What Is TISAX?
TISAX® (Trusted Information Security Assessment Exchange) is the automotive industry framework for assessing information security.
Many vehicle manufacturers and Tier 1 suppliers require organisations to demonstrate appropriate security controls before sensitive information, engineering data or prototype information can be shared.
TISAX provides a recognised approach for evaluating information security using the VDA ISA catalogue and allows assessment results to be shared through the ENX platform.

Customer Requirements
Many OEMs and Tier 1 suppliers require TISAX as part of supplier onboarding and contract requirements.

Information Security
Demonstrate appropriate controls for protecting confidential information, engineering data and customer information.

Trusted Assurance
Provide recognised assurance through a standardised assessment and result-sharing process.
Who Needs TISAX?
TISAX is commonly required for organisations operating within the automotive supply chain.

Automotive Suppliers
Component manufacturers and production suppliers working with OEMs and Tier 1 organisations.

Engineering & Design
Businesses handling CAD files, research data, technical drawings and development information.

Software & Technology Providers
IT, cloud, SaaS and technology providers supporting automotive customers.
Our TISAX Consultancy Services
We provide practical consultancy services to help organisations prepare for successful TISAX assessments.

TISAX Gap Analysis
We review your current controls against VDA ISA requirements and identify areas requiring improvement.

Scope Definition
Define locations, systems, suppliers, processes and information assets that fall within scope.

ENX Registration Support
Guidance through registration, participant setup and assessment preparation.

Documentation Development
Policies, procedures, evidence registers, risk assessments and supporting documentation.

Internal Assessment
Independent reviews to verify readiness before engagement with an audit provider.

Corrective Action Support
Practical assistance implementing improvements and closing identified gaps.
Guidance on Selecting the Right TISAX Accredited Audit Provider
Receive independent guidance on selecting a suitable audit provider. Understand the TISAX Trusted Information Security Assessment Exchange. Avoid common assessment delays.
Trusted by Leading Brands
Trusted by original equipment manufacturers and suppliers across the automotive sector for reliable and consistent assessment outcomes.
Understanding Assessment Levels
Assessment levels are determined by customer requirements and information sensitivity.

AL1 – Self-assessment only
Suitable primarily for internal benchmarking and readiness activities.

AL2 – Independent remote assessment
The most common assessment level for automotive suppliers handling confidential information.

AL3 – Independent on-site assessment
Typically required for prototype protection and highly sensitive information environments.
Begin Your TISAX Journey
Discover exactly how ParkinsonHowe can benefit your business. Request a conversation with our expert team. See how the road to a TISAX label can be simple and how we work for you and your company.
Our TISAX Delivery Process

Step 1 – Readiness Review
Understand customer requirements, business activities and current maturity.

Step 2 – Gap Analysis
Assess existing controls against VDA ISA requirements.

Step 3 – Improvement Programme
Develop documentation, strengthen controls and address gaps.

Step 4 – Evidence Preparation
Compile assessment-ready evidence and supporting records.

Step 5 – Mock Assessment
Test readiness through interviews and evidence reviews.

Step 6 – Assessment Support
Support your team before and during the assessment process.

Step 7 – Finding Resolution
Assist with corrective actions and assessment follow-up activities.

Step 8 – Result Sharing
Support ENX result-sharing activities and future improvements.
Note: Only ENX-approved audit providers can issue TISAX assessments and labels. Audit providers who conduct assessments are not allowed to offer consultancy services.
Why Choose ParkinsonHowe?

Automotive Experience
Extensive experience supporting organisations across automotive supply chains.

Security Expertise
Specialists in ISO 27001, business continuity and automotive information security.

Practical Approach
Clear recommendations focused on simplifying assessment preparation.

Independent Support
Objective guidance focused on helping your organisation achieve readiness.
Frequently Asked Questions

Can ParkinsonHowe issue a TISAX label?
No. Only ENX-approved audit providers can conduct TISAX assessments and issue TISAX labels. We provide consultancy, readiness reviews and implementation support.

How long does TISAX take?
Most organisations complete readiness activities within two to six months depending on scope, existing controls and assessment objectives.

Do I need AL2 or AL3?
This depends on customer requirements, information sensitivity and assessment objectives.

















