TISAX is the European automotive industry's information security assessment, based on the VDA ISA catalog. Major OEMs require it through the supply chain, which reaches many Nordic manufacturers and their subcontractors: if you supply automotive, directly or through a tier above you, TISAX shows up in the contract.
Who it applies to
Suppliers to the European automotive industry at any tier: manufacturers, component suppliers, engineering firms, and service providers handling OEM data or prototypes.
What OptiTech provides
- The VDA ISA catalog as controls: information security, prototype protection, and data protection modules
- Assessment-level scoping: TISAX has assessment levels (AL1 to AL3) depending on protection needs. OptiTech scopes which level your customer relationships require.
- Cross-mapping from ISO 27001: VDA ISA builds on ISO 27001, so an existing program carries most of the weight
- The evidence trail: your TISAX assessor reviews the same timestamped evidence log as every other framework
OptiTech prepares you for the assessment; the assessment itself is performed by an accredited TISAX audit provider.
What non-compliance costs
Without a TISAX label, automotive customers can't share protected information with you, which in practice means losing the business to a supplier who has one.
Cross-mapping
TISAX builds directly on ISO 27001. Companies with an active ISO 27001 program typically add TISAX as an increment rather than a new project.
Get started
TISAX is available on every plan. Book a free gap analysis or compare plans.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.