Skip to content

TISAX

TISAX Information Security Assessment Checklist

A TISAX checklist based on VDA ISA: scoping labels, controls, and audit provider readiness.

Estimated time
4–9 Months
Audience
Automotive Suppliers Handling OEM Prototype or Personal Data
Last updated

Operational reference for TISAX preparation. Labels are issued through the ENX / TISAX process and approved audit providers.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Registration & Scope

Phase 2: ISA Implementation

Phase 3: Assessment

Phase 4: Maintain

FAQ

Is TISAX an ISO standard?+

No. It is an automotive assessment mechanism based on VDA ISA, often mapped to ISO 27001.

Who sees the result?+

Participants you share with via the ENX exchange, typically OEMs.

Do we need prototype protection?+

Only if that assessment objective is in the OEM requirement.

How long is a label valid?+

Typically three years, subject to ENX rules.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer