TISAX
TISAX is the assessment standard of the automotive industry for information security at suppliers and service providers.
TISAX (Trusted Information Security Assessment Exchange) is an assessment and exchange procedure for information security in the automotive industry. The ENX Association operates it on behalf of the German Association of the Automotive Industry (VDA).
How it works
The process is based on the VDA ISA catalogue of questions, which is aligned with ISO 27001. It includes additional requirements for prototype protection and data protection. An accredited audit provider assesses the organisation against one of three assessment levels. The result is then stored on the ENX platform. Manufacturers and suppliers can access it there, avoiding the need for their own audits. The assessment is typically valid for three years.
A practical example
A Swiss supplier develops components for a German car manufacturer. The manufacturer demands a TISAX label for handling confidential design data. The supplier already has an ISMS according to ISO 27001. They add the missing requirements, like prototype protection, and pass the assessment.
What to look out for
- Clarify with your client which assessment level (usually Assessment Level 2 or 3) and which objectives are required.
- Use an existing ISMS based on ISO 27001 as a foundation.
- Note the physical protection requirements for prototypes if you handle them.
- Plan sufficient time. An on-site audit is required for Assessment Level 3.
When this is relevant for Swiss companies
TISAX is relevant for Swiss suppliers, development partners, and toolmakers in the automotive industry. The obligation arises from contracts with manufacturers or larger suppliers, mostly from Germany. No law requires a company to have a TISAX label.
How it differs from ISO 27001
ISO 27001 is a cross-industry standard that leads to a certification. TISAX is tailored to the automotive sector and results in a label shared on a common platform. The content of both standards overlaps significantly.
Relevance for the SOC
The VDA ISA catalogue includes requirements for logging, monitoring, and incident response. A SOC provides evidence for meeting these requirements.
Typical mistakes
The assessment scope is often defined too narrowly, for example to a single location. If the client later requires a broader scope, a new assessment is necessary.
How we implement it
Our SOC reports provide evidence for the requirements on monitoring and incident handling. The assessment itself is conducted by an accredited audit provider.