treating each assessment as a separate project.

Frequently Asked Questions About TISAX

What is TISAX?

TISAX stands for Trusted Information Security Assessment Exchange. It is an assessment and exchange mechanism for information security used across the automotive industry. TISAX assessments are based on the VDA Information Security Assessment, or ISA, and are performed by audit providers approved by the ENX Association.

Is TISAX a certification?

No. Although “TISAX certification” is commonly used informally, TISAX is an assessment and exchange mechanism rather than a certification scheme. Organizations select assessment objectives and, after completing the applicable assessment, receive the corresponding TISAX labels.

What is the VDA ISA?

The VDA Information Security Assessment, or ISA, is the catalog of information security requirements that serves as the basis for TISAX assessments. It is maintained by the VDA and contains the requirements for evaluating an organization's information security management system and applicable protection needs.

How many TISAX assessment objectives are there?

There are currently 10 TISAX assessment objectives. An organization must select at least one assessment objective when defining its assessment scope and can select multiple objectives when appropriate.

What is a TISAX assessment objective?

A TISAX assessment objective defines the expected protection level for the type of information an organization handles on behalf of a business partner. It is a key input to the assessment and determines the applicable assessment level.

What are the TISAX assessment levels?

TISAX uses Assessment Levels 1, 2, and 3. AL1 is primarily a self-assessment and is not used for TISAX assessment results. AL2 involves a plausibility check by an audit provider, including a review of evidence and an interview. AL3 involves more comprehensive verification and additional assessment activities, including on-site elements.

How do you prepare for a TISAX assessment?

TISAX preparation typically includes defining the assessment scope and objectives, completing the applicable ISA self-assessment, evaluating current maturity, identifying gaps, remediating deficiencies, organizing supporting evidence, and preparing for assessment by an approved TISAX audit provider.

Can ISO 27001 controls and evidence be reused for TISAX?

Existing ISO/IEC 27001 controls, documentation, and evidence may support applicable TISAX requirements, but they should be evaluated against the specific TISAX scope, assessment objectives, and ISA requirements. A control-based approach helps identify where existing work can be reused and where additional work is required.

What is ISA2027?

ISA2027 is the next version of the VDA Information Security Assessment catalog. It will be the basis for TISAX assessments ordered in 2027 and introduces a year-based versioning model for future ISA releases.

How long are TISAX assessment results valid?

TISAX assessment results generally have a validity period of three years. Organizations should continue maintaining their information security environment during that period rather than treating the assessment as a one-time compliance exercise.

How can GRC software help with TISAX?

GRC software can help organizations evaluate requirements, identify gaps, assign remediation, manage evidence, track maturity, and maintain readiness over time. A control-based GRC platform can also help identify where controls supporting TISAX support other security and compliance requirements.

Does Cyturus perform TISAX assessments?

No. TISAX assessments are performed by TISAX audit providers approved by the ENX Association. Cyturus helps organizations manage the controls, readiness, evidence, gaps, remediation, and ongoing governance surrounding the assessment.

Prepare for TISAX Without Rebuilding Work You Already Have

If TISAX is now a customer or business requirement, begin by assessing your organization’s existing controls and processes. Cyturus helps you evaluate TISAX against your existing control environment, identify what can be reused, expose what is missing, manage evidence and remediation, and maintain visibility as requirements change.


References and Additional TISAX Resources

More from Cyturus

Keep reading; There's more worth your time

More ideas on workflows, alignment, strategy, and what it actually takes to build teams that stay focused and move forward together.

See Cyturus Cyber Resilience Tracker in Action

Bring your frameworks. We'll show you how a single control answer maps everywhere and where your real maturity stands today.

No rip-and-replace · Works alongside your existing program · Built by practitioners