TISAX assessments without the six-month evidence hunt.
TISAX is how the automotive industry decides whether you are allowed to hold an OEM's prototype data. The VDA ISA catalogue is demanding, the assessment level is set by your data, and the evidence is operational. Lojycal keeps it collected between assessments instead of reconstructing it before each one.
What TISAX actually demands
TISAX is an assessment and exchange mechanism built on the VDA ISA catalogue. Four realities shape the work.
Your assessment level follows your data
AL2 for most information-security scopes, AL3 where prototype protection or very high protection needs apply — AL3 means on-site verification, not a plausibility check.
Maturity levels, not yes/no answers
Each ISA control is scored 0–5. Target maturity is 3 ('established'), which requires documented, operated, and evidenced process — not intent.
Prototype and third-party modules
Scopes involving prototype parts or vehicles add physical and organisational controls beyond the information-security catalogue.
Labels expire
TISAX labels run three years. Estates drift far faster, so the next assessment finds whatever decayed in between.
The Lojycal TISAX engine
ISA controls are scored from the operational systems that actually implement them.
ISA control maturity
Each mapped control carries a maturity score, an owner, and the live evidence behind it — so the self-assessment matches what an auditor will find.
Policy Lab → TISAX
Scope and asset boundary
Which sites, systems, and devices are in scope, kept current from asset and identity data rather than a diagram drawn last year.
Asset Lifecycle + Infrastructure Governance
Supplier and connection controls
Third-party access, data-exchange paths, and connected suppliers tracked with their own attestation state.
Vendor Governance + Application Library
Assessment evidence pack
Signed export per ISA chapter with the underlying records, ready to hand to the audit provider.
Trust Center → Evidence Pack
VDA ISA chapters → Lojycal controls
A sampled view of where the evidence originates:
| ISA chapter | Example control | Lojycal source |
|---|---|---|
| 1 — IS policies and organisation | Information security policy and responsibilities | Policy Lab |
| 2 — Human resources | Joiner/mover/leaver and awareness | HR Automation |
| 3 — Physical security | Site and asset protection | Asset Lifecycle (partial) |
| 4 — Identity and access | Access rights and privileged accounts | RBAC + Access Reviews |
| 5 — IT security / cyber | Endpoint protection, patching, logging | Endpoint Governance + Patch Lab |
| 6 — Supplier relationships | Third-party assessment and monitoring | Vendor Governance |
| 7 — Compliance | Evidence retention and internal review | WORM Audit Log |
| Prototype protection | Access to prototype areas and data | Manual + Asset scoping |
Sampled — Lojycal maps a subset of the catalogue's controls, weighted towards those provable from live data. Physical and prototype controls remain largely manual and the export labels them as such.
Evidence your audit provider can check
TISAX assessments turn on whether the maturity you claimed is visible in operation.
Lojycal writes control operation to a WORM audit log continuously, so the maturity score has a history behind it rather than a screenshot taken the week before. The signed evidence pack bundles ISA chapters with their records and a detached signature the audit provider can verify independently.
From scope to label
The long pole in TISAX is evidence collection. That part becomes continuous.
- Week 1–2
Scope
Fix the assessment scope and level, and map in-scope sites, systems, and suppliers from live data.
- Week 3–8
Self-assessment
Score the ISA catalogue honestly against evidence, with owners on every gap.
- Week 9–16
Remediate
Close gaps to maturity 3 and let the audit log build the operating history.
- Week 17+
Assess
Hand the signed evidence pack to your audit provider and run the assessment.
TISAX questions
Is TISAX the same as ISO 27001?
No, though they overlap substantially. TISAX assesses against the VDA ISA catalogue, is scored by maturity level, and produces a shareable label on the ENX exchange rather than a certificate. Organisations with ISO 27001 typically have most of the base controls but still need the automotive-specific and prototype elements.
Which assessment level do we need?
Your customer's requirement decides it, driven by the protection needs of the data you handle. AL2 covers most information-security scopes with a plausibility-checked remote assessment; AL3 adds on-site verification and applies to high protection needs and prototype scopes.
Does Lojycal cover prototype protection?
Only partially, and we say so plainly. Prototype protection is heavily physical — secured areas, vehicle handling, photography controls. Lojycal covers the asset scoping and access-control side and marks the physical controls as manual evidence in the export.
What happens between assessments?
That gap is where labels quietly become inaccurate. Lojycal keeps scoring the mapped controls continuously and raises drift when a control that was at maturity 3 stops operating, so the next assessment holds no surprises.
Where do I switch it on?
Policy Lab → Available frameworks (off) → Enable on the TISAX card. It appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.
Keep the label. Skip the scramble.
ISA controls, scored continuously from the estate you run, with signed evidence for your audit provider.
