ITVC GLOBAL · BUSINESS SERVICES
ENX Association governs TISAX. It approves audit providers, monitors the quality of assessments and their results, and maintains the TISAX ACAR criteria framework. The TISAX Committee supports governance of the scheme.
ENX Association maintains the TISAX ACAR framework, approves audit providers and monitors assessment quality.
Audit providers are organisations approved by ENX Association to conduct assessments and supply the assessed participant with its assessment results.
Participants are companies registered in TISAX. They can commission assessments and exchange results with other participants.
The TISAX Participant Handbook explains the scheme, the organisations involved and the steps needed to complete an assessment and share its results with business partners.
Some participants require many suppliers to demonstrate that their information security management systems meet defined requirements. Managing numerous assessment results can be demanding, so they use managed service providers for support. Some providers work behind the scenes; others handle supplier communications directly. Your business partner or its provider will explain the arrangements and any specific requirements.
The TISAX Committee is an advisory body that supports openness, transparency, stakeholder oversight and implementation of TISAX through ENX Association. Its roles include:
Participant registration requires:
Assessment-scope registration requires:
A company becomes a TISAX participant by registering. Only registered participants can exchange assessment results through TISAX. Participants can commission an ENX-approved audit provider, share their results with other participants and receive results that other participants authorise them to access. Registration is therefore the first step in using the scheme.
Open My Scopes and Assessments in the ENX portal and edit the incomplete scope to continue registration.
Registration fees depend on the locations included in the scope. Consult the current TISAX price list for the applicable registration charges.
To register on a company’s behalf, you must have the necessary authority to accept the General Terms and Conditions for Participation in TISAX for that company.
The scope defines which parts of the organisation the information-security assessment covers. In practical terms, it should include the parts handling classified information from automotive business partners. It tells the audit provider what needs to be assessed.
The scope matters for two reasons:
Specify the intended scope when requesting quotations. Each assessment relates to a particular scope. An organisation with several locations can include them in one scope or register separate scopes; a participant may have more than one scope.
Discuss TISAX consulting and assessment preparation with ITVC
Send your requirements so ITVC can advise on the service scope and provide a suitable quotation.
Send a service request →Missing registration information can be completed in the portal. If billing details such as the charging arrangement or VAT ID cannot be edited, contact ENX Association at +49 69 9866927-77 or email tisax@enx.com .
Use the ENX portal to register the location and review the scope under My Scopes and Assessments . If labels are already valid, agree a scope-extension assessment with your existing audit provider. A scope must contain at least one location; the assessment objectives must cover its locations appropriately.
Review the location and scope in the ENX portal and confirm the applicable change procedure with ENX and your audit provider. Removing a location record must not be assumed to change the coverage of an already completed assessment.
Large organisations with many locations can contact ENX Association about the simplified group assessment process.
See the question “What is a simplified group assessment?” for more information.
For a small organisation with one location, the scope may be straightforward. Larger organisations should consider whether one combined scope or several separate scopes best match their business relationships and operational needs.
A single scope covering all locations can offer these advantages:
It can also have disadvantages:
After successful registration, ENX supplies registration information and access to approved audit-provider contacts. Use your registration or scope excerpt to request quotations and compare the providers’ suitability, availability and proposed assessment costs.
Participant ID: identifies the registered company and the participant with whom results are shared. Several scopes may belong to one participant. The original article estimated three to five days for issuing an ID after approval; confirm actual processing times with ENX.
Scope ID: identifies a particular assessment scope. The original three-to-five-day estimate after approval is indicative, not a guaranteed processing time.
Assessment ID: identifies an individual assessment. A scope can have several assessments over time, depending on the assessment type and validity period.
Assessments use the ISA information-security questionnaire associated with VDA and ENX. The catalogue provides the applicable requirements and self-assessment structure and is available in English and German.
Find the catalogue and version information on the ENX ISA page .
Assessment objectives reflect the protection needs of the information and activities within the scope and guide the applicable requirements and assessment level. Choose at least one objective, in line with your partner’s needs. Several objectives can apply; check the current ENX list when registering.
A label indicates successful assessment against the corresponding objective. Labels are viewed in the ENX portal; they are not a conventional certificate or a label printed in the assessment report.
Temporary labels may be issued when a corrective-action-plan assessment records an overall minor non-conformity result. They can help demonstrate progress while corrective actions are completed, subject to the business partner’s acceptance. Their validity is limited:
A corrective-action-plan assessment is optional. You can proceed directly to a follow-up assessment if you:
Once all corrective actions are complete, request a follow-up assessment.
Discuss TISAX consulting and assessment preparation with ITVC
Call ITVC to discuss your needs and a suitable service approach.
Call for quotation: 0914 564 579The objective states what you intend to demonstrate at the start of the assessment. A corresponding label records a successful outcome. Agree the required objectives with your partner and check the current ENX objective-to-label mapping.
Some higher-level labels cover corresponding lower-level requirements. Check the applicable ENX label hierarchy and scope rather than assuming that every higher-level assessment covers every lower-level objective.
The assessed participant receives its report and results. The audit provider normally submits sections A and B to the ENX platform unless this is declined. Access by other participants depends on the assessed company’s publication or sharing permissions.
For organisations with many locations, a conventional TISAX assessment can require substantial effort. ENX offers a simplified group assessment, or SGA, where the eligibility requirements are met.
SGA is a special process intended for organisations with at least three locations and a mature, centrally managed information security management system. When eligible, it can reduce assessment effort. See the linked ENX SGA document for the detailed conditions. TISAX (EN) .
The original article describes a historical transition arrangement for Volkswagen-specific assessments completed after 2015. Do not treat it as automatic acceptance today; ask ENX and your partner to confirm whether the particular assessment can still be recognised. TISAX registration remains necessary.
Check the scope row under “Scopes and Assessments” in the ENX portal after your audit provider submits the result. ENX indicates that results are usually available five to ten business days after report issue. This is a processing estimate, not a two-week limit on access.
The report records the assessment outcome. Its main sections are:
A. Assessment-related information.
B. Summarised results.
C. Assessment result summary.
D. ISA maturity levels - results worksheet.
E. Detailed assessment results.
The report moves from general information to increasingly detailed findings. Its sections correspond to the levels of information that can be shared with other participants.
The ENX portal enables participants to exchange TISAX assessment results. This is a central part of the scheme: a suitable assessment result can be shared with multiple business partners, reducing the need for repeated assessments of the same scope.
The audit provider uploads report sections A and B. Initially, only the assessed participant can access this information. Use the account created at registration to enter the ENX portal and manage sharing with other participants.
You choose the recipients and level of disclosure. Publishing makes the selected information available across the TISAX community; selective permissions provide information to particular participants. Check the permanence rules before granting access: an authorised disclosure cannot simply be withdrawn as if the recipient had never received it.
Publishing makes the permitted information available to all other TISAX participants. ENX permits publication for a conforming overall result, with the following choices:
These options correspond to the structure of the TISAX assessment report.
Sharing grants a particular business partner access to a specified level of information. You need that partner’s Participant ID; ask the partner if it has not supplied the ID. The available sharing levels follow the report structure.
Publishing provides the selected information to the whole TISAX participant community. Sharing provides selected information to a specific participant. Both can apply to one scope: for example, publish general assessment information without labels to the community while granting one partner a higher level of detail.
ITVC GLOBAL · SERVICE ENQUIRIES
Share your requirements and preferred timing. ITVC will review your enquiry and discuss a suitable service scope.
Call for quotation: 0914 564 579
Ho Chi Minh City: 0859 553 986
Email: itvc.haiphong@itvc-global.com
Head office: 6th Floor, 22 Ly Tu Trong, Hong Bang Ward, Hai Phong, Vietnam.
Copyright © 2014 ICTV. All Rights Reserved.
tư vấn iso, tu van iso, kiểm toán năng lượng, kiem toan nang luong