Automotive. Security. Trust.
TISAX: the security the automotive supply chain demands
TISAX (Trusted Information Security Assessment Exchange) is the information security standard for the automotive supply chain, required by OEMs such as Volkswagen, BMW, Mercedes-Benz and Stellantis. AtWorkStudio supports you in preparing for the assessment with dedicated consulting, gap analysis and a management system certified to ISO/IEC 27001, 27017, 27018 and ISO 9001.
What is your cyber maturity level?
Find out in 15 minutes with our assessment based on the NIST Cybersecurity Framework 2.0. The results are a concrete starting point to understand how close you are to TISAX requirements.
106 questions · Instant report · No commitment
What TISAX requires from your company
Information security
Prototype protection
Personal data protection
Supply chain security
Business continuity
3 Assessment Levels
The path to TISAX compliance
VDA ISA gap analysis
Implementation and hardening
ISO 27001 Certifications
Frequently asked questions about TISAX
Answers to the most common questions about TISAX compliance for automotive supply chain companies.
TISAX (Trusted Information Security Assessment Exchange) is the information security assessment mechanism for the automotive supply chain, managed by the ENX Association on behalf of VDA (Verband der Automobilindustrie). It applies to suppliers and partners handling confidential information from OEMs such as Volkswagen, BMW, Mercedes-Benz, Stellantis and others.
TISAX is based on ISO/IEC 27001 requirements but adds automotive-specific controls: prototype protection, design data management, supply chain security and GDPR personal data protection. ISO 27001 is an excellent starting point but does not cover the additional requirements of the VDA ISA catalogue.
TISAX has 3 Assessment Levels (AL): AL 1 (self-assessment, rarely required), AL 2 (verification by an ENX-accredited audit provider, the most common) and AL 3 (in-depth verification for highly confidential information such as prototypes). The required level depends on the type of information handled and the commissioning OEM.
It depends on your current maturity level. For a company already ISO 27001 certified, the process can take 3–6 months to close the specific gaps in the VDA ISA catalogue. Starting from scratch, timelines extend to 9–12 months. The free NIST CSF 2.0 assessment is a good starting point to understand where you stand.
No. AtWorkStudio is not a TISAX certification body and does not hold a TISAX label. We provide consulting and technical support to prepare your company for the assessment: gap analysis, VDA ISA control implementation, infrastructure hardening and staff training. Our management system certified to ISO/IEC 27001, 27017, 27018 and ISO 9001 ensures a structured and verifiable approach.
Yes. Our office is in Piacenza and we operate across Italy. We support automotive supply chain, manufacturing and component companies in Emilia-Romagna on the path to TISAX compliance. As Clusit members and with certifications to ISO/IEC 27001, 27017, 27018 and ISO 9001, we guarantee a structured and verifiable approach.
The automotive supply chain demands security: take the first step
Contact us for dedicated TISAX compliance consulting. We will guide you from gap analysis to assessment preparation, with a concrete approach and no surprises.