Africa and the market

Getting ready for TISAX when your customer requires it

For many automotive suppliers a TISAX label is a condition of trade. What a readiness baseline found, and why the gap is usually between a control being designed and a control being switched on.

In short
  • Only an ENX-accredited audit provider can carry out a TISAX assessment. A readiness partner's job is to get you ready for it.
  • Prepare against the catalogue your assessment will use: VDA ISA 6 for assessments ordered in 2026, ISA2027 from 2027.
  • Most gaps in a young environment are controls that were designed and never switched on.

Information security is no longer a question on a tender form for suppliers to the German motor industry. The carmakers and many of their tier-one suppliers require a TISAX label, and a supplier without one eventually stops being a supplier. That puts a hard date on work that has often been treated as optional.

We recently ran a baseline security assessment for a manufacturer preparing for its first TISAX assessment. The environment had been built quickly, and in several respects built well.

Who does what

TISAX is run by the ENX Association. Assessments are carried out only by ENX-accredited audit providers, and labels are issued through ENX. A readiness partner is not the auditor, and a proposal that blurs that line is promising something it cannot deliver. Our role was to establish where the environment stood, show what would need to change and prepare the evidence the auditor will ask for.

Two terms cause most of the early confusion. The assessment level describes how deeply the auditor checks. The labels describe what is checked, such as confidential information, availability or prototype protection. Both have to be settled before anyone can size the work.

The catalogue has a version

TISAX assessments are made against the VDA Information Security Assessment catalogue. Assessments ordered in 2026 use version 6, and the target for each relevant control is maturity level 3, which is broadly a control that is documented, implemented and consistently applied. A new catalogue, VDA ISA2027, was published in July 2026 and applies to assessments ordered from January 2027. Preparing against the wrong version wastes months.

Designed, and not yet on

The pattern that ran through the findings was the gap between a control being designed and a control being enforced. Network segmentation had been designed sensibly and was only partly enforced. Device compliance and encryption policies were planned and not yet in force, and privileged accounts were few, as they should be, but not yet fully protected.

Most of the work is finishing what already exists, and several of the highest-value fixes were configuration changes measured in hours. The strengths were real too: multi-factor authentication and a block on legacy sign-in were enforced across the tenant, email authentication was in place, and an external scan found nothing reachable from the internet on the company's own edge.

Unverified means open

We applied one rule throughout. A control we could not verify from evidence was rated as open and labelled unverified, with a note of exactly what would close it. A readiness report full of green that nobody checked is worse than no report once the real auditor arrives.

We also said plainly that a clean baseline does not predict the assessment. Governance, people, physical security, continuity and supplier controls are assessed too, and they were the next phase of the work.

Before you price the work

Confirm which labels apply, and prepare against the catalogue version your assessment will use. Expect the largest gaps to be in tools you have already bought and not yet switched on. Penetration testing is not mandatory for the label at the common assessment level, although the catalogue recommends it where protection needs are high, and a vulnerability assessment with a configuration review usually provides the evidence required.

Our cyber security practice runs this work from baseline to readiness.

Sources
Keep reading

More from Insights

Africa and the market

What two bases bring to an initiative anywhere in Africa

Companies with one foot in Mauritius and one in South Africa get described as having two offices. The useful description is what each base does for an initiative in another African country, and what the partner on the ground gets back.

23 September 2026 · 6 min read
Data and decisions

Measuring personal growth honestly

Wellbeing products are full of impressive numbers. Most of them measure how people feel about themselves. That is worth measuring, as long as everyone is clear that it is what is being measured.

2 September 2026 · 3 min read