[{"data":1,"prerenderedAt":289},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-tisax":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":64,"entities":239,"extension":243,"faq":244,"keywords":263,"meta":266,"navigation":267,"ogImage":268,"path":63,"persona":269,"publishedAt":268,"regulation":270,"relatedFeatures":271,"relatedPages":274,"seo":276,"shortTitle":62,"slug":270,"sources":277,"stem":285,"tldr":286,"updatedAt":287,"__hash__":288},"regulations_en\u002Fen\u002Fregulations\u002Ftisax.md","TISAX: AL1-AL3 Assessment Levels and the VDA ISA Catalogue | CISAPP","CISAPP",{"type":108,"value":109,"toc":232},"minimark",[110,115,123,142,146,218,222,225],[111,112,114],"h2",{"id":113},"what-does-tisax-cover-for-an-automotive-supplier","What does TISAX cover for an automotive supplier?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"As soon as an automotive customer requires access to sensitive information — development data, prototypes, project-related personal data — it typically requires a TISAX label at a given assessment level."," The standard relies on the VDA ISA catalogue and is operated by the ENX Association, which accredits assessment providers and runs the platform used to exchange results between suppliers and customers.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,139],"ul",{},[130,131,132],"li",{},"VDA ISA catalogue: information security controls, structurally close to ISO 27001, tailored to automotive risks.",[130,134,135],{},"Three assessment levels (AL1, AL2, AL3), from lightest to most demanding.",[130,137,138],{},"Optional labels: prototype protection, high data protection.",[130,140,141],{},"Label validity: three years, provided findings are remediated.",[111,143,145],{"id":144},"which-assessment-level-for-which-requirement","Which assessment level, for which requirement?",[147,148,150],"comparison-table",{"caption":149},"TISAX assessment levels",[151,152,153,172],"table",{},[154,155,156],"thead",{},[157,158,159,163,166,169],"tr",{},[160,161,162],"th",{},"Level",[160,164,165],{},"Method",[160,167,168],{},"Scope",[160,170,171],{},"Typical use",[173,174,175,190,204],"tbody",{},[157,176,177,181,184,187],{},[178,179,180],"td",{},"AL1",[178,182,183],{},"Self-assessment, no external verification",[178,185,186],{},"Declarative",[178,188,189],{},"Rarely sufficient for a demanding customer",[157,191,192,195,198,201],{},[178,193,194],{},"AL2",[178,196,197],{},"Remote document review by an accredited provider",[178,199,200],{},"Documentary evidence review",[178,202,203],{},"Standard sensitive information",[157,205,206,209,212,215],{},[178,207,208],{},"AL3",[178,210,211],{},"Full on-site audit (interviews, technical checks)",[178,213,214],{},"In-depth on-site verification",[178,216,217],{},"Highly sensitive information, prototypes, high data protection",[111,219,221],{"id":220},"how-cisapp-links-tisax-to-your-existing-compliance","How CISAPP links TISAX to your existing compliance",[116,223,224],{},"CISAPP's multi-framework compliance module maps every VDA ISA control to evidence already collected for ISO 27001 or GDPR, avoiding repeated requests for the same information from internal teams or suppliers. Findings identified during a preparatory self-assessment are tracked in the evidence register through to closure, ahead of the official assessment by an accredited provider.",[116,226,227,228,231],{},"See also the ",[229,230,50],"a",{"href":51}," page.",{"title":233,"searchDepth":234,"depth":234,"links":235},"",2,[236,237,238],{"id":113,"depth":234,"text":114},{"id":144,"depth":234,"text":145},{"id":220,"depth":234,"text":221},[240,241,242],"VDA ISA","ENX Association","TISAX label","md",[245,248,251,254,257,260],{"q":246,"a":247},"What is TISAX?","TISAX is an information security assessment exchange standard specific to the automotive industry. It relies on the VDA ISA control catalogue, published by the German automotive industry association (VDA), and is operated by the ENX Association, which accredits assessment providers and runs the platform used to share results.",{"q":249,"a":250},"What are the TISAX assessment levels?","There are three levels. AL1 is a self-assessment with no external verification, generally insufficient for a demanding customer. AL2 adds a remote document review by an accredited assessment provider. AL3 requires a full on-site audit, including interviews and technical checks. The required level is set by the customer requesting the label, based on the sensitivity of the information exchanged.",{"q":252,"a":253},"How does TISAX differ from ISO 27001?","TISAX is not an ISO certification but a sector-specific automotive standard, with a control catalogue (VDA ISA) broadly compatible with ISO 27001's structure but focused on risks specific to the automotive supply chain: protection of development data, prototypes and highly sensitive information exchanged with manufacturers. An existing ISO 27001 certification eases a TISAX assessment but does not replace it.",{"q":255,"a":256},"Who needs a TISAX label?","Any automotive supplier or subcontractor that a manufacturer or tier-1 supplier contractually requires to hold TISAX in order to access sensitive information: development data, prototypes, technical drawings, or personal data handled in automotive projects.",{"q":258,"a":259},"How long is a TISAX label valid?","The label is valid for three years from the completion of the assessment, provided any findings are remediated within the required timeframe. The supplier must then renew the assessment to keep the label active on the ENX platform.",{"q":261,"a":262},"Does CISAPP help prepare for a TISAX assessment?","Yes. CISAPP's multi-framework compliance module reuses evidence already collected for ISO 27001 or GDPR against the VDA ISA control catalogue, and the evidence register tracks findings through to closure ahead of the assessment.",[62,240,241,264,242,265],"TISAX assessment level","automotive information security",{},true,null,"fournisseur","tisax",[272,273],"Multi-framework compliance","Evidence register",[275],"iso-27001",{"title":105,"description":64},[278,281],{"label":279,"url":280,"publisher":241},"TISAX — official overview","https:\u002F\u002Fwww.enx.com\u002Fen-US\u002FTISAX\u002F",{"label":282,"url":283,"publisher":284},"VDA ISA — assessment catalogue","https:\u002F\u002Fvda-qmc.de\u002Fen\u002Faudits\u002Finformation-security-assessment\u002F","VDA QMC","en\u002Fregulations\u002Ftisax","TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's information security assessment standard, operated by the ENX Association on the basis of the VDA ISA catalogue. It defines three assessment levels (AL1: self-assessment, AL2: remote document review, AL3: on-site audit) and optional labels (prototype protection, high data protection). A TISAX label is valid for three years and shareable through the ENX platform with customers who require it contractually.","2026-08-28","MDMVcBfmvIn7aFql9gzdKHjbabrjK1aa5x3IrgAE1pY",1791391138809]