TISAX - Trusted Information Security Assessment Exchange
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Access Control
| Code | Title |
|---|---|
| TISAX-ACCESS-01 | Identity and Access Management |
Assessment Process
| Code | Title |
|---|---|
| TISAX-ASSESS-01 | TISAX Assessment Execution by Audit Provider |
Assessment and Exchange
TISAX assessment process and results sharing
| Code | Title |
|---|---|
| TISAX-AE-01 | Assessment Levels |
| TISAX-AE-02 | Assessment Process |
| TISAX-AE-03 | Results Exchange |
Business Continuity
| Code | Title |
|---|---|
| TISAX-BCM-01 | Business Continuity and IT Disaster Recovery |
Data Protection
| Code | Title |
|---|---|
| TISAX-DP-01 | Data Protection Module Controls |
Development
| Code | Title |
|---|---|
| TISAX-DEV-01 | Secure Software Development |
Human Resources
| Code | Title |
|---|---|
| TISAX-HR-01 | Human Resources Security |
ISMS Operation
| Code | Title |
|---|---|
| TISAX-AUDIT-01 | Internal Audit and Management Review |
IT Operations
| Code | Title |
|---|---|
| TISAX-OPS-01 | IT Operations and System Hardening |
Incident Management
| Code | Title |
|---|---|
| TISAX-IM-01 | Incident Management and Reporting |
Information Security
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | Information Security Policy and Organisation |
| TISAX-IS-02 | Information Security Risk Management |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Information Security
VDA ISA information security requirements
| Code | Title |
|---|---|
| 37.1401(a) | General Security Requirements for SEFs |
| 38.1051(a) | General Security Requirements for DCMs |
| 39.18(a) | General Security Requirements for DCOs |
| 49.24(a) | General Security Requirements for SDRs |
| DSPF-INFO-1 | Information Classification |
| DSPF-INFO-2 | Information Handling |
| DSPF-INFO-3 | Information Access Controls |
| DSPF-INFO-4 | Security Markings |
| GLI33-4.1 | Information Security System Assessment |
| GLI33-4.2 | Penetration Testing |
| GLI33-4.3 | Data Protection and Encryption |
| GLI33-4.4 | Audit Trail and Logging |
| PSPF-INFO-1 | Sensitive and Classified Information |
| PSPF-INFO-2 | Security Classification System |
| PSPF-INFO-3 | Information Holdings |
| PSPF-INFO-4 | Information Disposal |
| PSPF-INFO-5 | Information Sharing |
| PSPF-INFO-6 | Security Caveated Information |
| PSPF-INFO-7 | Accountable Material |
| TISAX-IS-01 | Information Security Policy and Organisation |
| TISAX-IS-02 | Information Security Risk Management |
| TISAX-IS-03 | Third-Party Risk Management |
| TSSR-INFO-1 | Network Data Protection |
| TSSR-INFO-2 | Stored Communications Security |
| TSSR-INFO-3 | Lawful Interception Capability |
Information Security Management
ISMS governance, risk management, and policies
| Code | Title |
|---|---|
| TISAX-ISM-01 | IS Policies and Organization |
| TISAX-ISM-02 | Risk Management |
| TISAX-ISM-03 | Human Resources Security |
| TISAX-ISM-04 | Supplier and Third-Party Management |
Network Security
| Code | Title |
|---|---|
| TISAX-COMMS-01 | Communications and Network Security |
Physical Security
| Code | Title |
|---|---|
| TISAX-PHYS-01 | Physical Security and Environmental Controls |
Programme Setup
| Code | Title |
|---|---|
| TISAX-SCOPE-01 | TISAX Scope Definition and Assessment Level Selection |
| TISAX-SCOPE-02 | TISAX Labels Selection |
Prototype Protection
| Code | Title |
|---|---|
| TISAX-PROTO-01 | Prototype Protection Requirements |
| TISAX-PROTO-02 | Test Vehicle and Component Handling |
Prototype and Data Protection
Automotive-specific prototype protection and data privacy
| Code | Title |
|---|---|
| TISAX-PROT-01 | Prototype Protection (Physical) |
| TISAX-PROT-02 | Prototype Protection (Digital) |
| TISAX-PROT-03 | Data Protection (Privacy) |
Result Exchange
| Code | Title |
|---|---|
| TISAX-EXCH-01 | Result Exchange and Customer Engagement Levels |
Supplier Management
| Code | Title |
|---|---|
| TISAX-SUPP-01 | Supplier and Third Party Information Security |
Technical and Operational Controls
Access control, cryptography, operations, and communications security
| Code | Title |
|---|---|
| TISAX-TECH-01 | Access Control and Identity Management |
| TISAX-TECH-02 | Cryptography |
| TISAX-TECH-03 | Operations and Communications Security |
| TISAX-TECH-04 | Incident Management |
Your Compliance Coverage
If you comply with TISAX - Trusted Information Security Assessment Exchange, you already cover:
NIST SP 800-53 Rev 5
34%
19 controls mapped
Compare →Protective Security Policy Framework (PSPF) Release 2024
34%
19 controls mapped
Compare →Telecommunications Sector Security Reforms (TSSR)
34%
19 controls mapped
Compare →+ 398 more: Singapore Government Instruction Manual on ICT&SS Management (IM8) (32%), South Korea ISMS-P (32%)
See all 401 mapped frameworks ↓Maps to 401 other frameworks
Frequently Asked Questions
What is TISAX - Trusted Information Security Assessment Exchange?
TISAX - Trusted Information Security Assessment Exchange is a compliance framework from International (Automotive) with 21 domains and 58 controls. TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does TISAX - Trusted Information Security Assessment Exchange have?
TISAX - Trusted Information Security Assessment Exchange has 58 controls organised across 21 domains. The largest domains are Information Security (25 controls), Information Security Management (4 controls), Technical and Operational Controls (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does TISAX - Trusted Information Security Assessment Exchange map to?
TISAX - Trusted Information Security Assessment Exchange maps to 401 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (34% coverage), Protective Security Policy Framework (PSPF) Release 2024 (34% coverage), Telecommunications Sector Security Reforms (TSSR) (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with TISAX - Trusted Information Security Assessment Exchange compliance?
Start your TISAX - Trusted Information Security Assessment Exchange compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about TISAX - Trusted Information Security Assessment Exchange requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 58 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required