Skip to content
Independent readiness resources for automotive information security teams

Turn security requirements into evidence-driven readiness.

Practical TISAX and ISO/IEC 27001 readiness tools for automotive suppliers and information security teams. Structured gap assessment, risk treatment, evidence management and internal verification — as one connected system rather than a folder of documents.

Around 10 minutes. No account needed to start, and your answers stay in your browser until you ask for the report.

Verifiedevidence trailRequirementsProcessesEvidence
  • TISAX readiness and ISA-aligned preparation
  • ISO/IEC 27001 alignment layer
  • Evidence-first methodology
  • Built for Tier 1–3 automotive suppliers
The gap most teams discover late

A policy alone does not demonstrate operational readiness.

Documentation matters — it is where expectations become explicit. But an assessor, a customer or your own internal auditor is looking for something else: proof that the expectation is actually met, by someone, on a date, in a way that can be traced. Readiness is the distance between those two things.
Defined

Requirements

What is expected of your organisation. Necessary, and the easiest part to obtain — a requirement list is not a programme.

Operating

Processes

How the requirement is actually met in daily operation: who does it, when, and what happens when it is not done.

Demonstrable

Evidence

The dated, attributable record that the process ran. Decided in advance, produced as you go, retrievable on request.

Organisations that prepare well do not simply write more documents. They build the structure that connects the three: processes that implement the requirement, and evidence produced as a by-product of the work rather than assembled retroactively in the four weeks before an assessment.

The ISAREADY method

Assess → Identify Gaps → Implement → Collect Evidence → Verify → Improve

A loop, not a checklist. The first pass gets you ready; the loop is what keeps you ready after the team changes.
  1. 1

    Assess

    Establish scope and an honest baseline. What is actually in place, not what the documents claim.

  2. 2

    Identify Gaps

    Convert the baseline into findings with an owner, a priority and a target date.

  3. 3

    Implement

    Do the work: processes, controls and the decisions that make them stick in daily operation.

  4. 4

    Collect Evidence

    Produce the record as the activity happens. Decided in advance, not reconstructed later.

  5. 5

    Verify

    Check yourself against your own rules through internal audit before anyone else does.

  6. 6

    Improve

    Close findings at root cause and feed the outcome back into risk, controls and awareness.

Free self-assessment

How ready is your organisation?

Around 30 original questions across governance, risk, access, suppliers, evidence, audit and management review. You get a readiness indicator per theme, your strongest areas, your priority gaps, and a specific list of what to do next.
This assessment provides an indicative ISAREADY readiness view. It is not an official TISAX assessment and does not predict or guarantee an assessment result.

What you receive

  • ISAREADY Readiness Indicator

    An overall percentage plus a band — Strong, Developing, Attention Required or Priority Action.

  • Category breakdown

    A score per theme, so effort goes where the gap actually is rather than where it feels productive.

  • Evidence readiness view

    A separate score for whether you could produce the records, which is usually the weakest part.

  • Prioritised next steps

    Concrete actions in sequence, and a downloadable PDF you can circulate internally.

The toolkit

A structured readiness system, not a folder of templates

Three tiers, depending on whether you need a defensible baseline, a working programme, or governance across several sites.

Starter

Prepare

$49one-time

The documentation foundation: policy set, readiness roadmap and the evidence guidance that tells you what to keep and why.

  • Core information security policy set
  • Quick start guide and readiness roadmap
  • Evidence guidance by requirement theme
  • Basic readiness assessment tools

Best for: Smaller suppliers starting preparation, or teams that need a defensible document baseline before anything else.

Most popular

Professional

Assess & Implement

$119one-time

Everything in Starter plus the working instruments of a readiness programme: structured gap assessment, risk treatment, supplier assessment, internal audit and management review.

  • Structured gap assessment workbook
  • Information security risk register and treatment plan
  • Supplier and third-party assessment set
  • Internal audit programme and management review pack
  • ISO/IEC 27001 alignment layer with Statement of Applicability
  • Prototype protection and data protection readiness
  • ISA 6 to ISA2027 transition support

Best for: Most preparation teams. The tier that moves an organisation from documents to demonstrable operation.

Enterprise

Govern & Scale

$249one-time

Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.

  • Multi-site governance model and scope mapping
  • CAPA tracker with ownership and verification
  • KPI / KRI dashboard structure
  • Third-party portfolio register
  • Training and competence matrix
  • Executive reporting pack

Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.

Resources

Practical guidance from readiness work

Written for people who have to do this, not for search engines.
All articles
ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

Read
ISO/IEC 270014 min read

TISAX vs ISO/IEC 27001: What Actually Transfers

The two are often discussed as alternatives. They are different kinds of thing. Here is what each one is, which work transfers between them, and where preparation still differs.

Read
TISAX Readiness5 min read

How to Prepare for a TISAX Assessment

A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.

Read
The ISAREADY approach

Built for practical assessment preparation

Structured around evidence, ownership and continual improvement — because those are the three things that hold up when someone external starts asking questions.

We separate official requirements from our own opinion

Every substantive statement in our guidance is labelled as official framework information, industry good practice, or an ISAREADY recommendation. You should always verify official requirements against the current source documentation.

We do not promise outcomes we cannot control

No toolkit, ours included, guarantees a TISAX label, an ISO certification or a specific assessment result. What preparation changes is whether you can demonstrate what you do — which is the part you control.

We publish what we would use ourselves

The structure in the toolkit is the structure we would apply to run a readiness programme: scope, gap assessment, risk treatment, implementation, evidence, internal audit, management review.

Questions about scope, tiers or an enterprise rollout? Talk to us.

Get started

Start your readiness journey

Begin with an indicative view of where you stand. Ten minutes, no account, and a report you can share with management.

Your answers stay in your browser until you request the report.