TISAX® (Trusted Information Security Assessment Exchange) is an industry-specific mechanism for exchanging information security assessment results in the automotive industry. These assessments are based on the VDA-ISA test catalog, which covers information security checks in the areas of information security (based on ISO 27001), prototype, and data protection.
With the TISAX® assessment, you demonstrate the maturity of your information security management system (ISMS) in line with customer requirements. This can be achieved at various assessment levels and with additional requirements regarding the prototype and customer data protection. As proof of your information security management system's maturity, you receive test labels that you can share with your business partners.
This makes TISAX® the foundation for testing and implementing an information security management system in the automotive industry. Implementation requires a solid foundation, which can be achieved through this qualification.
More information can be found at:cis-cert.com.pl
- Meeting the requirements of automotive industry customers
- Recognition of research results in the automotive market/supply chain
- Protecting your company's value
- Raising awareness among employees
- The basis for possible ISO 27001 certification
- Separate protection for prototyping and data protection
- Sharing obtained test labels with selected business partners
- Internal self-assessment based on the VDA-ISA assessment catalogue
- Registration on the ENX platform
- Selecting an Assessment Provider (CIS)
- Kick-off meeting
- TISAX® Assessment (Level 2 Remote, Level 3 On-site)
- Common understanding on assessment results
- Derivation of a normalized report
- Measures procedure
- Issuance of a rating label
The TISAX® assessment procedure is similar to an audit. The duration of the assessment depends on the size and structure of your company, and therefore the complexity of your ISMS, and is agreed upon with you by your CIS representative. Individual elements are assessed using maturity levels, providing a good overall picture of the strengths and potential of the implemented ISMS.
If your company is already certified according to ISO 27001, this provides an excellent foundation and facilitates a TISAX® audit based on it. However, ISO 27001 is not a mandatory prerequisite, and TISAX® requirements can also be implemented completely independently.




