OnwynStandards › TISAX (VDA ISA 6.0)

Scheme / framework · VDA ISA 6.0

TISAX (VDA ISA 6.0)

TISAX is the automotive industry's information security assessment scheme, governed by the ENX Association and based on the VDA ISA catalogue. OEMs and tier-1 suppliers require a TISAX label before sharing sensitive data with partners — if you supply the German automotive industry, it is effectively a market-access requirement. Assessments come in levels (AL2 remote plausibility check, AL3 on-site for high protection needs) and modules: information security for everyone, plus prototype protection and data protection where relevant. The catalogue uses a maturity model — you are scored on how well processes are established, not just whether a control exists.

26
Requirements
10
Areas
21
Recommended documents
1
Mapped frameworks
Start TISAX free Have us do it instead

What this standard asks for

Every requirement in TISAX (VDA ISA 6.0), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

IS policies, organization & risk

5 requirements

  • 1.1.1Information security policies
  • 1.2.1Information security organization and responsibilities
  • 1.3.1Asset identification and classification
  • 1.4.1Information security risk management
  • 1.5.1Assessments, effectiveness checks and continual improvement

Human resources

2 requirements

  • 2.1.1Personnel qualification and security awareness
  • 2.1.2Employment obligations and offboarding

Physical security

2 requirements

  • 3.1.1Security zones and physical access control
  • 3.1.2Protection of information and equipment in and outside premises

Identity & access management

3 requirements

  • 4.1.1Identity management and user accounts
  • 4.1.2Secure authentication
  • 4.2.1Access rights management and regular review

IT security & operations

6 requirements

  • 5.1.1Cryptography and key management
  • 5.2.1Protection against malware and vulnerabilities
  • 5.2.2Event logging and detection
  • 5.2.3Network security and segmentation
  • 5.2.4Backup and recovery
  • 5.3.1Change and development security

Supplier relationships

1 requirement

  • 6.1.1Supplier and subcontractor security

Incidents & continuity

2 requirements

  • 1.6.1Security incident and crisis management
  • 1.6.2Business continuity for critical services

Compliance

1 requirement

  • 7.1.1Legal, regulatory and contractual compliance

Prototype protection (module)

2 requirements

  • 8.1Prototype protection — physical and environmental security
  • 8.2Prototype protection — organizational and handling requirements

Data protection (module)

2 requirements

  • 9.1Data protection module — processing on behalf of customers
  • 9.2Data protection module — technical and organizational measures

The documents you will end up with

The recommended document set for TISAX (VDA ISA 6.0) — 21 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Information Security Policy

The top-level security commitment and the topic policies underneath it, approved by management and known to staff.

Information Security Organization and Responsibilities

Who owns security, who they report to, and how security gets a say in projects and decisions.

Asset Inventory and Classification Scheme

What information and equipment you hold, who owns each, how sensitive it is, and how it must then be handled.

Information Security Risk Management Procedure

How security risks are identified, scored, treated and reviewed, and who accepts a risk you decide to live with.

Assessment and Improvement Plan

How you check your own controls actually work, on what cycle, and how findings get closed.

Awareness and Qualification Plan

What security training each role gets, how often, and how you evidence it — including the prototype and data-protection specifics where they apply.

HR Security Procedure

The security obligations in employment contracts, and what happens on joining, moving and leaving.

Physical Security and Zone Concept

Your security zones, who may enter each, and how information and equipment are protected inside and outside the site.

Identity and Access Management Policy

How accounts are issued, how people prove who they are, and how access rights are granted, reviewed and removed.

Cryptography and Key Management Policy

Where encryption is required, which algorithms are acceptable, and how keys are created, stored and retired.

Malware and Vulnerability Management Standard

What protects your machines from malicious software, how vulnerabilities are found, and how fast they must be patched.

Logging and Detection Standard

What events are recorded, how long logs are kept, and who notices when something looks wrong.

Network Security and Segmentation Policy

How the network is divided up and defended, and what is allowed to talk to what.

Backup and Recovery Policy

What is backed up, how often, where copies live, and how restores are proven to work.

Change and Development Security Policy

How changes reach production safely, and how security is built into anything you develop yourself.

Supplier and Subcontractor Security Policy

How you check a supplier's security before you engage them, what goes into the contract, and how subcontractors are controlled.

Security Incident and Crisis Management Procedure

How incidents are reported, triaged and escalated, when a crisis team is convened, and who tells the customer.

Business Continuity Plan

What has to keep running for your customers, how quickly it must be back, and the tested plans that deliver it.

Legal and Contractual Compliance Register

The laws, regulations and customer contract clauses that bind your security, and who checks you still meet them.

Prototype Protection Concept

How pre-series vehicles, parts and their data are physically protected, who may see them, and the rules for events, transport and photography.

Data Protection Agreement and Technical Measures Description

Where you handle personal data for a customer: the processing agreement and the description of the technical and organisational measures behind it.

Work that counts twice

TISAX (VDA ISA 6.0) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start TISAX today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.