TISAX / VDA ISA

TISAX assessments without the six-month evidence hunt.

TISAX is how the automotive industry decides whether you are allowed to hold an OEM's prototype data. The VDA ISA catalogue is demanding, the assessment level is set by your data, and the evidence is operational. Lojycal keeps it collected between assessments instead of reconstructing it before each one.

What TISAX actually demands

TISAX is an assessment and exchange mechanism built on the VDA ISA catalogue. Four realities shape the work.

  • Your assessment level follows your data

    AL2 for most information-security scopes, AL3 where prototype protection or very high protection needs apply — AL3 means on-site verification, not a plausibility check.

  • Maturity levels, not yes/no answers

    Each ISA control is scored 0–5. Target maturity is 3 ('established'), which requires documented, operated, and evidenced process — not intent.

  • Prototype and third-party modules

    Scopes involving prototype parts or vehicles add physical and organisational controls beyond the information-security catalogue.

  • Labels expire

    TISAX labels run three years. Estates drift far faster, so the next assessment finds whatever decayed in between.

The Lojycal TISAX engine

ISA controls are scored from the operational systems that actually implement them.

ISA control maturity

Each mapped control carries a maturity score, an owner, and the live evidence behind it — so the self-assessment matches what an auditor will find.

Policy Lab → TISAX

Scope and asset boundary

Which sites, systems, and devices are in scope, kept current from asset and identity data rather than a diagram drawn last year.

Asset Lifecycle + Infrastructure Governance

Supplier and connection controls

Third-party access, data-exchange paths, and connected suppliers tracked with their own attestation state.

Vendor Governance + Application Library

Assessment evidence pack

Signed export per ISA chapter with the underlying records, ready to hand to the audit provider.

Trust Center → Evidence Pack

VDA ISA chapters → Lojycal controls

A sampled view of where the evidence originates:

ISA chapterExample controlLojycal source
1 — IS policies and organisationInformation security policy and responsibilitiesPolicy Lab
2 — Human resourcesJoiner/mover/leaver and awarenessHR Automation
3 — Physical securitySite and asset protectionAsset Lifecycle (partial)
4 — Identity and accessAccess rights and privileged accountsRBAC + Access Reviews
5 — IT security / cyberEndpoint protection, patching, loggingEndpoint Governance + Patch Lab
6 — Supplier relationshipsThird-party assessment and monitoringVendor Governance
7 — ComplianceEvidence retention and internal reviewWORM Audit Log
Prototype protectionAccess to prototype areas and dataManual + Asset scoping

Sampled — Lojycal maps a subset of the catalogue's controls, weighted towards those provable from live data. Physical and prototype controls remain largely manual and the export labels them as such.

Evidence your audit provider can check

TISAX assessments turn on whether the maturity you claimed is visible in operation.

Lojycal writes control operation to a WORM audit log continuously, so the maturity score has a history behind it rather than a screenshot taken the week before. The signed evidence pack bundles ISA chapters with their records and a detached signature the audit provider can verify independently.

From scope to label

The long pole in TISAX is evidence collection. That part becomes continuous.

  1. Week 1–2

    Scope

    Fix the assessment scope and level, and map in-scope sites, systems, and suppliers from live data.

  2. Week 3–8

    Self-assessment

    Score the ISA catalogue honestly against evidence, with owners on every gap.

  3. Week 9–16

    Remediate

    Close gaps to maturity 3 and let the audit log build the operating history.

  4. Week 17+

    Assess

    Hand the signed evidence pack to your audit provider and run the assessment.

TISAX questions

Is TISAX the same as ISO 27001?

No, though they overlap substantially. TISAX assesses against the VDA ISA catalogue, is scored by maturity level, and produces a shareable label on the ENX exchange rather than a certificate. Organisations with ISO 27001 typically have most of the base controls but still need the automotive-specific and prototype elements.

Which assessment level do we need?

Your customer's requirement decides it, driven by the protection needs of the data you handle. AL2 covers most information-security scopes with a plausibility-checked remote assessment; AL3 adds on-site verification and applies to high protection needs and prototype scopes.

Does Lojycal cover prototype protection?

Only partially, and we say so plainly. Prototype protection is heavily physical — secured areas, vehicle handling, photography controls. Lojycal covers the asset scoping and access-control side and marks the physical controls as manual evidence in the export.

What happens between assessments?

That gap is where labels quietly become inaccurate. Lojycal keeps scoring the mapped controls continuously and raises drift when a control that was at maturity 3 stops operating, so the next assessment holds no surprises.

Where do I switch it on?

Policy Lab → Available frameworks (off) → Enable on the TISAX card. It appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.

Keep the label. Skip the scramble.

ISA controls, scored continuously from the estate you run, with signed evidence for your audit provider.