When a Client Asks Your Agency for TISAX Compliance

A request for TISAX compliance can arrive during an automotive industry pitch, a supplier review, or a new automotive campaign. It may sound like a simple procurement requirement. In practice, it can affect how your agency handles sensitive information across people, systems, suppliers, and client projects.
The good news is that a client request doesn't automatically mean your whole agency must meet every compliance requirement through a formal TISAX assessment. It isn't automatically the start of a certification process or proof that the whole agency needs a formal assessment. First, understand precisely what the client expects and which parts of your operation are involved.
A clear scope turns an uncertain request into a manageable security workstream.
What the client is really asking for
TISAX, short for Trusted Information Security Assessment Exchange, is an information security assessment and sharing mechanism operated by the ENX Association. It is built around the VDA ISA catalogue, also known as the VDA Information Security Assessment catalogue.
Across the automotive industry, automotive manufacturers and suppliers use it to gain assurance that partners can protect confidential information. For an advertising agency, that could include campaign plans, product launch material, customer data, unreleased vehicle imagery, design assets, or prototype-related content.
A request is not always a formal assessment requirement
A client may ask whether you can demonstrate TISAX compliance because they need supplier assurance. They may accept evidence of your existing controls, an ISO 27001 certificate, a security questionnaire, or a clear improvement plan instead of requiring a formal certification process.
A formal TISAX assessment becomes necessary only when the client requires a TISAX label for a defined scope. Don’t assume this is the case. Ask the client whether they need a label, which assessment objectives apply, the required assessment level, and when they need the result.
Why agencies can fall within scope
Agencies often sit closer to sensitive automotive information than they realise. A creative team may receive confidential product names before launch. A production partner may access unreleased vehicle footage. A media agency may process customer audiences or campaign performance data.
TISAX compliance is not about whether your agency builds vehicles. It’s about whether you can demonstrate controlled handling of the information entrusted to you.
Turn the request into a defined scope
A vague client email should not trigger a company-wide certification process. First, define the assessment scope and identify the evidence the client actually requires.
Start by mapping the service you provide, the information you receive, and the systems and locations supporting that work. This shows your current security posture in relation to the client’s information and delivery model.
This creates the basis for a proportionate response. It also prevents an agency from spending time and money securing areas unrelated to the required assessment scope.
Map the project, data and locations
Identify which teams work on the automotive account and where they work. Include permanent offices, home-working arrangements, production locations, studios, and shared spaces used for confidential work.
Record the information involved, how it is classified, where it is stored, who can access it, and how it leaves the agency. Consider cloud storage, project-management platforms, creative review tools, email, asset libraries, removable media, and printed material.
The scope must match reality. An assessor will expect the documented scope and day-to-day practice to align.
Include freelancers and third parties
The agency's security position is only as strong as the suppliers who receive client information. That may include freelance creatives, film crews, print houses, localisation agencies, PR partners, hosting providers, and managed IT suppliers.
Practical supply chain management means reviewing contractual confidentiality terms, onboarding checks, access approvals, data-sharing arrangements, and offboarding. You need to know who has access, why they need it, and when that access ends.
A confidential campaign can leave scope through a supplier before it leaves through your own systems.
For agencies without internal security leadership, virtual CISO services can provide practical oversight while responsibilities, risks, and evidence are brought under control.
TISAX compliance and assessment levels
TISAX is not a conventional certification process. It is an assessment and exchange framework, with results recorded and shared through the ENX Portal with selected partners.
The VDA ISA catalogue builds on ISO/IEC 27001 principles but adds automotive expectations around information security, data protection, prototype protection, physical security, and supplier relationships. An information security management system aligned with the ISO 27001 standard can provide a useful foundation, but it doesn't automatically satisfy the applicable VDA ISA requirements or replace a required TISAX assessment.
AL1, AL2 and AL3 are not interchangeable
The TISAX Participant Handbook describes three assessment levels:
Assessment level | Assessment approach | Typical assurance |
|---|---|---|
AL1 | Self assessment | Internal confirmation only |
AL2 | Evidence review and expert interview | Moderate assurance |
AL3 | Evidence review, expert interviews, and on-site inspection | Highest assurance |
AL1 doesn't provide the externally validated label that many automotive clients expect. AL2 and AL3 involve an external assessment by an approved provider, including an independent audit of the relevant evidence and controls.
The assessment level is not a matter of preference. It is driven by the client's requirements, the assessment objectives, and the sensitivity of the information in scope.
Highly confidential work may require AL3
AL3 is the most detailed assessment level. It may apply where an agency handles highly confidential prototype information or works in environments requiring close physical and technical controls.
That doesn't mean every unreleased campaign needs AL3. The client must confirm the assessment objectives and level expected. An appropriately qualified TISAX professional can then help test whether the proposed scope and control set are suitable.
What the TISAX assessment process looks like
Once a formal assessment is confirmed, TISAX compliance becomes a structured programme rather than a rushed, document-only certification process. Agencies need governance, working controls, records, and people who understand their responsibilities.
Carry out a gap analysis first
Compare current arrangements against the applicable VDA ISA requirements. A useful gap analysis covers governance, risk management, security controls, asset control, access control, incident response, HR processes, supplier security, awareness training, physical security, and evidence management.
Risk analysis should also consider cyber threats that could expose client information. Look beyond policies. An access policy has limited value if former freelancers retain file-sharing access. An incident process is not enough if account teams do not know how to report a suspected disclosure.
ISO 27001 consultancy can help agencies strengthen the management-system foundations that support a TISAX assessment.
Register and appoint the right assessment provider
The organisation registers its assessment scope and objectives through the ENX Portal. It then selects an ENX-approved TISAX Assessment Provider, rather than an unqualified generic audit provider. Only approved providers can conduct the independent assessment.
The provider reviews evidence, interviews relevant employees, and, for AL3, carries out an on-site inspection. This external audit-style review is independent, but TISAX isn't a conventional certification audit. Account directors, operations leads, IT, HR, procurement, and senior management may all need to contribute.
Current VDA ISA 6.0 applies during 2026. The VDA ISA 2027 update applies to assessments ordered from 1 January 2027. Agencies planning ahead should account for this change rather than building an evidence pack that soon needs rework.
Managing findings without losing momentum
Few organisations begin with every required control fully evidenced. TISAX compliance works best as an operational improvement programme, not a paperwork exercise. Findings and corrective actions prepare the agency for the required assessment, rather than making the certification process a tick-box exercise.
Treat corrective actions as operational work
Each finding needs an owner, target date, risk assessment, and evidence of completion. Keep the language practical. "Improve access management" is not a corrective action. "Remove dormant accounts, implement quarterly access reviews, and retain review records" is.
Prioritise material weaknesses that could expose client information. Shared accounts, unmanaged external sharing, unclear supplier terms, missing asset records, and weak leaver processes should receive early attention.
Keep the client informed, not overwhelmed
A client does not need every internal detail. They do need confidence that you understand their requirement and are managing the work responsibly.
Agree what you will provide, when you will provide it, and who is authorised to discuss security matters. If a deadline is tight, be direct about what is already in place, what remains open, and whether a formal label is realistic within the required timescale.
TISAX audit readiness guidance can help an agency confirm scope, prepare evidence, and address gaps before the external assessment.
Make security part of automotive project onboarding
TISAX compliance should improve how an agency works, not become a separate compliance folder nobody opens after the assessment. Build the relevant checks into new project and supplier processes, rather than treating the certification process as a one-off exercise.
Give account teams a simple route to follow
Create an onboarding step for projects involving confidential automotive material. It should confirm the information classification, approved storage location, authorised people, subcontractors, physical requirements, and client reporting contacts.
The account team should know when to involve IT, operations, legal, or security. This is especially important when a project expands quickly or moves into production.
Maintain the controls after the assessment
TISAX labels are generally valid for a maximum of three years. The ENX TISAX overview confirms the three-year validity period, but the controls must remain effective throughout it.
Maintain access reviews, supplier reviews, staff awareness training, risk assessments, incident response, internal audits, and management reviews. Treat significant changes, such as a new studio, major platform migration, or outsourced production model, as a reason to reassess the scope.
Key takeaways for agency leaders
Confirm whether the client wants evidence of sound security practices or a formal TISAX label. Clarify their compliance requirements before promising an assessment outcome.
Define the assessment scope across the teams, locations, systems, data, and suppliers involved.
Ask the client to confirm assessment objectives and whether AL2 or AL3 is required.
Build evidence around working controls, not policy documents alone.
Assign senior ownership, because TISAX affects client delivery, procurement, HR, IT, and operations.
Keep the client updated through clear, factual communication.
Frequently asked questions
Does every agency with an automotive client need TISAX?
No. TISAX is commonly driven by a client's supplier requirements. An agency may need to complete a questionnaire, show existing security assurance, or obtain a formal label. Confirm the requirement before starting a full assessment programme.
Can an ISO 27001 certificate replace TISAX?
Not automatically. TISAX is an assessment and exchange framework, rather than a conventional certification process. ISO 27001 provides a strong information-security foundation, but TISAX uses the automotive-focused VDA ISA catalogue and defined assessment objectives. A client may still require a TISAX result for the relevant service scope.
What should an agency do first?
Ask the client for the required assessment objectives, level, deadline, scope, and accepted evidence. Then complete a focused gap analysis with qualified information-security or TISAX assessment support. This gives leadership a realistic plan before making commitments.
A controlled response builds client confidence
A TISAX request signals that an automotive client wants greater assurance over TISAX compliance and how its information is handled. It isn't an instruction to promise a generic certification process before you understand the scope and requirements.
The strongest response is clear and proportionate. Confirm the client's expectations, assess the relevant risks, strengthen the controls that matter, and communicate progress with confidence.
If you would like to find out more information or require any of our services, Please Contact Us




Comments