TISAX Compliance: What Suppliers Get Wrong the First Time
TISAX (Trusted Information Security Assessment Exchange) shows up in a lot of automotive and manufacturing supply chains as a customer requirement rather than a voluntary initiative: a Tier 1 or OEM customer requires it, and suddenly a supplier that's never heard of the VDA ISA catalogue has a deadline. That origin story shapes a lot of what goes wrong.
It is not just "ISO 27001 for cars"
TISAX shares a lot of DNA with ISO 27001 (both are built around a risk-based ISMS), but the VDA Information Security Assessment catalogue that underpins TISAX goes deeper into specifics that ISO 27001 leaves abstract: prototype protection, data handling for connected vehicle information, and, depending on assessment level, physical security requirements that a generic ISMS document set won't cover out of the box.
Organizations that repurpose an existing ISO 27001 ISMS without mapping it against the actual VDA ISA questions consistently get surprised by gaps in the assessment. The frameworks rhyme; they don't match one-to-one.
The assessment level decision matters more than people expect
TISAX has multiple assessment levels (based on the protection needs of the information being handled), and the level isn't something a supplier gets to freely choose. It's driven by what your customer requires, which is itself driven by the sensitivity of what you're handling for them. Committing to the wrong scope early, usually underestimating it to save assessment cost, is one of the most common causes of a failed or delayed assessment, because gaps discovered mid-assessment take far longer to remediate under time pressure than they would have as part of planned scoping work.
Where first-time assessments actually lose points
- Prototype and confidential information handling. Physical controls around prototype vehicles or parts, and information barriers around unreleased product data, get underestimated by suppliers whose main business isn't handling this kind of material day to day.
- Scope boundary confusion. TISAX assessments are scoped to specific locations and business units. Suppliers that assume "we got assessed once, we're covered everywhere" run into trouble when a new customer requires assessment of a facility or scope that wasn't previously covered.
- Evidence that exists but isn't organized for the assessor. Much like ISO 27001 audits, the controls often genuinely exist, but if evidence is scattered across systems with no clear mapping to the VDA ISA catalogue, the assessment takes far longer and surfaces more (avoidable) findings than it should.
Making it sustainable, not a one-time scramble
The suppliers who handle TISAX well treat it the same way they'd treat any recurring customer compliance requirement: map controls to the catalogue once, keep evidence continuously current rather than reconstructing it before each exchange, and revisit the assessment level whenever the nature of customer data being handled changes. Treating it as a periodic fire drill instead of an ongoing discipline is the single biggest predictor of a rough assessment cycle, and it's entirely avoidable with the same governance habits that make any compliance program durable.