CÔNG TY TNHH ITVC TOÀN CẦU

Ngôn ngữ: vien

0914 564 579

Giờ làm việc: 08:00–17:00 (Thứ 2–Thứ 7)


TISAX frequently asked questions

ITVC GLOBAL · BUSINESS SERVICES

TISAX frequently asked questions

1. Overview

What is ENX Association’s role in TISAX?

ENX Association governs TISAX. It approves audit providers, monitors the quality of assessments and their results, and maintains the TISAX ACAR criteria framework. The TISAX Committee supports governance of the scheme.

What are the benefits of TISAX?

  • Facilitates the continuation of existing supplier relationships.
  • Supports new business relationships through industry-wide recognition.
  • Makes assessment pricing more transparent.
  • Encourages competition among approved audit providers.
  • Establishes a shared approach to information security in the industry.
  • Enables mutual recognition of assessment results.
  • Can reduce duplicated effort and costs for manufacturers and suppliers.

What are the roles within TISAX?

ENX Association maintains the TISAX ACAR framework, approves audit providers and monitors assessment quality.

Audit providers are organisations approved by ENX Association to conduct assessments and supply the assessed participant with its assessment results.

Participants are companies registered in TISAX. They can commission assessments and exchange results with other participants.

What is the TISAX Participant Handbook?

The TISAX Participant Handbook explains the scheme, the organisations involved and the steps needed to complete an assessment and share its results with business partners.

What is a managed service provider?

Some participants require many suppliers to demonstrate that their information security management systems meet defined requirements. Managing numerous assessment results can be demanding, so they use managed service providers for support. Some providers work behind the scenes; others handle supplier communications directly. Your business partner or its provider will explain the arrangements and any specific requirements.

What is the TISAX Committee?

The TISAX Committee is an advisory body that supports openness, transparency, stakeholder oversight and implementation of TISAX through ENX Association. Its roles include:

  • Acting as an escalation body for disagreements between assessed participants and audit providers, including interpretations of VDA ISA or other applicable catalogues.
  • Deciding on approval of audit providers.
  • Advising ENX Association on the development and implementation of TISAX.

2. Registration

What information is needed for registration?

Participant registration requires:

  • Participant name.
  • Main participant contact.
  • Participant address.

Assessment-scope registration requires:

  • Scope name.
  • Scope type.
  • Assessment objectives.
  • Locations included in the scope.
  • Main scope contact.
  • Additional scope contacts, where applicable.
  • Billing information.

What is a TISAX participant?

A company becomes a TISAX participant by registering. Only registered participants can exchange assessment results through TISAX. Participants can commission an ENX-approved audit provider, share their results with other participants and receive results that other participants authorise them to access. Registration is therefore the first step in using the scheme.

How can I resume an interrupted assessment-scope registration?

Open My Scopes and Assessments in the ENX portal and edit the incomplete scope to continue registration.

How much does TISAX registration cost?

Registration fees depend on the locations included in the scope. Consult the current  TISAX price list for the applicable registration charges. 

Can I register on behalf of another company?

To register on a company’s behalf, you must have the necessary authority to accept the General Terms and Conditions for Participation in TISAX for that company.

What is a TISAX assessment scope?

The scope defines which parts of the organisation the information-security assessment covers. In practical terms, it should include the parts handling classified information from automotive business partners. It tells the audit provider what needs to be assessed.
The scope matters for two reasons:

  • The result can meet your partner’s needs only if the relevant parts of your organisation are included.
  • A clearly defined scope enables audit providers to prepare an appropriate quotation.

Specify the intended scope when requesting quotations. Each assessment relates to a particular scope. An organisation with several locations can include them in one scope or register separate scopes; a participant may have more than one scope.

Discuss TISAX consulting and assessment preparation with ITVC

Send your requirements so ITVC can advise on the service scope and provide a suitable quotation.

Send a service request →

Can I add missing registration information later?

Missing registration information can be completed in the portal. If billing details such as the charging arrangement or VAT ID cannot be edited, contact ENX Association at +49 69 9866927-77 or email tisax@enx.com .

How can I add another location to a scope?

Use the ENX portal to register the location and review the scope under My Scopes and Assessments  . If labels are already valid, agree a scope-extension assessment with your existing audit provider. A scope must contain at least one location; the assessment objectives must cover its locations appropriately.

How can I remove a location from a scope?

Review the location and scope in the ENX portal and confirm the applicable change procedure with ENX and your audit provider. Removing a location record must not be assumed to change the coverage of an already completed assessment.

We have many locations. Must each be added manually?

Large organisations with many locations can contact ENX Association about the simplified group assessment process.
See the question “What is a simplified group assessment?” for more information.

How should we define the assessment scope?

For a small organisation with one location, the scope may be straightforward. Larger organisations should consider whether one combined scope or several separate scopes best match their business relationships and operational needs.

A single scope covering all locations can offer these advantages:

  • One assessment report, result and expiry date.
  • Potentially lower assessment effort where central processes, procedures and resources can be assessed once.

It can also have disadvantages:

  • The result is not complete until every included location has been assessed, which can be inconvenient when results are needed urgently.
  • The overall result depends on all included locations meeting the requirements; a problem at one location can affect the entire scope.

How do I select a TISAX audit provider?

After successful registration, ENX supplies registration information and access to approved audit-provider contacts. Use your registration or scope excerpt to request quotations and compare the providers’ suitability, availability and proposed assessment costs.

How are participants, scopes and assessments identified?

Participant ID: identifies the registered company and the participant with whom results are shared. Several scopes may belong to one participant. The original article estimated three to five days for issuing an ID after approval; confirm actual processing times with ENX.

Scope ID: identifies a particular assessment scope. The original three-to-five-day estimate after approval is indicative, not a guaranteed processing time.

Assessment ID: identifies an individual assessment. A scope can have several assessments over time, depending on the assessment type and validity period.

3. Assessment

What is the assessment based on?

Assessments use the ISA information-security questionnaire associated with VDA and ENX. The catalogue provides the applicable requirements and self-assessment structure and is available in English and German.

Where can I find the latest ISA catalogue?

Find the catalogue and version information on the ENX ISA page .

What is a TISAX assessment objective?

Assessment objectives reflect the protection needs of the information and activities within the scope and guide the applicable requirements and assessment level. Choose at least one objective, in line with your partner’s needs. Several objectives can apply; check the current ENX list when registering.

What is a TISAX label?

A label indicates successful assessment against the corresponding objective. Labels are viewed in the ENX portal; they are not a conventional certificate or a label printed in the assessment report.

What is a temporary TISAX label?

Temporary labels may be issued when a corrective-action-plan assessment records an overall minor non-conformity result. They can help demonstrate progress while corrective actions are completed, subject to the business partner’s acceptance. Their validity is limited:

  • The maximum is nine months after the initial closing meeting; the actual period follows the approved corrective-action deadlines and may be shorter.
  • They are replaced by regular labels after successful follow-up confirms that the non-conformities have been resolved, within the permitted timeframe.
  • They are not renewable.

A corrective-action-plan assessment is optional. You can proceed directly to a follow-up assessment if you:

  • Do not need temporary TISAX labels; and
  • Are confident that you can implement corrective actions without prior approval of the plan by the audit provider.

Once all corrective actions are complete, request a follow-up assessment.

Discuss TISAX consulting and assessment preparation with ITVC

Call ITVC to discuss your needs and a suitable service approach.

Call for quotation: 0914 564 579

How does an assessment objective differ from a TISAX label?

The objective states what you intend to demonstrate at the start of the assessment. A corresponding label records a successful outcome. Agree the required objectives with your partner and check the current ENX objective-to-label mapping.

Can a result meet a lower protection requirement?

Some higher-level labels cover corresponding lower-level requirements. Check the applicable ENX label hierarchy and scope rather than assuming that every higher-level assessment covers every lower-level objective.

Who receives the assessment report and results?

The assessed participant receives its report and results. The audit provider normally submits sections A and B to the ENX platform unless this is declined. Access by other participants depends on the assessed company’s publication or sharing permissions.

What is a simplified group assessment?

For organisations with many locations, a conventional TISAX assessment can require substantial effort. ENX offers a simplified group assessment, or SGA, where the eligibility requirements are met.

SGA is a special process intended for organisations with at least three locations and a mature, centrally managed information security management system. When eligible, it can reduce assessment effort. See the linked ENX SGA document for the detailed conditions. TISAX (EN) .

Can a Volkswagen-specific operational-services assessment be used in TISAX?

The original article describes a historical transition arrangement for Volkswagen-specific assessments completed after 2015. Do not treat it as automatic acceptance today; ask ENX and your partner to confirm whether the particular assessment can still be recognised. TISAX registration remains necessary.

Where can I find my completed assessment results?

Check the scope row under “Scopes and Assessments” in the ENX portal after your audit provider submits the result. ENX indicates that results are usually available five to ten business days after report issue. This is a processing estimate, not a two-week limit on access.

What is a TISAX assessment report?

The report records the assessment outcome. Its main sections are:

A. Assessment-related information.
B. Summarised results.
C. Assessment result summary.
D. ISA maturity levels - results worksheet.
E. Detailed assessment results.

The report moves from general information to increasingly detailed findings. Its sections correspond to the levels of information that can be shared with other participants.

4. Exchange of assessment results

What is the exchange platform?

The ENX portal enables participants to exchange TISAX assessment results. This is a central part of the scheme: a suitable assessment result can be shared with multiple business partners, reducing the need for repeated assessments of the same scope.

Who can access my assessment results?

The audit provider uploads report sections A and B. Initially, only the assessed participant can access this information. Use the account created at registration to enter the ENX portal and manage sharing with other participants.

You choose the recipients and level of disclosure. Publishing makes the selected information available across the TISAX community; selective permissions provide information to particular participants. Check the permanence rules before granting access: an authorised disclosure cannot simply be withdrawn as if the recipient had never received it.

What does publishing an assessment mean?

Publishing makes the permitted information available to all other TISAX participants. ENX permits publication for a conforming overall result, with the following choices:

  • Do not publish - the default.
  • A: Assessment-related information, without labels.
  • A: Assessment-related information plus labels.
  • A: Assessment-related information, labels and B: Summarised results.

These options correspond to the structure of the TISAX assessment report.

What does sharing an assessment mean?

Sharing grants a particular business partner access to a specified level of information. You need that partner’s Participant ID; ask the partner if it has not supplied the ID. The available sharing levels follow the report structure.

What is the difference between publishing and sharing?

Publishing provides the selected information to the whole TISAX participant community. Sharing provides selected information to a specific participant. Both can apply to one scope: for example, publish general assessment information without labels to the community while granting one partner a higher level of detail.

ITVC GLOBAL · SERVICE ENQUIRIES

Discuss TISAX consulting and assessment preparation with ITVC

Share your requirements and preferred timing. ITVC will review your enquiry and discuss a suitable service scope.

Send a service request →

Call for quotation: 0914 564 579
Ho Chi Minh City: 0859 553 986
Email: itvc.haiphong@itvc-global.com

Head office: 6th Floor, 22 Ly Tu Trong, Hong Bang Ward, Hai Phong, Vietnam.

 



Copyright © 2014 ICTV. All Rights Reserved.

tư vấn iso, tu van iso, kiểm toán năng lượng, kiem toan nang luong

0914 564 579