
TISAX Readiness
Problem
For automotive suppliers the request arrives the same way every time: a customer names a label, a date, and a contract that depends on both. What the request rarely explains is which assessment objectives are actually required — and that decision drives the entire scope.
So companies book the assessment first and find out afterwards. An incomplete result means remediation under time pressure, a re-assessment fee, and a delayed contract.
Solution
We start from your customer’s actual requirement and translate it into scope: which assessment objectives, which locations, and which modules — information security, prototype protection, data protection — genuinely apply.
Then we run the gap analysis against the VDA ISA catalogue, close what’s missing, and assemble the evidence set before the accredited assessment provider arrives. We stay independent of that provider, so the preparation and the assessment remain properly separated.
Agenda
Execution
The point of this engagement is that the assessment is uneventful. We prepare you; an ENX-accredited provider assesses you; those two roles stay separate.
You receive:
Scope determination with assessment objectives and modules.
VDA ISA gap report with maturity levels per control.
Remediation plan prioritised against the assessment.
Evidence pack organised per control.


Target Audience
Automotive suppliers: tier 1, tier 2 and below, facing a customer requirement.
Engineering and development partners: handling prototypes or pre-series data.
Companies with ISO 27001: who want to reuse it rather than start over.
Anyone who failed once: and cannot afford a second incomplete result.
ROI & Business Impact
Why Invest in This?
Pass First Time
A re-assessment costs the fee twice and delays the contract that triggered it. Preparation is the cheaper half.
Contract Access
For automotive suppliers the label is a precondition, not a differentiator. Without it you are not in the conversation.
Reuse Your ISO Work
Much of the information security module maps onto ISO 27001. If you have it, you are further along than you think.
Pricing
Scoped Around Your Team.
Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.
FAQ
Common Questions
Do you perform the assessment?
Which assessment level do we need?
We already have ISO 27001. How much carries over?
Do we need prototype protection?
That's not all









