TISAX - Trusted Information Security Assessment Exchange
TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants.
TISAX - Trusted Information Security Assessment Exchange is a compliance framework from International (Automotive) with 10 domains and 28 controls that map to 179 other frameworks. The largest domains are Technical and Operational Security (10 controls), Assessment Scope, Levels and Exchange (4 controls), Information Security Management (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Assessment
| Code | Title |
|---|---|
| TISAXASS-1 | Assessment Levels and Process |
Assessment Scope, Levels and Exchange
| Code | Title |
|---|---|
| TISAX-AUDIT-01 | Internal Audit and Management Review |
| TISAX-EXCH-01 | Result Exchange and Customer Engagement Levels |
| TISAX-SCOPE-01 | TISAX Scope Definition and Assessment Level Selection |
| TISAX-SCOPE-02 | TISAX Labels Selection |
Data Protection
| Code | Title |
|---|---|
| TISAXASS-4 | Data Protection (GDPR Alignment) |
Data Protection Module
| Code | Title |
|---|---|
| TISAX-DP-01 | Data Protection Module Controls |
ISA
| Code | Title |
|---|---|
| TISAXASS-2 | ISA Catalog Implementation |
Information Security Management
| Code | Title |
|---|---|
| TISAX-ISM-01 | IS Policies and Organization |
| TISAX-ISM-02 | Risk Management |
| TISAX-ISM-03 | Human Resources Security |
| TISAX-ISM-04 | Supplier and Third-Party Management |
People and Third Parties
| Code | Title |
|---|---|
| TISAX-HR-01 | Human Resources Security |
| TISAX-IS-03 | Third-Party Risk Management |
| TISAX-SUPP-01 | Supplier and Third Party Information Security |
Prototype
| Code | Title |
|---|---|
| TISAXASS-3 | Prototype Protection and Confidentiality |
Prototype Protection
| Code | Title |
|---|---|
| TISAX-PROTO-01 | Prototype Protection Requirements |
| TISAX-PROTO-02 | Test Vehicle and Component Handling |
Technical and Operational Security
| Code | Title |
|---|---|
| TISAX-BCM-01 | Business Continuity and IT Disaster Recovery |
| TISAX-COMMS-01 | Communications and Network Security |
| TISAX-DEV-01 | Secure Software Development |
| TISAX-IM-01 | Incident Management and Reporting |
| TISAX-OPS-01 | IT Operations and System Hardening |
| TISAX-PHYS-01 | Physical Security and Environmental Controls |
| TISAX-TECH-01 | Access Control and Identity Management |
| TISAX-TECH-02 | Cryptography |
| TISAX-TECH-03 | Operations and Communications Security |
| TISAX-TECH-04 | Incident Management |
Your Compliance Coverage
If you comply with TISAX - Trusted Information Security Assessment Exchange, you already cover:
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
39%
11 controls mapped
Compare →NIST SP 800-53 Rev 5
36%
10 controls mapped
Compare →South Korea ISMS-P
36%
10 controls mapped
Compare →+ 176 more: Singapore Government Instruction Manual on ICT&SS Management (IM8) (36%), ISO/IEC 27011:2024 (32%)
See all 179 mapped frameworks ↓Maps to 179 other frameworks
What is TISAX - Trusted Information Security Assessment Exchange and who does it apply to?
TISAX - Trusted Information Security Assessment Exchange is a compliance framework from International (Automotive) with 10 domains and 28 controls. TISAX (Trusted Information Security Assessment Exchange) is an information security assessment and exchange mechanism for the European automotive industry. Managed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Based on VDA Information Security Assessment (ISA) catalogue, which builds on ISO/IEC 27001 with automotive-specific requirements. Covers information security, prototype protection, and data protection. Assessment results shared via the TISAX portal between participants. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does TISAX - Trusted Information Security Assessment Exchange actually require?
TISAX - Trusted Information Security Assessment Exchange has 28 controls organised across 10 domains. The largest domains are Technical and Operational Security (10 controls), Assessment Scope, Levels and Exchange (4 controls), Information Security Management (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of TISAX - Trusted Information Security Assessment Exchange do I already cover?
TISAX - Trusted Information Security Assessment Exchange maps to 179 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (39% coverage), NIST SP 800-53 Rev 5 (36% coverage), South Korea ISMS-P (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement TISAX - Trusted Information Security Assessment Exchange?
Start your TISAX - Trusted Information Security Assessment Exchange compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about TISAX - Trusted Information Security Assessment Exchange requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required