SCRM Supplier Compliance & Risk Management

Explainer · how an assessment runs

TISAX from registration to label.

TISAX is not a certification but an assessment and exchange mechanism. Knowing the process avoids the most expensive surprise: an assessment commissioned with the wrong scope.

It rests on the VDA information security catalogue, largely aligned with ISO/IEC 27001 and extended by sector-specific objectives. Accredited assessment providers examine; the result is shared with customers through the ENX platform rather than published as a public certificate.

That construction has two consequences. First, there is no certificate to hang on the wall but labels you release to individual business partners. Second, you determine the scope yourself – and that is where most errors and costs arise.

The process in six steps

  1. RegistrationRegister with the ENX Association and create the company profile.This also fixes which sites are included. A forgotten site means an additional assessment later.
  2. Define the scopeWhich objectives and which assessment level are needed?What your customers require governs. Ask before commissioning – later extensions are expensive.
  3. Self-assessmentAssessment against the VDA catalogue, with maturity levels per requirement.The self-assessment is the basis of the assessment. Over-optimistic ratings are spotted and cost credibility.
  4. Engage a providerChoose from the accredited providers and schedule.Lead times of several months are normal. Needing a label for a customer deadline means commissioning early.
  5. AssessmentExamination of maturity, remotely or on site depending on the level.Evidence is examined, not descriptions. Unable to produce records means the requirement is not met.
  6. Actions and labelOn deviations, an action plan with deadlines, then the label is issued.Labels are valid for three years. Release to individual customers happens through the ENX platform.

Which assessment level

The level follows from the protection needs of the information you handle – and from what your customer requires.

LevelForm of examinationTypical trigger
AL 1Self-assessment without third-party examinationRarely accepted for exchange between business partners; uncommon in practice.
AL 2Plausibility check of the self-assessment, largely remoteThe normal case at ordinary protection needs, for providers without prototype access.
AL 3In-depth examination with an on-site visit and interviewsFor high protection needs, prototype protection or particularly sensitive data.

A level set too high costs unnecessarily; one set too low is not accepted by the customer and must be repeated. That question belongs before commissioning, not after.

The assessment objectives

Information security
The backbone, close in substance to ISO/IEC 27001. Running an ISMS covers most of it already.
Prototype protection
Its own requirements on access, transport, storage and photography bans. This is the part ISO 27001 does not cover and that can trigger structural measures.
Data protection
Assessed additionally where personal data is processed on instruction.

Preparation: what makes the difference

  • Get the customer requirement in writing: which level, which objectives, by when. Anything else is guessing.
  • Capture all sites, including warehouses, development offices and home workplaces where relevant.
  • Collect evidence, not descriptions: records, approvals, training confirmations, access lists with dates.
  • Have the provider register ready – subcontractors with access to design data will be asked about.
  • Fill the self-assessment honestly. A maturity level the assessor cannot confirm lengthens the process.
  • Commission early: assessment provider lead times are the most common reason for missed customer deadlines.

The part that takes longest in an assessment

Experience says assembling the evidence costs more time than the assessment itself. In SCRM, providers, access, commitments and deadlines already sit in order – including for the repeat in three years.

Request a consultation Go to TISAX How audits run