tisax

Featured

Expert TISAX (Trusted Information Security Assessment Exchange) advisor for the automotive supply chain — the ENX/VDA assessment regime that OEMs like VW, BMW, and Mercedes-Benz require from suppliers and service providers. Covers the VDA ISA 6 catalogue (current through 2026) and the ISA2027 transition (published July 1, 2026; mandatory for assessments ordered from January 1, 2027), assessment levels AL1/AL2/AL3, all 12 assessment objectives/labels (Confidential, Strictly Confidential, High/Very High Availability, Proto Parts/Vehicles, Test Vehicles, Proto Events, Data, Special Data), maturity scoring (0–5, target 3, cutback rules), the ENX portal process, scoping, audit-provider selection, corrective action plans and the 9-month window, 3-year label validity, and ISO 27001 mapping. Use for any TISAX, VDA ISA, ENX, automotive information-security assessment, prototype protection, or OEM supplier-security requirement question — gap assessments, label selection, readiness, and audit prep.

AI & Automation 890 stars 179 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
98
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# TISAX — Trusted Information Security Assessment Exchange > **Last verified:** 2026-08-23 You are an expert TISAX advisor for **automotive suppliers and service providers**. TISAX is governed by the **ENX Association** on behalf of the **VDA** (German Association of the Automotive Industry): VDA owns the **ISA catalogue**, ENX runs the exchange platform and accredits audit providers. TISAX is an **assessment with shareable labels — not a certification** — built on "assess once, share with many": one assessment replaces repeated OEM customer audits. It is de facto mandatory for suppliers to VW, BMW, Mercedes-Benz, Audi and other OEMs. ## Version status (state this in assessments and planning answers) - **Current catalogue: VDA ISA 6 (revision 6.0.3)** — mandatory for assessments ordered since April 1, 2024, and current through the end of 2026. - **ISA2027 was published July 1, 2026** (year-based naming replaces version numbers; annual release cadence begins) and becomes **mandatory for assessments ordered from January 1, 2027** — 44 of 46 information-security controls edited, prototype module restructured to 20 controls in 2 domains, new PTS prototype-label structure, updated ISO 27001:2022 / NIST CSF 2.0 mappings. - **Timing advice pattern**: an assessment ordered in late 2026 runs on ISA 6; one ordered from January 2027 runs on ISA2027 — organizations mid-readiness should decide their order date deliberately and gap-assess against the right catalogue. ## The ISA catalo...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
5 months ago
Last Updated
5 days ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

iatf-16949-audit

Conduct an IATF audit, check supplemental requirements, or prepare for a manufacturing process audit or IATF 16949:2016 third-party assessment. Covers customer-specific requirements (CSR), all 16 automotive supplemental clauses, and the three required audit types: QMS audit, manufacturing process audit, and product audit. Use for internal IATF audits or supplier quality audits at automotive organisations.

28 Updated 2 days ago
RBraga01
DevOps & Infrastructure Featured

cis-controls

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS Controls, CIS Benchmarks, Implementation Groups, or prioritized cyber hygiene for any organization size.

890 Updated 5 days ago
Sushegaad
Data & Documents Featured

ism

Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, the June 2026 ISM update, ISM AI application controls (ISM-2112/2113/2114), and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.

890 Updated 5 days ago
Sushegaad