Automotive assurance

Prepare information security for automotive exchange.

TISAX enables automotive organizations to assess information security against the VDA ISA catalogue and share results through the ENX process. We help build the management practices and evidence needed before an approved audit provider performs the assessment.

Our implementation focus

Make the requirements operational.

  1. 01

    Confirm the customer-requested assessment objectives

  2. 02

    Set locations, services, and information in scope

  3. 03

    Complete an ISA-based self-assessment

  4. 04

    Improve information security and relevant prototype or data protection practices

  5. 05

    Prepare evidence and corrective actions for the approved provider

Independent assessment

Normstone is an implementation advisor, not an ENX-approved TISAX audit provider. The provider performs the assessment and ENX governs result sharing.

Questions we hear

Get the distinctions right.

Is TISAX the same as ISO/IEC 27001 certification?

No. TISAX uses the VDA ISA and an ENX-governed assessment and result-sharing process; ISO/IEC 27001 is a separate ISMS standard and certification path.

Who decides which TISAX objectives apply?

The organization should confirm the requested objective with its automotive partner and use ENX guidance to scope the assessment.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation