Practical TISAX readiness for automotive suppliers and service providers, built on ISO 27001 foundations. Streamline prepares your information security management system to meet the VDA ISA requirements, working directly with an experienced information security auditor.

What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry’s information security assessment and exchange mechanism, administered by the ENX Association on behalf of the German automotive association (VDA). It is based on the VDA ISA catalogue, which is derived from ISO/IEC 27001 and 27002 and adapted for the automotive sector. Automotive manufacturers commonly require their suppliers to hold a valid TISAX assessment before sharing sensitive data.
TISAX assessment levels and labels
- AL1: self-assessment only
- AL2: self-assessment plus a plausibility check (usually remote) by an approved audit provider
- AL3: self-assessment plus an on-site assessment, for the most sensitive data
Assessments are mapped to labels such as Information (confidentiality and availability), Prototype Protection and Data Protection, and each audit objective is scored on a maturity scale where level 3 (“established”) is generally the target.
How Streamline helps
We provide TISAX readiness: implementing or aligning an ISO 27001-based information security management system to the VDA ISA catalogue, running a gap assessment against your required assessment level and labels, and preparing you for the formal assessment. The TISAX assessment itself is conducted by an ENX-approved audit provider. We get you ready to pass it the first time.
The TISAX assessment process
TISAX is not a one-off audit but a structured process, and most of the effort is in preparation. The typical path is:
- Register with the ENX Association and define your assessment scope, level and labels.
- Complete the VDA ISA self-assessment against the current catalogue, scoring each objective on the maturity scale.
- Implement and document controls to reach maturity level 3 (“established”) for the relevant objectives.
- Undergo the assessment by an ENX-approved audit provider: a remote plausibility check for AL2, an on-site assessment for AL3.
- Share your TISAX label with your automotive customers through the ENX exchange.
Streamline focuses on the preparation: getting your ISMS and evidence to the point where the assessment is a formality.
How TISAX builds on ISO 27001
Because the VDA ISA catalogue is derived from ISO/IEC 27001 and 27002, an ISO 27001 system gives you most of what TISAX requires. We map your existing ISO 27001 controls to the VDA ISA objectives, identify the automotive-specific additions (such as prototype protection or data protection labels), and close the gaps. If you don’t yet have ISO 27001, we can build a single system that serves both.
Who needs TISAX?
Any organisation that handles sensitive information on behalf of an automotive manufacturer or tier-one supplier, including engineering, design, manufacturing, IT, logistics and professional services providers. If a vehicle manufacturer has asked you for a TISAX label, Streamline can get you ready to achieve it. We support suppliers across Australia, remotely and on site.
Frequently asked questions
Is TISAX the same as ISO 27001?
They are closely related. The VDA ISA catalogue behind TISAX is based on ISO/IEC 27001 and 27002, adapted for the automotive industry. If you already have ISO 27001, you have a strong foundation. We map and extend it to meet the VDA ISA requirements.
What TISAX assessment level do I need?
It depends on the sensitivity of the data your customer shares with you. Your automotive customer specifies the required assessment level and labels. We help you confirm the scope and prepare for the right level.
Speak with an experienced ISO auditor
Need TISAX to keep supplying an automotive customer? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990











