Automotive Information Security

TISAX Assessment (Level 2 & Level 3) Consulting

Guiding automotive suppliers, engineering partners, and manufacturers to achieve recognized TISAX labels under the VDA ISA framework — across Assessment Level 2 (AL2) and Assessment Level 3 (AL3).

Automotive Industry Security Standard (ENX & VDA ISA)

TISAX (Trusted Information Security Assessment Exchange) is governed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). It establishes a standardized cybersecurity and information security baseline recognized by all major automotive manufacturers (Audi, BMW, Porsche, Volkswagen, Daimler/Mercedes-Benz).

StaticGlobal provides end-to-end consulting, VDA ISA catalog gap assessments, prototype facility physical hardening, policy creation, and full audit facilitation with accredited audit providers (TÜV SÜD, DEKRA, DQS).

Core TISAX Assessment Modules

  • Information Security (VDA ISA): Comprehensive ISMS controls aligned with ISO/IEC 27001 with automotive-specific supply chain security.
  • Prototype Protection (Vehicles & Components): Physical security, access controls, test track confidentiality, and camouflaged part handling.
  • Third-Party Connection Security: Dedicated network segmentation, secure remote access, and encrypted CAD/engineering file exchanges.
  • Data Protection & Privacy (GDPR): Protecting test driver telemetry, customer data, and connected vehicle personal data.

Achieve Your TISAX Label

Meet OEM contractual cybersecurity prerequisites and share your audit results seamlessly on the ENX portal.

Start TISAX Gap Audit

TISAX Assessment Level 2 (AL2) vs Level 3 (AL3)

Tailored assessment preparation based on your protection requirements and OEM data classification.

TISAX Assessment Level 2 (AL2)

High Protection Need

Designed for suppliers handling confidential data, standard CAD models, and tier supplier communications.

  • Plausibility check of documentation and self-assessments
  • Interviews conducted via remote web-conference and evidence sampling
  • Valid for standard Tier-1/Tier-2 supply chain engagements

TISAX Assessment Level 3 (AL3)

Very High Protection Need (Strict OEM Mandate)

Required for suppliers handling secret prototype parts, test vehicles, camouflaged hardware, and critical telemetry.

  • Full comprehensive verification with mandatory on-site inspection
  • Physical security audit of development centers, labs, and prototype zones
  • Prerequisite for critical prototype development and OEM partnership

Ready for Your TISAX Audit?

Speak with our automotive cybersecurity team to prepare and achieve your TISAX label with zero non-conformities.

Request Consultation