Standards / Sector schemes
TISAX Automotive information security
Information security assessment exchange used across the automotive supply chain.
Core documents AMS builds
- VDA ISA self-assessment
- Prototype protection controls
- Information security policies
- Assessment evidence
Drafted from your actual processes and systems, then kept under version control with review dates.
The path to TISAX
Six steps from first conversation to TISAX. AMS and our consultants handle each one with you.
- 1Scope
Define which sites, teams, processes and systems TISAX will cover.
- 2Gap assessment
Compare what you do today with every TISAX requirement and list what is missing.
- 3Documents
Write the policies, procedures and records TISAX expects, starting with the vda isa self-assessment.
- 4Implement and collect evidence
Put the processes into daily work and capture proof that they run, on a schedule.
- 5Internal review
Check readiness with an internal audit or self-assessment, and close the findings.
- 6Formal assessment
An authorized assessor reviews your evidence and confirms your level, label or conformance report.
TISAX questions
Planning TISAX? Talk to our team
How long does TISAX implementation take?
Most organizations need about 12–20 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.
What documents does TISAX require?
Core documents usually include: vda isa self-assessment, prototype protection controls, information security policies, assessment evidence. AMS drafts them from your actual processes and keeps them under version control.
Can TISAX be combined with other standards?
Yes. TISAX is often run together with IATF 16949, AS9100, CMMI. AMS maps shared requirements, so one record can count toward several standards.
How does AMS help with TISAX?
AMS runs the full TISAX program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your certification body.