The Assessment Level Your Customer Actually Asked For

The Assessment Level Your Customer Actually Asked For

The Assessment Level Your Customer Actually Asked For

VDA ISA gap analysis, the right assessment objectives and modules, and the evidence set your assessment provider will ask to see — before you book them.

VDA ISA gap analysis, the right assessment objectives and modules, and the evidence set your assessment provider will ask to see — before you book them.

Aligned with the VDA ISA Catalogue

Aligned with the VDA ISA Catalogue

A prototype vehicle under a cover in a dark hall under a single spotlight

TISAX Readiness

Problem

No Label, No Contract

No Label, No Contract

For automotive suppliers the request arrives the same way every time: a customer names a label, a date, and a contract that depends on both. What the request rarely explains is which assessment objectives are actually required — and that decision drives the entire scope.

So companies book the assessment first and find out afterwards. An incomplete result means remediation under time pressure, a re-assessment fee, and a delayed contract.

Solution

Ready Before You Book the Assessment

Ready Before You Book the Assessment

We start from your customer’s actual requirement and translate it into scope: which assessment objectives, which locations, and which modules — information security, prototype protection, data protection — genuinely apply.

Then we run the gap analysis against the VDA ISA catalogue, close what’s missing, and assemble the evidence set before the accredited assessment provider arrives. We stay independent of that provider, so the preparation and the assessment remain properly separated.

Agenda

How It Works

How It Works

01

Label & Scope Determination

  • Read your customer’s requirement and translate it into assessment objectives.

  • Determine the modules that apply — and the ones that don’t.

  • Define locations and scope boundaries before they cost you money.

  • Registration guidance for the ENX portal.

01

Label & Scope Determination

  • Read your customer’s requirement and translate it into assessment objectives.

  • Determine the modules that apply — and the ones that don’t.

  • Define locations and scope boundaries before they cost you money.

  • Registration guidance for the ENX portal.

02

VDA ISA Gap Analysis

  • Full gap analysis against the current VDA ISA catalogue.

  • Maturity levels assessed per control, the way the assessor will.

  • Existing ISO 27001 work credited rather than repeated.

  • Findings separated into control gaps and evidence gaps.

02

VDA ISA Gap Analysis

  • Full gap analysis against the current VDA ISA catalogue.

  • Maturity levels assessed per control, the way the assessor will.

  • Existing ISO 27001 work credited rather than repeated.

  • Findings separated into control gaps and evidence gaps.

03

Remediation & Evidence Build

  • Remediation prioritised by what would fail the assessment.

  • Evidence collected and organised per control.

  • Prototype protection measures where the objectives require them.

  • Physical and organisational controls, not just documentation.

03

Remediation & Evidence Build

  • Remediation prioritised by what would fail the assessment.

  • Evidence collected and organised per control.

  • Prototype protection measures where the objectives require them.

  • Physical and organisational controls, not just documentation.

04

Assessment Preparation

  • Dry run in the assessor’s format, including interviews.

  • Evidence pack organised the way the provider will request it.

  • Your people prepared for the questions they will be asked.

  • Support during the assessment itself if you want us there.

04

Assessment Preparation

  • Dry run in the assessor’s format, including interviews.

  • Evidence pack organised the way the provider will request it.

  • Your people prepared for the questions they will be asked.

  • Support during the assessment itself if you want us there.

4

Assessment Preparation

  • Dry run in the assessor’s format, including interviews.

  • Evidence pack organised the way the provider will request it.

  • Your people prepared for the questions they will be asked.

  • Support during the assessment itself if you want us there.

Execution

One Attempt, Not Two

One Attempt, Not Two

The point of this engagement is that the assessment is uneventful. We prepare you; an ENX-accredited provider assesses you; those two roles stay separate.

You receive:

  • Scope determination with assessment objectives and modules.

  • VDA ISA gap report with maturity levels per control.

  • Remediation plan prioritised against the assessment.

  • Evidence pack organised per control.

Target Audience

Ideal For:

Ideal For:

  • Automotive suppliers: tier 1, tier 2 and below, facing a customer requirement.

  • Engineering and development partners: handling prototypes or pre-series data.

  • Companies with ISO 27001: who want to reuse it rather than start over.

  • Anyone who failed once: and cannot afford a second incomplete result.

ROI & Business Impact

Why Invest in This?

Pass First Time

A re-assessment costs the fee twice and delays the contract that triggered it. Preparation is the cheaper half.

Contract Access

For automotive suppliers the label is a precondition, not a differentiator. Without it you are not in the conversation.

Reuse Your ISO Work

Much of the information security module maps onto ISO 27001. If you have it, you are further along than you think.

Pricing

Scoped Around Your Team.

Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.

TISAX Readiness

Scope determination, VDA ISA gap analysis and evidence preparation

  • Format: on-site and remote sessions, per location in scope.

  • Duration: typically two to four months to assessment-readiness.

  • Scope: scope determination, VDA ISA gap analysis, evidence build.

  • Deliverables: gap report, remediation plan, evidence pack, dry run.

  • Note: assessment provider fees are billed separately by ENX-accredited providers.

TISAX Readiness

Scope determination, VDA ISA gap analysis and evidence preparation

  • Format: on-site and remote sessions, per location in scope.

  • Duration: typically two to four months to assessment-readiness.

  • Scope: scope determination, VDA ISA gap analysis, evidence build.

  • Deliverables: gap report, remediation plan, evidence pack, dry run.

  • Note: assessment provider fees are billed separately by ENX-accredited providers.

TISAX Readiness

Scope determination, VDA ISA gap analysis and evidence preparation

  • Format: on-site and remote sessions, per location in scope.

  • Duration: typically two to four months to assessment-readiness.

  • Scope: scope determination, VDA ISA gap analysis, evidence build.

  • Deliverables: gap report, remediation plan, evidence pack, dry run.

  • Note: assessment provider fees are billed separately by ENX-accredited providers.

FAQ

Common Questions

Do you perform the assessment?
Which assessment level do we need?
We already have ISO 27001. How much carries over?
Do we need prototype protection?

That's not all

Continue the Journey

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.