What are the requirements for certification on TISAX®?
TISAX® is based on a comprehensive catalogue of security controls. These requirements define how organizations manage information security, data protection, and specific automotive risks.
Overview of requirements for the assessment on TISAX® (VDA ISA)
The VDA ISA (Information Security Assessment) catalog defines the requirements behind every assessment on TISAX®. It sets out what your organization must implement and how auditors evaluate your security level.
The catalog is structured into domains and control objectives. Each domain focuses on a specific area of information security and combines:
- Organizational measures such as roles, policies, and governance
- Technical controls such as access restrictions, system security, and monitoring
Auditors look at how these controls are applied in practice. You need to demonstrate that responsibilities and processes are clearly defined, controls are implemented, and documentation is complete and auditable.
The requirements are grouped into domains such as:
- Information security organization and governance
- Human resources security and awareness
- Identity and access management
- IT operations security and system protection
- Supplier and third-party management
- Incident management and business continuity
Each domain defines clear objectives but allows flexibility in implementation. This ensures that controls fit your company's setup while meeting automotive expectations.
Key security areas covered
TISAX® assessments focus on three core protection areas. These reflect the main risks in the automotive industry and extend beyond standard security frameworks.
Information security
This area evaluates your overall security management approach. It focuses on how you identify, manage, and monitor risks.
Typical requirements include:
The objective is to ensure consistent and controlled security across your organization.
Data protection
Data protection covers how you handle personal data in daily operations. It aligns closely with regulatory expectations.
Auditors assess whether you:
- Process personal data based on clear rules
- Apply principles such as data minimization
- Protect data during storage and transfer
- Manage data subject requests
The focus lies on secure and transparent data handling.
Prototype protection
Prototype protection is specific to the automotive sector. It addresses risks related to sensitive development assets.
Typical requirements include:
- Securing facilities and test environments
- Restricting access to prototypes
- Preventing unauthorized recordings or leaks
- Protecting related data and documentation
This ensures that confidential development work remains protected throughout its lifecycle.
How strict are the requirements for the assessment on TISAX®?
The level of strictness depends on the selected assessment level and the expectations of your customers.
OEMs often define minimum requirements that suppliers must fulfill. As a result, companies need to align their security posture with both the VDA ISA catalog and specific contractual expectations.