TISAX Evidence Checklist for Automotive Security Assessments

Automotive suppliers face increasing pressure to protect sensitive information, prototype materials and customer data across the automotive supply chain. A well-managed TISAX evidence checklist demonstrates TISAX compliance through operating records, not just documented policies, and helps evidence your organisation's security posture.
TISAX is not an ISO 27001 certification. It is an automotive assessment and exchange mechanism, managed by the ENX Association, that allows organisations to share assessment results with authorised supply-chain partners. Original equipment manufacturers may share sensitive information with suppliers through these relationships. Understanding what TISAX means for automotive suppliers is the starting point. A successful TISAX assessment depends on demonstrating working controls and reliable information security evidence.
The checklist below helps you prepare evidence that fits your defined scope, assessment objectives and required assessment level.
Key takeaways for evidence readiness
TISAX compliance requires controls to be documented, implemented and operating in practice.
Your assessment scope should cover the relevant sites, systems, departments, information and outsourced services.
Assessment objectives and applicable VDA ISA criteria determine what evidence is needed, particularly for prototype protection, data protection and highly confidential information.
The TISAX assessment levels are AL1, AL2 and AL3. AL2 and AL3 require evidence and interviews, while AL1 is a self-assessment and does not result in a TISAX label.
A controlled evidence register prevents last-minute document searches and conflicting versions.
Requirements can change with the VDA ISA catalogue, and the VDA ISA maturity level differs from the TISAX assessment level. Confirm the applicable material with ENX and your assessment provider before finalising your project plan.
Start with scope, objectives and assessment levels
The strongest evidence pack can still fail to answer the right questions if the scope is unclear. For TISAX compliance, confirm which legal entity, locations, systems, teams and third parties process automotive information.
The ENX TISAX overview explains that assessments are based on the VDA ISA criteria. Your selected assessment objective and information protection needs determine the evidence your assessor will expect to review.
Assessment Level 1, 2 and 3
TISAX assessment levels define the depth of review required. A VDA ISA maturity level describes control maturity and shouldn't be confused with an AL designation.
Assessment Level 1, or AL1, is an internal self-assessment. An assessor verifies that the self-assessment exists but doesn't assess its content in detail. It doesn't create a TISAX label for exchange.
AL2 includes a plausibility check of your self-assessment through evidence and interviews. It's used for objectives such as information requiring high protection, confidentiality, high availability, test vehicles, prototype events and data protection.
AL3 is a more comprehensive assessment for higher-sensitivity objectives. It applies to scenarios such as information requiring very high protection, strictly confidential information, very high availability, prototype parts, prototype vehicles and special data.
Define the business boundary
Document the locations where relevant work takes place, including offices, development centres, warehouses, workshops and home-working arrangements where applicable. Record the systems used to store, process or exchange customer information.
Include supporting functions. HR, facilities, procurement and IT often hold evidence that's central to the assessment, even if they don't deal directly with an OEM.
An evidence pack should show how controls operate within the agreed scope, not how the wider organisation works in theory.
Build your TISAX evidence checklist around real records
A policy alone doesn't prove that security controls work. Assessors will usually need to see the policy, the process behind it and records showing that people follow it.
Create a register that maps each VDA ISA requirement in scope to its owner, evidence location, document version and review date. Map each requirement to the relevant security controls and records, supporting traceable TISAX compliance. Review it against the applicable VDA ISA compliance requirements and complete a gap analysis before the assessment. The VDA ISA information page is the right reference point for the standardised requirements behind the assessment.
An ISO 27001 control set can be mapped to this checklist, but it doesn't replace automotive-specific evidence. Together, the records should demonstrate your security posture in practice.
Use this practical evidence checklist as a starting point:
Evidence area | Documents to prepare | Operating evidence to retain |
|---|---|---|
Governance | Information security management system (ISMS) scope, information security policy, roles and responsibilities | Management review minutes, approved actions |
Risk management | Risk assessment method, risk register, treatment plan | Risk owners, review records, completed actions |
Asset management | Asset register, information classification rules | Device ownership, disposal records, periodic reviews |
Access control | Access control policy, joiner and leaver procedure | User access reviews, privileged access approvals, leaver records |
Technical security | Patch, backup, logging and vulnerability procedures | Patch reports, backup test results, vulnerability tickets |
Incident management | Incident response plan and escalation process | Incident log, exercise records, lessons learned |
Supplier security | Supplier assessment process and contractual requirements | Due diligence records, supplier reviews, remediation actions |
Physical security | Site security procedures and visitor rules | Visitor logs, access logs, CCTV maintenance records |
Prototype protection | Prototype handling, transport and storage procedures | Access lists, inspection records, secure storage checks |
Store evidence in read-only folders where possible. Give each record a meaningful name and remove superseded drafts from the assessment folder.
Governance and ISMS evidence
TISAX is closely aligned with ISO/IEC 27001 principles, but it applies automotive-specific assessment objectives. An existing ISO 27001 information security management system can provide a strong base, while governance evidence forms the foundation of TISAX compliance. It won't automatically cover every TISAX expectation. A gap analysis against the selected objectives can show whether governance arrangements meet the required maturity level.
Policies, risks and senior ownership
Prepare an approved information security policy supported by practical procedures. Your documentation should identify who owns information security, who approves risks and who reviews performance.
The risk register should cover threats relevant to the assessment scope and classify information according to its protection needs. This may include unauthorised access to customer portals, insecure prototype transport, ransomware, supplier compromise and accidental disclosure. Link each material risk to a treatment decision, relevant security controls and evidence that agreed actions were completed.
Management review records should show more than attendance. They should cover security performance, incidents, audit results, risks, resources and improvement actions.
Training and employee awareness
Training records need to show that relevant employees understand their responsibilities. General security awareness is useful, but staff handling prototypes, restricted customer data or privileged accounts may require role-specific instruction covering data protection practices.
Prepare induction materials, training attendance records, awareness campaigns and refresher schedules. During interviews, employees should be able to explain how they follow the incident response plan, protect confidential material and follow access rules.
Organisations building a wider management system can draw on ISO 27001 consultancy for automotive organisations to align core governance, risk and internal audit activities.
Technical and operational security evidence
Technical evidence is strongest when it connects a written standard to system-generated records and security controls. This supports TISAX compliance by showing how controls operate in practice. Avoid collecting screenshots without context. Record the date, system owner and purpose of each item.
Map each system-generated record to the relevant security controls, rather than presenting isolated exports. For audit preparation, sample records across systems and review periods. Aligned technical controls under ISO 27001 may provide supporting evidence. Independent reports from a hosted service or technology provider can support a third-party audit.
Identity, access and privileged accounts
Show how access is approved before it’s granted, reviewed during employment and removed promptly when roles change. Evidence can include access request tickets, active directory group reviews, multi-factor authentication settings and offboarding checklists.
Privileged accounts need particular attention. Maintain a list of administrators, justify their access and show periodic review. Shared administrator accounts make accountability difficult and should be tightly controlled.
Vulnerability, backups and incidents
Prepare recent vulnerability scans, patch compliance reports and records of exceptions. Where a patch couldn’t be applied, show the risk decision and compensating measure.
Backup evidence should include successful jobs and restoration tests. A backup report without proof of recovery doesn’t demonstrate that critical information can be restored. Together, access, vulnerability and recovery records demonstrate your security posture.
Your incident response plan should define reporting routes, escalation responsibilities and communication decisions. Tabletop exercises are useful evidence when minutes show scenarios, outcomes and assigned improvements.
Supplier security and data protection evidence
Automotive information often moves through cloud providers, logistics partners, managed service providers and specialist engineering firms. Original equipment manufacturers and their suppliers must classify information according to its protection needs. Your evidence should show TISAX compliance by managing supplier risk throughout the relationship.
Third-party oversight
Use vendor risk management as the organising principle for supplier oversight. Maintain a list of relevant suppliers and classify them by the information or services they provide.
For higher-risk suppliers, retain due diligence questionnaires, security certifications, contractual clauses, relevant security controls and review records. An ISO 27001 certificate can support control evidence, but it doesn't replace TISAX. Independent third-party audit reports can provide additional assurance.
Contracts should address confidentiality, data handling, incident notification, subcontracting and access return at the end of the relationship. Where issues are found, document the decision, corrective action and follow-up against relevant compliance requirements.
Personal and special data
Data protection objectives require clear evidence of data protection practices and how personal data is handled. Keep data flow records, privacy notices, retention rules and procedures for responding to data subject requests where they apply.
If special data is within scope, identify where it is stored, who can access it and how transfers are protected. TISAX does not replace UK GDPR obligations, so align security records with your wider privacy governance.
Prototype protection evidence for higher-risk objectives
Prototype protection is often where generic information security measures are not enough. Prototype parts, test vehicles and confidential events need physical, operational and people-based security controls. TISAX compliance depends on the selected assessment objective and protection needs, which determine the evidence required.
Secure areas and controlled access
Document restricted-area boundaries, access approval rules, visitor management and security patrols as physical security measures. Evidence may include floor plans, access-card reports, visitor logs, escort records and CCTV maintenance checks.
Secure storage and prototype movement require physical security measures. Show how prototype parts, keys, removable media and printed designs are locked away, inventoried and issued only to authorised people.
Prototype movement and events
For prototype vehicles and parts, keep movement records that identify custody, transport arrangements, delivery checks and handover controls. If vehicles are tested off-site, document who authorises use and how exposure risks are managed.
Prototype events need a separate plan. It should cover guest approval, photography controls, restricted zones, equipment checks and an incident response plan for photography breaches, unauthorised access or lost items. The precise evidence depends on the selected TISAX objective and the sensitivity of the customer material.
Register with ENX and prepare for assessment
Once scope and objectives are agreed, TISAX compliance preparation includes registering through the ENX portal and selecting an appropriate audit provider. The TISAX Participant Handbook explains the TISAX assessment levels: AL1 is a self-assessment, while AL2 or AL3 may lead to a TISAX label after a successful assessment. That TISAX label can then be shared with authorised partners.
Prepare people as well as folders
Nominate evidence owners before the assessment. Each owner should understand their process, know where records are held and be ready to explain how exceptions are managed.
Run a focused internal review and gap analysis against your target maturity level. Test a small sample of access approvals, supplier reviews, training records and physical security measures, and check supplier assurance evidence for a third-party audit.
Manage corrective actions properly
If an issue is identified, create a corrective action plan with an owner, completion date, risk rating, evidence of closure and a check against applicable compliance requirements. Avoid closing actions because a policy has been updated when the practical control has not yet been tested.
Existing ISO 27001 evidence can support audit preparation, but it can't replace TISAX preparation. Assessment requirements and catalogue versions can change. The ENX TISAX downloads page includes current and upcoming materials, including the planned VDA ISA2027 questionnaire for assessments ordered in 2027. Confirm the applicable version with your provider.
Frequently asked questions
Is TISAX the same as ISO 27001?
No. ISO 27001 is an international standard for an information security management system and can lead to certification. TISAX is an automotive assessment and exchange mechanism based on the VDA ISA catalogue. ISO 27001 controls may support TISAX compliance, but they don't automatically establish it because automotive-specific objectives may require additional evidence.
Which assessment level produces a TISAX label?
The three TISAX assessment levels are AL1, AL2 and AL3. AL2 and AL3 assessments can result in TISAX labels that participants share through the ENX portal with authorised partners. AL1 is a self-assessment and does not result in a label.
Is a TISAX audit the same as a TISAX assessment?
Organisations may use the terms informally, but TISAX formally refers to an assessment conducted by an approved provider. It isn't ISO 27001 certification.
How long does TISAX preparation take?
The timeframe depends on your existing controls, number of locations, assessment objectives and available internal resource. A business with a mature ISMS may progress quickly, while AL3 prototype protection can require site improvements, process testing and broader employee involvement.
A stronger route to TISAX readiness
A successful assessment is built on working evidence, not a folder of polished policies. Define the correct scope, map each requirement to a control owner and collect records that show consistent day-to-day operation and support your security posture.
TISAX evidence expectations vary by assessment objective, scope and assessment level. For AL2 or AL3, meeting the relevant requirements can support a TISAX label, rather than ISO 27001 certification. Validate the latest ENX requirements with your assessment provider, then use an evidence-led readiness review for audit preparation. Record unresolved weaknesses in a corrective action plan before the external assessment begins.
For organisations seeking a structured roadmap, evidence review or assessment support for TISAX compliance, TISAX consultancy services can help turn requirements into practical, auditable controls.
If you require any services or would like to find out more - Contact Us




Great article!