TISAX
TISAX Information Security Assessment Checklist
A TISAX checklist based on VDA ISA: scoping labels, controls, and audit provider readiness.
- Estimated time
- 4–9 Months
- Audience
- Automotive Suppliers Handling OEM Prototype or Personal Data
- Last updated
Operational reference for TISAX preparation. Labels are issued through the ENX / TISAX process and approved audit providers.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Registration & Scope
Phase 2: ISA Implementation
Phase 3: Assessment
Phase 4: Maintain
FAQ
Is TISAX an ISO standard?+–
No. It is an automotive assessment mechanism based on VDA ISA, often mapped to ISO 27001.
Who sees the result?+–
Participants you share with via the ENX exchange, typically OEMs.
Do we need prototype protection?+–
Only if that assessment objective is in the OEM requirement.
How long is a label valid?+–
Typically three years, subject to ENX rules.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer