Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

TISAX – The Path to Certification.

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s standard for information security. mgm security partners brings your information security management system up to the VDA-ISA level, prepares you for the assessment, and supports you all the way to obtaining the shared label. Pragmatic, customized, and provided by experts who understand the technology—not just the questionnaire.

Candidates are typically ready for the assessment within a few months, depending on their starting point, the assessment objective, and the assessment level. Those who start early can achieve the required maturity level 3 without time pressure before the assessment date.

Background

Fundamentals

What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s assessment and exchange process for information security. It is operated by the ENX Association on behalf of the VDA (German Association of the Automotive Industry). It is based on the VDA ISA (Information Security Assessment) questionnaire, which is closely modeled after ISO/IEC 27001 but supplements it with industry-specific requirements such as prototype protection and data protection. Since April 2024, version VDA ISA 6.0 has been the mandatory assessment standard.

Unlike with ISO 27001, companies do not receive a certificate, but rather one or more TISAX labels, which are shared with business partners via the ENX platform. This means that information security needs to be audited only once and can be demonstrated multiple times. For many suppliers and service providers, a TISAX label is now a prerequisite for working with manufacturers (OEMs). The assessment is conducted at three levels (AL 1 through AL 3) by accredited assessment service providers. A label is valid for three years.

3 Inspection Depths
Assessment Levels AL 1 through AL 3, depending on protection needs
10 Labels
Exam objectives in five categories, ranging from information to data protection
3 years
Validity of the label; a reassessment follows
VDA ISA 6.0
Mandatory audit basis as of April 2024; Maturity Level 3 required

The challenge

Attention!
  • The OEM is requiring a TISAX certification in the near term as a prerequisite for the contract
  • It is unclear which test objective and which assessment level are actually required
  • VDA ISA 6.0 includes over 300 requirements with a required maturity level of 3
  • Prototype protection requires additional physical security measures
  • Data protection audit objectives under Article 28 of the GDPR must be thoroughly addressed
  • Uncertainty about whether the assessment by the testing service provider will be passed

Our Added Value

Result
  • Experienced auditors will guide you, seeing things from the auditor's perspective
  • Experts who are familiar with the technology, not just the list of questions
  • Pragmatic implementation tailored specifically to your company
  • Clear Definition of Scope, Audit Objectives, and Assessment Level
  • Integration with existing standards such as ISO 27001, where it is beneficial
  • Reliable preparation and support all the way to obtaining the shared TISAX label

Our TISAX Services

Offer

Five coordinated steps, from the initial assessment to passing the evaluation and receiving the label.

  • Analyze the requirements of OEMs and partners
  • Determine Appropriate Assessment Objectives (Labels) and Assessment Levels
  • Clearly Define the Scope and Locations
  • Assist with registration on the ENX platform
  • How to Complete the VDA ISA 6.0 Self-Assessment in a Structured Manner
  • Assess the level of maturity for each requirement honestly and objectively
  • Quantify the gaps to the required maturity level 3
  • Prioritized Roadmap with Milestones Leading Up to the Assessment
  • Develop lean and audit-ready policies, processes, and documentation
  • Define Roles, Responsibilities, and Reporting Lines
  • Implementing Technical Controls in a Concrete and Effective Manner
  • Ensure Level 3 maturity in practice rather than just on paper
  • Implementing and Evaluating Physical Security Measures for Prototype Protection
  • Meet the requirements for test vehicles and test events
  • Properly Set Up Data Processing in Accordance with Article 28 of the GDPR
  • Take availability requirements into account as needed
  • Readiness Check and Preparation for the Assessment
  • Support During the Assessment Process with the Testing Service Provider
  • Handling Nonconformities and Corrective Actions
  • Support for sharing the label via the ENX platform

From Registration to a Shared Label

Approach

We provide pragmatic, personalized support throughout the entire TISAX process—from scoping and self-assessment through implementation to the assessment and awarding of the label. The reassessment takes place after three years.

  • 1 – Registration & Scoping: Register on the ENX platform; define the scope of the audit, audit objectives, and assessment level.
  • 2 – Self-Assessment: Complete the VDA ISA 6.0 and evaluate the maturity level for each requirement.
  • 3 – Actions & Maturity Level 3: Close gaps, establish processes, and achieve Maturity Level 3 in practice.
  • 4 – TISAX Assessment: Audit conducted by an accredited service provider, AL 2 remotely or AL 3 on-site.
  • 5 – Labels & Sharing: Receive labels and share them with partners via the ENX platform.

Which level and which labels you need

Information

The appropriate assessment level and testing objectives depend on your protection needs and your partners’ requirements. A high protection need typically results in a remote assessment (AL 2), while a very high protection need or prototype protection requires an on-site assessment (AL 3). We determine both of these together with you to ensure that you have neither too much nor too little testing performed.

ISO 27001 as a Solid Foundation

An existing ISO 27001 ISMS already covers many TISAX requirements and significantly speeds up the path to obtaining the label. Risk management, policies, roles, and technical measures are already systematically established within the system, so that a large portion of the VDA-ISA catalog can build on existing processes. However, ISO 27001 is not mandatory for TISAX.

In the gap analysis, we assess what you already have in place, leverage existing structures where they are beneficial, and otherwise focus solely on implementing the additional requirements specified by TISAX, such as prototype protection and industry-specific data protection audit objectives.

No in-house resources? Outsourced ISB

The certification is the starting point, not the goal: The required level of maturity must be maintained on an ongoing basis; a reassessment is scheduled after three years. If you lack the internal capacity to do so, we can assume the role of Information Security Officer as a service and reliably maintain your ISMS at the TISAX level.

Auditors Who Understand the Technology

  • 25+ Years of Enterprise Security Consulting
  • Project experience with OEMs and suppliers
  • A pragmatic, customized approach instead of a standard checklist
  • 100% led by senior security experts

Our consultants are experienced auditors and security experts. They have an in-depth understanding of the VDA-ISA catalog and know how controls actually work from a technical perspective, based on over 25 years of experience working on projects for automakers, suppliers, industrial companies, and software manufacturers. We implement TISAX pragmatically and tailor it to each company’s specific needs, rather than rolling out standard templates. We do not conduct TISAX assessments, so we are fully on your side.

TISAX Consulting: Quick Answers to Your Questions

TISAX is based on ISO/IEC 27001 but is an industry-specific standard for the automotive industry. It is based on the VDA ISA questionnaire, which covers not only information security but also prototype protection and data protection. Instead of a certificate, you receive TISAX labels, which are shared with partners via the ENX platform. An existing ISO 27001 ISMS provides an excellent foundation for TISAX.

This depends on the security requirements for the information being processed and the specifications of your partners. High security requirements usually result in a remote assessment (AL 2), while very high security requirements and prototype protection typically result in an on-site assessment (AL 3). The OEM often specifies the test objectives and level. During the gap analysis, we work with you to determine what is actually necessary.

No. The assessment may only be conducted by an audit service provider accredited by ENX. This is precisely why we can be fully on your side: We prepare your ISMS, conduct readiness checks, and guide you through the assessment without any conflict of interest.

That depends on the current situation, the audit objective, and internal resources. Companies with an existing ISMS are often ready for assessment within a few months. The gap analysis quickly provides a reliable roadmap with realistic time and resource estimates and milestones leading up to the required maturity level 3.

A TISAX certification is valid for three years. After that, a reassessment is required to renew the certification. The required maturity level must be maintained throughout the entire validity period. If you lack the internal capacity to do so, we—as your external information security officer—will reliably ensure that your ISMS remains up to standard.

Maximiliane Mayer

Ready for your TISAX certification? Contact us for a free initial consultation and an initial assessment of your audit objectives and assessment level!