TISAX consultancy
for automotive suppliers

Supporting automotive suppliers, manufacturers and service providers with TISAX readiness, VDA ISA implementation, ENX registration support and assessment preparation.

Whether you are preparing for an AL2 or AL3 assessment, we help you define scope, identify gaps, develop evidence and prepare for assessment with confidence.

What Is TISAX?

TISAX® (Trusted Information Security Assessment Exchange) is the automotive industry framework for assessing information security.

Many vehicle manufacturers and Tier 1 suppliers require organisations to demonstrate appropriate security controls before sensitive information, engineering data or prototype information can be shared.

TISAX provides a recognised approach for evaluating information security using the VDA ISA catalogue and allows assessment results to be shared through the ENX platform.

What is TISAX and Why It Matters

Many OEMs and Tier 1 suppliers require TISAX as part of supplier onboarding and contract requirements.

The Right Customer Requirements

Demonstrate appropriate controls for protecting confidential information, engineering data and customer information.

Delivering TISAX with Confidence

Provide recognised assurance through a standardised assessment and result-sharing process.

Who Needs TISAX?

TISAX is commonly required for organisations operating within the automotive supply chain.

TISAX Registration (ENX Platform)

Component manufacturers and production suppliers working with OEMs and Tier 1 organisations.

VDA ISA Audit Readiness

Businesses handling CAD files, research data, technical drawings and development information.

Exchange (ENX Portal)

IT, cloud, SaaS and technology providers supporting automotive customers.

Our TISAX Consultancy Services

We provide practical consultancy services to help organisations prepare for successful TISAX assessments.

TISAX Assessment Levels (AL1–AL3)

We review your current controls against VDA ISA requirements and identify areas requiring improvement.

Scope and Evidence Control

Define locations, systems, suppliers, processes and information assets that fall within scope.

Assessment Deliverables

Guidance through registration, participant setup and assessment preparation.

Pricing Drivers (Scope, AL Levels)

Policies, procedures, evidence registers, risk assessments and supporting documentation.

How Does TISAX Differ from ISO 27001?

Independent reviews to verify readiness before engagement with an audit provider.

Delivering TISAX with Confidence

Practical assistance implementing improvements and closing identified gaps.

Guidance on Selecting the Right TISAX Accredited Audit Provider

Receive independent guidance on selecting a suitable audit provider. Understand the TISAX Trusted Information Security Assessment Exchange. Avoid common assessment delays.

DNV — ISO 27001, ISO 22301, ISO 9001, TISAX
BSI — ISO 27001, ISO 22301, TISAX
SGS — ISO 27001, ISO 22301, TISAX
Bureau Veritas — ISO 27001, ISO 22301, TISAX
TUV - TISAX

Trusted by Leading Brands

Trusted by original equipment manufacturers and suppliers across the automotive sector for reliable and consistent assessment outcomes.

TISAX services for Gestamp Tallent - TISAX Consultancy
Samuelson Wylie Associates (SWA) - TISAX Consultancy
Optical 3D Ltd - TISAX Consultancy
NIDEC - TISAX Consultancy
Scoutbee - TISAX Consultancy
Keepit A/S - Tisax Consultancy
Ryobi Aluminium Casting UK Ltd - TISAX Consultancy

Understanding Assessment Levels

Assessment levels are determined by customer requirements and information sensitivity.

Automotive Supply Chain Expertise

Suitable primarily for internal benchmarking and readiness activities.

ISO 27001 Aligned Approach

The most common assessment level for automotive suppliers handling confidential information.

Audit Ready Deliverables

AL3 – Independent on-site assessment

Typically required for prototype protection and highly sensitive information environments.

Our TISAX Delivery Process

Scope & Objective Alignment

Understand customer requirements, business activities and current maturity.

ENX Registration & Support

Assess existing controls against VDA ISA requirements.

Assessment Delivery Outcomes

Step 3 – Improvement Programme

Develop documentation, strengthen controls and address gaps.

Do We Need AL3 or Is AL2 Sufficient?

Step 4 – Evidence Preparation

Compile assessment-ready evidence and supporting records.

How Long Does the TISAX Process Take?

Step 5 – Mock Assessment

Test readiness through interviews and evidence reviews.

How Does TISAX Differ from ISO 27001?

Step 6 – Assessment Support

Support your team before and during the assessment process.

Flexible Consultancy Options

Step 7 – Finding Resolution

Assist with corrective actions and assessment follow-up activities.

Delivering TISAX with Confidence

Step 8 – Result Sharing

Support ENX result-sharing activities and future improvements.

Note: Only ENX-approved audit providers can issue TISAX assessments and labels. Audit providers who conduct assessments are not allowed to offer consultancy services.

Why Choose ParkinsonHowe?

Scoping & Readiness

Automotive Experience

Extensive experience supporting organisations across automotive supply chains.

Remediation & Audit Preparation

Security Expertise

Specialists in ISO 27001, business continuity and automotive information security.

Assessment & Result Sharing

Practical Approach

Clear recommendations focused on simplifying assessment preparation.

Independent Support

Independent Support

Objective guidance focused on helping your organisation achieve readiness.

Frequently Asked Questions

Pricing Drivers (Scope, AL Levels)

Can ParkinsonHowe issue a TISAX label?

No. Only ENX-approved audit providers can conduct TISAX assessments and issue TISAX labels. We provide consultancy, readiness reviews and implementation support.

Fixed‑Fee Readiness Packages

How long does TISAX take?

Most organisations complete readiness activities within two to six months depending on scope, existing controls and assessment objectives.

Flexible Consultancy Options

Do I need AL2 or AL3?

This depends on customer requirements, information sensitivity and assessment objectives.

Case Studies

Samuelson Wylie Associates TISAX Case Study
Gestamp TISAX Case Study
NIDEC TISAX Case Study
Keepit TISAX Case Study