How do you systematically prepare for a TISAX audit? We guide you through the entire certification process: gap analysis based on the VDA ISA catalog, preparation for Stage 1 and Stage 2, audit provider selection, and support through to your TISAX label.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










Thorough audit preparation can increase the success rate of achieving the target TISAX label by up to 90% and significantly reduce the time and cost of the certification process.
Years of Experience
Employees
Projects
We follow a proven methodology to prepare you optimally for the TISAX audit and maximize your chances of achieving the target label.
Pre-assessment and readiness evaluation
Gap closure and evidence preparation
Mock audits and team training
Audit accompaniment and support
Labeling and post-audit optimization
"ADVISORI's support in preparing for our TISAX audit was invaluable. The structured approach and expertise ensured we achieved our target label on the first attempt."

Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
We offer you tailored solutions for your digital transformation
Comprehensive evaluation of your TISAX readiness and identification of gaps that need to be closed before the audit.
Professional management of the entire TISAX labeling process from audit preparation to successful label achievement.
Choose the area that fits your requirements
OEMs like BMW, Volkswagen, and Mercedes-Benz require every supplier to hold a valid TISAX label. We guide Tier-1 and Tier-2 suppliers through the entire process: gap analysis per VDA ISA, ISMS setup, and assessment preparation — so your position in the automotive supply chain stays secure.
Where does your organisation stand against TISAX requirements? Our gap analysis systematically evaluates every control objective in the VDA ISA catalogue, determines your current maturity level and delivers a prioritised remediation roadmap for certification.
TISAX audit preparation starts with a gap analysis based on the VDA ISA questionnaire. You assess your current information security posture against TISAX requirements, identify gaps, and create an action plan. Then you implement the required measures, prepare documentation, and conduct an internal self-assessment before the accredited audit provider performs the official assessment.
Assessment Level
2 (AL2) is conducted remotely through document review and plausibility checks via phone or video. Assessment Level
3 (AL3) requires a full on-site audit by the audit provider, typically lasting two to three days. The required level depends on the protection needs of the information processed — Level
3 is mandatory for prototype protection or highly confidential data.
In Stage 1, the auditor reviews your ISMS documentation, policies, risk analyses, and the implementation status of VDA ISA requirements. In Stage 2, the auditor verifies practical implementation on-site: checking whether documented processes are actually followed, conducting employee interviews, and inspecting technical measures such as access controls and data encryption.
The most common major findings in TISAX audits include: incomplete or outdated risk analyses, missing evidence of employee security awareness training, gaps in access and authorization concepts, insufficient documentation of security incidents, and missing emergency plans. Lack of regular ISMS reviews and inadequate prototype protection are also frequently cited.
The audit fees from the accredited provider range from EUR 3,
000 to EUR 15,000, depending on the assessment level and company size. Total costs including preparation, ISMS implementation, and external consulting typically range from EUR 15,
000 to EUR 40,
000 for mid-sized companies. Preparation time ranges from three to twelve months depending on your current maturity level.
A TISAX label is valid for three years. After that, a new assessment by an accredited audit provider is required. It is recommended to plan recertification six to nine months before expiry to allow sufficient time for any remediation. Between audits, the ISMS should be maintained through internal audits and continuous improvement.
If major findings are identified, you receive an action plan with deadlines for remediation. Typically, you have up to nine months to address the findings before a follow-up audit takes place. Minor findings can often be resolved through the regular improvement process. Important: the ENX Association allows a maximum of nine months between registration and successful completion of the assessment.
Discover how we support companies in their digital transformation
Klöckner & Co
Digital Transformation in Steel Trading

Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Festo
Intelligent Networking for Future-Proof Production Systems

Bosch
AI Process Optimization for Improved Production Efficiency

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance