In the automotive industry, an unreleased vehicle design or proprietary autonomous driving algorithm represents billions of euros in competitive advantage. TISAX establishes a mutual recognition mechanism: suppliers undergo an accredited audit once, and the resulting TISAX label is accepted by automotive manufacturers globally.
1. The Three TISAX Assessment Levels (AL)
The required assessment level depends on the sensitivity of the data handled by the supplier:
Assessment Level 1 (AL 1)
Internal self-assessment for non-critical information. Primarily used for internal gap identification; rarely recognized by automotive OEMs for production contracts.
Assessment Level 2 (AL 2)
Pluasibility check conducted by an accredited independent audit provider (TÜV, DEKRA, DQS). Entails video interviews, technical evidence verification, and document audits. Required for 'High' protection needs.
Assessment Level 3 (AL 3)
Comprehensive on-site physical audit and deep technical verification. Mandatory for 'Very High' protection needs and any supplier handling physical pre-series prototypes or test vehicles.
2. VDA ISA 6.0: Key Evolutionary Changes
The release of VDA ISA version 6.0 restructured the assessment catalog to mirror modern manufacturing realities:
Key Updates in VDA ISA 6.0
- Modular Architecture: Clear separation between general Information Security, Prototype Protection, and Data Protection modules.
- Cloud & Multi-Tenant Scrutiny: Stricter validation of cloud encryption key custody, tenant isolation, and administrative access logging.
- Operational Technology (OT) & Production Networks: Explicit requirements governing the cybersecurity of industrial production machinery, SCADA systems, and plant floor networks.
3. Specialized Prototype Protection Requirements
Suppliers working with physical or digital automotive prototypes must satisfy dedicated controls:
Physical Separation & Access Control
Secure prototype design studios, window masking, continuous CCTV surveillance, and multi-factor biometric turnstiles.
Camouflage & Transport Security
GPS-monitored enclosed vehicle transport, anti-drone detection at test facilities, and strict photography embargoes.
Digital CAD/CAM Security
End-to-end encryption of 3D CAD models, digital rights management (DRM) preventing unauthorized export, and air-gapped simulation clusters.
4. Conclusion: Preparing for Audit Readiness
Achieving a TISAX label is often the decisive factor in winning lucrative OEM supply contracts. Organizations should maintain continuous compliance baselines, map ISO 27001 controls directly to VDA ISA requirements, and conduct regular internal mock audits to ensure seamless certification renewals.