Pillar guide
TISAX readiness: turning requirements into something you can demonstrate
Readiness is not the same as documentation. This guide describes how we structure preparation for an automotive information security assessment — scope, gap assessment, risk treatment, implementation, evidence, internal verification and improvement — and is deliberately explicit about which parts are official requirements, which are common practice, and which are our own recommendations.
Last updated 18 August 2026 · ISAREADY Editorial Team
What readiness actually means
Most organisations that struggle in an assessment are not careless. They have policies. They have people who take security seriously. What they lack is the connective tissue: a defined scope, an assigned owner for each expectation, a process that runs whether or not anyone remembers to run it, and a record that shows it ran.
We describe readiness as the distance between three things: requirements (what is expected), processes (how the expectation is met in daily operation), and evidence (the record proving it was met). A policy closes the first gap only. It says nothing about the second and nothing at all about the third.
ISAREADY recommendation This three-part framing is ours. It is not a framework requirement — it is how we have found it useful to organise preparation work so that effort lands where the actual gap is.
Getting the terminology right
Precision here is not pedantry. It affects what you write in customer correspondence and tender responses.
- TISAX assessment — the assessment performed by a TISAX audit provider approved by ENX Association.
- TISAX label — the result that can be shared with participants through the exchange mechanism.
- TISAX audit provider — the organisation approved by ENX Association to perform the assessment. ENX approves audit providers and monitors the quality of their work. Not us.
- ISA — the Information Security Assessment catalogue published by the VDA and used in TISAX assessments.
- ISO/IEC 27001 — a standard specifying requirements for an information security management system. Organisations may choose to be certified against it by an independent certification body. This one genuinely is a certification; ISO itself does not certify anyone.
Official framework information The framework relationships above are publicly documented by ENX Association and the VDA. Verify current details in their own documentation before relying on them contractually.
The readiness loop
Preparation goes wrong in a predictable shape: a document sprint, a quiet period, and then a scramble. The alternative is a loop that keeps running.
- 1
Assess
Establish scope and an honest baseline. What is actually in place, not what the documents claim.
- 2
Identify Gaps
Convert the baseline into findings with an owner, a priority and a target date.
- 3
Implement
Do the work: processes, controls and the decisions that make them stick in daily operation.
- 4
Collect Evidence
Produce the record as the activity happens. Decided in advance, not reconstructed later.
- 5
Verify
Check yourself against your own rules through internal audit before anyone else does.
- 6
Improve
Close findings at root cause and feed the outcome back into risk, controls and awareness.
The loop matters more than any individual artefact, because it is what survives a change of personnel. A binder of policies written by someone who has since left is not readiness; a cycle that produces reviewed policies, dated records and closed findings is.
Start with scope and ownership
Two decisions determine how much of the rest is wasted effort.
Scope. Which sites, legal entities, systems and information types are covered? An undefined scope makes gap assessment unbounded and evidence collection infinite. Write it down, have it approved, and revisit it when the business changes.
Ownership. Who is accountable, with what authority, and with what resources? “IT handles it” is not an assignment. A named role with a written remit, and a management decision that allocated time or budget to it, is.
Industry good practice Defining scope and assigning responsibility before starting improvement work is standard management-system practice, not a framework-specific rule.
Risk management that produces decisions
A risk register that nobody acts on is an expensive spreadsheet. The parts that make it real are unglamorous: a documented method so two people reach comparable results, an owner per risk, a treatment action with a target date, and residual risk formally accepted by someone with the authority to accept it.
The most common failure we see is the third one. Risks get identified and treated, but nobody ever formally accepts what remains — so when someone asks “who decided this level of risk was acceptable?”, there is no answer.
Revisit risks on a cycle and after significant change. A register last touched eighteen months ago tells an assessor something you would rather it did not.
Evidence: decide the record before the activity
This is the theme that determines how the final month of preparation feels. Teams that decided in advance what record demonstrates each activity spend that month reviewing. Teams that did not spend it reconstructing.
For each key activity, answer three questions before the activity happens: what record demonstrates it, who produces that record, and where it lives. Then apply a blunt test: pick a control and try to produce representative, current evidence for it, efficiently and traceably. If you cannot, the gap is not in the control.
ISAREADY recommendation We use “a twelve-month span, retrieved within one working day” as the deliberately demanding version of that test. It is an ISAREADY benchmark for finding weak spots, not an official retention period or response-time requirement — no framework we know of specifies either. Use whatever period is representative for how often the activity runs.
The evidence management guide goes through this in detail, including what “dated, attributable and retained” means in practice.
Suppliers and third parties
Information rarely stays inside your perimeter. Identify which suppliers and service providers access, process or store in-scope information — including cloud services and subcontractors reached through another supplier, which is where the register usually turns out to be incomplete.
Agree security requirements in writing before information is shared, assess suppliers proportionately to their criticality, and — the step most often skipped — follow findings through to closure. A completed questionnaire filed away is not supplier security. A follow-up log showing what was raised and when it was closed is.
Verify yourself before anyone else does
Internal audit is the cheapest possible way to find out what an external party will find. It is also the most commonly treated as a formality.
Run it against a planned programme covering the scope over a defined period. Use someone with enough independence to be uncomfortable. And track findings to closure with root cause actually considered — a finding closed on assertion has been recorded, not resolved.
Management review closes the loop: structured input (risk status, incidents, audit results, objectives, supplier performance), recorded decisions, and actions that get followed up. A verbal update in a monthly meeting does not produce the record.
Keep it, do not rebuild it
The first cycle gets you ready. The subsequent cycles are what stop readiness from decaying into a document set that describes an organisation you used to be.
Practically: a fixed review cadence, corrective actions tracked with verified closure, a small set of indicators someone actually looks at, and evidence that keeps accumulating as a by-product of the work rather than as a project.
ISAREADY recommendation Our recommendation is to choose fewer indicators than feels comfortable. Four measures reviewed seriously beat twenty collected mechanically.
The mistakes we see most often
- Documentation as the whole plan. Writing policies is visible progress; implementing them is not. The visible work finishes first and then stalls.
- Undefined scope. Everything downstream becomes negotiable, and nobody can say when preparation is finished.
- Risks without owners. A register where the owner column says “IT” is a register with no owners.
- Supplier questionnaires with no follow-up. Sent, returned, filed, forgotten.
- Evidence decided afterwards. The single most expensive mistake, and the most avoidable.
- Internal audit as theatre. An audit that finds nothing is not good news.