> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# TISAX

> Achieve automotive industry information security certification through TISAX assessment.

TISAX (Trusted Information Security Assessment Exchange) is an information security assessment standard specifically designed for the automotive industry. Managed by the ENX Association, it enables automotive companies and their suppliers to share assessment results through a mutual recognition system.

## Who needs TISAX?

<CardGroup cols={2}>
  <Card title="Automotive suppliers" icon="car">
    Tier 1, 2, and 3 suppliers to major automotive manufacturers who require TISAX certification for supplier onboarding.
  </Card>

  <Card title="Service providers" icon="building">
    IT, engineering, and consulting firms working with automotive OEMs that handle sensitive technical data or prototypes.
  </Card>
</CardGroup>

## Assessment levels

| Level    | Description                                            |
| -------- | ------------------------------------------------------ |
| **AL 1** | Self-assessment (not commonly accepted)                |
| **AL 2** | Remote assessment by accredited auditor                |
| **AL 3** | On-site assessment by accredited auditor (most common) |

## Key assessment areas

* **Information security** — based on ISO 27001 with automotive-specific additions
* **Prototype protection** — physical and digital protection of pre-release vehicles and components
* **Data protection** — GDPR compliance for personal data handling

## How DSALTA helps

* **TISAX-specific controls** mapped to the VDA ISA catalog
* **ISO 27001 foundation** — TISAX builds on ISO 27001, so existing controls carry over
* **Evidence collection** automated through integrations
* **Cross-framework mapping** — significant overlap with ISO 27001 and GDPR

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How does TISAX relate to ISO 27001?" icon="diagram-project">
    TISAX is based on the VDA ISA (Information Security Assessment) catalog, which builds on ISO 27001 with automotive-specific requirements. ISO 27001 certified organizations have a strong head start.
  </Accordion>

  <Accordion title="How long is a TISAX label valid?" icon="clock">
    TISAX labels are valid for 3 years. After expiration, a new assessment is required.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**368** of DSALTA's automated checks contribute evidence to this framework, drawn from **73** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [ISO 27001](/frameworks/iso27001/overview)
* [Active Frameworks](/guides/compliance/frameworks-active)
