SCRM Supplier Compliance & Risk Management

Home

VDA ISA · ENX · objectives and assessment levels

No TISAX label, no bid. That is the position in automotive.

TISAX is not a standard but an assessment and exchange mechanism. Working for German manufacturers means going through it – and evidencing your own providers along the way.

It rests on the VDA information security catalogue, largely aligned with ISO/IEC 27001 and extended by sector-specific objectives: prototype protection, handling of particularly sensitive data, in part data protection. Accredited providers assess; results are shared with customers through the ENX platform.

The part that regularly trips suppliers up is not their own technology but the chain behind it. Passing development, production or IT operations onward means showing that the requirements apply there too – and that this is verified.

Who needs a label

  • Direct suppliers to German automotive manufacturers, wherever they are based.
  • Development and engineering providers with access to design data.
  • Firms producing or storing prototypes and pre-series parts.
  • IT and logistics providers of the above – through their evidence duties.

What concerns the chain

Providers
Anchor requirements for subcontractors contractually and verify compliance.
Prototype protection
Govern access, transport and storage at commissioned third parties too.
Access
Control external access to design and production data with documentation.
Incidents
Reporting routes that also capture events at a provider.
Validity
Labels expire; renewal wants planning, not discovery.

How SCRM covers it

Labels in view

Validity of your own label and your providers’ labels, with reminders.

Subcontractors

Who works on which data – the question the assessment asks.

Evidence store

Contracts, assurances and assessment results on the supplier, not in a project folder.

Customer demands

Which manufacturer requires which assessment level, with a deadline.

Frequently asked

Is ISO 27001 enough instead of TISAX?

Often not. TISAX includes objectives absent from ISO 27001, such as prototype protection. An existing ISMS is nevertheless the best preparation, because most requirements overlap.

We are a Swiss supplier. Does it apply?

Yes, as soon as a customer asks. TISAX is not law but a contractual market requirement – and those ignore borders.

Must our suppliers hold TISAX too?

Not necessarily. You must pass the requirements on and verify compliance. How deeply is a risk decision – one you must be able to justify.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required