Your situation

TISAX® consulting: preparing your ISMS for the assessment

Your client requires TISAX® evidence? TISAX is a procedure for assessing information security and exchanging the assessment results. Together with you, we clarify which sites are affected and where you still need to act before the assessment. In doing so, we build on your existing information security management system (ISMS) or your current processes.

Free of charge and without obligation.

  • ISO 27001 Lead Auditors on the team
  • Our own ISO 27001-certified ISMS
  • BSI-certified for IS consulting and IS audit
Top view of joint map work with notes, compasses and navigation instruments
TISAX® consulting: well prepared for the assessment.

Your situation

Your vehicle manufacturer (OEM) or client requires a TISAX® label?

As a supplier to the automotive industry, you need to demonstrate that you adequately protect your clients' information, prototypes and data. The benchmark is the VDA ISA, the assessment catalogue of the German Association of the Automotive Industry (VDA). The result is exchanged via TISAX® of the ENX Association so that you are not assessed separately by every manufacturer. Assessments commissioned up to the end of 2026 are subject to ISA 6; assessments commissioned from 1 January 2027 follow ISA2027, published in July 2026.

The questions are then usually the same: which sites and areas belong in the scope? Is an existing ISO 27001 ISMS sufficient? And how do you reach the required maturity level by the assessment date? Unlike "native" ISO 27001, VDA ISA places more weight on the implementation of security measures – and sets additional requirements for third-party connection, prototype protection and data protection.

This is where we come in: with a modular approach, we take you from your starting point to an auditable security level as quickly as possible. The basis is an ISMS to ISO 27001 that you can also use beyond the automotive sector if you wish. An internal audit based on VDA ISA shows in advance whether the maturity level is sufficient for the assessment.

Services & results

Step by step to an auditable security level based on VDA ISA

You get an overview of the open topics for your TISAX® assessment based on VDA ISA and the order in which you should tackle them. The basis is a quick check of your management system and your measures against the VDA ISA catalogue, including prototype protection, third-party connection and data protection; your existing ISMS remains the foundation.

The modules can be commissioned individually. We are transparent about our approach and pass on the knowledge so that your team can continue the ISMS independently after the assessment.

Quick check: your starting point against VDA ISA

In the quick check, we record the current status of your management system and the implementation of your security measures. We compare them, within the agreed scope, with the requirements of the VDA ISA catalogue – including the additional requirements for prototype protection, third-party connection and data protection.

Your priorities

An overview of the open topics and the order in which you should tackle them.

Define the scope

Automotive assessments usually only cover the parts of the company relevant to the sector. Whether you limit the ISMS to these or introduce it company-wide is a strategic decision. We show you both options.

As a rule, using the ISMS you need anyway for all of your information security brings considerable synergies. The scope can be extended step by step.

Guided introduction of management processes

Where management processes are missing, we introduce them step by step with your responsible staff: control cycles, risk assessments and the associated documentation to ISO 27001. We use an existing ISMS as the basis.

Prioritising and supporting implementation

VDA ISA assesses implementation using a maturity model. We help prioritise open implementation topics and support the implementation of security measures. During ongoing ISMS operation, we are available as your contact for questions.

If you want the status reviewed independently before the assessment, we carry out an internal audit based on VDA ISA.

Preparing for and supporting the assessment

The TISAX® assessment is carried out by an audit provider accredited by ENX. We prepare your team for it and provide expert support during audits by third parties.

Ready for the assessment

Evidence showing how your company has implemented the requirements – and an ISMS that your team continues on its own.

Our expertise

Our team has many years of experience implementing ISO 27001, including in the context of the automotive industry. We have been providing IT security consulting since 1988. Implementing technical security measures is as much established practice for us as building control cycles and risk assessments.

For suppliers, we also cover related evidence: internal audits based on VDA ISA and penetration tests in accordance with IATF 16949 (Sanctioned Interpretations, clause 6.1.2.3 "Contingency plans").

Getting started

Agree the consulting scope and internal involvement

Bring the requirement, documents and date

Bring your client's requirement and an overview of the sites concerned. Tell us your preferred assessment date. Existing ISMS documents and evidence of implementation help to assess the need for consulting.

Define tasks and effort

To estimate the effort, we clarify the implementation status and the open requirements. We discuss which internal staff will be involved and which tasks secuvera takes on. Your team provides information, implements the agreed measures and continues the processes in day-to-day operations.

Discuss your TISAX® preparation
Hands writing notes next to a compass and navigation instruments on a map
VDA ISA requirements and sites clarified early.

Keeping consulting and the TISAX® assessment separate

The TISAX® assessment is carried out by an audit provider approved by the ENX Association. The audit provider assesses the implementation and determines the assessment result. secuvera provides the agreed consulting and preparation. TISAX® is a registered trademark of the ENX Association.

Questions about TISAX® consulting and assessment preparation

Does the TISAX® project have to cover our entire company?

Not necessarily. Which sites and activities belong in the assessment depends on your client's requirement and the TISAX rules. Regardless of this, you can use your ISMS company-wide or extend its scope step by step.

Is our ISO 27001 certificate sufficient as TISAX® evidence?

An ISO 27001 certificate does not replace a TISAX assessment result. TISAX is based on the requirements of the ISA catalogue. Clarify with your client which evidence they specifically require.

Can we commission just a quick check to begin with?

Yes. You can start with a quick check and then decide on further support. This can relate to individual measures, management processes or preparation for the assessment.

As a supplier, do we also need a penetration test?

That depends on your requirements. If you are certified to IATF 16949, the Sanctioned Interpretations of clause 6.1.2.3 "Contingency plans" can make a penetration test necessary. We carry out such penetration tests as a separate service.

Which version of VDA ISA applies to our assessment?

This depends on the date on which you commission the assessment. TISAX® assessments commissioned in 2026 are subject to ISA 6. Assessments commissioned from 1 January 2027 follow ISA2027, which the VDA published in July 2026. According to ENX, future versions will each be published in summer and apply from 1 January of the following year.

How can we support you with TISAX®?