Prepare for your TISAX assessment
What is TISAX?
TISAX — the Trusted Information Security Assessment Exchange — is how the automotive industry assesses and shares information security maturity across its supply chain. It is governed by the ENX Association and built on the VDA ISA (Information Security Assessment) catalogue created by the German automotive industry association. Rather than each OEM auditing each supplier, suppliers undergo a single assessment by an accredited audit provider and exchange the results with partners on the ENX portal.
Labels and assessment levels
A TISAX assessment is scoped by labels — information security, prototype protection (for organizations handling pre-series parts and vehicles), and data protection (aligned with GDPR) — and by assessment level (AL1, AL2, or AL3), which determines how rigorous the audit is. The OEM or customer requesting the assessment specifies the labels and level required. A successful assessment yields labels that are typically valid for three years.
How TISAX relates to ISO 27001
The VDA ISA catalogue is closely aligned with ISO/IEC 27001, so an organization with a mature ISMS already meets a large share of TISAX requirements. The main differences are the automotive-specific prototype-protection controls and the maturity-based scoring model.
How episki helps
episki maps the VDA ISA catalogue to controls evaluated continuously, with crosswalks to ISO 27001 derived through the SCF hub so the ISMS work counts for both. Assessment levels are expressed as scope, prototype and data protection requirements carry their own controls, and findings route to owners with due dates. Start a free trial or book a demo.
TISAX outcomes with episki
Why teams choose episki for TISAX
- Information security control catalogue
- Prototype protection where in scope
- Data protection module aligned to GDPR
- Assessment levels AL1, AL2, and AL3
- Information security, prototype, and data protection labels
- Maturity-based scoring per control
- Crosswalk to ISO 27001 Annex A
- Evidence shared with SOC 2 and NIST CSF
- One control set, multiple audiences
TISAX readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ Scope and assessment-level determination
- ✓ VDA ISA information-security controls implemented
- ✓ Prototype protection controls (if in scope)
- ✓ Data protection module (if in scope)
- ✓ Maturity-level evidence per control
- ✓ Audit-provider evidence package and ENX exchange