attackless
← Back to services
Automotive supply chain security

TISAX assessment preparation

TISAX (Trusted Information Security Assessment Exchange) is how automotive manufacturers and suppliers share proof of information security maturity across the supply chain. We help you scope the right assessment, close the gaps that would otherwise block a passing result, and walk into the assessment ready — without ever standing in for the independent assessor.

Assessment levels

Three assessment levels, one shared framework

TISAX defines three Assessment Levels — AL1 through AL3 — that scale with how sensitive the information involved is. Your customers, not attackless, decide which level applies to you: a manufacturer handling your prototype data will typically require a higher level than one exchanging routine supplier documents. The right level depends on what your customers require, and often only becomes clear once you know who's asking.

1
AL1
Self-assessment

A plausibility check of your own self-assessment. Lowest bar of the three, typically requested for lower-sensitivity information exchange.

2
AL2
Remote plausibility check

A TISAX-accredited provider reviews your evidence remotely against the applicable VDA ISA requirements. The most common level for standard supplier relationships.

3
AL3
On-site audit

A full on-site audit by the assessment provider. Reserved for the most sensitive data — prototype protection, high-value IP — and the most rigorous of the three.

These levels and their definitions belong to the TISAX standard, administered by the ENX Association — we don't set or alter them. Our job is to help you understand which one your customer requirement points to and get your organization ready for it.

What we help with

Preparation, not the label itself

  • Scope and objective planning. Defining which locations, assets, and information domains fall inside your assessment scope before you commit to a level.
  • Gap review against VDA ISA. Walking your controls against the applicable VDA Information Security Assessment requirements and flagging where reality and documentation diverge.
  • Remediation support. Closing the gaps we find — policy, technical controls, process — in the order that matters most before assessment day.
  • Evidence preparation. Getting the documentation, records, and artifacts your assessor will actually ask to see into a state that holds up under review.

TISAX assessment outcomes are determined by the independent assessment process defined by the ENX Association and delivered through accredited assessment providers — attackless is not an assessor and does not issue TISAX labels. We prepare your organization so the independent assessment reflects the work you've already done, not a scramble on the day.