Skip to content

Pillar guide

TISAX readiness: turning requirements into something you can demonstrate

Readiness is not the same as documentation. This guide describes how we structure preparation for an automotive information security assessment — scope, gap assessment, risk treatment, implementation, evidence, internal verification and improvement — and is deliberately explicit about which parts are official requirements, which are common practice, and which are our own recommendations.

Last updated 18 August 2026 · ISAREADY Editorial Team

What readiness actually means

Most organisations that struggle in an assessment are not careless. They have policies. They have people who take security seriously. What they lack is the connective tissue: a defined scope, an assigned owner for each expectation, a process that runs whether or not anyone remembers to run it, and a record that shows it ran.

We describe readiness as the distance between three things: requirements (what is expected), processes (how the expectation is met in daily operation), and evidence (the record proving it was met). A policy closes the first gap only. It says nothing about the second and nothing at all about the third.

ISAREADY recommendation This three-part framing is ours. It is not a framework requirement — it is how we have found it useful to organise preparation work so that effort lands where the actual gap is.

Getting the terminology right

Precision here is not pedantry. It affects what you write in customer correspondence and tender responses.

  • TISAX assessment — the assessment performed by a TISAX audit provider approved by ENX Association.
  • TISAX label — the result that can be shared with participants through the exchange mechanism.
  • TISAX audit provider — the organisation approved by ENX Association to perform the assessment. ENX approves audit providers and monitors the quality of their work. Not us.
  • ISA — the Information Security Assessment catalogue published by the VDA and used in TISAX assessments.
  • ISO/IEC 27001 — a standard specifying requirements for an information security management system. Organisations may choose to be certified against it by an independent certification body. This one genuinely is a certification; ISO itself does not certify anyone.

Official framework information The framework relationships above are publicly documented by ENX Association and the VDA. Verify current details in their own documentation before relying on them contractually.

The readiness loop

Preparation goes wrong in a predictable shape: a document sprint, a quiet period, and then a scramble. The alternative is a loop that keeps running.

  1. 1

    Assess

    Establish scope and an honest baseline. What is actually in place, not what the documents claim.

  2. 2

    Identify Gaps

    Convert the baseline into findings with an owner, a priority and a target date.

  3. 3

    Implement

    Do the work: processes, controls and the decisions that make them stick in daily operation.

  4. 4

    Collect Evidence

    Produce the record as the activity happens. Decided in advance, not reconstructed later.

  5. 5

    Verify

    Check yourself against your own rules through internal audit before anyone else does.

  6. 6

    Improve

    Close findings at root cause and feed the outcome back into risk, controls and awareness.

The loop matters more than any individual artefact, because it is what survives a change of personnel. A binder of policies written by someone who has since left is not readiness; a cycle that produces reviewed policies, dated records and closed findings is.

Start with scope and ownership

Two decisions determine how much of the rest is wasted effort.

Scope. Which sites, legal entities, systems and information types are covered? An undefined scope makes gap assessment unbounded and evidence collection infinite. Write it down, have it approved, and revisit it when the business changes.

Ownership. Who is accountable, with what authority, and with what resources? “IT handles it” is not an assignment. A named role with a written remit, and a management decision that allocated time or budget to it, is.

Industry good practice Defining scope and assigning responsibility before starting improvement work is standard management-system practice, not a framework-specific rule.

Risk management that produces decisions

A risk register that nobody acts on is an expensive spreadsheet. The parts that make it real are unglamorous: a documented method so two people reach comparable results, an owner per risk, a treatment action with a target date, and residual risk formally accepted by someone with the authority to accept it.

The most common failure we see is the third one. Risks get identified and treated, but nobody ever formally accepts what remains — so when someone asks “who decided this level of risk was acceptable?”, there is no answer.

Revisit risks on a cycle and after significant change. A register last touched eighteen months ago tells an assessor something you would rather it did not.

Evidence: decide the record before the activity

This is the theme that determines how the final month of preparation feels. Teams that decided in advance what record demonstrates each activity spend that month reviewing. Teams that did not spend it reconstructing.

For each key activity, answer three questions before the activity happens: what record demonstrates it, who produces that record, and where it lives. Then apply a blunt test: pick a control and try to produce representative, current evidence for it, efficiently and traceably. If you cannot, the gap is not in the control.

ISAREADY recommendation We use “a twelve-month span, retrieved within one working day” as the deliberately demanding version of that test. It is an ISAREADY benchmark for finding weak spots, not an official retention period or response-time requirement — no framework we know of specifies either. Use whatever period is representative for how often the activity runs.

The evidence management guide goes through this in detail, including what “dated, attributable and retained” means in practice.

Suppliers and third parties

Information rarely stays inside your perimeter. Identify which suppliers and service providers access, process or store in-scope information — including cloud services and subcontractors reached through another supplier, which is where the register usually turns out to be incomplete.

Agree security requirements in writing before information is shared, assess suppliers proportionately to their criticality, and — the step most often skipped — follow findings through to closure. A completed questionnaire filed away is not supplier security. A follow-up log showing what was raised and when it was closed is.

Verify yourself before anyone else does

Internal audit is the cheapest possible way to find out what an external party will find. It is also the most commonly treated as a formality.

Run it against a planned programme covering the scope over a defined period. Use someone with enough independence to be uncomfortable. And track findings to closure with root cause actually considered — a finding closed on assertion has been recorded, not resolved.

Management review closes the loop: structured input (risk status, incidents, audit results, objectives, supplier performance), recorded decisions, and actions that get followed up. A verbal update in a monthly meeting does not produce the record.

Keep it, do not rebuild it

The first cycle gets you ready. The subsequent cycles are what stop readiness from decaying into a document set that describes an organisation you used to be.

Practically: a fixed review cadence, corrective actions tracked with verified closure, a small set of indicators someone actually looks at, and evidence that keeps accumulating as a by-product of the work rather than as a project.

ISAREADY recommendation Our recommendation is to choose fewer indicators than feels comfortable. Four measures reviewed seriously beat twenty collected mechanically.

The mistakes we see most often

  • Documentation as the whole plan. Writing policies is visible progress; implementing them is not. The visible work finishes first and then stalls.
  • Undefined scope. Everything downstream becomes negotiable, and nobody can say when preparation is finished.
  • Risks without owners. A register where the owner column says “IT” is a register with no owners.
  • Supplier questionnaires with no follow-up. Sent, returned, filed, forgotten.
  • Evidence decided afterwards. The single most expensive mistake, and the most avoidable.
  • Internal audit as theatre. An audit that finds nothing is not good news.

Frequently asked questions

Is TISAX a certification?
Calling it a certification is imprecise. TISAX is an assessment and exchange mechanism operated by ENX Association: an audit provider approved by ENX Association performs an assessment, and the result can be shared with participants as a label rather than issued as a certificate in the ISO sense. ISO/IEC 27001, by contrast, is a certifiable management system standard. The distinction matters when you write about it in tender documents.
How long does preparation usually take?
It depends far more on your starting point than on the framework. An organisation with an operating management system and existing records may need a focused gap-closure period. One starting from scattered documentation and no assigned ownership should plan in quarters, not weeks — most of the elapsed time goes into evidence that has to accumulate over a period rather than be produced in an afternoon.
Does a toolkit guarantee a successful assessment?
No, and you should be sceptical of anyone who says otherwise. No toolkit — ours included — can guarantee a TISAX label, an ISO certification or any specific assessment result. What structured preparation changes is whether you can demonstrate what you do, which is the part within your control.
Where do I find the official requirements?
From the bodies that publish them. ENX Association publishes the TISAX participant documentation and the ISA catalogue; ISO publishes ISO/IEC 27001 and 27002. Always work from the current official source. Anything on this site is preparation guidance and does not substitute for it.
We already have ISO/IEC 27001. Are we ready?
You are considerably further along than most, because the management system disciplines transfer directly: scope, risk, internal audit, management review, corrective action. The work that typically remains is scope alignment, automotive-specific expectations such as prototype protection where applicable, and evidence organised the way an assessment needs to consume it.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.