Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

For automotive suppliers

Your customer asked for TISAX. Now comes the part nobody explains.

That clause landed in your contract, and with it a pile of new words: scope, assessment objective, VDA ISA, audit provider. DM11 turns the request into plain language and a plan with owners and deadlines, then walks your company to the assessment with the outcome already predictable.

Take the self-assessmentTalk to a specialist

DM11 prepares your company for the assessment. The assessment itself, and the labels, come from an accredited auditor (an audit provider) contracted by the ENX Association, the body that runs TISAX. That separation is not our choice: it is a rule of TISAX itself.

Who runs the preparation

  • 17 years in information security and in governance, risk and compliance (GRC)
  • ISO 27001 Lead Auditor
  • Data protection and privacy specialists
  • Experience with bank audits and with the Big Four (the four largest audit firms)

Where it starts

The requirement is contractual, and the clock belongs to your customer

TISAX is not a law and not a government regulation. It is a requirement the carmaker (the OEM) or one of its major suppliers (a Tier 1) writes into the contract, with a deadline that customer sets. That is why the first conversation is not about information security: it is about understanding exactly what was asked, because the ask sets the size of everything that follows.

Who runs TISAX

TISAX is run by the ENX Association, an industry body, which also contracts the accredited auditors (the audit providers). The list of criteria, called VDA ISA, is published by the German automotive industry association. ENX members include Audi, BMW, Bosch, Ford, Magna, Mercedes-Benz, Renault, Valeo and Volkswagen.

Why they ask you

When your company receives engineering drawings, data on a part still in development or personal data from a customer, that customer's risk now lives on your network. TISAX is how the supply chain checks this once, instead of every carmaker auditing every supplier separately.

What changes day to day

You publish the result once and release it to the partners you choose. That routine of answering a different security questionnaire for every customer ends, each with its own spreadsheet and its own deadline. The X in the name comes from exactly that: exchange.

Without the labels

  • An open contract clause with the clock running
  • Excluded from new sourcing before you even get to compete on price
  • A different security questionnaire for every customer, all year
  • Engineering information circulating with no written rule on who accesses what
  • Investment decisions made under pressure, when the deadline closes in

With the labels

  • A result valid for three years, with no annual surveillance audit
  • Controlled sharing: you decide who sees your result
  • One process answering every customer that requires TISAX
  • Access, classification and disposal rules that keep working even when people leave
  • Predictability, because remediation became a project instead of an emergency

What it actually is

TISAX is not a certification, and that difference has practical consequences

The official participant handbook answers straight: there is no certificate to hang on your wall. TISAX is a way to assess your security and then exchange that result with whoever you choose. An auditor reviews your company against the VDA ISA catalogue, you receive labels, and you share them on the ENX platform only with whoever you authorise. Anyone who treats it as a certification usually gets the rest wrong too.

Assessment, not certification

The result is labels published on the ENX platform, not a certificate. A supplier promising to “certify your company in TISAX” is promising something that does not exist.

VDA ISA, the catalogue

The assessment uses the VDA ISA catalogue, a list of items covering information security, prototype protection and data protection. Each item gets a maturity score from 0 to 5, instead of a simple pass or fail.

The version that applies to you

Whatever version is in force when you order the assessment is the one that applies. VDA ISA 6.0.3 governs assessments ordered until 31/12/2026. From 01/01/2027, VDA ISA2027 applies. Published in July 2026, it strengthens supply chain security requirements and reorganises prototype protection.

Three years, no annual surveillance

Labels are valid for three years, counted from the closing meeting of the first assessment. Unlike ISO 27001, there is no yearly audit in that period. To renew, you repeat the process, and the official advice is to start a year before expiry.

Scope is per location

The assessment covers addresses (your locations), not the company as a legal entity. Three plants can mean three locations in the same scope, and every location in a scope must carry the same assessment objectives. Getting this size wrong at registration costs you later: widening the scope afterwards is not a simple adjustment.

Failing is not the end

If the result is a minor non-conformity (a small problem), you receive temporary labels while you work through the corrective action plan. There is no permanent failure, and nobody has to see the result of an earlier attempt. What does exist is a deadline: corrective actions are capped at nine months.

Translation

What your customer asked for, and what it means in practice

In TISAX, what you order is the assessment objective (what needs protecting), and the objective sets the assessment level. If your customer's request does not name the objective, that is the first question to put to them, before any budgeting.

What they ask forWhat it meansWhat it demands of you
“We need you to have TISAX”Incomplete request. The assessment objective is missing.Go back to your customer and get the objective in writing. Without it any budget is guesswork and the registration may be wrong.
ConfidentialInformation that needs strong protection for secrecy. Assessment level AL 2 (the middle level, done remotely).A self-assessment that stands up on its own, a check that it makes sense, and an interview, usually by web conference.
Strictly confidentialInformation that needs very high protection. Level AL 3 (the top level, with an assessor at your site).An assessor on your site, thorough examination of evidence, planned and unplanned interviews, observation of your processes.
High availabilitySystems that must stay up and running (high availability). Level AL 2.Business continuity with evidence of testing, not just a written plan.
Proto parts, Proto vehiclesProtection of prototype parts, components or vehicles (models not yet launched). Level AL 3.Separated areas, physical access control with logging, camera and phone rules, and specific handling of media (USB drives, hard disks and the like).
Test vehicles, Proto eventsTest vehicles and prototypes at events or shootings. Level AL 2.Rules for handling, transport and covering the vehicles, with a named owner for each event.
DataProtection of personal data, based on GDPR Article 28 (the EU data protection law) on processors. Level AL 2.Processing records, impact assessment, transfer rules and handling of data subject requests. Directly connected to what privacy law already requires of you.
Special dataSensitive personal data (special categories, such as health or biometrics). Level AL 3.Everything above, with on-site verification and reinforced controls.

The Info high and Info very high objectives stopped being selectable in April 2024. If your customer's request still uses those names, confirm with them: it usually means Confidential or Strictly confidential, and the difference changes the assessment level.

Levels

AL 1, AL 2 and AL 3

AL stands for Assessment Level. It is not your choice: it follows from the assessment objective your customer requires.

AL 1Self-assessment

Internal use

The assessor only confirms that a self-assessment exists, without examining its content. The part that surprises people: AL 1 produces no TISAX label. It serves internal purposes or a specific partner, outside the exchange mechanism.

AL 2Remote

Most suppliers

The assessor checks that your self-assessment makes sense, reviews the evidence and interviews whoever owns information security, usually by web conference. The internal effort here is high: your self-assessment has to stand on its own, with proof behind every score.

AL 3On site

Prototypes and very high protection

The assessor comes to your locations. They examine documents and evidence, run planned interviews with process owners and surprise interviews with the people who do the work, observe local conditions and watch the processes actually run. This is the level where the gap between the written process and the real one shows.

If you already have ISO 27001

How far you have already come, and what exactly is missing

Having ISO 27001 helps a lot, but it does not exempt you from the TISAX assessment. The VDA ISA catalogue follows the good practice of that standard and shows where the two line up, so much of your documentation can be reused. What usually trips people up is not what already exists: it is what ISO does not ask for, and the way scope is defined, which works the other way around.

Usually reusable

  • Security policy and governance structure
  • Inventory and classification of assets (equipment, systems and data)
  • Risk management and incident handling
  • People-related (HR) security and staff awareness
  • Identity and access management
  • Cryptography and operations security
  • Security requirements in supplier contracts

What is usually missing

  • Prototype protection: an entire chapter ISO does not have, covering physical access control, separated-area rules and the handling of vehicles and parts
  • Data protection in the GDPR Article 28 model, including processing records and impact assessment
  • Maturity scoring from 0 to 5 for each item, instead of ISO's conforms or does not conform
  • The way scope works is inverted: in TISAX the assessment scope is set in advance and must fit inside your management system scope, rather than be identical to it
  • Registering scope and locations on the ENX platform before approaching any assessor
  • Evidence at the depth the TISAX check demands, which tends to run deeper than ISO's yearly audit

Self-assessment

Where your company stands today

Fourteen questions across the topics the VDA ISA catalogue covers. The full result appears on screen, with a score for each topic and an honest read on how far you are from an assessment. We do not ask for your email to show it.

Policy and organisationQuestion 1 of 14

Is there an information security policy approved by management and reviewed periodically?

Approved by management, with a review date. An old document with no owner usually counts as absent.

How we run it

From the contract clause to published labels

Every phase ends with a deliverable, not a status report. You know what you get before you start.

  1. 01

    Understand the request

    Before any technical diagnosis, we translate what your customer required into assessment objective, level and locations. This decision drives the size of everything that follows, and it is the one most often rushed.

    You get

    • Assessment objective and level confirmed
    • Locations in scope defined
    • Formal questions to send your customer
  2. 02

    Gap analysis against VDA ISA

    We assess your current position control by control, in the catalogue version that will govern your assessment, using the maturity scoring the assessor will use. The output shows the real distance, not an impression.

    You get

    • Self-assessment completed with a score per control
    • Gap report prioritised by risk and effort
    • Effort sizing per workstream
  3. 03

    Remediation plan

    We turn the gaps into a plan with owners, deadlines and an execution order. Sequence matters: some controls depend on others, and running them out of order creates rework.

    You get

    • Plan with owners and schedule
    • Workstream sequencing
    • Clear split between internal work and third parties
  4. 04

    Guided implementation

    We run execution alongside your team: policies, processes, physical and logical access control, supplier management and the documentation that supports each score. Your team learns to operate what was built.

    You get

    • Approved policies and procedures
    • Evidence organised by control
    • Training for the areas involved
  5. 05

    Dry run before the assessment

    We simulate the assessment with the assessor's rigour, including interviews with process owners and with the people who execute. This is where the gap between the written process and the practised one appears, while there is still time to fix it.

    You get

    • Readiness report
    • Findings list, corrected before the real assessment
    • Preparation for the people who will be interviewed
  6. 06

    Support through to the labels

    We support you during the assessment run by the audit provider and, if there are non-conformities, in building and executing the corrective action plan within the scheme's deadline.

    You get

    • Support during the assessment
    • Corrective action plan where applicable
    • Guidance on sharing via the platform

Stories

Four situations we have already solved

We change our clients' names with the same confidentiality that will protect your company later. The names change, but the pattern of the problems repeats. When the client agrees, we share named references in a conversation.

Technical rubber products

The company that had never heard the acronym

Situation
The German carmaker was polite but firm: without the labels, the supplier was out of the next global car platform. The deadline was one qualification cycle. In a company used to being measured on part dimensions and durability, nobody knew what TISAX was, and the first instinct was to find whoever could issue the certificate fastest.
What we did
We started by clearing up the myth: there is no certificate. The customer's request had to be translated into an assessment objective, that is, exactly what needs protecting. Then came the gap analysis using the VDA ISA catalogue, a remediation plan in order of priority, and implementation alongside the team, including how customer drawings and material specifications are handled.
Outcome
Labels obtained within the qualification window. The contract held and even grew to a second product line. What most surprised the board was discovering, along the way, how many customer drawings were sitting in open folders and personal email.
Engine components

It had ISO 27001 and assumed it was covered

Situation
The company had held ISO 27001 (an international information-security standard) for four years and took the customer's request confident that showing the certificate would be enough. It was not. The difference was not in what it already had, but in what the standard does not ask for.
What we did
We checked, item by item, what the management system already covered and what was missing. The work focused on the real gaps: prototype protection, the data protection block, and the way scope is defined, which in TISAX is set in advance and has to fit inside the management system scope rather than mirror it.
Outcome
Remediation took far less effort than starting from zero, because the foundation already worked. The board began treating both requirements as one programme, instead of two projects competing for the same people.
Automotive components, three plants

The scope that was nearly registered wrong

Situation
With three plants in the country, the company was about to register all of them in the same scope because it looked simpler. Only one of them received customer design work; the others made catalogue items to their own drawings. And the request they received did not say which assessment objective applied.
What we did
We stopped the registration and wrote, together with the company, the questions their customer still had to answer. With those answers in hand, we built the scope around the information flowing through each plant, not around the org chart or the revenue split.
Outcome
The scope came out the right size, matching what the customer actually required. The assessment covered the right plants, and the others followed later at their own pace, with no outside deadline pressing.
Fluid transfer lines

When the assessor walks onto the shop floor

Situation
The assessment objective involved prototype parts for a car not yet launched, which means an on-site assessment and a close look at what actually happens on the floor. The paperwork was immaculate. Practice, less so: the sample room and the development tooling sat behind a badge almost everyone held.
What we did
We gave the physical side the same weight as the paperwork: real separation of the area, access control that logs who comes in, camera and phone rules, and controlled disposal of samples and scrap, which had been leaving the plant with no control at all. Then we simulated the assessment with interviews, including the people who run the process day to day, not just those who wrote it.
Outcome
The dry run found what the assessment would find, with time to fix it. In the real assessment the gap between the written process and what people actually do had closed, which is precisely what this level checks.

A question you should be asking

Why DM11 does not assess, and why that protects you

The participant handbook is explicit: an audit provider may only run your assessment if they have not done consulting work for you before. Whoever prepares you is barred from assessing you. This is not red tape: it is what makes the result credible to the OEM that will rely on it.

  • Buying preparation from an audit provider burns that assessor for your assessment. You are left with the others, and the choice of assessor stops being yours.
  • ENX itself advises against buying a pre-assessment or gap analysis from an audit provider: you end up paying for two full assessments instead of an initial one and a short follow-up.
  • DM11 is not an audit provider and has no stake in the assessment result beyond yours. We prepare you, and you choose freely among the assessors contracted by ENX.
  • Be wary of anyone promising to certify your company in TISAX. Certificates do not exist in the scheme, and whoever assesses cannot have prepared you.

Frequently asked

What people ask before deciding

Answers anchored in the official participant handbook. Where no official figure exists, we say so.

No. The official participant handbook answers this directly: there is no certificate to be issued. TISAX is an assessment and exchange mechanism. You are assessed against the VDA ISA catalogue, you receive labels, and you share them on the ENX platform with the partners you authorise. A supplier promising a certificate is describing something the scheme does not have.

More questions? See DM11's full FAQ

Start by understanding the real size of the problem

A thirty minute conversation is usually enough to turn your customer's requirement into scope, level and an order of magnitude for effort. No obligation.

Talk to a specialistTake the self-assessment