TISAX: the automotive industry’s security gate. Sentrix gets you through it.
Trusted Information Security Assessment Exchange is the mandatory security standard for suppliers to BMW, Volkswagen, Mercedes-Benz, and most major OEMs. Without a valid TISAX label, you cannot exchange sensitive information with automotive customers. Sentrix maps your existing ISO 27001 controls to TISAX requirements so you achieve your label without rebuilding your security program.
VDA ISA controls. ENX assessment. Label shared in the TISAX portal.
TISAX assessments are based on the VDA Information Security Assessment (ISA) questionnaire, which covers information security, prototype protection, and data protection. Assessments are conducted by ENX-accredited audit providers and results are shared through the ENX TISAX portal rather than published publicly.
- Assessment Level 1 (AL1): self-assessment for basic information security requirements
- Assessment Level 2 (AL2): assessment with spot checks by an ENX-accredited provider
- Assessment Level 3 (AL3): full assessment for high-protection needs (e.g. prototype data)
- VDA ISA covers information security (IS), prototype protection (PP), and data protection (DP)
TISAX · VDA ISA coverage (IS)
AL2 TARGETFrom VDA ISA self-assessment to ENX label—without rebuilding your program.
ISO 27001 to TISAX mapping
TISAX VDA ISA aligns substantially with ISO 27001. Sentrix maps your existing ISO 27001 evidence to TISAX requirements, showing the gap—typically less than 25% of controls are TISAX-specific.
VDA ISA questionnaire preparation
Pre-populated VDA ISA questionnaire based on your actual control implementation. Evidence links attached to each ISA question so your ENX assessor can verify directly without additional requests.
Prototype protection (PP)
TISAX prototype protection requirements for suppliers handling vehicle prototype data or images. Separate control set tracked alongside your standard IS controls with specific physical security evidence.
Assessment readiness tracking
Real-time TISAX readiness score against your selected assessment level (AL1, AL2, or AL3). Open findings prioritized by assessment impact with remediation owners assigned and tracked.
Label renewal management
TISAX labels are valid for three years. Sentrix tracks your label expiry, maintains continuous evidence for renewal assessments, and alerts you 6 months before expiry so renewal is not a scramble.
NIS2 crosswalk
Automotive suppliers operating in the EU may also fall under NIS2. Sentrix maps your TISAX/ISO 27001 controls to NIS2 Article 21 measures and shows exactly where additional work is needed.
See your TISAX readiness gap against VDA ISA.
We map your existing ISO 27001 controls to TISAX requirements live in the demo.