top of page
Search

How to Start Your TISAX Compliance Journey

Writer: AKRUP
AKRUP
6 days ago
7 min read

Many organisations begin their TISAX compliance journey because an automotive customer, OEM, or supply-chain partner asks for proof that sensitive information is protected. That request can affect a new contract, an existing supplier relationship, or the ability to handle higher-risk work.

 

TISAX compliance journey is not about producing a folder of policies and calling the job complete. TISAX is an automotive information security assessment and exchange scheme. It tests whether security controls work across your people, processes, technology, suppliers, and sites.

 

The right starting point is to understand the information you handle, where it goes, and what could put it at risk.

 

How do we start our TISAX compliance journey?

 

Start by confirming the business requirement with the customer or partner that raised it. Ask what assessment objectives, protection needs, locations, and deadlines apply. A vague request for "TISAX certification" isn't enough to plan a reliable project.

 

TISAX stands for Trusted Information Security Assessment Exchange. It is operated by the ENX Association and uses the VDA Information Security Assessment, commonly known as VDA ISA. The catalogue covers information security, prototype protection, and data protection requirements for the automotive industry.

 

Gather the information that already exists before selecting a route. This should include customer contracts, security questionnaires, data-flow maps, current policies, audit reports, incident records, supplier arrangements, and any ISO/IEC 27001 certification. ISO 27001 provides a strong foundation, but it doesn't automatically meet every automotive-specific TISAX requirement.

 

A senior owner should be accountable for the programme. They need authority to approve scope, allocate resources, accept residual risk, and keep the work moving across departments. TISAX consultancy support can help organisations turn customer expectations into a practical, proportionate plan.

 

Start with the information and risks you must protect

 

List the information handled for automotive customers. This may include vehicle designs, prototypes, test results, manufacturing plans, logistics data, commercial terms, customer information, and personal data.

 

For each information type, identify its owner, users, storage locations, suppliers, and transfer routes. Include email, file-sharing platforms, cloud services, removable media, paper records, engineering tools, and home-working arrangements.

 

The risk picture must go beyond cyber attacks. Consider physical access to buildings, visitor management, unauthorised photography, lost devices, weak access rights, supplier failures, and staff leaving the business. GDPR applies where personal data is involved, but GDPR and TISAX address different needs. One does not replace the other.

 

 

Choose a realistic scope before building controls

 

The scope may cover a single site, several UK locations, overseas offices, a department, a legal entity, an information system, or a customer project. It can also include shared IT, HR, procurement, and facilities services that support the assessed activity.

 

Avoid setting a scope so narrowly that it ignores real dependencies. Equally, don't include every business activity without a clear reason. An unmanageable scope creates unnecessary cost, evidence work, and audit effort.

 

Document exclusions and explain why they sit outside the assessment. If a central IT team manages access, backups, or cloud services for the scoped site, those controls still matter. Scope decisions affect the usefulness of the final TISAX label, so they need customer agreement and management approval.

 

Select the right TISAX assessment objectives and level

 

Assessment objectives should reflect the information and services your organisation handles. They are not marketing labels to select because they appear more impressive.

 

Assessment Level 1 is a self-assessment route. It may be useful internally, but many OEMs and automotive customers require independent assurance at AL2 or AL3. ENX's TISAX guidance explains that AL2 is a plausibility check of the self-assessment, supported by evidence and interviews. AL3 is a more detailed on-site assessment involving document review and interviews.

 

High protection needs commonly map to AL2. Objectives such as Info high, Confidential, High availability, and Data may fall into this category. Very high protection needs commonly require AL3, including Info very high, Strictly confidential, Very high availability, special data, and prototype-related objectives.

 

Confirm whether prototype protection applies

 

Prototype protection has its own requirements. It may apply to prototype vehicles, parts, test vehicles, restricted engineering areas, prototype events, or confidential testing activity.

 

This work often needs stronger physical security. Controls may include restricted access, visitor rules, photography restrictions, secure transport, protected storage, and clear escalation procedures when something goes wrong.

 

Don't assume a standard information security objective covers prototype activity. Confirm the exact requirement with the customer before registering the assessment.

 

Register in the ENX Portal and plan the assessment

 

The formal route begins with registration as a participant in the ENX Portal. You then define your scope and assessment objectives, select a contracted TISAX assessment provider, and arrange the assessment.

 

The TISAX Participant Handbook confirms that ENX manages participation and results exchange, while the assessment provider carries out the assessment. The provider must be independent and cannot have previously provided consultancy to the assessed organisation.

 

ENX participation fees and audit-provider fees are separate. Total cost also depends on scope, locations, objectives, provider choice, and your current security maturity. TISAX labels are generally valid for up to three years, so renewal planning should start well before expiry.

 

Assessment orders placed up to 31 December 2026 can continue under VDA ISA6. Assessments ordered from 1 January 2027 will follow ISA2027. Review the ENX ISA2027 transition announcement and check current customer requirements before committing.

 

Turn the gap analysis into an audit-ready security programme

 

A gap analysis compares your current practices and evidence against the applicable VDA ISA requirements. It should identify what is missing, what works inconsistently, and where controls exist but cannot yet be proven.

 

Rate each gap by risk, customer impact, effort, dependency, and deadline. Then build a tracked remediation plan with a named owner, target date, required resources, and evidence of completion. A policy library alone won't satisfy an assessor if daily practice tells a different story.

 

An existing ISMS can reduce the work involved. ISO 27001 specialists can help strengthen governance, risk management, internal audit, and management review processes that support TISAX preparation. The TISAX assessment still needs its own scope, objectives, and evidence.

 

Build evidence into normal business processes

 

Auditors may ask for approved policies, risk assessments, asset registers, access reviews, supplier checks, training records, incident logs, backup tests, vulnerability records, patching reports, physical access records, management reviews, and internal audit findings.

 

Evidence should be dated, consistent, owned, and linked to the stated scope. A training record for one office won't prove staff awareness at an unlisted second site. A risk assessment that ignores a cloud service won't support a scope that depends on it.

 

Create an evidence index for each applicable requirement. It should point to the right document, system report, operational record, or interview owner. This makes preparation more controlled and reduces last-minute confusion.

 

  Records created days before an assessment rarely demonstrate that a control is operating in normal business activity.  

 

Involve the whole organisation, not just the IT team

 

IT is central to access control, endpoint security, backups, monitoring, and technical protection. It cannot own every TISAX requirement.

 

Senior management must approve scope, provide resources, review risks, and decide whether residual risks are accepted or treated. HR manages onboarding, screening where appropriate, training, and offboarding. Procurement needs supplier checks and contractual security requirements.

 

Facilities and site managers control visitors, keys, restricted areas, and physical protection. Engineering and project teams need clear rules for prototypes, customer data, removable media, and secure collaboration. Short, role-based training works better than a generic annual presentation.

 

Test readiness before the TISAX assessment

 

Before the formal assessment, carry out an independent internal audit or readiness review against the selected objectives. Interview staff, sample evidence, walk through physical sites, and test whether controls work in practice.

 

A consultant can identify weaknesses and help prepare the organisation. Only an approved TISAX assessment provider can perform the official assessment. Organisations needing independent challenge before that stage can draw on AKRUP's audit and consultancy expertise.

 

 

Check the essentials before the assessor arrives

 

A final readiness review should confirm the following:

 

  • The assessment scope has management approval and reflects real information flows.

  • The customer-required objectives, assessment level, and ISA version are confirmed.

  • Risk treatment actions, management review, and internal audit activity are complete.

  • Staff understand their responsibilities and know how to report incidents.

  • Supplier evidence, physical security records, and technical control records are current.

  • Assessment logistics, interviews, site access, and evidence owners are organised.

 

If an assessor raises a finding, understand the underlying cause before responding. Assign an owner and deadline, provide objective evidence of the fix, and verify it works. Closing paperwork without correcting the process creates the same problem at the next review.

 

Avoid the mistakes that delay TISAX readiness

 

Common delays begin with the wrong assessment objective or an unrealistic deadline. Others come from copied policies that do not reflect daily practice, weak ownership, or management teams that only engage near the audit date.

 

Shared services are often missed. A site may appear separate, yet rely on group IT, central HR, external cloud platforms, or a third-party security provider. Those dependencies need assessment.

 

Don't treat GDPR as a substitute for TISAX. Don't leave physical security, employee controls, and supplier management until the end. ISO 27001 certification is helpful, but it doesn't guarantee a TISAX outcome.

 

Keep improving after you receive your TISAX label

 

A TISAX label is evidence of an assessed security programme. It is not permission to stop managing risk.

 

Keep assets, suppliers, access rights, training, incidents, vulnerabilities, corrective actions, backups, and business continuity plans under review. Changes to sites, systems, customer work, data types, cloud services, or prototype handling may affect the assessment scope.

 

Use regular internal audits and management reviews to spot gaps early. The ENX Portal supports the secure sharing of results with authorised partners, reducing repeated customer security questionnaires.

 

A maintained programme also supports stronger customer trust, better supplier governance, and more consistent security decisions across the business.

 

Final thoughts

 

A successful TISAX compliance journey begins with customer expectations and a clear understanding of the sensitive information your organisation handles. From there, define a workable scope, select the correct objectives and assessment level, register through ENX, and address the priority gaps.

 

The work involves management, IT, HR, operations, suppliers, physical sites, and project teams. Strong evidence, trained staff, and tested controls matter as much as written documentation.

 

For UK automotive suppliers, TISAX readiness becomes far more manageable when requirements are converted into a practical, owned roadmap. Book a readiness discussion with AKRUP to turn customer requirements into focused next steps.


If you would like to find our more or require any TISAX services please Contact Us

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page