TISAX — Trusted Information Security Assessment Exchange
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Assessment and Exchange
TISAX assessment process and results sharing
| Code | Title |
|---|---|
| TISAX-AE-01 | Assessment Levels |
| TISAX-AE-02 | Assessment Process |
| TISAX-AE-03 | Results Exchange |
Information Security
VDA ISA information security requirements
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| EIOPA-GL-10 | ICT Operations Security |
| EIOPA-GL-11 | Security Monitoring |
| EIOPA-GL-12 | Information Security Reviews, Assessment and Testing |
| EIOPA-GL-13 | Information Security Training and Awareness |
| EIOPA-GL-6 | Information Security Policy |
| EIOPA-GL-7 | Information Security Function |
| EIOPA-GL-8 | Logical Security |
| EIOPA-GL-9 | Physical Security |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | ISMS Requirements |
| TISAX-IS-02 | Prototype Protection |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Information Security Management
ISMS governance, risk management, and policies
| Code | Title |
|---|---|
| TISAX-ISM-01 | IS Policies and Organization |
| TISAX-ISM-02 | Risk Management |
| TISAX-ISM-03 | Human Resources Security |
| TISAX-ISM-04 | Supplier and Third-Party Management |
Prototype and Data Protection
Automotive-specific prototype protection and data privacy
| Code | Title |
|---|---|
| TISAX-PROT-01 | Prototype Protection (Physical) |
| TISAX-PROT-02 | Prototype Protection (Digital) |
| TISAX-PROT-03 | Data Protection (Privacy) |
Technical and Operational Controls
Access control, cryptography, operations, and communications security
| Code | Title |
|---|---|
| TISAX-TECH-01 | Access Control and Identity Management |
| TISAX-TECH-02 | Cryptography |
| TISAX-TECH-03 | Operations and Communications Security |
| TISAX-TECH-04 | Incident Management |
Maps to 651 other frameworks
Frequently Asked Questions
What is TISAX — Trusted Information Security Assessment Exchange?
TISAX — Trusted Information Security Assessment Exchange is a compliance framework from International (Automotive) with 5 domains and 47 controls. TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does TISAX — Trusted Information Security Assessment Exchange have?
TISAX — Trusted Information Security Assessment Exchange has 47 controls organised across 5 domains. The largest domains are Information Security (33 controls), Information Security Management (4 controls), Technical and Operational Controls (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does TISAX — Trusted Information Security Assessment Exchange map to?
TISAX — Trusted Information Security Assessment Exchange maps to 651 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (55% coverage), Protective Security Policy Framework (PSPF) Release 2024 (53% coverage), South Korea Cloud Security Assurance Program (CSAP) (53% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with TISAX — Trusted Information Security Assessment Exchange compliance?
Start your TISAX — Trusted Information Security Assessment Exchange compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about TISAX — Trusted Information Security Assessment Exchange requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required