Frameworks / TISAX - Trusted Information Security Assessment Exchange / TISAXASS-1 TISAX - Trusted Information Security Assessment Exchange
Assessment
TISAX - Trusted Information Security Assessment Exchange TISAXASS-1: Assessment Levels and Process Per TISAX VDA ISA: assessment levels + process. Requirements include (a) Assessment Levels AL1 + AL2 + AL3 per scope + risk + (b) Assessment Process via TISAX-approved audit provider + (c) Results Exchange via ENX Portal + (d) cooperate with auditor.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 106 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO-20400-6.5 Monitoring and continuous improvement ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability P2-S1 Partnership IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures A.1 Point-of-Care Testing Additional Requirements ISO-15189-6.8 Externally provided products and services ISO-15189-8.1 General requirements ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach SII-P2-09 Outsourcing Requirements SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing AS9100D-10.2 Nonconformity and Corrective Action AS9100D-8.4 Control of Externally Provided Processes, Products, Services CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting IEC62304-4.1 Quality Management System IEC62304-9.6 Analyze Problems for Trends ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO-41001-10.1 Nonconformity and corrective action ISO-41001-8.4 Control of outsourced processes and services ISO-17025-8.1 Options ISO-17025-8.7 Corrective actions NFPA1600-7.2 After-Action Reporting NFPA1600-8.2 Corrective Action 2.5.2 Verification Activities 2.7.2 Food Fraud Plan ISMSP-MS-04 Management Review and Improvement ISMSP-PI-03 Third-Party Provision and Outsourcing CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records ACQS-8-3 Continuous Improvement Clause 3 Suppliers and service providers ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials DIQ-2 Data Quality Management IS.AR.210 Findings and Corrective Actions CJIS-19 Supply Chain Risk Management ISO-14064-1-8 Quality management of the GHG inventory ISO22316-14 Supply chain continuity ISO-26000-6.6 Fair operating practices ISO30401-15 Nonconformity and corrective action ISO-39001-10.1 Nonconformity and corrective action ISO-50001-8.3 Procurement ISO-56002-10.2 Deviation, nonconformity and corrective action ISO23894-A.6 AI System Security 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain 27014-5.6 Continuous improvement ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SASB-BMI-3 Supply Chain Management SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain IM8-TPM.4 Supply Chain Risk Management GT-3 Supply Chain Compromise UKOPRES-5 Third-Party Risk, Concentration Risk UKGAMBLE-4 Resilience and Incident Response SEMD-PS-3 Supply Chain Security USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability VERMONTAICDA-4 Vermont AG Enforcement and Cure VPSHR-3 Implementation Guidance and Reporting Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 106 it maps to, and the evidence behind each claim, over MCP and REST.