TISAX consulting: what automotive suppliers really need to pass the assessment
TISAX assessments rarely fail due to technology, often due to unclear scope, incomplete documentation and officer roles that are not filled. The article shows how a reliable TISAX consultation is structured and where CIVAC relieves the burden with Workspace and Officer-as-a-Service.
TISAX (Trusted Information Security Assessment Exchange) is the industry standard for information security in the automotive industry. It is operated by the ENX Association based in Frankfurt am Main and is based on the test catalogue of the Association of the Automotive Industry (VDA Information Security Assessment, VDA-ISA for short). Anyone who works as a supplier with personal data, prototype information or confidential design data is regularly required by their OEM customer to provide TISAX verification. Depending on the scope, the catalogue includes around 80 to 90 test points on information security, prototype protection and data protection. The assessment levels range from AL1 (self-disclosure) to AL2 (plausibility check) to AL3 (on-site audit) and determine the depth of preparation, the time frame and the budget of the entire measure.
This article explains what a substantial TISAX consultation achieves, which pitfalls first-time candidates regularly overlook, such as the interaction between the information security officer (ISB), data protection officer (DSB) and management works and how CIVAC accompanies the process as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. You will learn how to clearly define the scope, realistically assess the level of maturity, pass the assessment in the first attempt and keep the label stable beyond its three-year validity period without personnel changes leading to gaps in the evidence.
Key Takeaways
- TISAX success is determined by the scope: a scope that is too broad makes the assessment more expensive, while a scope that is too narrow leaves OEM requirements out of the picture.
- The VDA-ISA catalogue (currently version 6.0.4) is the relevant test basis; AL2 requires a plausibility check, AL3 requires an on-site inspection with random checks.
- An appointed information security officer with an appointment document, reporting line and risk assessment documented in an audit is actually a requirement, not an option.
What TISAX is and when it becomes mandatory
TISAX is not a law, but an industry requirement that becomes binding through contracts with OEMs and Tier 1 suppliers. The ENX Association operates the label, accredits testing service providers and makes the results available to participants via the ENX portal platform. A central feature of TISAX is the one-time test with multiple use: you pay once for the assessment, but you can use the result to all OEMs that accept TISAX. This saves considerable effort compared to bilateral audits of each supply relationship, avoids multiple checks with the same content and is the main reason for the market implementation of the standard since 2017.
TISAX is made mandatory in practice by the procurement guidelines of OEMs and Tier 1 suppliers. Volkswagen, BMW, Mercedes-Benz, Stellantis, Ford and large Tier 1 houses such as Bosch, Continental or ZF require proof of suppliers with access to confidential information. Engineering service providers, IT providers, logistics companies and tool makers are also expanding the scope of application outside of pure vehicle development. Anyone who acquires a new order as a supplier should therefore clarify in the offer phase which assessment level and scope are required in order to plan the lead time correctly and not lose a delivery date due to a missing label.
CIVAC accompanies the preparation with the role Information Security Officer, which is assigned to the workspace with the appointment certificate, risk register, action plan and reporting line to the Management is preconfigured. Whoever licences the workspace manages the internal ISB function in a structured manner. Anyone who chooses the officer-as-a-service variant has an external information security officer appointed who takes on the mandate and all duties. In both variants, the appointment certificate, signed, filed and verifiable, is the first document that a TISAX auditor wants to see. If it is missing, the assessment begins with a negative impression, which continues in the following samples.
The VDA-ISA catalogue at a glance: modules, measures, maturity levels
The VDA-ISA catalogue is the technical backbone of the TISAX assessment. The current version 6.0.4 includes three modules: information security, prototype protection and data protection according to GDPR. The information security module contains around 41 controls, grouped into topics such as organisation, access control, supplier management, incident management and continuity management. Prototype protection addresses physical security, secrecy and photo/recording bans in particularly sensitive development areas. Data protection essentially takes over GDPR obligations that apply to every supplier regardless of TISAX. Which modules are evaluated depends on the scope and the OEM requirement.
The evaluation is carried out for each control on a maturity scale of 0 to 5. Maturity level 0 means that no measure exists. Maturity level 3 corresponds to documented, lived and verified practice and is the minimum threshold for a passed assessment, unless the OEM sets higher requirements. Maturity level 4 also requires quantitative measurement of effectiveness, while maturity level 5 requires continuous improvement with optimization of the measured variables. First-time candidates should aim for maturity level 3 in each individual control, rather than achieving higher maturity levels in certain areas and remaining below 3 in other controls. An uneven distribution costs more in the assessment than a solid level across the board.
A substantial TISAX consultation begins with the gap analysis for each control. CIVAC carries these out in the workspace as a guided questionnaire that accurately maps the VDA-ISA structure and automatically links document evidence. Hygiene, IT and HR processes are assigned to each control so that in the end it is clear which measure fulfils which control and which evidence is missing. Audit-proof, documented, VDA-ISA-proof. In the assessment, this trace is sufficient for the plausibility check in AL2 and in AL3 for the on-site sample, without having to collect documents from different repositories.
Scope definition: the most important and often underestimated step
The TISAX scope determines the effort, costs and significance of the label. It is entered in the ENX portal and checked in the assessment. A scope that is too broad increases the inspection time and costs significantly because more locations, departments and systems have to be considered. A scope that is too narrow means that OEMs do not accept the label because the areas relevant to them are not covered. The most common mistake is limiting it to a single department, even though the OEM wants to examine the location as a whole.
A reliable scope lists locations with addresses, business areas with job descriptions and protection requirements classes for the information processed. The protection requirement classes are defined in TISAX as normal, high and very high and correspond to the assessment levels AL1, AL2 and AL3. Those booked for design data for a particular model are typically rated high or very high, resulting in AL2 or AL3. Once a scope has been entered, it can only be changed through a new assessment, which is why care at the beginning is crucial.
CIVAC supports the scope definition in the workspace with a template that records locations, areas, data flows and protection requirement classes in a structured manner. The external or internal information security officer checks the plausibility of the entries with management and ensures that contractual clauses with OEMs do not fall out of scope. If there are several locations, a multi-site scope can be created, which allows the central security functions to be checked once and location-specific features are documented separately. Others run compliance like a filing cabinet. We run it like software. This protects the audit from the unpleasant question of why an OEM-relevant area is not in the scope and who is responsible for it.
Assessment level AL1, AL2, AL3: what is really being tested
The three assessment levels differentiate between the depth and form of the examination. AL1 corresponds to a self-disclosure by the supplier without external validation, which is rarely required and accepted in practice. AL2 is the standard level for information requiring high levels of protection. An accredited testing service provider checks the plausibility of the self-disclosure through a document check and interview, usually remotely via video conference. AL3 also requires an on-site inspection with random tests at the location. In many cases, AL3 is mandatory for prototype protection because physical security measures such as photo bans, access controls and visitor registers can only be checked on site. The choice of level is therefore not a question of style, but rather a consequence of the need for protection.
The testing service provider works according to standardised sampling plans. Documents are randomly requested for each inspection, and interviews with employees verify current practice. A common complaint is the discrepancy between document status and employee knowledge: the policy exists, but the relevant employee knows nothing about it. This gap regularly arises when policies are introduced without training and without a trail of evidence, often just before the assessment. The result is a major non-conformity, which leads to a repeat test and thus to significant additional costs and a delivery date risk for the OEM customer.
CIVAC links each guideline in the workspace with the associated training module and the receipt of each employee. When preparing for the assessment, the platform creates a provision index that bundles the relevant documents, proof of training and interview preparation for each control. The auditor calls, the evidence is ready. Before the actual assessment, management and ISB can carry out a test run with the 490 audit templates from the workspace, which simulates typical sample tests. This reduces the likelihood that surprises will occur in the real assessment that jeopardize the label or force a re-examination.
Preparation: typical time and cost framework for a TISAX consultation
The preparation time for a TISAX assessment depends on the initial level of maturity and the desired level. Experience has shown that first-time candidates with unstructured documents need six to nine months to be ready for the assessment. Companies with an existing ISO/IEC 27001-ISMS shorten the preparation to three to four months because many VDA-ISA controls correspond to ISO 27001 Annex A controls. A complete new documentation of information security is usually not necessary, but an adaptation to the TISAX-specific requirements for prototype protection and data flow mapping is required.
The costs are made up of three blocks. Firstly, the ENX registration fee, which ranges between 525 and 2,500 euros depending on the size of the company and is valid for three years. Secondly, the fee of the testing service provider, which is between 8,000 and 30,000 euros depending on the scope and level. Thirdly, internal preparation with advice, training and implementation of measures. Depending on the level of maturity, the costs here are between 15,000 and 80,000 euros. The biggest variable is not the testing service provider, but the question of how many measures still need to be implemented before the assessment.
CIVAC offers the CIVAC SLA of 2 working days instead of the usual 2 to 6 weeks for consultation requests. The status of each control can be continuously tracked in the workspace, which relieves the ISB's burden when reporting to management. With the officer-as-a-service variant, an external information security officer takes over the mandate and carries out the preparation with the 490 audit templates, the risk register and the catalogue of measures. The costs remain predictable because there is no additional effort for unclear responsibilities and improvised documentation. The platform carries out annual reviews and follow-up training throughout the three-year validity of the label, so that the re-assessment preparation remains significantly leaner than the initial examination.
ISB role as a mandatory element: order, reporting line, liability
The role of the information security officer is explicitly required in the VDA-ISA catalogue. It is not just a position, but a formal appointment with a task description, reporting line to top management and a commitment to resources. The auditor regularly checks four aspects in the assessment: If there is an appointment certificate, the reporting line is defined, the ISB has access to top management and the necessary resources have been promised to it. A mere role designation in the organisational chart without an order is not enough in the audit. An order without a documented reporting line and resources is also assessed as inadequate and can lead to non-conformity, which delays or prevents the label.
The liability of the ISB is regulated under civil law in Germany. In the event of intentional or grossly negligent behaviour, he can be held liable for damages caused by failure to fulfil or incorrect fulfilment of duties. In practice, however, liability usually works through the employment relationship and through the external ISB's professional liability insurance. Anyone who appoints an internal ISB should make the task description precise and document the replacement arrangements so that vacation and illness periods do not lead to gaps. Anyone who orders an external ISB pays attention to the scope of insurance, the SLA response times and availability in the event of an escalation.
CIVAC provides the appointment certificate, the task description, the reporting line and the representation concept as a template in the workspace. In the officer-as-a-service variant, CIVAC representatives take on the mandate with documented insurance and a fixed response window of 2 working days. The appointment certificate, signed, filed, verifiable. The platform keeps the ISB activities in a diary format so that the measures taken can be verified in the event of damage. This track is not only relevant for TISAX, but also for the ongoing reporting obligation to management, which is also examined in the event of a group audit.
Interfaces: Cleanly merge TISAX, ISO 27001, NIS-2 and GDPR
TISAX is not an isolated standard, but rather touches on several parallel sets of rules. ISO/IEC 27001:2022 is the international standard for information security management systems. Your 93 Annex A controls overlap around 70% with the VDA-ISA requirements. NIS-2 requires essential and critical facilities to adopt structured security measures, including 24-hour early warning and 72-hour follow-up reporting requirements. The GDPR regulates the protection of personal data and is directly integrated via the TISAX data protection module. Anyone who has several of these obligations benefits from an integrated view instead of parallel documentation that can contradict each other in content.
A well-designed compliance platform maps the controls once and links them to all relevant standards. Anyone who has an access control policy simultaneously fulfils Annex A 5.15 in ISO 27001, a VDA-ISA control in TISAX and the Art. 32 GDPR obligation for technical and organisational measures. When auditing to a different standard, existing evidence can be reused instead of creating a new document. This reuse is the main reason why medium-sized suppliers with multiple obligations can get the effort under control and do not have to build their own compliance function for each standard.
CIVAC manages multiple compliance in a workspace with 25 representative roles. The ISB coordinates TISAX and ISO 27001, the data protection officer takes over responsibility for the GDPR and data protection modules, and an NIS 2 officer carries out the reporting obligations. All roles work on the same database with different views. A change to a guideline takes effect immediately in all standards, without creating parallel versions. The platform's EU data residency ensures that the compliance data itself is not transferred to third countries, which is a relevant design decision for companies with a US parent and is noted positively in the audit.
By label: re-assessment, updating, incident management
The TISAX label is valid for three years. During this time, the evidence must be kept stable, which requires continuous maintenance of information security management. Changes to the scope, for example due to new locations, new business areas or new OEM customers, trigger the need for adjustments, which in the worst case scenario forces an early re-assessment. Changes in personnel at the ISB, the DSB or in key roles such as IT management and HR can lead to breaks in the document track if the handovers are not carried out systematically. Incident management and data breaches must continue to be documented in accordance with the TISAX requirements, including reporting to OEM customers if the contract requires this.
The re-assessment is regularly leaner than the initial assessment, provided the maturity level is stable over the term. Anyone who achieved the label in the first attempt with low levels of maturity runs the risk of failing the re-assessment because interim personnel changes and failure to carry out annual reviews have reduced the effectiveness of the measures. Continuous maintenance in the workspace with reminders, reviews and training loops is the only reliable strategy for permanently maintaining the label and avoids costly emergency advice shortly before the re-audit.
CIVAC carries out the annual reviews, training repetitions and action reviews in the workspace with automatic reminders and escalations to the reporting line. Incidents are recorded via a structured reporting path that covers the NIS 2 path with 24-hour early warning and 72-hour follow-up notification as well as the GDPR path with 72 hours according to Art. 33. Deadline begins as soon as we become aware of it. Substitution situations during vacation or illness are handled by the platform, so that OEM reporting does not stop even when there are staff shortages. The EU data residency and ISO 27001:2022 conformity of the workspace itself are documented and can be directly proven in supplier audits.
From consulting services to a resilient TISAX organisation
A TISAX consultation that only prepares the assessment and then leaves the supplier alone often creates exactly the pattern that fails the re-assessment. Reliable advice is provided that structurally anchors the ISB mandate, transfers the documentation into a maintainable system and automatically initiates the annual maintenance cycles. This is exactly what CIVAC is designed for. CIVAC is a compliance platform and officer-as-a-service with workspace, 490 audit templates, appointment certificates, reporting line, NIS-2 reporting path, ISO 27001:2022 ISMS and EU data residency. Licence the workspace for your internal representatives or have our representatives order it.
The model is tailored to medium-sized businesses. Anyone who has an experienced ISB in-house licences the workspace and uses the templates, the risk register and the reporting line as a tool. If you do not have an ISB or need a temporary solution in the event of a change in personnel, appoint a CIVAC representative with documented insurance and a fixed SLA. In both variants, the document track is identical and can be accessed immediately in the audit. Others run compliance like a filing cabinet. We run it like software. It is also possible to switch from the internal to the external mandate or back without having to rebuild documentation.
If you want to prepare a specific TISAX assessment, maintain the label or bring a disorganized document situation into a verifiable form, we start with a structured gap analysis. Turn reading into an assignment. Write to info@civac.de or use the contact form to arrange an initial assessment of your maturity level. Within two working days you will receive a gap list with delivery dates and a suggestion as to which variant (internal workspace or officer-as-a-service) suits your organisation. The result is a TISAX organisation that is successful in the first assessment and confirmed in the re-assessment.
FAQ
How long does it take to prepare for a TISAX assessment?
First-time candidates without a structured information security management system require 6 to 9 months. Companies with an existing ISO/IEC 27001 certificate shorten the preparation to 3 to 4 months because many VDA-ISA controls correspond to ISO 27001 Annex A. What matters is not the industry, but the initial level of maturity and the completeness of the existing documentation and training.
Which assessment level do I need?
The level results from the protection requirement of the information processed. Personal data and confidential design data usually require AL2 (remote plausibility check). Prototype information and particularly sensitive data usually require AL3 with an on-site inspection. Your OEM customer states the required level in the procurement guidelines or in the supplier contract and should be actively queried.
How much does a TISAX assessment cost in total?
The total costs consist of the ENX registration fee (525 to 2,500 euros), testing service provider fee (8,000 to 30,000 euros depending on scope and level) and internal preparation (15,000 to 80,000 euros). Preparation dominates the budget, which is why the initial level of maturity is more important than the choice of testing service provider.
Do I need an external information security officer for TISAX?
The VDA-ISA catalogue requires an ordered ISB, but does not specify whether internal or external. Medium-sized suppliers without dedicated ISB capacity often choose the officer-as-a-service variant because it structurally solves the insurance and representation issue. CIVAC offers both variants with an identical document track in the workspace and a fixed 2-working day SLA.
How are TISAX and ISO/IEC 27001 related?
The two standards overlap by around 70%. Anyone who is already ISO 27001:2022 certified can achieve TISAX-AL2 with significantly less additional effort. Conversely, TISAX is not a complete replacement for ISO 27001 because it is only accepted in the automotive industry. Corporations with a mixed customer structure therefore often operate both standards in parallel on the same ISMS basis.
What happens if I fail the assessment?
Major non-conformities require a re-inspection, usually within 90 days of resolution. The company bears the costs of the inspection. For minor non-conformities, a documented action plan is usually sufficient without another on-site appointment. Only after all findings have been successfully concluded does the examiner issue the TISAX label and publish it in the ENX portal.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.