The label the automotive supply chain requires
If you handle a car maker’s information, prototypes or personal data, your customer will ask for a TISAX label before the contract goes any further. We get you assessed and labelled.
One assessment, shared with every customer
TISAX — Trusted Information Security Assessment Exchange — is run by the ENX Association. You are assessed once by an approved audit provider against the VDA ISA catalogue, and share the result with any participant who needs it, instead of being audited separately by every manufacturer.
- Assessment objectives cover information security, and where relevant prototype protection and data protection
- Assessment level is set by how sensitive the information is — AL2 is the common case, AL3 involves deeper on-site verification
- It begins with a VDA ISA self-assessment and a maturity rating against each control
- The label is published on the ENX exchange and shared with your customers
- Labels are valid for three years, after which you reassess
Self-assessment to label
1. Scoping
Which sites, which assessment objectives, which level. Getting this wrong is expensive, because the scope is what the audit provider is booked against.
2. VDA ISA self-assessment
We complete the catalogue with you and rate maturity honestly. An inflated self-assessment fails at the audit and costs you a cycle.
3. Remediation
Closing the maturity gaps — policy, access control, network segmentation, physical security, supplier management, and prototype protection where it applies.
4. Evidence
Building the documentation and records the audit provider will sample, structured against the catalogue rather than scattered.
5. The assessment
We support you through the audit provider’s assessment and handle the corrective action plan if findings come up.
6. Maintaining the label
Three years passes quickly, and scope changes in between. We keep the ISA current so reassessment is routine.
Common questions
Is ISO 27001 enough instead?
No. The catalogues overlap heavily, but automotive customers ask specifically for a TISAX label. If you already hold ISO 27001 the work is much shorter.
Which assessment level do we need?
Your customer tells you, and it depends on the sensitivity of what you handle. Prototype-related work typically pushes you to the higher levels.
Can you issue the label?
No. Only an ENX-approved audit provider can assess and label you. We prepare you, and support you through their assessment.
We have several sites. One assessment or several?
It depends on how the sites are run and what each one handles. We work that out at scoping, because it drives the whole cost.
Start before your customer sets the deadline.
Most TISAX projects arrive with a contract date attached. Call early and the timeline stops being the problem.
02 3537 5791
