Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTTalk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Automotive supply chain

Your customer asked for TISAX. Now comes the part nobody explains.

The clause arrived, and with it a new vocabulary: scope, assessment objective, VDA ISA, audit provider. DM11 turns that request into a plan with owners and deadlines, and takes your company to the assessment with the outcome already predictable.

Take the self-assessmentTalk to a specialist

DM11 prepares your company for the assessment. The assessment itself, and the labels, come from an audit provider contracted by the ENX Association. That separation is a requirement of the scheme itself.

Who runs the preparation

  • 17 years in GRC and information security
  • ISO 27001 Lead Auditor
  • Data protection and privacy specialists
  • Experience with bank and Big Four audits

Where it starts

The requirement is contractual, and the clock belongs to your customer

TISAX is not law and not regulation. It is a requirement the OEM or Tier 1 writes into the contract, with a deadline they set. That is why the first conversation is not about information security: it is about understanding exactly what was asked, because the ask determines the size of everything that follows.

Who governs the scheme

The ENX Association governs TISAX and contracts the audit providers. The criteria catalogue, VDA ISA, is published by the German automotive industry association. ENX members include Audi, BMW, Bosch, Ford, Magna, Mercedes-Benz, Renault, Valeo and Volkswagen.

Why they ask you

When your company receives engineering drawings, data on a part still in development or personal data from a customer, their risk now lives on your network. TISAX is how the supply chain verifies that once, instead of every OEM auditing every supplier.

What changes day to day

You publish the result once and release it to the partners you choose. The cycle of answering a different security questionnaire for every customer ends, each with its own spreadsheet and its own deadline. The X in the name is exactly that: exchange.

Without the labels

  • An open contract clause with the clock running
  • Excluded from new sourcing before you even get to compete on price
  • A different security questionnaire for every customer, all year
  • Engineering information circulating with no written rule on who accesses what
  • Investment decisions made under pressure, when the deadline closes in

With the labels

  • A result valid for three years, with no annual surveillance audit
  • Controlled sharing: you decide who sees your result
  • One process answering every customer that requires TISAX
  • Access, classification and disposal rules that survive people leaving
  • Predictability, because remediation became a project instead of an emergency

What it actually is

TISAX is not a certification, and that difference has practical consequences

The official participant handbook answers the question directly: there is no certificate to hang on your wall. TISAX is an assessment and exchange mechanism. You are assessed against the VDA ISA catalogue, you receive labels, and you share them on the ENX platform with whoever you authorise. Anyone who treats it as a certification usually gets the rest wrong too.

Assessment, not certification

The result is labels published on the ENX platform, not a certificate. A supplier promising to “certify your company in TISAX” is describing something the scheme does not have.

VDA ISA, the catalogue

The assessment uses the VDA ISA catalogue, covering information security, prototype protection and data protection. Each control is scored for maturity from 0 to 5, not simply pass or fail.

The version that applies to you

The version in force when you order the assessment is the one that applies. VDA ISA 6.0.3 governs assessments ordered until 31/12/2026. From 01/01/2027, VDA ISA2027 applies, published in July 2026, strengthening supply chain security requirements and restructuring prototype protection.

Three years, no annual surveillance

Labels are valid for three years from the closing meeting of the initial assessment. Unlike ISO 27001, there is no annual surveillance audit during that period. Renewal repeats the process, and the official recommendation is to start a year before expiry.

Scope is per location

The assessment covers locations, not the legal entity. Three plants may mean three locations in the same scope, and every location in a scope must carry the same assessment objectives. Getting this wrong at registration costs you later: extending scope afterwards is not a simple adjustment.

Failing is not the end

If the result is minor non-conformity you receive temporary labels while you work through the corrective action plan. There is no permanent failure, and nobody has to see the result of an earlier attempt. What does exist is a deadline: corrective actions are capped at nine months.

Translation

What your customer asked for, and what it means in practice

Within TISAX what you order is the assessment objective, and the objective determines the level. If your customer's request does not name the objective, that is the first question to put to them, before any budgeting.

What they ask forWhat it meansWhat it demands of you
“We need you to have TISAX”Incomplete request. The assessment objective is missing.Go back to your customer and get the objective in writing. Without it any budget is guesswork and the registration may be wrong.
ConfidentialHigh protection need, in the confidentiality dimension. Level AL 2.A self-assessment that stands up on its own, plausibility check and interview, usually by web conference.
Strictly confidentialVery high protection need. Level AL 3.An assessor on your site, thorough examination of evidence, planned and unplanned interviews, observation of your processes.
High availabilityHigh protection need in the availability dimension. Level AL 2.Business continuity with evidence of testing, not just a written plan.
Proto parts, Proto vehiclesProtection of prototype parts, components or vehicles. Level AL 3.Segregated areas, physical access control with logging, camera and phone rules, specific media handling.
Test vehicles, Proto eventsTest vehicles and prototypes at events or shootings. Level AL 2.Handling, transport and coverage rules, with accountability defined per event.
DataData protection, derived from GDPR Article 28 on processors. Level AL 2.Processing records, impact assessment, transfer rules and handling of data subject requests. Directly connected to what privacy law already requires of you.
Special dataSpecial categories of personal data. Level AL 3.Everything above, with on-site verification and reinforced controls.

The Info high and Info very high objectives stopped being selectable in April 2024. If your customer's request still uses those names, confirm with them: it usually means Confidential or Strictly confidential, and the difference changes the assessment level.

Levels

AL 1, AL 2 and AL 3

The level is not your choice. It follows from the assessment objective your customer requires.

AL 1Self-assessment

Internal use

The assessor only confirms that a self-assessment exists, without examining its content. The part that surprises people: AL 1 produces no TISAX label. It serves internal purposes or a specific partner, outside the exchange mechanism.

AL 2Remote

Most suppliers

A plausibility check of your self-assessment, supported by evidence review and an interview with whoever owns information security, usually by web conference. Internal effort here is high: your self-assessment has to stand on its own, with evidence behind every score.

AL 3On site

Prototypes and very high protection

The assessor comes to your locations. They examine documents and evidence, run planned interviews with process owners and unplanned ones with the people who execute, observe local conditions and watch the processes actually run. This is the level where the gap between the written process and the practised process shows.

If you already have ISO 27001

How far you have already come, and what exactly is missing

Having ISO 27001 helps considerably and does not exempt you from the TISAX assessment. The VDA ISA catalogue is aligned with the standard's good practice and carries cross references, so much of your documentation is reusable. What usually catches people out is not what already exists: it is what ISO does not ask for, and the scope logic, which works the other way around.

Usually reusable

  • Security policy and governance structure
  • Asset inventory and classification
  • Risk management and incident handling
  • Human resources security and awareness
  • Identity and access management
  • Cryptography and operations security
  • Security requirements in supplier contracts

What is usually missing

  • Prototype protection: an entire chapter ISO does not have, covering physical access control, segregated area rules and handling of vehicles and parts
  • Data protection in the GDPR Article 28 model, including processing records and impact assessment
  • Maturity scoring from 0 to 5 per control, instead of ISO's conforms or does not conform
  • Inverted scope logic: in TISAX the assessment scope is predefined and must be contained within your management system scope, not identical to it
  • Registering scope and locations on the ENX platform before approaching any assessor
  • Evidence at the depth a plausibility check demands, which tends to run deeper than ISO's annual surveillance audit

Self-assessment

Where your company stands today

Fourteen questions across the domains the VDA ISA catalogue covers. The full result appears on screen, with a score per domain and an honest read on the distance to an assessment. We do not ask for your email to show it.

Policy and organisationQuestion 1 of 14

Is there an information security policy approved by management and reviewed periodically?

Approved by management, with a review date. An old document with no owner usually counts as absent.

How we run it

From the contract clause to published labels

Every phase ends with a deliverable, not a status report. You know what you get before you start.

  1. 01

    Understand the request

    Before any technical diagnosis, we translate what your customer required into assessment objective, level and locations. This decision drives the size of everything that follows, and it is the one most often rushed.

    You get

    • Assessment objective and level confirmed
    • Locations in scope defined
    • Formal questions to send your customer
  2. 02

    Gap analysis against VDA ISA

    We assess your current position control by control, in the catalogue version that will govern your assessment, using the maturity scoring the assessor will use. The output shows the real distance, not an impression.

    You get

    • Self-assessment completed with a score per control
    • Gap report prioritised by risk and effort
    • Effort sizing per workstream
  3. 03

    Remediation plan

    We turn the gaps into a plan with owners, deadlines and an execution order. Sequence matters: some controls depend on others, and running them out of order creates rework.

    You get

    • Plan with owners and schedule
    • Workstream sequencing
    • Clear split between internal work and third parties
  4. 04

    Guided implementation

    We run execution alongside your team: policies, processes, physical and logical access control, supplier management and the documentation that supports each score. Your team learns to operate what was built.

    You get

    • Approved policies and procedures
    • Evidence organised by control
    • Training for the areas involved
  5. 05

    Dry run before the assessment

    We simulate the assessment with the assessor's rigour, including interviews with process owners and with the people who execute. This is where the gap between the written process and the practised one appears, while there is still time to fix it.

    You get

    • Readiness report
    • Findings list, corrected before the real assessment
    • Preparation for the people who will be interviewed
  6. 06

    Support through to the labels

    We support you during the assessment run by the audit provider and, if there are non-conformities, in building and executing the corrective action plan within the scheme's deadline.

    You get

    • Support during the assessment
    • Corrective action plan where applicable
    • Guidance on sharing via the platform

Stories

Four situations we have already solved

We anonymise our clients with the same confidentiality that will protect your company later. The names change, and the pattern of the problems repeats. Named references, where the client authorises them, we present in conversation.

Technical rubber products

The company that had never heard the acronym

Situation
The German automaker was polite and firm: without the labels, the supplier was out of the next global platform. The deadline was one qualification cycle. In a company used to being measured on dimensional tolerance and durability, nobody knew what TISAX was, and the first instinct was to look for whoever could issue the certificate fastest.
What we did
We started by correcting the premise: there is no certificate, and the customer's request had to be translated into an assessment objective. Then came the gap analysis against VDA ISA, a prioritised remediation plan and implementation alongside the team, including how customer drawings and material specifications are handled.
Outcome
Labels obtained within the qualification window. The contract held and extended to a second product line. What most surprised the board was discovering, along the way, how many customer drawings were sitting in open folders and personal email.
Engine components

It had ISO 27001 and assumed it was covered

Situation
The company had held ISO 27001 for four years and received the customer's request confident that presenting the certificate would be enough. It was not. The difference was not in what already existed, but in what the standard does not ask for.
What we did
We mapped, control by control, what the management system already covered and what was missing. The work concentrated on the real gaps: prototype protection, the data protection module, and the scope logic, which in TISAX is predefined and has to fit inside the management system scope rather than mirror it.
Outcome
Remediation took a fraction of the effort of starting from zero, because the foundation was reusable. The board began treating both requirements as one programme, instead of two projects competing for the same people.
Automotive components, three plants

The scope that was nearly registered wrong

Situation
With three sites in the country, the company was about to register all of them in the same scope because it looked simpler. Only one of them received customer design work; the others produced catalogue items to their own drawings. The request they received did not say which assessment objective applied.
What we did
We stopped the registration and drafted, together with the company, the questions their customer still had to answer. With that in hand, we designed the scope around the information flowing through each plant, rather than around the org chart or the revenue split.
Outcome
The scope came out proportionate to what the customer actually required. The assessment covered the right sites, and the others followed later at their own pace, with no third-party deadline pressing.
Fluid transfer lines

When the assessor walks onto the shop floor

Situation
The assessment objective involved prototype parts for a platform not yet launched, which means an on-site assessment and scrutiny of what actually happens on the floor. The documentation was immaculate. Practice, less so: the sample room and the development tooling sat behind a badge almost everyone held.
What we did
We treated the physical with the same weight as the documentary: real segregation of the area, access control with logging, camera and phone rules, and controlled disposal of samples and scrap, which had been leaving the plant with no control at all. Then we simulated the assessment with interviews, including the people who run the process rather than those who wrote it.
Outcome
The dry run found what the assessment would find, with time to fix it. In the real assessment the gap between the written process and the practised one had closed, which is precisely what this level verifies.

A question you should be asking

Why DM11 does not assess, and why that protects you

The participant handbook is explicit: an audit provider may only conduct your assessment if they have had no previous consulting assignments with you. Whoever prepares you is barred from assessing you. This is not bureaucratic detail. It is what makes the result credible to the OEM that will rely on it.

  • Buying preparation from an audit provider burns that assessor for your assessment. You are left with the others, and the choice of assessor stops being yours.
  • ENX itself advises against buying a pre-assessment or gap analysis from an audit provider: you end up paying for two full assessments instead of an initial one and a short follow-up.
  • DM11 is not an audit provider and has no stake in the assessment result beyond yours. We prepare you, and you choose freely among the assessors contracted by ENX.
  • Be wary of anyone promising to certify your company in TISAX. Certificates do not exist in the scheme, and whoever assesses cannot have prepared you.

Frequently asked

What people ask before deciding

Answers anchored in the official participant handbook. Where no official figure exists, we say so.

No. The official participant handbook answers this directly: there is no certificate to be issued. TISAX is an assessment and exchange mechanism. You are assessed against the VDA ISA catalogue, you receive labels, and you share them on the ENX platform with the partners you authorise. A supplier promising a certificate is describing something the scheme does not have.

More questions? See DM11's full FAQ

Start by understanding the real size of the problem

A thirty minute conversation is usually enough to turn your customer's requirement into scope, level and an order of magnitude for effort. No obligation.

Talk to a specialistTake the self-assessment