Skip to main content
All answers

What is TISAX?

TISAX (Trusted Information Security Assessment Exchange) is the automotive sector's information-security passport, managed by the ENX Association. Tier-1 and Tier-2 suppliers undergo TISAX assessments at Assessment Levels (AL1, AL2, AL3) corresponding to data-sensitivity tiers. The technical-controls layer derives from ISO 27001 Annex A. OEMs require TISAX assessment evidence from every supplier.

The longer answer.

TISAX exists to solve a supply-chain problem specific to carmakers: an OEM shares sensitive design and prototype data with hundreds of suppliers, and it cannot practically audit each one itself. Instead the industry agreed on a shared assessment that a supplier undergoes once and can then present to any participant, so a single credible result substitutes for many redundant customer audits across the network.

Because its control catalog is built on ISO 27001's Annex A, much of what TISAX asks for at the technical level overlaps with the same secure-configuration expectations that other information-security frameworks impose. A supplier that already maintains hardened, continuously evidenced systems is therefore addressing a substantial part of the technical scope, leaving the assessment to concentrate on process maturity and the automotive-specific handling requirements layered on top.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.