Onwyn › Standards › TISAX (VDA ISA 6.0)
Scheme / framework · VDA ISA 6.0TISAX (VDA ISA 6.0)
TISAX is the automotive industry's information security assessment scheme, governed by the ENX Association and based on the VDA ISA catalogue. OEMs and tier-1 suppliers require a TISAX label before sharing sensitive data with partners — if you supply the German automotive industry, it is effectively a market-access requirement. Assessments come in levels (AL2 remote plausibility check, AL3 on-site for high protection needs) and modules: information security for everyone, plus prototype protection and data protection where relevant. The catalogue uses a maturity model — you are scored on how well processes are established, not just whether a control exists.
What this standard asks for
Every requirement in TISAX (VDA ISA 6.0), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
IS policies, organization & risk
5 requirements
- 1.1.1Information security policies
- 1.2.1Information security organization and responsibilities
- 1.3.1Asset identification and classification
- 1.4.1Information security risk management
- 1.5.1Assessments, effectiveness checks and continual improvement
Human resources
2 requirements
- 2.1.1Personnel qualification and security awareness
- 2.1.2Employment obligations and offboarding
Physical security
2 requirements
- 3.1.1Security zones and physical access control
- 3.1.2Protection of information and equipment in and outside premises
Identity & access management
3 requirements
- 4.1.1Identity management and user accounts
- 4.1.2Secure authentication
- 4.2.1Access rights management and regular review
IT security & operations
6 requirements
- 5.1.1Cryptography and key management
- 5.2.1Protection against malware and vulnerabilities
- 5.2.2Event logging and detection
- 5.2.3Network security and segmentation
- 5.2.4Backup and recovery
- 5.3.1Change and development security
Supplier relationships
1 requirement
- 6.1.1Supplier and subcontractor security
Incidents & continuity
2 requirements
- 1.6.1Security incident and crisis management
- 1.6.2Business continuity for critical services
Compliance
1 requirement
- 7.1.1Legal, regulatory and contractual compliance
Prototype protection (module)
2 requirements
- 8.1Prototype protection — physical and environmental security
- 8.2Prototype protection — organizational and handling requirements
Data protection (module)
2 requirements
- 9.1Data protection module — processing on behalf of customers
- 9.2Data protection module — technical and organizational measures
The documents you will end up with
The recommended document set for TISAX (VDA ISA 6.0) — 21 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The top-level security commitment and the topic policies underneath it, approved by management and known to staff.
Who owns security, who they report to, and how security gets a say in projects and decisions.
What information and equipment you hold, who owns each, how sensitive it is, and how it must then be handled.
How security risks are identified, scored, treated and reviewed, and who accepts a risk you decide to live with.
How you check your own controls actually work, on what cycle, and how findings get closed.
What security training each role gets, how often, and how you evidence it — including the prototype and data-protection specifics where they apply.
The security obligations in employment contracts, and what happens on joining, moving and leaving.
Your security zones, who may enter each, and how information and equipment are protected inside and outside the site.
How accounts are issued, how people prove who they are, and how access rights are granted, reviewed and removed.
Where encryption is required, which algorithms are acceptable, and how keys are created, stored and retired.
What protects your machines from malicious software, how vulnerabilities are found, and how fast they must be patched.
What events are recorded, how long logs are kept, and who notices when something looks wrong.
How the network is divided up and defended, and what is allowed to talk to what.
What is backed up, how often, where copies live, and how restores are proven to work.
How changes reach production safely, and how security is built into anything you develop yourself.
How you check a supplier's security before you engage them, what goes into the contract, and how subcontractors are controlled.
How incidents are reported, triaged and escalated, when a crisis team is convened, and who tells the customer.
What has to keep running for your customers, how quickly it must be back, and the tested plans that deliver it.
The laws, regulations and customer contract clauses that bind your security, and who checks you still meet them.
How pre-series vehicles, parts and their data are physically protected, who may see them, and the rules for events, transport and photography.
Where you handle personal data for a customer: the processing agreement and the description of the technical and organisational measures behind it.
Work that counts twice
TISAX (VDA ISA 6.0) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start TISAX today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.