TISAX · READINESS

TISAX readiness guide

This page helps automotive industry organizations and their partners prepare for and self-assess against a TISAX assessment (Trusted Information Security Assessment Exchange).

Framework scope

Relevant for automotive OEMs, suppliers, engineering service providers and partners that need to demonstrate information security through the shared ENX-VDA ISA platform.

TISAX is based on the VDA ISA (Information Security Assessment) and assesses information security across areas such as ISMS, data and information protection, human resources, physical security, IT security and additional modules (prototype, connection).

Orientation score

0%

0 / 100 points

Evidence examples

  • VDA ISA self-assessment and ISMS documentation
  • Security concept and control catalogue
  • Risk assessment and reports
  • Classification policy and handling of customer data
  • Access concept with review evidence
  • MFA and SSO configuration
  • Training records and non-disclosure agreements
  • CCTV/access records and alarm plans
  • Contracts and security questionnaires for partners

Common gaps

  • VDA ISA criteria are not fully mapped to the process landscape
  • Missing classification of customer and prototype data
  • Access and permission reviews are not periodic
  • Employee training and confidentiality are not demonstrable
  • TISAX-specific obligations are missing in supplier contracts

CloudForge workflow

CloudForge provides VDA ISA criteria as structured tasks, collects evidence per area, supports internal TISAX readiness checks and prepares documentation for the ENX-VDA platform and external audit.

Official references

  • VDA ISA: Information Security Assessment based on ISO/IEC 27001 and 27002
  • ENX-VDA TISAX platform and assessment process
  • TISAX Rules of the ENX Association

Assessments must be validated with owners, scope and reliable evidence. This page is not a TISAX assessment, label or certification.

This guide is for orientation and preparation. It does not replace a formal TISAX assessment or label and does not automatically lead to certification or confirmation by an external assessor.

CloudForge Team — Cloud, Container and AI under control