TISAX

TISAX is how automotive suppliers prove their information security to manufacturers and other partners without repeating the same audit for each one. The assessment runs against the VDA-ISA catalogue and results in a label you share through the ENX exchange. turingsecure holds the controls and evidence the catalogue asks for and keeps them ready for the assessor.

What the Standard Requires

One Assessment, Recognised Across the Supply Chain

TISAX is based on the VDA-ISA catalogue, the German automotive industry's information security questionnaire. You assess your organisation against its control questions and reach one of two assessment levels: AL2, verified mainly through a documentation review and a remote interview, and AL3, which adds an on-site audit for higher protection needs.

The catalogue is split into modules. The information security module is the core, prototype protection covers the physical and logical handling of confidential development parts, and data protection maps GDPR-relevant requirements. You are assessed only against the modules your partners require.

TISAX assessment against the VDA-ISA catalogue at levels AL2 and AL3

How TISAX Works

From Self-Assessment to Shared Label

VDA-ISA Self-Assessment

Answer the catalogue's control questions and set a maturity level for each one. turingsecure maps those questions to controls you maintain once.

Assessment Level AL2 or AL3

Reach AL2 through a documentation review or AL3 with an on-site audit, depending on the protection needs your partners set.

Assessment Modules

Cover information security, prototype protection and data protection. Evidence stays linked to the module and control it belongs to.

ENX Exchange and Label

A passed assessment produces a TISAX label. Through the ENX exchange, partners see your result without running their own audit.

Earn Your TISAX Label Once

Book a personal demo and see how turingsecure keeps the VDA-ISA evidence ready for your AL2 or AL3 assessment.