Advantage Through Knowledge and Experience
VDA ISA · AUTOMOTIVE INFORMATION SECURITY

Professional support for the implementation of TISAX for automotive suppliers

CONSUVATION prepares your company systematically for the VDA ISA requirements catalogue – from gap analysis through implementing measures to assessment readiness for information security, prototype protection and data protection.

Note: TISAX is a registered trademark of the ENX Association. CONSUVATION GmbH has no business relationship with the ENX Association and does not issue assessment results or labels itself. We exclusively offer independent consulting services for the implementation of TISAX; the actual assessment is carried out by an audit provider accredited by the ENX Association.

Prototype protection since 2006
VDA ISA aligned
ISO 27001 synergies
Independent consulting
DACH and international

What it's about

What the implementation of TISAX means for your company

The VDA ISA requirements catalogue forms the technical basis for an industry-wide assessment and exchange mechanism in the automotive sector. OEMs and Tier-1 suppliers increasingly require their partners to demonstrate a defined level of security – the implementation of TISAX is therefore no longer an optional project for many suppliers, but a business requirement.

01

Gap Analysis

We assess your current status against the full VDA ISA requirements catalogue and identify concrete areas for action.

VDA ISAMaturity Level

02

Implementing Measures

Together with your team, we implement the required organisational and technical measures in a practical way.

ISMSDocumentation

03

Assessment Readiness

We support you through to registration and prepare your company in terms of content for the assessment carried out by an accredited audit provider.

AssessmentLabel

Assessment Areas

The three protection needs in the VDA ISA catalogue

Which assessment areas are relevant for your company depends on your customer's requirements and the type of data processed. We assess your actual protection needs together with you.

Information Security

Protection of confidential information, development data and trade secrets against unauthorised access, loss or manipulation. The specific scope of requirements depends on your customer's specifications.

Needs-based

Prototype Protection

Additional requirements for companies working with physical or digital prototypes, components or camouflaged test vehicles.

Needs-based

Data Protection

Relevant when personal data is processed on behalf of the customer – supplemented by requirements from the GDPR. On request, we build your data protection management system on the basis of ISO 27701 and ISO 27100.

Needs-based

Our Approach

How we guide you to assessment readiness

A structured, six-step consulting process from the initial assessment to a successful audit.

1

Kick-off & Protection Needs Assessment

Clarifying which assessment areas and which assessment target level are relevant for your company.

approx. 1–2 weeks
2

Gap Analysis Against VDA ISA

Systematic comparison of your existing measures against the full requirements catalogue.

approx. 2–4 weeks
3

Measures & Implementation Plan

Prioritised roadmap including responsibilities, effort estimation and timeline.

approx. 1–2 weeks
4

Supported Implementation

Support with documentation, technical measures and staff training.

approx. 6–16 weeks
5

Internal Pre-Audits

Simulated assessment situation to identify remaining gaps before the official assessment.

approx. 2 weeks
6

Registration & Assessment Support

Support with registration as well as expert guidance during the assessment by the accredited audit provider.

approx. 2–4 weeks

Synergies

How the implementation of TISAX interacts with other standards

Companies that have already invested in other management systems benefit when implementing TISAX – CONSUVATION shows you the concrete synergies.

Prototype Protection Since 2006 → Implementation of TISAX

CONSUVATION has been supporting the protection of physical and digital prototypes in the automotive industry since 2006 – well before today's VDA ISA requirements catalogue was introduced. These early precursor concepts have created a practice-tested understanding of the prototype protection assessment area, which flows directly into our consulting for the implementation of TISAX today.

Since 2006Prototype ProtectionExperience

ISO 27001 → Implementation of TISAX

The VDA ISA requirements catalogue is structurally aligned with ISO 27001 Annex A. Companies with a certified ISMS often achieve the implementation of TISAX with significantly reduced additional effort.

ISMSAnnex ASynergy

Implementation of TISAX → IEC 62443 (OT)

Current requirements catalogues are increasingly extending their scope to production and OT environments. For manufacturing companies, IEC 62443 complements the organisational requirements with technical OT depth.

OT SecurityProduction

Implementation of TISAX → GDPR

If the data protection assessment area is relevant, requirements from the GDPR flow directly into the assessment – particularly regarding data processing agreements and technical-organisational measures.

GDPRData Protection

Implementation of TISAX → NIS2

For suppliers who also fall under NIS2, information security measures from the implementation of TISAX can largely be transferred to the NIS2 requirements.

NIS2Compliance

Added Value

Why the implementation of TISAX pays off

CriterionWithout Implementation
Eligibility for ContractsLikely exclusion from OEM tenders
Trust with PartnersSelf-declared assurances without external confirmation
ResponsivenessSecurity gaps often only identified after an incident
Competitive PositionDisadvantage against already-assessed competitors
CriterionWith Implementation
Eligibility for ContractsMeets common OEM requirements
Trust with PartnersExternally confirmed level of security
ResponsivenessEstablished risk-detection processes
Competitive PositionDifferentiation in the tender process

Our Solutions

E-learning portal for training on the implementation of TISAX

To ensure that the requirements of the VDA ISA catalogue are not just documented but also lived in practice by your staff, CONSUVATION offers its own e-learning portal with training modules covering the three core assessment areas.

ISMS Training

Covers the fundamentals of the information security management system, roles and responsibilities, and secure behaviour in everyday work.

ISMSAwareness

Data Protection Training

Practical modules on handling personal data, aligned with GDPR, ISO 27701 and ISO 27100.

GDPRISO 27701

Prototype Protection Training

Trains secure handling of physical and digital prototypes – building on our practical experience since 2006.

Prototype ProtectionSince 2006

Our Packages

Three packages for the implementation of TISAX

Tailored to company size and protection needs – based on the structure of proven consulting packages for automotive compliance.

STARTER

For small companies with up to 50 employees

  • Protection needs assessment
  • Gap analysis against VDA ISA
  • Measures plan incl. prioritisation
  • Documentation templates
  • E-learning access (ISMS module)
  • Remote consulting
Get in touch

ENTERPRISE

For corporations and suppliers with 250+ employees

  • All PROFESSIONAL services
  • Multi-site coordination
  • Integration with existing ISMS
  • Supplier management support
  • E-learning portal for all staff
  • Dedicated project team
  • Long-term support
Get in touch

Why CONSUVATION

Experience that secures your implementation of TISAX

Our consultants combine practical experience from ISO 27001 projects with specific industry knowledge of the automotive sector. Through our proprietary correlation matrix, we identify synergies between standards that remain hidden to other consulting approaches.

Experience Since 2006

CONSUVATION has been protecting prototypes and sensitive development data in the automotive industry since 2006 – long before today's VDA ISA requirements catalogue existed. These early precursor concepts for prototype protection still form the practical foundation of our consulting for the implementation of TISAX today.

The CONSUVATION Correlation Matrix

Our correlation matrix maps requirements from VDA ISA, ISO 27001, NIS2, IEC 62443 and the GDPR simultaneously. This allows us to identify, already during the gap analysis, which measures satisfy multiple standards at once – saving time and budget in your implementation of TISAX.

Long-Standing Consultants with Broad Standards Know-How

Our consulting team has many years of experience and is familiar with all major standards in information security and management systems – including Business Continuity Management according to ISO 22301. This broad foundation flows directly into your implementation of TISAX, for example when assessing emergency and recovery requirements.

VDA ISA Expertise

In-depth knowledge of the current requirements catalogue

ISO 27001 Synergy

Efficient dual use of existing ISMS structures

Independence

No business relationship with audit providers

DACH and International

Consulting for Germany, Austria, Switzerland and international clients

BCM According to ISO 22301

Emergency and recovery know-how complementing information security

Frequently Asked Questions

FAQ on the implementation of TISAX

What does the implementation of TISAX specifically mean for our company?

The implementation of TISAX refers to the structured preparation of your company for an assessment mechanism for information security in the automotive industry, based on the VDA ISA requirements catalogue. Depending on protection needs, the areas of information security, prototype protection and data protection are assessed.

Who needs an implementation of TISAX?

Automotive suppliers, development service providers, engineering firms, IT and cloud providers, and logistics service providers working with OEMs or Tier-1 suppliers are increasingly required to undergo an implementation of TISAX.

How long does an implementation of TISAX take?

Depending on maturity level and company size, an implementation of TISAX typically takes between three and nine months, from gap analysis through implementing measures to assessment readiness.

What role does ISO 27001 play in the implementation of TISAX?

The VDA ISA requirements catalogue is structurally aligned with ISO 27001 Annex A. Companies with an existing ISMS based on ISO 27001 can achieve the implementation of TISAX with significantly less additional effort.

Does CONSUVATION issue the assessment result itself?

No. CONSUVATION is an independent consulting firm and has no business relationship with the ENX Association. We exclusively support the content-related and organisational preparation; the actual assessment is carried out by an accredited audit provider.

What is the difference between information security, prototype protection and data protection?

Which assessment area is relevant for your company depends on your customer's requirements: information security is requested when confidential information or development data is involved, prototype protection when physical or digital prototypes are processed, and data protection when personal data of customers is processed – the specific combination depends on your customer's protection needs.

Does CONSUVATION also offer training for the implementation of TISAX?

Yes. Through our e-learning portal, we offer training modules on the three core assessment areas of ISMS, data protection and prototype protection, so that requirements are not just documented but also lived by your staff in everyday work.

Can CONSUVATION also build data protection on a standards basis?

Yes. On request, we build your data protection management system on the basis of ISO 27701 and ISO 27100, so that it integrates seamlessly into your implementation of TISAX.

Ready for the implementation of TISAX?

Schedule a free initial consultation and receive an initial assessment of effort and approach for your company.

Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com